Mudi7 Remote · Practical guide

Mudi 7 router VPN: WireGuard, OpenVPN and OpenClash

Understand router VPN profiles, tunnel priorities and how they differ from OpenClash and an iPhone VPN in Mudi7 Remote.

On this page

Mudi7 Remote’s development preview brings router VPN controls into Device → VPN. These configure a compatible GL.iNet Mudi 7; the app does not create a VPN tunnel on your iPhone or supply a VPN subscription.

This guide reflects the completed 1.4 development snapshot. Router VPN status reads have been checked on physical hardware. Importing, connecting and policy changes still need complete physical-router traffic validation, so the preview is not a guarantee of routing, failover or traffic protection.

Three different controls

AreaWhat it does
Device → VPNManages supported WireGuard and OpenVPN profiles, tunnels and router-side policies.
OpenClashControls an existing OpenClash installation, its configured groups and rules.
An iPhone VPNRuns on the phone through a separate VPN app or system configuration. Mudi7 Remote does not create one.

GL.iNet documents its firmware’s profiles, tunnel priority and traffic policies in the official VPN Dashboard guide. Mudi7 Remote exposes a bounded subset, depending on your router’s firmware and capabilities.

Prepare a supported profile

The preview accepts a single-peer WireGuard configuration from a file or QR code, or a self-contained OpenVPN configuration with optional username and password. Have your own provider or server configuration ready. Multi-file archives and VPN provider subscriptions are outside this import workflow.

Importing a profile and connecting a tunnel are separate steps. A newly created tunnel starts disabled. Review its profile and intended traffic policy before choosing to connect. The app saves a local encrypted configuration backup before supported persistent changes; a backup is not a way to reconnect an unreachable router.

Understand priority before changing it

Profile backup order within a group determines which profile the group should try first. Tunnel priority determines which matching tunnel policy takes precedence. They are separate settings.

The preview includes selected-device and manual-destination policies, per-tunnel protection, and an action for other traffic. Read the displayed scope carefully. A protection setting on one tunnel does not by itself establish that all devices and destinations are covered.

OpenClash and router VPN can both affect traffic. The app checks for supported conflicts; review the current state before changing either area. If a response is lost, reconnect and read the router state before repeating the action.

Server and remote-network features

The preview also includes supported WireGuard and OpenVPN server controls, WireGuard peer management and configuration export, and OpenVPN user management. Exported configurations can contain access secrets; share them only with the intended device or person.

Optional Tailscale and ZeroTier controls depend on the router’s installed components and their own accounts. An explicit account step can open the corresponding external service. These features do not turn Mudi7 Remote itself into a controller that works from anywhere: the app still requires local Wi-Fi access to your paired router.

Check what actually works

After any supported change, read the refreshed tunnel state and independently check the intended device’s connectivity and traffic path. A connected label alone is not proof of the intended exit, fallback behavior or traffic protection. Firmware, provider configuration and the network remain part of the result.

For nearby-router setup, start with connecting Mudi 7 to iPhone or iPad. For node groups and connection inspection, use the OpenClash guide. Data handling is described in the privacy policy.

More guides