VPNRank.io
How-To Guides

How to Set Up a VPN on Your Router: A Plain-English Walkthrough

The exact menu for each router firmware, where each VPN hides its router file, what the router's chip does to your speed, and the documented fixes for double NAT, DNS leaks, MTU and clock problems.

Diego PereyraBy Diego PereyraPublished Updated 25 min read

vpnrank.io is reader-supported: we may earn a commission if you buy through links in this article. This never affects our rankings.

As of October 2026, you need a router whose firmware has a VPN client (ASUS, GL.iNet, TP-Link, OpenWrt, DD-WRT) or a provider-built router: upload your VPN's WireGuard or OpenVPN file to its VPN client page and switch it on.

Done once, that single connection covers every device on the router's Wi-Fi: phones, laptops, smart TVs and game consoles included. There are three ways to get a VPN client onto a router: use the one already built into its firmware, flash open-source firmware such as DD-WRT, FreshTomato or OpenWrt onto a router that lacks one, or buy hardware that arrives with the VPN set up. Typing server details into the router by hand still works on most firmware, but importing your provider's file has largely replaced it. Every menu path, file location and speed figure below was read in October 2026 from the router maker's, firmware project's or VPN provider's own documentation, or from the standard behind it, and anything we could not verify is left out.

A router VPN covers every device on its Wi-Fi, including the ones that can't run an app

A router-level VPN moves the encryption from individual apps to the single point every device connects through. That means everything on your Wi-Fi is covered the moment it joins the network — no app to open, no toggle to forget, and no per-device limit to hit. It's the difference between protecting five gadgets and protecting your whole home.

  • One connection covers everything. Most VPN plans cap simultaneous device connections, but a router counts as a single connection while shielding the devices behind it. Proton VPN's router page says the router "only counts as one connection" on its Free plan, "no matter how many devices you connect to it", and ExpressVPN's router FAQ says you can connect as many devices as you want to the router.
  • It reaches devices that can't run an app. Smart TVs, older streaming sticks, and gaming consoles rarely have a VPN app — but they all connect through the router, so they inherit its protection automatically.
  • It's always on. Because the tunnel lives on the router, there's nothing to remember to switch on. Guests, IoT gadgets, and every new device get encrypted traffic by default.
  • Consistent geography. Everything on the network appears in the same location, which is handy when you want a whole household watching from one region.

The trade-offs are real, though, and Proton VPN lists four of them on its own router page: speeds "depend on your router's processing power"; changing location means updating the router configuration rather than tapping a server; app features such as NetShield or split tunneling "may not be available"; and the router's settings apply to every device on it. Setup is also more involved than tapping a button. If you mainly want to check what's available in another region on one device now and then, an app is simpler; the router shines when you want blanket, hands-off coverage. Our best VPN routers guide ranks the providers and hardware, and the five-minute video walkthrough shows the setup on screen.

Your router needs a VPN client, and a VPN server menu is the wrong feature

Before you touch a setting, find out whether your router can act as a VPN client, the role that connects out to a provider. Many routers ship only a VPN server, which does the opposite job: it lets you reach your home network from outside. NETGEAR's stock VPN Service, under ADVANCED › Advanced Setup › VPN Service, is that kind of feature: NETGEAR documents it as a way to access your home network securely while you are away, connecting from the OpenVPN app on your phone. NordVPN's router page is blunt about the other common case: if your router was issued by your ISP, "it probably does not support VPN configurations".

  1. 1VPN client support. Look in the admin panel for a menu called VPN Fusion, VPN Client, WireGuard Client or OpenVPN Client; the firmware table below shows where each one lives. One ASUS-specific catch from its own FAQ: a router can be a VPN server and a VPN client at once, but not of the same VPN type at the same time.
  2. 2Processing power and memory. Encryption is CPU-intensive, and the router's processor does it for every device behind it. For custom firmware, OpenWrt describes 8 MB of flash as "barely enough" and recommends at least 16 MB of flash and 128 MB of RAM if you want to add packages such as a VPN client; underpowered units will bottleneck your whole connection.
  3. 3Protocol support. WireGuard is usually much faster than OpenVPN on router hardware. GL.iNet's published figures show WireGuard at two to five times OpenVPN's ceiling on chips without OpenVPN DCO, and close to level on newer models that have it (see the speed section). If your router or firmware supports WireGuard, use it.
  4. 4Your provider's router files. Confirm your VPN publishes router instructions and files for your firmware. Most of the nine we track do, but the details differ: NordVPN hands out OpenVPN configuration files plus separate service credentials, Surfshark and Proton VPN let you download WireGuard files, and TotalVPN publishes no router guide at all.

If your current router falls short, you don't necessarily need to flash anything — a router with a built-in client, or one sold with a provider already set up, may cost less than an afternoon of troubleshooting. It's also worth running a quick baseline on our VPN speed test page so you know what "normal" looks like before and after.

There are three ways to get a VPN client onto a router

Which path you take depends on the router you already own and how much risk you will accept. The first costs nothing if your router qualifies, the second costs money but no effort, and the third costs time and carries a real chance of breaking the router.

Path 1: the VPN client already in your firmware (the easy way)

Many current ASUS routers, GL.iNet's routers, supported TP-Link models and anything running Asuswrt-Merlin or OpenWrt already contain a VPN client. Two vendors go a step further and build named providers into the firmware. ASUS's VPN Fusion lists NordVPN as a VPN type that you sign into with an access token (firmware 3.0.0.6.102.34713 or later; 3.0.0.6.102.44669 on the ExpertWiFi series) and Surfshark as a type that uses WireGuard with a private key from your Surfshark account (ASUS lists firmware later than 3.0.0.4.388.23000 or 3.0.0.4.388.31900). GL.iNet's WireGuard client has built-in profiles for ten providers, five of which are in our database: IPVanish, NordVPN, Private Internet Access, PureVPN and Surfshark.

Path 2: hardware sold with the VPN already inside

ExpressVPN stands out here: it's the provider best known for a genuine router app, and it also sold its own Aircove routers — Wi-Fi 6 AX1800 units managed from expressvpnrouter.com and the ExpressVPN app — with the VPN preinstalled. You can sort devices into up to five groups on a router running ExpressVPN and point each group to a different VPN location, no VPN or no internet, so the TV can appear in one country while the laptop appears in another; all groups share one VPN protocol.

That line has now changed. On 16 September 2026 ExpressVPN said Aircove and Aircove Go "are being retired from sale" and that it "will not produce additional units". Existing Aircove (AX1800) routers get security updates through 2027 and Aircove Go (AXG1800) through 2028. The replacement is Fortify, which is GL.iNet's GL-MT6000 (the Flint 2 platform) running GL.iNet firmware rather than AircoveOS, sold at a $199.99 MSRP with 12 months of ExpressVPN's Advanced plan, and which "connects to ExpressVPN using WireGuard" at launch. Aircove owners are offered 20% off. Other providers take the partner route: IPVanish and Private Internet Access point buyers to pre-configured routers from FlashRouters, and NordVPN recommends FlashRouters' Privacy Hero 2 for its "exclusive NordLynx integration".

Path 3: flashing DD-WRT, FreshTomato or OpenWrt

If your router runs locked-down stock firmware with no VPN client, you can replace that firmware with an open-source alternative that adds one. This is called flashing. The mainstays are DD-WRT, Tomato (now maintained as FreshTomato) and OpenWrt, and all of them add OpenVPN and WireGuard clients that much factory firmware omits. It's more advanced, but it unlocks routers that otherwise couldn't do the job.

  • DD-WRT gives complete control over nearly every router setting and supports a huge range of models — but the interface is dense and can be intimidating if you're new to networking. For WireGuard support you'll want build 43045 or higher, the minimum Surfshark's DD-WRT guide specifies.
  • FreshTomato is prized for its clean interface and is excellent for getting OpenVPN running quickly. The catch: its own site describes it as firmware "for Broadcom based routers", and its hardware compatibility list is dominated by Asus, Linksys and Netgear models, so your exact router may not be covered. Release 2026.4 (14 September 2026) lists a built-in OpenVPN client and "full Wireguard support with PBR (ARM)".
  • OpenWrt runs on the widest range of hardware, but you install the VPN packages yourself: openvpn-openssl for OpenVPN, wireguard-tools for WireGuard (plus luci-proto-wireguard if you want it in the web interface).

A serious warning: flashing the wrong firmware image for your exact model and hardware revision can permanently brick the router. IPVanish's router page says it plainly: "Incorrect flashing by choosing the wrong firmware can permanently damage your router." Always match the firmware to your precise model number, follow the project's own instructions, and read them twice. If that risk makes you nervous, buy a router that's already been flashed and configured by a specialist service, or take the built-in path instead.

  • Fastest to set up: a provider-built router (Fortify, or an Aircove you already own) or a preconfigured unit from a flashing service.
  • Best balance: a WireGuard-capable router paired with a provider that publishes ready-made router files.
  • Most control: your own hardware running custom firmware.

Each firmware puts the VPN client behind a different menu

The setting you need exists on most modern routers; the hard part is finding it, because every firmware names and files it differently. The table gives the exact path for each, read from the firmware maker's own documentation, and the last column says what a "yes" does not guarantee. If you own the router already, find its row first and only then pick a provider file to match.

Matrix of nine router firmwares showing OpenVPN client support, WireGuard client support, per-device routing and the exact menu path for each: ASUSWRT VPN Fusion, older ASUSWRT, Asuswrt-Merlin, GL.iNet, TP-Link, OpenWrt, DD-WRT, FreshTomato and NETGEAR's server-only VPN Service
Where each firmware keeps its VPN client. Sources: ASUS FAQs, Asuswrt-Merlin changelog and wiki, GL.iNet docs, TP-Link FAQ 3135, OpenWrt, NETGEAR KB 29826, freshtomato.org, Proton VPN and Surfshark DD-WRT guides. Verified October 2026.
FirmwareOpenVPN clientWireGuard clientExact menu pathChoose which devicesSourceWhat it doesn't automatically prove
ASUSWRT, firmware later than 3.0.0.4.388YesYes, on firmware later than 3.0.0.4.388.23000 and listed modelsVPN › VPN Fusion › Add profileTurn off Apply to all devices, then Edit DeviceASUS FAQs 1051131 and 1048282That your model has WireGuard: ASUS points to a model list, and Proton VPN says RT-ACxxx and some RT-AXxxx models lack it
ASUSWRT, 3.0.0.4.388 or earlierYes, alongside PPTP and L2TPNoAdvanced Settings › VPN › VPN Client › Add profileNot documentedASUS FAQ 1011232That it recovers by itself: ASUS says the client "will not automatically reconnect" after the VPN server goes off and comes back
Asuswrt-MerlinYes, up to five clientsYes, up to five clients, since 388.1 (3 December 2022)VPN › VPN Client (OpenVPN); routing in VPN DirectorVPN Director rules by local IP, up to 199 rulesMerlin changelog and wikiThat every ASUS model qualifies: 388.1 was AX-only, and Merlin notes that enabling WireGuard disables hardware NAT acceleration
GL.iNet, firmware 4.xYesYesVPN › VPN Client Profile › Add Manually (v4.9 and later); VPN › WireGuard Client on v4.7–4.8VPN Dashboard: All Clients or Specified DevicesGL.iNet router docsThat the steps match older units: the docs cover v4.7 and later, and features vary by model
TP-Link, supported modelsYes, alongside PPTP and L2TP/IPSecSelect models onlyAdvanced › VPN Client › Server List › AddDevice List › Add; unselected devices skip the VPNTP-Link FAQ 3135, updated 17 April 2026That several locations can run at once: up to six profiles, one active, and the .ovpn file must be under 20 KB in unified format
OpenWrtYes (openvpn-openssl)Yes (wireguard-tools)Network › Interfaces › Add new interface › WireGuard VPNNot covered in the client guidesOpenWrt client guides; Proton VPN's OpenWrt guideThat it is preset: you install the packages and set the firewall zone and DNS yourself
DD-WRTYesYes, build 43045 or laterSetup › Tunnels › Add Tunnel (WireGuard); Services › VPN › OpenVPN ClientNot verifiedSurfshark and Proton VPN DD-WRT guidesThat DD-WRT documents it this way: its own wiki refused our automated check, so these paths come from provider guides
FreshTomatoYesYes, "full Wireguard support with PBR (ARM)"Not verified in this passPolicy-based routing on ARM buildsfreshtomato.org, release 2026.4That your router can run it: Broadcom-based models only
NETGEAR stock VPN ServiceNo, server onlyNoADVANCED › Advanced Setup › VPN Service—NETGEAR KB 29826, updated 7 July 2025That the router can reach a VPN provider: it lets your phone reach your home network, the reverse direction

Router firmware VPN clients and menu paths, verified October 2026.

Two rows are worth a second look. The two ASUS rows are the same brand on either side of a firmware line: on 3.0.0.4.388 and earlier the feature is called VPN Client and has no WireGuard, while later firmware calls it VPN Fusion. And Fortify, ExpressVPN's new router, is GL.iNet hardware running GL.iNet firmware, so the GL.iNet row describes the platform it is built on.

Every VPN provider hands out its router file from a different place

A router can't show a sign-in screen, so it needs either a configuration file, separate manual credentials or a login token from your VPN account. Each of the nine providers we track puts these somewhere different, and some don't offer them at all. The table records where each provider's own documentation says to look, and which router products it supports. For which provider performs best on a router, see the router ranking; this table is only about getting the file.

ProviderRouter guides it publishesProtocols for routersWhere the file or login comes fromRouter-specific productsSourceWhat it doesn't automatically prove
ExpressVPNManual OpenVPN guides (Asus, DD-WRT, Tomato, Sabai, pfSense and others) plus its router appOpenVPN for manual setups; Fortify uses WireGuard at launch; Aircove used LightwayApplications › Advanced setup › Manual Configuration: username, password and .ovpn filesFortify (GL-MT6000, from 16 September 2026); Aircove and Aircove Go retired from saleExpressVPN router FAQ, Fortify announcement, Asus setup guideEqual protection: ExpressVPN says manual OpenVPN "does not offer the same security and privacy benefits as the ExpressVPN app"
NordVPNASUS WRT, Merlin, DD-WRT, OpenWRT, GL.iNet, TP-Link, Tomato, pfSense, OPNsense and othersOpenVPN files; access token where NordVPN is built into the firmwareNord Account › NordVPN › Advanced settings › Set up NordVPN manually (files, plus a Service credentials tab); tokens under Get access tokenPre-configured FlashRouters units, including Privacy Hero 2NordVPN support; ASUS FAQ 1051215NordLynx on your router: NordVPN says popular self-bought Asus models (RT-AX86U, RT-AX68U, RT-AX88U) "will not support NordLynx"
SurfsharkWireGuard for GL.iNet, OpenWRT, DD-WRT, TP-Link, FRITZ!Box and Asus VPN Fusion; OpenVPN for AsusWRT and OpenWRTWireGuard and OpenVPNVPN › Manual setup › Router › WireGuard: generate a key pair, then download one file per locationBuilt into ASUS VPN Fusion and GL.iNet's WireGuard clientSurfshark support; ASUS FAQ 1049833That your account password works: these are "not your regular credentials", and ASUS warns the private key is shown once
Proton VPNAsusWRT, AsusWRT-Merlin, DD-WRT, FreshTomato, GL.iNet Flint, MikroTik, OpenWRT, OPNsense, pfSense, VilfoWireGuard and OpenVPNaccount.protonvpn.com › Downloads › WireGuard configuration, platform Router; OpenVPN username under AccountNone; router connections work on every plan, Free includedProton VPN supportApp features: NetShield and split tunneling "may not be available" through a router
Private Internet AccessASUSWRT, Asuswrt-Merlin and DD-WRT named on its router pageOpenVPN in its guides; built into GL.iNet's WireGuard clientModel-specific guides in PIA's support portalPre-configured FlashRouter needing "almost zero setup"PIA router page; GL.iNet docsExact menu paths: PIA's helpdesk blocked our automated read, so none are quoted here
CyberGhostDD-WRT, Tomato, OpenWRT, AsusWRT and AsusWRT-MerlinOpenVPNDevices › Configure a new device › Other, then download the OpenVPN filesNoneCyberGhost router pageWireGuard on a router: its router page mentions only OpenVPN
IPVanishDD-WRT, AsusWRT, OpenWRT and ASUSWRT-Merlin, plus a supported-router listOpenVPN in its router specs; built into GL.iNet's WireGuard clientIts manual setup guidesPre-configured routers from partner FlashRoutersIPVanish routers pageHelp if it goes wrong: it offers DIY steps "but no support for this installation"
TotalVPNNone foundNone documented for routersNo router path documentedNoneTotalVPN help centre (Technical, Account and Billing sections)That a router can't work: only that you would be doing it unaided
PureVPNAsus, DD-WRT, FreshTomato, GL.iNet, Linksys, MikroTik, Netgear, OpenWRT, pfSense, OPNsense, Synology NAS, TP-Link, TRENDnet and othersOpenVPN and WireGuardWireGuard file from the Member Area; OpenVPN files from its knowledge baseBuilt into GL.iNet's WireGuard clientPureVPN support, updated 10 July 2026That it will work behind your ISP box: it asks you to make sure the router "is not working as a modem"

Router files and products by provider, read from each provider's own pages. Verified October 2026.

The pattern matters more than any single row. A provider that publishes only OpenVPN files can still run over WireGuard on a router whose firmware has that provider built in: GL.iNet does this for IPVanish, NordVPN, Private Internet Access and PureVPN, and ASUS does it for NordVPN and Surfshark. So check your firmware's built-in list before you conclude a provider is "OpenVPN-only" on routers.

On an ASUS router, VPN Fusion imports a provider's file in seven steps

ASUS is the most common router brand in provider guides, and on firmware later than 3.0.0.4.388 the whole job happens on one page. These steps follow ASUS's own FAQs for the WireGuard and OpenVPN clients, with the account paths from each provider's guide.

  1. 1Get the file from your VPN account. For WireGuard: Proton VPN under Downloads › WireGuard configuration with the platform set to Router; Surfshark under VPN › Manual setup › Router › WireGuard. For OpenVPN: NordVPN under Advanced settings › Set up NordVPN manually; ExpressVPN under Applications › Advanced setup › Manual Configuration. Note the separate username and password that OpenVPN files need.
  2. 2Open the router's settings. Connect a laptop by cable or Wi-Fi and go to http://www.asusrouter.com or the router's LAN address (Proton VPN's guide gives 192.168.50.1), then sign in.
  3. 3Go to VPN › VPN Fusion and click Add profile.
  4. 4Name the connection and pick the VPN type: WireGuard or OpenVPN. ASUS notes the client must use the same VPN type as the server.
  5. 5Import the file. WireGuard: Upload Config (Proton's guide calls the button Import config file) and choose the .conf file. OpenVPN: Import .ovpn file, wait for the "Complete" hint, then enter the provider's manual credentials, not your website login.
  6. 6Choose devices. Leave Apply to all devices on to cover the whole home, or turn it off and use Edit Device to pick only the TV, console or streaming stick.
  7. 7Click Apply and Enable (Apply all settings on some versions). When the profile shows Connected, test from a device as described further down.

If you use NordVPN or Surfshark, step 5 can be skipped: choose the provider itself as the VPN type, then paste a NordVPN access token or a Surfshark WireGuard private key and pick a region. Both are shown only once when you create them, so copy them before closing the page. ASUS also notes that some regions may not offer these built-in types.

Asuswrt-Merlin needs a few OpenVPN settings that stock firmware hides

Merlin exposes the full OpenVPN client, which means more fields to get right. Proton VPN's guide uses Advanced settings › VPN › VPN Client › OpenVPN and sets Accept DNS Configuration to Exclusive, Redirect Internet traffic to Yes (all), Compression to Disabled and Automatic start at boot time to Yes. NordVPN's Merlin guide recommends Strict for a whole home and Exclusive for specific devices, and adds the optional kill switch, Block routed clients if tunnel goes down. Merlin's WireGuard clients have fewer choices: since 388.1 their DNS handling is identical to OpenVPN's Exclusive mode, and their routing always runs through VPN Director rules.

On GL.iNet, OpenWrt and DD-WRT, WireGuard is a file upload or a pasted config

These three firmwares cover most of the remaining provider guides. GL.iNet is closest to ASUS in effort; OpenWrt and DD-WRT expose the raw WireGuard fields, so a single wrong character in a key stops the tunnel.

GL.iNet, firmware 4.9 and later

  1. 1Sign in at 192.168.8.1, GL.iNet's default address.
  2. 2Go to VPN › VPN Client Profile. For a built-in provider, sign in from its entry; otherwise click Add Manually under WireGuard (or OpenVPN) and upload the file. GL.iNet accepts zip, tar, gz, conf and txt uploads.
  3. 3Click the three-dot icon next to the server and connect. A green dot appears once the tunnel is up.
  4. 4Open the VPN Dashboard to switch on Kill Switch, which cuts internet for the local network if the VPN drops, and to choose All Clients or Specified Devices.

On firmware 4.7 and 4.8 the same controls sit under separate pages, VPN › WireGuard Client and VPN › OpenVPN Client; PureVPN's GL.iNet guide follows that older layout, using VPN › WireGuard Client › Set up WireGuard Manually. GL.iNet merged them into the single VPN Client Profile page in v4.9.

OpenWrt, using the LuCI web interface

  1. 1System › Software, then Update lists, and install luci-proto-wireguard.
  2. 2Network › Interfaces › Add new interface: give it a name and choose WireGuard VPN as the protocol.
  3. 3Import configuration › Load configuration and paste the contents of your provider's .conf file.
  4. 4On the Peers tab, edit the peer and tick Route Allowed IPs. OpenWrt's own client guide recommends a persistent keepalive of 25 seconds.
  5. 5Network › Firewall › Zones: Proton VPN's guide adds a VPN zone with masquerading on, allows forwarding to it from lan, and turns on MSS clamping in the lan zone. OpenWrt's guide takes the shorter route of adding the VPN interface to the wan zone.
  6. 6Network › Interfaces › wan › Edit › Advanced Settings: untick Use DNS servers advertised by peer and enter your VPN's DNS server (Proton VPN's is 10.2.0.1). Then Save & Apply.

DD-WRT, with WireGuard or OpenVPN

  1. 1Log in to the router admin panel. Open a browser on a device connected to the router and go to the router's address — commonly 192.168.1.1 — then sign in with your admin credentials.
  2. 2Grab the config from your VPN. In your provider's dashboard, generate a manual router configuration for your chosen protocol and server location. This gives you the keys, addresses, and port you'll need.
  3. 3Open the tunnels section. On build 43045 or later, go to the Setup tab, select Tunnels, click Add Tunnel and enable it with WireGuard as the protocol.
  4. 4Enter the connection details. Paste in the private key, peer public key, endpoint address, port, and allowed IPs exactly as your provider supplied them. Surfshark's DD-WRT guide also sets MTU 1420, listen port 51820 and a persistent keepalive of 30, and switches on the inbound firewall and Kill Switch.
  5. 5Save and apply. Commit the settings and let the router reboot or reload the interface.
  6. 6OpenVPN instead: Proton VPN's guide uses Services › VPN › OpenVPN Client › Import Configuration, the separate OpenVPN credentials, then Status › OpenVPN, which should read Client: CONNECTED SUCCESS. It also disables IPv6 under Setup › IPV6.
  7. 7Confirm it's working. From a connected device, check that your public IP now shows the VPN server's location, and run a leak check. Our glossary explains what a DNS leak and a WebRTC leak are and why you should test for both.

If the connection fails, the usual culprits are a mistyped key, the wrong port, or firmware that's too old for WireGuard. Roll back to OpenVPN to isolate the problem, or update your firmware build and try again; our VPN won't connect guide covers the checks that apply on any device.

Want the least painful route to a whole-home VPN? A provider with a real router app skips the flashing entirely.

See our top-ranked VPNs →

The router's processor caps VPN speed for the whole house, and GL.iNet publishes the ceilings

Every byte that crosses the tunnel is encrypted by the router's own processor, which is far weaker than a laptop's, and that one chip works for every device in the house. Proton VPN's router page puts it simply: "routers with weaker processors may experience slower speeds". GL.iNet publishes VPN throughput on each of its product pages, which makes it the clearest public evidence of how much the chip and the protocol matter.

Bar chart of GL.iNet's published maximum VPN client speeds for nine routers, WireGuard against OpenVPN: Mango 45 vs 11 Mbps, Opal 65 vs 12, Beryl AX 300 vs 150, Brume 2 355 vs 150, Slate 7 490 vs 385, Slate AX 550 vs 560, Flint 3 680 vs 680, Flint 2 900 vs 880, Beryl 7 1,100 vs 1,000; the last five use OpenVPN DCO
GL.iNet's own maximum VPN client figures, tested on a local network in client mode. Source: GL.iNet product pages. Verified October 2026.
Router (model)WireGuard, max.OpenVPN, max.OpenVPN type
Mango (GL-MT300N-V2)45 Mbps11 MbpsStandard
Opal (GL-SFT1200)65 Mbps12 MbpsStandard
Beryl AX (GL-MT3000)300 Mbps150 MbpsStandard
Brume 2 (GL-MT2500)355 Mbps150 MbpsStandard
Slate 7 (GL-BE3600)490 Mbps385 MbpsDCO
Slate AX (GL-AXT1800)550 Mbps560 MbpsDCO
Flint 3 (GL-BE9300)680 Mbps680 MbpsDCO
Flint 2 (GL-MT6000)900 Mbps880 MbpsDCO
Beryl 7 (GL-MT3600BE)1,100 Mbps1,000 MbpsDCO

GL.iNet's published "Max." VPN client speeds, read October 2026.

Two things stand out. On the four models whose OpenVPN runs without DCO, WireGuard's published ceiling is two to about five times OpenVPN's, from 300 against 150 Mbps on the Beryl AX to 65 against 12 on the Opal. On the five with OpenVPN DCO (Data Channel Offload), the two protocols land within about a quarter of each other, and on the Slate AX OpenVPN is slightly ahead. GL.iNet's Flint 3 page explains why: DCO "uses kernel-level acceleration to handle encryption and decryption across multiple CPU cores". The blanket rule that WireGuard is several times faster holds for routers without OpenVPN DCO, not for every router sold in 2026.

Firmware can cost speed too. When Asuswrt-Merlin added WireGuard in 388.1, its changelog noted that "enabling WireGuard will disable hardware NAT acceleration due to compatibility reasons", so on a fast line the router's ordinary routing may slow down once a WireGuard client is on. GL.iNet's own footnote is the other caveat: its figures come from "tests conducted on a local network" in client mode, and real-world speeds may differ. They describe the chip, not your ISP line or how far away your VPN server is.

Practical rule:Choose WireGuard unless your router's maker publishes an OpenVPN DCO figure close to it, and treat any published ceiling as the most your whole household will share, not what each device gets.

For the protocol differences beyond routers, see what WireGuard is and our WireGuard vs OpenVPN vs IKEv2 guide; the fastest VPN comparison covers provider speeds.

Behind an ISP modem-router, double NAT is the first thing that breaks

Most homes can't replace the ISP's box, so the VPN router plugs into it: ExpressVPN's router guide describes exactly that, an Ethernet cable from the VPN router's Internet port to a LAN port on your modem or existing router. The tunnel usually connects fine this way. What breaks is everything around it, because both boxes now translate addresses (NAT) and your network is split in two.

Diagram of an ISP modem-router (NAT layer 1, LAN 192.168.1.x) feeding a VPN router (NAT layer 2, LAN 192.168.8.x) that serves a smart TV, console, laptop and phone, with six numbered failure points: double NAT, address clash, DNS lookups outside the tunnel, devices with their own DNS, MTU on PPPoE lines and the router's clock
Where a router VPN behind an ISP box goes wrong. Sources: ASUS, ExpressVPN, GL.iNet, Asuswrt-Merlin, Proton VPN, NordVPN, RFC 2516, wireguard-tools, OpenWrt. Verified October 2026.
  • Inbound features stop. ASUS's WAN guide says a router with a private WAN address sits in a multi-layer NAT network where "DDNS service and Port Forwarding will not function properly".
  • Devices on the two halves can't see each other. ASUS says two routers in series "can divide your private network into two", so a phone still on the ISP's Wi-Fi may not find the TV on the VPN router. Put both on the VPN router's Wi-Fi.
  • Address clash. If both routers use the same range, GL.iNet shows "LAN subnet is in conflict with the WAN subnet. Please Change LAN Subnet to a different address." The fix is to change the third number of 192.168.8.1, for example to 192.168.10.1. ASUS has a sibling case: an OpenVPN client "will not work" when the router's LAN IP equals the VPN server's IP.

The fixes belong on the ISP box. ExpressVPN lists two: put the ISP modem-router into bridge mode ("also known as 'bridging', 'transparent bridging' or 'modem only' mode"), or put the VPN router in the ISP box's DMZ. ASUS's usual cure for double NAT, switching the second router to Access Point mode, doesn't fit here: in AP mode "the firewall, IP sharing, and NAT functions are disabled by default", and routing is the job the VPN router is there to do. PureVPN's router page adds a related check: make sure the router you are configuring "is not working as a modem".

DNS is where a working router VPN still leaks

A router can carry all your traffic through the tunnel and still send name lookups somewhere else, usually to the ISP's resolver that it learned on its WAN port. A leak test then shows your ISP even though the tunnel is up. Each firmware has a specific setting that decides this, and the provider guides tell you what to choose.

  • Asuswrt-Merlin, OpenVPN: set Accept DNS Configuration to Exclusive (Proton VPN) or Strict (NordVPN, which also sets the WAN DNS to its own servers, 103.86.96.100 and 103.86.99.100, with Connect to DNS Server automatically set to No). Since 388.1, an OpenVPN client that redirects all traffic in Exclusive mode "will now force redirect ALL DNS traffic".
  • OpenWrt: untick Use DNS servers advertised by peer on the wan interface and enter the VPN's DNS. OpenWrt's OpenVPN guide suggests confirming the result with a DNS leak test afterwards.
  • GL.iNet: leave Allow Custom DNS to Override VPN DNS off unless you mean it; when on, tunnel traffic is resolved by your custom DNS "instead of the DNS server settings from the VPN connections".
  • DD-WRT: Proton VPN's guide disables IPv6 under Setup › IPV6 so nothing travels outside an IPv4-only tunnel.

Some devices also ignore the router's DNS because they have their own servers configured. Two firmwares can force them back: Asuswrt-Merlin's DNS Director (in the LAN section) can make specific devices or the whole network use a chosen resolver, though its wiki warns it "will interfere with resolution of local hostnames"; and GL.iNet's Override DNS Settings for All Clients overrides "unencrypted DNS settings". Encrypted DNS set inside a device's own browser or system is outside what either feature covers. After any change, check from a device with no VPN app using our VPN status and leak check.

Router-specific failures have documented symptoms and fixes

Most router VPN problems announce themselves in a recognisable way, and the router or provider documentation already describes the fix. The table pairs each symptom with its documented cause and remedy, and says what the symptom does not prove, so you don't fix the wrong layer.

What you seeDocumented causeDocumented fixSourceWhat it doesn't automatically prove
GL.iNet: "LAN subnet is in conflict with the WAN subnet"VPN router and ISP box use the same address rangeOn the LAN page, change 192.168.8.1 to, say, 192.168.10.1 and ApplyGL.iNet docsAny fault in the VPN itself
ASUS OpenVPN profile never connectsRouter LAN IP is the same as the VPN server's IPChange the router's LAN IPASUS FAQ 1051131That this is common with commercial providers: ASUS's example is a home-to-home link
Port forwarding or DDNS on the VPN router does nothingPrivate WAN address behind the ISP box (multi-layer NAT)ISP box in bridge (modem-only) mode, or VPN router in its DMZASUS FAQ 1011715; ExpressVPN router guideThat the tunnel is affected: outbound VPN connections usually work
Phone can't find the TV or printerTwo routers in series split the network in twoJoin both devices to the VPN router's Wi-FiASUS FAQ 1047919A VPN fault: the devices are on different networks
Leak test shows your ISP's DNSRouter still forwards lookups to the WAN or ISP resolverMerlin: Accept DNS Configuration Exclusive or Strict; OpenWrt: untick Use DNS servers advertised by peer; GL.iNet: custom-DNS override offProton VPN, NordVPN, GL.iNetThat the tunnel is down: traffic can be encrypted while lookups go elsewhere
One device keeps its own DNSDevice configured with its own serversMerlin DNS Director, or GL.iNet Override DNS Settings for All ClientsMerlin wiki; GL.iNet docsCoverage of encrypted DNS: GL.iNet's override covers unencrypted settings
DD-WRT: IPv6 traffic bypasses the tunnelIPv6 left on with an IPv4 tunnelSetup › IPV6, disableProton VPN DD-WRT guideThat every firmware needs it: this is Proton's DD-WRT instruction
Some sites load, others hangTunnel packets bigger than the line allows, common on PPPoESet WireGuard MTU to the line's MTU minus 80 (1412 on PPPoE); MSS clamping on OpenWrtRFC 2516; wireguard-tools; Proton VPN OpenWrt guideThat MTU is the cause on a non-PPPoE line: change one thing and retest
Tunnel refused after a power cut, fine laterRouter clock wrong until it syncs over NTPMake sure NTP is on and reachable, then reconnectOpenWrt WireGuard basics; Merlin wiki; RFC 5280; WireGuard protocolA provider outage: check the router's time first
Older ASUS firmware: VPN stays down after the server blipsThe legacy VPN Client "will not automatically reconnect"Re-activate the profile, or update to VPN Fusion firmwareASUS FAQ 1011232That VPN Fusion behaves the same: ASUS's statement covers the older client
Devices go online unprotected when the tunnel dropsNo kill switch configuredGL.iNet: VPN Dashboard › Kill Switch; Merlin: Block routed clients if tunnel goes down (WireGuard clients since 3004.388.8); DD-WRT: Kill Switch in the tunnel settingsGL.iNet docs; Merlin changelog; NordVPN and Surfshark guidesThat router services are tunnelled: GL.iNet leaves Services From GL.iNet Use VPN off by default

Router VPN failures and their documented fixes, verified October 2026.

Why 1420 and 1412 are the MTU numbers that matter

Ethernet carries 1,500-byte packets, and RFC 2516 caps PPPoE lines, which many ISPs use, at 1,492 because PPPoE adds 8 bytes of header. WireGuard's own wg-quick tool sets the tunnel MTU to the underlying link's MTU minus 80, which gives the familiar 1420 on ordinary Ethernet and 1412 on PPPoE. A router config that hard-codes 1420 on a PPPoE line sends packets 8 bytes too large, and a common symptom is that small pages load while large ones stall. Lowering the tunnel MTU, or enabling MSS clamping as Proton VPN's OpenWrt guide does, removes the problem.

A router can come back from a power cut with the wrong time

Routers set their clocks over the internet with NTP after they boot, and until that sync completes the time can be wrong. Both VPN protocols notice. OpenVPN checks the server's certificate against a validity window defined in RFC 5280, using the router's own clock. WireGuard's protocol page says the server "discards packets containing timestamps less than or equal to" the greatest it has seen from that client, and OpenWrt's WireGuard documentation warns that WireGuard "can refuse to pass traffic if the peer's clock is out of sync" and recommends relying on NTP. Asuswrt-Merlin's wiki notes the same dependency for encrypted DNS: it "won't use encryption until after your router's clock has been properly set through NTP".

Practical rule:If the tunnel fails only after a reboot or power cut, check the router's clock and its NTP setting before you touch the VPN profile. A new config file can't fix a wrong date.

Choosing which devices skip the tunnel is a router setting, not an app setting

The router-level version of split tunneling is per device rather than per app, and every firmware with it hides it somewhere different. It's how you send the TV through the VPN while the work laptop, the banking app or a lag-sensitive console uses the normal line.

  • ASUS VPN Fusion: turn off Apply to all devices in the profile, then Edit Device and select the devices that should use it. ASUS also lets you run several VPN connections at once and assign different devices to different tunnels.
  • Asuswrt-Merlin: VPN Director rules match a local IP and send it to a client or to WAN to bypass every tunnel; WAN rules take priority, and the limit is 199 rules.
  • GL.iNet: the VPN Dashboard routes All Clients or Specified Devices, by connection type (LAN, guest network) and by destination, including an excluded domain or IP list.
  • TP-Link: add devices under Device List; anything not selected keeps using the regular connection.
  • Routers running ExpressVPN: up to five device groups, each with its own VPN location, no VPN or no internet, all on the same protocol.

This solves the two biggest router-VPN complaints at once: services that block VPN addresses get a clean route on one device, while everything else stays protected.

Smart TVs and consoles gain the most, but streaming services still detect VPNs

The whole point of a router VPN is reaching the gadgets an app can't. That's where it earns its keep: the living-room hardware you'd otherwise have no way to protect or relocate. But the same blanket coverage that makes it powerful also changes how streaming behaves, so it's worth setting expectations.

  • Smart TVs and streaming sticks — few run a proper VPN app, so the router is often the only practical way to route them through a tunnel. See our smart TV setup guide for the alternatives.
  • Game consoles — no native VPN support at all; a router lets them appear in another region for lobbies or content. Our PS5 and Xbox guide covers the console side.
  • IoT and smart-home gear — covered automatically, with nothing to install.
  • Phones and laptops — still work, though on these the standalone app is usually faster and lets you toggle location per device, and it keeps protecting them once they leave the house.

On streaming, be realistic: services actively detect and block VPN traffic, and they're good at it. A router VPN doesn't magically defeat that — you'll still need a provider with servers that work with your chosen platform. If watching from another region is your main goal, our guides for Netflix and BBC iPlayer cover which services hold up, and the Android TV guide is useful if your TV can actually run an app. Big live events are the classic use case — see our sports streaming hub for how a whole-home setup helps there.

Changing country on a router means switching profiles, not tapping a map

A router config file normally holds one server, so a new location means a new file or a second profile. Proton VPN says so directly: to change your VPN location "you need to update your router configuration", and "you can't switch servers instantly". Surfshark's router guide has you download one file per location for the same reason. The practical workaround is to load several profiles in advance and switch between them:

  • TP-Link: up to six profiles in the Server List, with one active at a time.
  • Asuswrt-Merlin: up to five OpenVPN and five WireGuard clients, each pointed at a different location and chosen per device in VPN Director.
  • ASUS VPN Fusion: several simultaneous tunnels, with devices assigned to each.
  • GL.iNet: built-in providers list their servers in the profile, so picking a new one is a menu choice rather than a new upload.
  • Routers running ExpressVPN: each of the up to five device groups can sit in a different country.

A free router VPN exists, and it counts as one connection

Among the nine providers we track, Proton VPN is the one whose free plan explicitly covers routers. Its router page says "Router connections are available on all Proton VPN plans, including Proton Free", and that the router "only counts as one connection on a Free plan, no matter how many devices you connect to it". The WireGuard file comes from the same Downloads › WireGuard configuration page, though on the Free plan "the only VPN option available to you is VPN Accelerator". Expect the router's processor, not the plan, to set your speed. Our Proton VPN review and free VPN guide cover the free plan's other limits.

Check the tunnel from a device that has no VPN app of its own

The router's status page tells you the tunnel is up; it doesn't tell you every device is using it. ASUS shows Connected on the profile, GL.iNet a green dot and the connected server in its VPN Dashboard, and DD-WRT Client: CONNECTED SUCCESS under Status › OpenVPN. Then test from the devices themselves, with their own VPN apps switched off so the result reflects the router:

  1. 1Open our VPN check or what is my IP on a phone joined to the router's Wi-Fi. It should show the VPN server's location, not yours.
  2. 2Run a DNS leak test. Any server belonging to your ISP means the DNS settings above need another look.
  3. 3Run the WebRTC leak test in a browser.
  4. 4Disable the VPN profile on the router for a moment and watch what happens. With a kill switch on, devices should lose internet rather than fall back to your real address; our kill switch test walks through it.
  5. 5Run a speed test through the tunnel and compare it with your baseline from the speed test page.

Our full testing guide explains what each result means.

A router VPN is the most complete home setup, and the most involved one

A router VPN is the most complete way to cover a household, but it's also the most involved to set up and the most likely to cost you some speed. Match the path to your patience: use the client already in your firmware if you have one, buy a provider-built router if you want it done in minutes, flash DD-WRT or FreshTomato if you want maximum control and don't mind the risk, and always test for leaks once it's live.

If you're still deciding between doing this at the router or just running an app on the devices you care about, weigh it against your actual habits. For hands-off, whole-home coverage the router wins; for a single TV or laptop and occasional use, the app is simpler and faster. When you're ready to pick hardware and a provider, start with our router VPN guide and cross-check pricing on the VPN price index.

Every source behind this guide was re-read in October 2026

Frequently asked questions

Do I need a special router to set up a VPN?

You need a router whose firmware has a VPN client, not just a VPN server. Many current ASUS routers (VPN Fusion), GL.iNet's routers, supported TP-Link models and routers running Asuswrt-Merlin or OpenWrt qualify. Many factory routers, NETGEAR's stock VPN Service among them, only run a server, so you'd need a VPN-ready model, a provider-built router, or custom firmware like DD-WRT or FreshTomato.

What's the difference between DD-WRT and Tomato?

Both are open-source firmwares that add VPN support your stock firmware may lack. DD-WRT is more powerful and supports far more router models, but its interface is dense; WireGuard needs build 43045 or later. Tomato, now FreshTomato, is cleaner and quick for OpenVPN, but it runs only on Broadcom-based routers, mostly Asus, Linksys and Netgear models. Release 2026.4 also has WireGuard. Choose DD-WRT for control, Tomato for simplicity.

Will a VPN on my router slow down my internet?

Usually, because the router's processor encrypts traffic for every device. GL.iNet's published figures show how much the chip matters: the Beryl AX reaches 300 Mbps on WireGuard and 150 on OpenVPN, while the Flint 2, with OpenVPN DCO, reaches 900 and 880. Use WireGuard unless your router publishes a comparable OpenVPN DCO figure, and measure your line before and after.

Which VPN has a native router app?

ExpressVPN is the provider best known for a dedicated router app. It retired its Aircove routers from sale on 16 September 2026 (updates continue to 2027 for Aircove and 2028 for Aircove Go) and now sells Fortify, a GL.iNet GL-MT6000 that connects over WireGuard. NordVPN and Surfshark are built into ASUS VPN Fusion as VPN types, and GL.iNet firmware has built-in profiles for IPVanish, NordVPN, PIA, PureVPN and Surfshark.

Can I use a router VPN to watch region-locked streaming?

It can help, but it's not guaranteed. A router VPN routes devices that can't run an app — like smart TVs and consoles — through a chosen region. However, streaming services actively detect and block VPN traffic, so you'll need a provider with servers that currently work for that platform. Check our streaming-specific guides for what holds up.

Is it safe to flash my router with custom firmware?

It's safe if done carefully, but flashing the wrong firmware image for your exact model and hardware revision can permanently brick the router — IPVanish's router page warns that incorrect flashing "can permanently damage your router". Always match the firmware to your precise model number and follow the project's official instructions. If that risk worries you, buy a pre-flashed router or choose a router with a built-in VPN client instead.

How many devices can a router VPN protect?

Effectively all of them. Because the tunnel lives on the router, every device that joins its Wi-Fi is covered through what your VPN counts as a single connection. Proton VPN says the router counts as one connection on its Free plan no matter how many devices connect, and ExpressVPN says you can connect as many devices as you want to the router. The real limit is the router's processor, which all those devices share.

Can I put a VPN on the router my ISP gave me?

Rarely. NordVPN says an ISP-issued router "probably does not support VPN configurations". The usual answer is to plug a VPN-capable router into a LAN port of the ISP box and join your devices to its Wi-Fi. That creates double NAT, so port forwarding and DDNS may stop working; bridge (modem-only) mode or a DMZ on the ISP box fixes it, and if both routers use the same address range, change the VPN router's LAN IP.

Can I use a free VPN on my router?

Yes, with Proton VPN. Its router page says router connections are available on all plans, including Proton Free, and that the router counts as one connection on the Free plan no matter how many devices use it. Download the WireGuard file from Downloads › WireGuard configuration with the platform set to Router; on the Free plan the only extra option is VPN Accelerator.

How do I change the VPN country on my router?

Load a different configuration file or switch to another saved profile, because one router file usually holds one location. Proton VPN notes you can't switch servers instantly on a router. TP-Link stores up to six profiles with one active, Asuswrt-Merlin runs up to five OpenVPN and five WireGuard clients, and routers running ExpressVPN support up to five device groups, each in a different location.

Why does my router VPN fail after a power cut?

Often because the router's clock is wrong until it syncs over NTP. OpenVPN checks certificate dates against that clock, and OpenWrt's documentation warns that WireGuard can refuse to pass traffic when clocks are out of sync. Make sure NTP is enabled and reachable, wait for the time to correct, then reconnect. On older ASUS firmware, the VPN client also won't reconnect by itself after the server drops.

Where is the VPN client setting on an ASUS router?

On firmware later than 3.0.0.4.388 it's VPN › VPN Fusion › Add profile, where you pick WireGuard or OpenVPN and import your provider's file (WireGuard needs firmware later than 3.0.0.4.388.23000 and a supported model). On 3.0.0.4.388 or earlier it's Advanced Settings › VPN › VPN Client › Add profile, which offers PPTP, L2TP and OpenVPN but not WireGuard.

The best VPNs of 2026, ranked

Now you know how — here are the VPNs we recommend, independently tested and ranked for speed, streaming, privacy and value. Any of them works for everything in this guide.

Editor’s Choice — Best VPN 2026
Visit ExpressVPN
1GET 79% OFF + 4 months FREE
ExpressVPN logo
9.9
Outstanding

ExpressVPN Ultra fast & secure. Great for privacy, downloads, and everyday browsing on all your devices. 24/7 live chat support.

3,000+ servers in 113 countries
Proprietary Lightway protocol
Works with all popular platforms, apps & services
Try risk free for 30 days
Visit IPVanish
2GET 83% OFFFamily Device Coverage
IPVanish logo
9.8
Excellent

IPVanish Fast speeds with unlimited device connections. Strong no-logs privacy and 24/7 live chat support. Great for families.

3,200+ servers in 112+ countries
Unlimited simultaneous connections
Company-owned server network
Try risk free for 30 days
Visit NordVPN
3GET 74% OFFAdvanced Features
NordVPN logo
9.7
Excellent

NordVPN Excellent speeds with one of the largest server networks. Strong security features and easy-to-use apps. 24/7 live chat support.

7,400+ servers in 118 countries
NordLynx protocol for top speeds
10 simultaneous devices
Try risk free for 30 days
Visit Proton VPN
4GET 70% OFFFree Tier Available
Proton VPN logo
9.6
Excellent

Proton VPN Swiss-based VPN with strong privacy focus. Audited no-logs policy and open-source apps. Great for privacy-conscious users.

20,000+ servers in 140+ countries
Swiss-based — strongest privacy laws
Open-source & independently audited
Try risk free for 30 days
Visit CyberGhost
5GET 86% OFF + 2 months FREEBeginner Friendly
CyberGhost logo
9.5
Great

CyberGhost Fast speeds and strong privacy tools. Simple apps, automatic WiFi protection, and 24/7 live chat support.

Servers in 100 countries
Automatic WiFi protection
No activity logs & no IP/DNS leaks
Try risk free for 45 days
Cheapest VPN
Visit TotalVPN
6GET 80% OFF
TotalVPN logo
9.4
Great

TotalVPN Affordable VPN with strong privacy and reliable speeds. Easy-to-use apps for all major devices. No-logs policy.

Servers in 50+ countries
Fast & secure connections
Strict no-logs policy
Try risk free for 30 days
Visit Private Internet Access
7GET 85% OFF + 2 months FREEAdvanced Security
Private Internet Access logo
9.3
Great

Private Internet Access High-speed VPN with a large server network and advanced security settings. Ad blocker included and 24/7 live chat support.

Servers in 91 countries
Ad & tracker blocker included
No activity logs & no IP/DNS leaks
Try risk free for 30 days
Visit Surfshark
8GET 88% OFF + 3 months FREEUnlimited Devices
Surfshark logo
9.2
Great

Surfshark Unlimited device connections at a budget-friendly price. Includes ad blocker and strong privacy tools. Great value for money.

4,500+ servers in 100 countries
Unlimited simultaneous connections
CleanWeb ad & malware blocker
Try risk free for 30 days

Rankings are based on our independent testing methodology. Each guide applies the criteria described on that page, including relevant performance, privacy, product features, and value data. We may earn affiliate commissions from links on this page, which helps fund our testing — this does not influence our rankings.