
This page contains affiliate links. If you make a purchase through one, we may earn a commission at no extra cost to you.
Running a VPN on your router protects every device on your home network at once — including smart TVs, game consoles, and IoT gadgets that can’t run a VPN app themselves. It’s more involved to set up than installing an app, so here’s what’s actually required before you start. See Surfshark’s current plans
Check Whether Your Router Supports It First
This is the step most guides skip, and it’s the one that actually determines whether this is a quick project or a frustrating one. Most stock ISP-provided routers, along with common consumer brands like Arris, Belkin, Cisco, most Linksys models, TRENDnet, TotoLink, and Ubee, don’t support the OpenVPN or WireGuard protocols out of the box. If your router is one of these, native VPN setup isn’t possible without replacing the firmware entirely.
Routers that do support manual VPN configuration include Asus (and ASUSWRT-Merlin firmware), OpenWRT, pfSense, DD-WRT, and GL.iNet routers that ship pre-flashed for this purpose. If you’re shopping for a new router specifically to do this, a GL.iNet model or an Asus router running Merlin firmware is the most beginner-friendly starting point.
Two Real Paths: Native Config or a Pre-Flashed Router
- Manual configuration on a supported router. If you already own an Asus, OpenWRT, pfSense, or DD-WRT router, Surfshark publishes setup guides for generating the OpenVPN or WireGuard configuration files and installing them directly on the router’s admin interface.
- A pre-flashed router. If your current router isn’t on the supported list and you don’t want to flash firmware yourself, a GL.iNet travel/home router ships with VPN client support built in and just needs your account credentials entered.
What You’re Actually Trading Off
A router-level VPN connection typically runs a single connection for the whole household rather than the per-device server selection you get from a phone or laptop app — so if one person wants to stream something region-locked while someone else just wants a fast, low-latency connection for gaming, you can’t set that up separately per device the way you could with individual device apps. Most router setups also cap out at a lower maximum speed than a direct device connection, since the router’s processor is doing the encryption work instead of a more powerful phone or laptop CPU. This is real and worth knowing before you commit the setup time, not a reason to avoid router-level VPN entirely — just a genuine trade-off against covering every device on the network at once.
Who This Setup Actually Makes Sense For
If you’re mainly protecting a phone and a laptop, per-device apps are simpler and give you more flexibility — see our guide to the best VPN setup for a multi-device household for that approach. Router-level VPN is worth the setup time specifically when you have devices that can’t run a VPN app at all — smart TVs, streaming boxes, consoles, or smart home hardware — and you want those covered too.
Do I need to replace my router to set up a VPN on it?
Only if your current router isn’t on the supported list (Asus, ASUSWRT-Merlin, OpenWRT, pfSense, DD-WRT, or pre-flashed GL.iNet). Most stock ISP routers and common consumer brands like Arris, Belkin, and most Linksys models don’t support this natively.
Will a router-level VPN slow down my whole network?
Some speed reduction is normal since the router’s processor handles the encryption instead of your phone or laptop’s CPU. How noticeable it is depends on your router’s hardware and your base internet speed.
Can different devices on the same router connect to different VPN servers?
Generally no — a router-level VPN typically applies one connection to the whole network, unlike device apps where each device can pick its own server independently.