I flashed my first WRT54G with DD-WRT v23 in June 2006. Twelve months on, here is what I wish someone had told me at the start.

1. NVRAM is smaller than you think

The WRT54G has 32KB of NVRAM. That sounds like plenty until you start adding custom iptables rules, static DHCP leases, and startup scripts. Check your usage regularly:

# nvram show 2>&1 | tail -1
size: 27341 bytes (5427 bytes free)

When you run out, the router starts behaving unpredictably. Settings disappear, configs revert on reboot. Keep it under 80% and you will be fine.

2. JFFS is your friend

Enable JFFS2 partition under Administration - Management. This gives you a writable filesystem on the flash chip where you can store scripts, cron jobs, and config files without eating into NVRAM. On a WRT54GL with 4MB flash, you get about 700KB of usable JFFS space after the firmware.

3. Cron jobs need the right path

DD-WRT's cron implementation is minimal. Scripts must have full paths and the environment is bare. Always use absolute paths to binaries:

*/5 * * * * /usr/sbin/wl rssi > /tmp/rssi.log 2>&1

If a cron job is not running, check that the script is executable and that you are not relying on environment variables that do not exist in the cron context.

4. Bandwidth monitoring is worth the flash space

DD-WRT's built-in bandwidth monitor (Status - Bandwidth) is useful but resets on reboot. Install the rflow or rstats mod if your build supports it. I run a daily cron job that logs WAN traffic to a file on JFFS:

0 0 * * * cat /proc/net/dev | /usr/bin/grep vlan1 >> /jffs/traffic.log

Not sophisticated, but enough to spot when something on the LAN is hammering the connection.

5. VPN overhead is real

Running OpenVPN on a 200MHz Broadcom MIPS processor is not fast. I measured about 3-4 Mbit/s throughput with Blowfish encryption and roughly 2 Mbit/s with AES-256. If you need more than that, run the VPN endpoint on a proper box and route through it. The WRT54G is brilliant as a router but it simply does not have the CPU for heavy crypto.

6. Do not overclock unless you add a heatsink

DD-WRT lets you overclock the CPU from 200MHz to 250MHz or higher. I tried 240MHz and it ran fine for a week, then started locking up randomly during hot weather. Stuck a small heatsink on the Broadcom chip with thermal adhesive and the lockups stopped. If you overclock, add cooling. It is a 3 quid fix.

7. Back up your NVRAM before changing anything major

# nvram backup /tmp/nvram-backup.bin

Then SCP it off the router. I have bricked a router by fiddling with wireless settings and not being able to get back to a known-good state. The web GUI backup works too, but having the raw NVRAM dump means you can restore even from a TFTP recovery session.

8. Static DHCP leases are better than static IPs

Rather than configuring static IPs on every machine, use DD-WRT's static DHCP lease table (Services - Services - Static Leases). Map MAC addresses to fixed IPs. This way your firewall rules and port forwards always work, but the clients still use DHCP and pick up DNS and gateway settings automatically.

9. The firewall GUI is not enough

DD-WRT's firewall GUI covers the basics, but for anything serious you need to write iptables rules by hand in the Administration - Commands section. The GUI cannot do 1:1 NAT, rate limiting, port knocking, or per-IP bandwidth caps. Learn iptables properly - it is the same on DD-WRT as on any Linux box.

10. Subscribe to the DD-WRT forum for your specific hardware

Every router model has its own quirks. The WRT54G v5 and above have half the RAM and flash of the earlier versions - they need the micro build and cannot run half the features. The WRT54GL is the one to buy now. The forums at dd-wrt.com are genuinely helpful, and the wiki is decent. Read the peacock thread before flashing anything.

Overall, DD-WRT has been rock solid. My uptime record is 94 days, ended only by a power cut. For the price of a second-hand WRT54GL on eBay (about 20 quid), you get a router that can do things a 200 pound consumer router cannot. Highly recommended.