Installing a VPN on your router protects every device on your network at once — including smart TVs, games consoles, streaming sticks and IoT gadgets that can’t run VPN apps themselves. You configure it once, and everything behind that router is covered automatically.
It’s the most thorough way to run a VPN at home. It’s also the most fiddly, and it isn’t the right answer for everyone. This guide covers whether you should do it, the four ways to get there, and the performance trade-off nobody mentions until after you’ve set it up.
Key Takeaway:
A router VPN trades convenience for coverage. Everything is protected, but you lose the ability to switch servers quickly or exclude one device — and your router’s processor becomes the speed limit for your whole household.
Should You Actually Do This?
Worth deciding before you start, because reversing it is more effort than setting it up.
A router VPN makes sense if you:
- Want smart TVs, consoles or IoT devices covered — they can’t run VPN apps
- Have more devices than your subscription allows connections for
- Want protection that can’t be forgotten or switched off by accident
- Have household members who won’t reliably connect a VPN themselves
Stick with apps on devices if you:
- Switch server locations regularly
- Need some devices on the VPN and others off it
- Have a fast connection and a modest router — you’ll lose a lot of speed
- Want a proper per-app kill switch, which router setups generally can’t provide
If you’re new to VPNs generally, start with How to Use a VPN and get comfortable with the apps first.
Does Your Router Support It?
You need VPN client mode — your router connecting out to a VPN service. This is different from VPN server mode, which lets you dial into your home network from elsewhere. Many routers offer the second and not the first, which trips people up constantly.
To check: log into your router’s admin panel (usually 192.168.1.1 or 192.168.0.1) and look for a section called VPN, VPN Client, or WireGuard.
| Router | VPN Client Support |
|---|---|
| Asus (most models) | ✅ Built in — the easiest mainstream option |
| GL.iNet | ✅ Designed for it, WireGuard included |
| Netgear Nighthawk | ⚠️ Some models only — check yours |
| Linksys WRT series | ⚠️ Usually needs third-party firmware |
| DD-WRT / OpenWRT / Tomato | ✅ Full support once flashed |
| ISP-supplied router | ❌ Almost never supported |
If you’re on an ISP router, don’t waste time trying — jump to Method 4.
Method 1: Your Provider’s Router Support
The simplest route. Several providers publish router-specific setup guides and configuration files, and some offer firmware or an applet that does most of the work.
- Sign into your VPN account and find the router or manual-configuration section.
- Pick your router model and follow the provider’s guide — they’re model-specific for a reason.
- Download whatever configuration files they supply.
- Apply them in your router’s VPN Client section.
Always follow the provider’s own instructions over a generic tutorial. Server addresses, ports and authentication details differ between services and change over time.
Method 2: Manual Setup (Asus Example)
Asus routers are the most common case, and the process is representative of most brands.
- Download the config files from your provider —
.ovpnfor OpenVPN, or a WireGuard config if supported. - Log into the router at
192.168.1.1. - Go to VPN → VPN Client → Add profile.
- Choose the protocol tab — WireGuard if it’s offered, since it’s dramatically faster on router hardware.
- Import the config file and enter your VPN username and password. Note that this is often a service-specific credential from your account dashboard, not your website login.
- Activate, then wait for the status to show connected.
If it fails, the usual culprits are the wrong credentials, a config file for the wrong protocol, or an expired server address.
Method 3: Flashing Third-Party Firmware
If your router lacks VPN client mode, replacing its firmware with DD-WRT, OpenWRT or Tomato adds it. This gives you the most control and works on a lot of otherwise-limited hardware.
Be clear about what you’re accepting:
- It voids your warranty.
- It can permanently brick the router if you flash the wrong build or lose power mid-write.
- Check the exact hardware revision — the same model name often covers incompatible internals, and this is the single most common way people destroy a router.
- Don’t do it to your only router unless you’re prepared to be offline while you fix it.
Confirm your specific model and revision on the firmware project’s supported-devices list before downloading anything.
Method 4: Buy a Pre-Configured or Second Router
Often the best answer, and rarely mentioned.
You can buy routers that ship with VPN-ready firmware already installed, which removes the flashing risk entirely. Compact travel routers from VPN-friendly brands are inexpensive and handle this well.
Better still is the two-router setup: leave your existing router as-is, and plug a second VPN-configured router into it. You then get two Wi-Fi networks — one normal, one tunnelled — and you choose per device simply by picking which network to join. That solves the biggest weakness of router VPNs (all-or-nothing coverage) without any compromise.
🔒 Providers With Good Router Support
Not every service documents router setup properly. These publish model-specific guides and supply the config files you’ll need:
- PureVPN — router guides and dedicated configuration files
- IPVanish — router support with unlimited device connections
More on choosing: Best VPN for Privacy in 2026.
Verify It’s Working
A connected status in the router panel isn’t proof. Test from a device on the network:
- Open What Is My IP — it should show the VPN server’s location, not yours.
- Run the VPN Leak Test to check for IP and DNS leaks.
- Check the DNS Checker — the resolver shouldn’t be your ISP’s.
- Test a second device to confirm coverage is network-wide.
Router setups leak DNS more often than apps do, because the router may keep handing out your ISP’s resolver. Set the VPN’s DNS servers manually in the router’s WAN or DHCP settings if needed — see DNS leaks explained.
Why Router VPNs Are Slower
This is the part that surprises people, and it’s worth understanding before you blame your provider.
Your router now has to encrypt and decrypt every packet for the whole household, and consumer routers have modest processors — most without hardware encryption acceleration. Your laptop handles this effortlessly; a router does not.
The practical result is that many consumer routers cap out well below their normal throughput on OpenVPN, sometimes by a large margin. If you have fast fibre and a mid-range router, you may lose a substantial share of your speed.
Two things help: use WireGuard if your router supports it, since it’s far lighter than OpenVPN, and pick a nearby server. If speeds are still poor, the router is the bottleneck — not the VPN. Compare with a speed test on and off the tunnel, and see how to diagnose slow internet.
Pros and Cons
| Advantages | Drawbacks |
|---|---|
| ✅ Covers every device automatically | ❌ Router CPU limits speed for everyone |
| ✅ Protects TVs, consoles, IoT | ❌ Changing servers means logging into the router |
| ✅ Uses one connection slot | ❌ No easy per-device exclusion |
| ✅ Can’t be forgotten or left off | ❌ Banking and streaming may object constantly |
| ✅ Guests are covered too | ❌ Setup is genuinely harder than an app |
⚠️ Troubleshooting
- Won’t connect: check you’re using the service-specific credentials from your account dashboard, not your website login.
- Connects then drops: the router may be underpowered for the protocol. Switch to WireGuard, or a closer server.
- Some devices unaffected: they may be on a guest network or 5GHz band routed differently — check your router’s network segments.
- DNS still shows your ISP: set the VPN’s DNS manually in the router settings.
- Streaming blocked for the whole house: expected. This is the moment most people move to the two-router setup.
- Locked out of the admin panel: connect by Ethernet, and if necessary reset to factory defaults with the pinhole button.
Frequently Asked Questions
Can I use a VPN on any router?
No. It needs VPN client support, either natively or through third-party firmware. Most ISP-supplied routers can’t do it at all.
Will this slow down my internet?
Yes, usually noticeably. The router handles encryption for every device, and consumer hardware isn’t built for it. WireGuard reduces the penalty substantially compared with OpenVPN.
Does it use up my device connection limit?
No — the router counts as a single connection no matter how many devices sit behind it. That’s one of the main reasons to do it.
Can I exclude one device from the VPN?
Not easily on most routers. Some Asus models support policy routing by device, but the reliable solution is the two-router setup with separate networks.
Is flashing DD-WRT safe?
It’s safe if you match the exact hardware revision and don’t interrupt the process. Get either wrong and you can permanently brick the router. Verify on the project’s supported-devices list first.
Will my smart TV work with it?
It’ll be covered, yes. Whether streaming apps cooperate is another matter — many detect and block VPN addresses regardless of how you connect. See Best VPN for Netflix.
Do I still need VPN apps on my devices?
Not at home. You will for phones and laptops once they leave the house, since the router only covers your own network.
Can I run a kill switch on a router?
Rarely in the way apps do it. Some firmware can block traffic when the tunnel drops, but it’s not standard — which is a genuine security gap compared with a desktop app.