NEW Self-serve signup is live. Free for 2 machines, forever. ₹349/machine/month after. See pricing →
/ tp-link · archer · wireguard

TP-Link Archer AX23 WireGuard guide

Set up WireGuard on the TP-Link Archer AX23. Budget consumer Wi-Fi 6 with WireGuard for home / small remote office. Firmware floor, throughput, peer limit, exact menu path, and what to do when one Archer AX23 grows into a mesh.

/ Archer AX23 at a glance
FamilyTP-Link Archer
Firmware floor for WireGuardArcher AX23 firmware 1.2.0 or later (late 2022)
WireGuard throughput (single tunnel)~180 Mbps single tunnel
Maximum peers per tunnel10
CPUDual-core 1.5 GHz ARM
Approx Indian retail (2026)~₹6,000
WireGuard menu pathAdvanced → VPN Server → WireGuard

Who the TP-Link Archer AX23 is for

Budget consumer Wi-Fi 6 with WireGuard for home / small remote office. The Archer AX23 sits in TP-Link's Archer family — alongside other models that share the same firmware UI and configuration patterns but differ in CPU, throughput, and peer caps.

Setting up WireGuard on the Archer AX23

The six steps below match what the dashboard's vendor-template picker generates for the Archer AX23:

  1. Confirm firmware. Log in to the admin interface (typically http://192.168.0.1) and verify the installed firmware is Archer AX23 firmware 1.2.0 or later (late 2022) or later. Update via Advanced → System → Firmware Upgrade if needed.
  2. Open the WireGuard page. Navigate to Advanced → VPN Server → WireGuard.
  3. Create a tunnel. Click Add. Generate a keypair. Set Listen Port to 51820. Set Tunnel IP to 10.100.0.1/24 for a hub or 10.100.0.2/32 for a spoke.
  4. Add a peer. Paste the remote public key. Set Allowed IPs to the remote tunnel /32 plus the remote LAN subnet. Set Endpoint Host and Endpoint Port if the remote has a stable public address. Persistent Keepalive: 21 if behind NAT.
  5. Enable and save. Toggle Enable and Save.
  6. Verify. The peer row should show a recent handshake timestamp within seconds of the remote side being configured.

Archer AX23-specific gotchas

  • Lowest-throughput WireGuard in the Archer family that supports it; ~180 Mbps is the ceiling.
  • Fine for 100-150 Mbps fibre uplinks; insufficient for 500 Mbps+.
  • Same UI as AX73 / AX90, just slower CPU.

What changes at multi-branch scale

The Archer AX23 handles 1-5 sites cleanly. Past that, the configuration burden grows quadratically — five sites in a full mesh = ten peer relationships, each configured on both ends. The practical pattern past 3 sites is hub-and-spoke (every branch peers with one central router) plus a managed mesh layer that generates the per-router peer lists. MeshWG generates paste-ready configuration in the exact format the TP-Link UI accepts, including for the Archer AX23 specifically.

Frequently asked questions

Does the TP-Link Archer AX23 support WireGuard?

Yes, on firmware Archer AX23 firmware 1.2.0 or later (late 2022) or later. The Archer AX23 runs on Dual-core 1.5 GHz ARM and achieves ~180 Mbps single tunnel on a single WireGuard tunnel. WireGuard is configured under Advanced → VPN Server → WireGuard in the admin interface, with up to 10 peers per tunnel on current firmware.

How fast is WireGuard on the TP-Link Archer AX23?

~180 Mbps single tunnel single-tunnel on the stock firmware, measured iperf3 over a stable LAN. The Archer AX23's Dual-core 1.5 GHz ARM runs WireGuard without hardware acceleration, so the CPU is the binding constraint. For typical Indian SMB fibre uplinks (100-300 Mbps) the router is well above the WAN limit.

What is the firmware version with WireGuard on the TP-Link Archer AX23?

Firmware Archer AX23 firmware 1.2.0 or later (late 2022) is the minimum that includes WireGuard. Confirm by visiting Advanced → System → Firmware Upgrade in the admin interface; if your installed version is below this floor, update via the same page first. Most Archer AX23 units shipped after the firmware floor date arrive with WireGuard available out of the box.

How do I find WireGuard in the TP-Link Archer AX23 admin UI?

Advanced → VPN Server → WireGuard. If the option isn't visible, the most likely cause is firmware below Archer AX23 firmware 1.2.0 or later (late 2022) — update first, then revisit. On Deco devices specifically, the WireGuard configuration lives in the Deco mobile app, not the web admin.

How many WireGuard peers can the TP-Link Archer AX23 support?

10 peers per tunnel on current firmware. This is the cap on devices connecting into this router as a WireGuard server (or peers this router has configured outbound). For deployments larger than this cap, the practical pattern is hub-and-spoke with a higher-capacity device (Omada ER7206 or ER8411) at HQ.

Can I run WireGuard between the TP-Link Archer AX23 and a different router brand?

Yes. WireGuard is the same protocol on every implementation — your Archer AX23 interoperates with WireGuard on MikroTik, OpenWrt, OPNsense, pfSense, Ubiquiti, Asus, GL.iNet, and the official Linux/Mac/Windows/iOS/Android clients. Configuration is the same set of fields (public key, endpoint, allowed IPs); only the UI for entering them differs per vendor.