GhostPort
GHOSTPORT
PRIVACY ROUTER // COMMAND DECK
CONNECTING...
UPTIME: --
GET APP
GhostPort
INSTALL GHOSTPORT
Add to your home screen for quick access
CONFIRM MODE SWITCH
Auto-reverting if not confirmed...
60
ISP
Open Waters
Full passthrough. No filtering. Sail free.
PRIVACY LEVEL
👻
Zero Trust
Ghost Cloak
DNS locked to the ship. Tailscale management active.
PRIVACY LEVEL
💀
Double Hop
Dead Man's Route
All LAN traffic through WireGuard. Tailscale stays up for management.
PRIVACY LEVEL
🏴‍☠️
Z-HOP
Davy Jones
Maximum stealth. WireGuard + DNS lockdown. Tailscale management only.
PRIVACY LEVEL
WireGuard
--
wg0
DATA TUNNEL
Tailscale
--
tailscale0
MANAGEMENT
OFF
Pi-hole
UP
DNS filter
ALWAYS ON
⚠ DNS LEAK DETECTED — Your DNS queries are being exposed to your ISP.
🛡 Kill Switch
Blocks all traffic if VPN drops or DNS leaks are detected, preventing your traffic from leaking to your ISP.
Protects you from: DNS leaks and VPN tunnel failures
OFF
Auto-trip on DNS leak
🔒 Encrypted DNS
Routes all DNS queries through Cloudflare's DNS-over-HTTPS (DoH) instead of cleartext. Your ISP can't see what sites you look up.
Protects you from: ISP snooping on your DNS queries and DNS spoofing attacks
OFF
🚫 QUIC Block
Blocks the QUIC protocol (UDP port 443) on all privacy modes. Forces browsers to fall back to standard HTTPS, which ensures Pi-hole DNS filtering can't be bypassed.
Protects you from: Browsers using QUIC to bypass DNS-based ad blocking and privacy filters
BLOCKING
🔍 DNS Leak Test
Checks if your DNS queries are leaking outside your VPN tunnel by comparing what resolver Cloudflare sees for local vs direct requests.
Protects you from: Unknowingly exposing your browsing to your ISP while on VPN
🎲 MAC Randomization
Generates a random MAC address for the WiFi AP on each reboot. Uses locally-administered (02:xx) prefix. Takes effect on next reboot.
Protects you from: Device fingerprinting and network tracking across locations
OFF
🖥️ Terminal Mode
Boots the Pi into a CLI-only terminal instead of the graphical desktop. Frees up RAM and CPU for routing. Takes effect on next reboot.
Benefit: Reduced attack surface and lower resource usage — ideal for headless operation
OFF
📋 Blocklist Manager
Controls how often Pi-hole updates its ad/tracker blocklists. Daily catches new threats faster; weekly is lighter on resources.
Protects you from: Ads, trackers, and malicious domains across all devices on your network
Block or Allow a Domain
📡 Connected Clients 0 devices
Shows all devices currently connected to GhostPort's WiFi network via DHCP.
Loading...
Scheduled Modes
Automatically switch security modes on a schedule. For example, switch to Z-HOP every night and back to ISP in the morning.
Speed Test
Measures download/upload speed and latency through your current tunnel. Shows the real-world performance impact of your privacy mode.
📡 Ping Test
Checks latency to your gateway, local DNS, and the internet. Helps pinpoint where connectivity issues are happening.
🌐 IP Leak Test
Checks if your real IP address is leaking outside the VPN tunnel by comparing your public IP against the WireGuard endpoint.
Protects you from: VPN misconfigurations that expose your real IP address
🛡 Security Scan
Full system security audit powered by Lynis. Checks firewall, SSH, permissions, kernel hardening, authentication, and 200+ security controls.
Scans for: Misconfigurations, weak permissions, missing hardening, vulnerable services, authentication weaknesses
🚷 Recent Blocked Domains
💾 Backup / Restore
Export your GhostPort settings or restore from a previous backup.
🔄 System Update
Runs apt update & upgrade to install the latest system and security patches. This may take several minutes.
COMING SOON
🧅Tor Mode
Route all traffic through Tor for anonymous browsing
COMING SOON
🔗Multi-VPN Chaining
Chain multiple VPN servers so no single provider sees the full picture
COMING SOON
📦IoT VLAN Isolation
Put smart devices on a separate network away from your computers
COMING SOON
🔬Suricata IDS
Watch for suspicious network patterns like malware beacons
COMING SOON
📊Traffic Padding
Add dummy traffic to hide your real browsing patterns
COMING SOON
📶Guest Network
A separate WiFi for visitors that can't see your devices
COMING SOON
💾Disk Encryption
Encrypt the router's storage to protect configs if it's stolen
🛡️
Family Shield
PARENTAL CONTROLS
⚠️
Adult Content
ALLOWED
🎰
Gambling
ALLOWED
Meta Apps
FB / IG / WhatsApp
ALLOWED
🎵
TikTok
ALLOWED
𝕏
X
ALLOWED
📡
Shielded Devices
Loading...
🔐 WireGuard Config
---
Set up your VPN tunnel to enable Double Hop & Z-HOP privacy modes.
🔑 Change Passcode
Change the passcode used to access this Command Deck. Leave "new passcode" blank to auto-generate a secure one.
🛡 Pi-hole Password
Change the Pi-hole admin password. This also updates the Command Deck's saved credentials so the connection stays active.
📶 SSID & Password
Change the WiFi network name and password for GhostPort's access point. Devices will need to reconnect after changes.
🎨 Neon Accent
Change the UI accent color. Choice is saved locally.
NEON GREEN
Ads Plundered
---
blocked this session
Current IP
---
---
DNS Resolver
Unbound
recursive / local
Encryption
---
---