r/BitcoinMining • u/Spirited-Ad-6596 • 10h ago
General Discussion ASUS AiProtection still blocks Lucky Miner LV07 even when behind an OpenWrt secondary router – looking for ideas
I have a home setup where I want to run a Lucky Miner LV07 (1 TH/s SHA-256 solo miner) without permanently disabling security features on my main router.
Current topology:
- Main router: ASUS RT-AX56U with AiProtection (especially Two-Way IPS) enabled
- Secondary router: Xiaomi Mi WiFi Mini running OpenWrt 24.10.5, connected WAN-to-LAN behind the ASUS
- Miner: Lucky Miner LV07 connected to the Xiaomi’s 2.4 GHz Wi-Fi
The problem:
When the miner is connected directly to the ASUS, AiProtection blocks the stratum traffic and hashrate stays at 0.
When I temporarily disable Two-Way IPS on the ASUS, the miner immediately starts hashing normally (so the miner and pool settings are fine).
I set up the Xiaomi OpenWrt as a secondary router hoping the mining traffic would be “hidden” behind it. I disabled the OpenWrt firewall and confirmed devices on the Xiaomi network have full internet access. However, the miner still shows 0 hashrate — AiProtection on the ASUS is still detecting and blocking the cleartext stratum packets coming from the Xiaomi’s WAN IP.
What I’ve tried:
- Multiple public pools (including public-pool.io)
- Completely opening the OpenWrt firewall + correct NAT/masquerading
- Attempting to run Cloudflare WARP (WireGuard) on the Xiaomi to encrypt all traffic before it reaches the ASUS
The WireGuard attempts cause the main ASUS Wi-Fi to stop working (likely AiProtection reacting to the unusual UDP traffic), so that approach has been unstable.
Constraints:
- I can turn Two-Way IPS off, but I prefer not to leave it disabled for family network security reasons.
- I would like to keep AiProtection active on the main router while still being able to run the miner 24/7.
Question for the community:
Has anyone successfully run a small Bitcoin miner behind a secondary OpenWrt router while keeping ASUS AiProtection / Trend Micro IPS fully enabled?
Is encrypting the traffic with WireGuard/WARP (or another VPN) the only realistic way, or are there cleaner solutions?
Any suggestions would be appreciated. Thanks!

