A VPN router runs the VPN connection itself, so every device on your network is covered without installing an app on each one. It is the only practical way to put a smart TV, games console or printer behind a VPN. The catch is that the router’s processor does all the encryption, and cheap routers slow to a crawl when asked to. Choosing one comes down to two things: a processor fast enough for your internet speed, and firmware that supports the WireGuard protocol. This guide explains when a VPN router is worth the trouble, which specs decide speed, the three ways to get one, and how to set it up so only the devices you choose go through the tunnel.
Key takeaways
- A VPN router protects devices that cannot run a VPN app: TVs, consoles, smart-home gear, and guests’ phones.
- VPN throughput depends on the router’s CPU, not its Wi-Fi rating. A router advertised for gigabit Wi-Fi may manage a small fraction of that through a VPN.
- WireGuard is faster and lighter than OpenVPN. Prefer routers and VPN services that support it.
- Policy-based routing (choosing which devices use the VPN) is the feature that makes a VPN router liveable. Without it, banking and streaming sites will fight you.
- You still need a VPN subscription; the router is only the client. Expect the router to cost from a low three-figure sum to several times that, at the time of writing.
Do you need a VPN router?
A VPN on your phone or laptop covers that one device. A VPN on the router covers everything behind it. That is the whole pitch. It is useful when:
- You want a streaming box or smart TV to appear in another country, and it has no VPN app.
- You have many smart-home devices and want their traffic hidden from your internet provider.
- You run a small office and want one policy for every machine.
- You want a guest network that is always tunnelled.
It is not useful when your goal is privacy from the sites you visit while logged in to them, or when you just want a VPN on a laptop that travels. For that, the app is simpler. If you have not chosen a VPN service yet, our comparison of NordVPN, ExpressVPN and Surfshark covers the router support each one offers.
The specs that decide VPN speed
Processor
Encryption is CPU work. A dual-core ARM chip at around 1 GHz, common in budget routers, might push tens of megabits per second through OpenVPN. A quad-core chip at 1.5 to 2 GHz with hardware crypto acceleration can push several hundred megabits through WireGuard. Router makers rarely publish VPN throughput figures, so look for the CPU model on the spec page and search for it alongside “WireGuard throughput”. Community-run forums for OpenWrt and DD-WRT publish real numbers.
Protocol support
| Protocol | Speed on the same hardware | Notes |
|---|---|---|
| WireGuard | Fastest | Modern, small codebase, supported by most VPN services now |
| OpenVPN | Slowest | Mature, works everywhere, heavy on CPU |
| IPsec / IKEv2 | Middle | Often hardware-accelerated; fewer consumer services support it on routers |
If a router supports only OpenVPN, expect a big speed loss. The WireGuard project’s own site explains the design and lists platforms.
Policy-based routing
Also called split tunnelling or VPN fusion depending on the brand. It lets you say “TV and console through the VPN, everything else direct” or the reverse. This solves the biggest day-to-day annoyance: banks, some shops and some streaming services block or challenge VPN addresses. Without policy routing you will be toggling the VPN on and off for the whole house.
Kill switch
If the VPN tunnel drops, a kill switch stops traffic from those devices leaking out unprotected. Check the firmware supports it per policy, not just globally.
RAM and storage
Matters mostly if you plan to flash open firmware. 256 MB of RAM and 128 MB of flash is comfortable for OpenWrt with a VPN client and extras such as ad blocking.

Three ways to get a VPN router
1. A consumer router with built-in VPN client support
ASUS is the best-known example. Most ASUS routers running its stock firmware include a VPN client with WireGuard, OpenVPN and per-device routing under the name VPN Fusion. TP-Link and Netgear offer VPN client features on some models, though often OpenVPN only. This route needs no flashing and keeps the maker’s support. ASUS lists the feature per model on its router product pages.
2. A router pre-configured by a VPN provider or reseller
Some VPN services sell or partner with routers that arrive with the VPN set up: ExpressVPN’s Aircove is one example. Setup is minimal and support comes from one place. The trade-off is being tied to that provider and paying a premium for the convenience.
3. A router flashed with OpenWrt, DD-WRT or similar
Open firmware gives the most control: any protocol, any provider, detailed routing rules, ad blocking and more. It also voids most warranties and takes an afternoon to set up properly. GL.iNet ships small routers with OpenWrt pre-installed and a friendly interface layered on top, which is the easiest entry point. Their travel-size units are covered in our travel router guide.
A fourth option: keep your router, add a box
If you like your current mesh system, you can put a small VPN-capable router between the modem and your existing system, or run the VPN on a mini PC or Raspberry Pi acting as a gateway. This works well with the setup in our Pi-hole guide, since the same device can filter ads.

Setting it up
- Get the config from your VPN provider. In your account dashboard, look for “manual setup” or “router” and download a WireGuard configuration file or OpenVPN profile for the server location you want.
- Import it into the router. On ASUS: VPN, then VPN Client, then Add profile, then upload the file. On OpenWrt: install the WireGuard packages, add an interface, paste the keys.
- Set DNS to the provider’s servers inside the VPN settings, or your DNS requests may leak outside the tunnel.
- Configure policy routing. Add the TV, console or whatever you want tunnelled by its local IP or MAC address. Give those devices a fixed IP in the DHCP settings so the rule does not break.
- Turn on the kill switch for the tunnelled devices.
- Test. From a tunnelled device, visit a “what is my IP” page and a DNS leak test page. From a non-tunnelled device, confirm you see your normal address.
- Run a speed test on a tunnelled device. If it is far below your plan, try a closer server or switch from OpenVPN to WireGuard.
Troubleshooting
- Slow speeds: the CPU is the limit. Use WireGuard, pick a nearby server, and stop tunnelling devices that do not need it.
- Streaming services show an error: the VPN server’s address is known to the service. Change servers or route that device outside the VPN.
- Some sites will not load: lower the MTU on the VPN interface (try 1420 for WireGuard, then 1380).
- Tunnel drops every few hours: add a keepalive setting (25 seconds is standard for WireGuard) and check the router is not overheating in a cupboard.
- Local devices cannot see each other: the VPN policy is catching local traffic. Add a rule to exclude your own subnet.
Common mistakes
- Buying by Wi-Fi speed. The Wi-Fi 7 badge tells you nothing about VPN throughput.
- Tunnelling everything. Banking apps, video calls and gaming get worse behind a VPN. Route only what needs it.
- Forgetting DNS. A tunnel with leaking DNS reveals every site you visit.
- Using a free VPN. If the service is free, your traffic is the product. Pay for a service with a published no-logs audit.
- Skipping firmware updates. Router flaws are exploited within days of disclosure. Turn on automatic updates.
Who this is not for
If the only device you want covered is a laptop or phone, the VPN app is faster, easier and free with your subscription. If your internet is 50 Mbps or less, almost any modern router will handle it and you can skip the CPU research. If you want to block ads rather than hide traffic, Pi-hole or a DNS filter does that without slowing anything. And if your aim is to protect your home network from outside attackers, a VPN router does not do that; a VPN hides outbound traffic, it does not firewall inbound. Keeping the router updated and turning off remote admin does more for that.
Frequently asked questions
Will a VPN router slow down my whole network?
Only the devices routed through the VPN, and only if the router’s CPU cannot keep up. Devices outside the tunnel run at normal speed.
Can I use my existing VPN subscription?
Usually. Most major services provide WireGuard or OpenVPN config files for routers. Check that your plan allows a router as one of its connections; some count it as one device.
Does a VPN router work with a mesh system?
Yes, if the VPN router is the main unit or sits upstream of the mesh. Putting the VPN on a satellite does not work.
Is WireGuard secure?
Yes. It uses modern cryptography and has been reviewed extensively. Its main limitation is that it does not obscure the fact you are using a VPN, which matters in a few countries.
Can I run a VPN server on the router instead?
Yes, and that is a different use: it lets you connect back to your home network from outside, for example to reach a NAS. Many routers support both client and server modes at once.
