Skip to main content
FixMyTech

What a VPN Router Is and Whether It Is Worth Setting Up

By

Published

7 min read

Share

Short answer

A VPN router runs the VPN client itself, so every device on the network is tunnelled without installing anything — including smart TVs, consoles and smart-home devices that have no VPN app. The cost is speed, because consumer router processors are weak at encryption, and the loss of per-device control unless the router supports policy routing.

On this page

A VPN router is simply a router running the VPN client, so the tunnel starts at the edge of your network rather than on each device. Everything behind it is tunnelled automatically, with nothing installed anywhere.

The appeal is obvious and the pitch is usually accurate as far as it goes. What gets left out is that consumer routers are, as a class, slow at the one task this asks of them, and that a network-wide tunnel makes every subsequent networking problem harder to diagnose.

Why it is slower than you expect

Encryption is arithmetic, and the processor in a typical home router is a low-power part chosen to move packets cheaply, not to do arithmetic. Most consumer models have no AES hardware acceleration at all.

Your laptop and your phone both do. Modern processors run AES in dedicated instructions, which is why the VPN app on your phone barely dents your battery while the same tunnel on a router caps out well below your line speed.

The practical result: a connection that delivers hundreds of megabits without a VPN can drop to a fraction of that once the router is doing the encryption. The exact figure depends entirely on the router’s processor and the protocol, and manufacturers rarely publish honest numbers, so the only reliable method is to test your own.

WireGuard changes the arithmetic meaningfully. It is a far smaller, simpler protocol than OpenVPN and routers that support it typically manage several times the throughput on identical hardware. If your router offers both, this is not a close call.

When it is genuinely the right answer

Situation Router VPN?
Smart TV, console or streaming stick with no VPN app Yes, this is the main case
Smart-home devices you want tunnelled Yes
More devices than your subscription’s connection limit Yes
You want it on your laptop and phone only No, use the apps
Your connection is faster than the router can encrypt No, you are paying in speed
You need to toggle the VPN often No, router changes are slow

The clearest case is a device that cannot run a VPN client. That is a real limitation with no other workaround, and it is why most people who set this up did it for a television.

Getting one working

Three routes, in increasing order of effort:

Stock firmware with built-in VPN client support. Some manufacturers include it; look for a VPN Client section in the admin page, distinct from the VPN Server section. If it is there, you upload a configuration file from your provider and it works. This is by far the least painful option.

Third-party firmware. OpenWrt, DD-WRT and similar replace the router’s operating system and add VPN client support to hardware that lacked it. Flashing firmware can permanently disable a router if the model is not exactly supported. Check your hardware revision against the project’s compatibility list before starting, not after.

A router sold preconfigured. Some vendors sell hardware with VPN client firmware already installed. It saves the flashing risk and you pay for that.

Step-by-step router VPN setup covers the configuration itself in detail.

What it does not cover

A router VPN protects devices on that network, which sounds comprehensive until you count what is not on it.

Your phone leaves the house. The moment it joins mobile data or any other Wi-Fi, it is on an untunnelled connection, and a router setup gives it nothing. The same applies to a laptop taken to an office or a café, which is precisely the situation people most often cite as the reason they wanted a VPN.

Guest networks are frequently routed separately in firmware and may bypass the tunnel entirely. So, on some routers, is any device given a static address outside the main DHCP range.

The practical consequence is that a router VPN is a supplement to apps on mobile devices rather than a replacement for them. If you set one up and uninstalled the apps, you reduced your coverage rather than extending it.

The diagnosis problem

This is the cost nobody mentions in the buying guides. Once the router tunnels everything, every network fault acquires an extra suspect.

A site that will not load might be the site, your provider, your DNS, or the VPN server being blocked by that site. A video call that stutters might be your Wi-Fi or might be the router’s processor saturating. A device that cannot find the printer might be a routing rule.

The usual troubleshooting instinct — turn the VPN off and see — now means logging into the router admin page and waiting for a reconnection, rather than clicking a toggle. You will do this more often than you think.

Two mitigations help. First, use a router that supports policy-based routing, so you can send specific devices around the tunnel and leave one laptop untunnelled as a control. Second, keep the VPN provider’s app installed on your phone anyway, so you can compare behaviour quickly.

What to check after setting it up

Do not trust the router’s status page. It reports that the tunnel is up, not that traffic is using it.

  1. On a device behind the router, load an IP-checking site and confirm it shows the VPN server’s location rather than yours.
  2. Run a DNS leak test. Routers commonly keep handing out the provider’s DNS servers over DHCP even with the tunnel up, which leaks every domain you visit to your internet provider while the status page says “connected”.
  3. Check the guest network separately if you use one.
  4. Check a device that was already connected before the tunnel came up, since it may be holding stale settings.

The full leak-checking procedure takes a couple of minutes and is worth doing after every firmware update, because updates reset DNS settings more often than they should.

Realistic expectations

If your internet connection is modest and your router is reasonably modern with WireGuard support, a router VPN is a fine arrangement and you may not notice the speed cost at all.

If you have a fast line, expect the router to become the ceiling. A gigabit connection through a consumer router’s VPN client is not a gigabit connection, and no setting changes that — the processor is the limit.

The honest recommendation is to run the apps on your laptop and phone, and use the router only for the devices that cannot run an app. That gets most of the coverage with almost none of the speed penalty, and it leaves you a working untunnelled path for diagnosing everything else.

Frequently asked questions

Will a VPN router slow down my whole network?
Usually yes, and often more than people expect. A typical consumer router manages somewhere in the tens of megabits with OpenVPN because its processor has no crypto acceleration; WireGuard is considerably more efficient but still bounded by that CPU.
Can I still use the internet normally on some devices?
Only if the router supports policy-based routing, which lets you choose per device or per destination which traffic goes through the tunnel. Many stock firmwares do not, in which case it is all or nothing.
Do I need to replace my router?
Not necessarily. Some manufacturers ship VPN client support in their stock firmware. Where they do not, third-party firmware adds it, but flashing carries a real risk of making the router unusable if the model is not supported.
Is a VPN router better than running the app on each device?
Better for coverage, worse for speed and flexibility. Apps on individual devices use that device's processor, which is far faster at encryption, and can be turned off per device in seconds.
Does a VPN router protect devices on guest Wi-Fi?
It depends on the firmware. Guest networks are often routed separately and may bypass the VPN entirely. Check by loading an IP-checking site on a device joined to the guest network rather than assuming.

All VPN guides