Skip to content
LunoVPN
Router

Put the VPN on your router

A console, a smart TV and a set-top box have one thing in common: none of them will ever run a VPN app. Configure the tunnel on the router instead and every device behind it is covered, whether or not it knows what a VPN is.

Get a router config
Consoles Smart TVs Everything else
Why bother

The devices that cannot help themselves

PlayStation and Xbox consoles have no VPN app and no way to install one. The same is true of most Samsung and LG smart TVs, Roku, Chromecast, older streaming boxes, e-readers, printers, smart speakers and essentially every piece of IoT hardware in the house.

Putting the tunnel on the router moves the problem up one level. The router holds the WireGuard connection, and every device on the network gets the tunnel simply by being connected — no app, no configuration, nothing to install on hardware that would not accept it anyway.

It also covers guests, and it survives a device being factory reset. If the goal is that everything on this network goes through the tunnel, the router is the only place that reliably delivers it.

Trade-offs

Router or per-device?

Neither is simply better. Most households end up doing both — router for the devices that cannot run an app, client apps on the ones that can.

On the routerOn each device
Covers consoles and TVsYesNo
Switch country quicklyNoYes
Per-app split tunnelingNoYes
Protects you away from homeNoYes
Speed ceilingRouter CPUDevice CPU
Setup difficultyModerateTrivial
Kill switchFirewall rulesBuilt in
Supported

What your router needs

OpenWrt

The best-supported option. WireGuard is available as a package, configuration is straightforward, and you get full control over routing and firewall rules. If your hardware can run OpenWrt, this is the path with the fewest surprises.

pfSense

Native WireGuard support and the routing flexibility to send only some VLANs or some clients through the tunnel while everything else goes direct. The right answer if you already run pfSense as your gateway.

AsusWRT

Many Asus routers support WireGuard client mode in the stock firmware, which means no flashing and no warranty questions. Check your model — support varies across the range and across firmware versions.

Most ISP routers

The box your provider supplied almost certainly cannot do this. It typically has no VPN client mode, no way to add one, and locked firmware. The usual solution is to put a capable router behind it and let the ISP box act only as a modem.

Router CPU is the real limit. Encryption is arithmetic, and a consumer router has a fraction of the processing power of a phone. A device that routes 900 Mbps unencrypted may manage 100–200 Mbps through WireGuard, and considerably less through OpenVPN. WireGuard is substantially lighter, which is why it is the only protocol we recommend for router use. If your connection is fast and the router is modest, expect the router to become the ceiling.

Setup

Roughly how it goes

Exact menus differ by firmware, but the shape is the same everywhere.

Confirm your router supports WireGuard

Check for a WireGuard or VPN client section in the firmware. If there is none and the device cannot be flashed with OpenWrt, no amount of configuration will help — you need different hardware.

Download a config file

Get a WireGuard configuration for the country you want from the download page. It is under 1 KB and contains the keys, endpoint and allowed IPs.

Import it and bring the tunnel up

Paste or upload the config into the router’s WireGuard client section and enable it. The router now holds the tunnel on behalf of everything behind it.

Set DNS to route through the tunnel

This is the step people skip. If the router keeps handing out your ISP’s resolver over DHCP, every device leaks its lookups even though traffic is tunnelled. Point DNS at the tunnel.

Add a firewall kill switch

Write a rule that drops WAN-bound traffic that is not going through the tunnel interface. Without it, a dropped tunnel silently means the whole house is browsing unprotected and nothing tells you.

Verify from a device on the network

Open the DNS leak test and what is my IP from a laptop or phone on that Wi-Fi. Both should show the VPN, not your provider.

FAQ

Common questions

How do I use a VPN on a PS5 or Xbox?
Through the router. Neither console supports a VPN app, and neither can install one. Configure WireGuard on the router and the console is covered automatically, because everything on the network is. The alternative — sharing a VPN connection from a PC over Ethernet — works but is fragile and has to be redone every time.
Can I put a VPN on a Samsung or LG smart TV?
Not directly; neither platform allows a VPN app. The router is the practical answer. An Android TV box connected to the TV is the other option, since Android TV does run VPN apps.
Will a router VPN slow down my internet?
Usually yes, and the router is the bottleneck rather than the VPN. Consumer routers have limited CPU for encryption — a device that handles 900 Mbps unencrypted may manage 100–200 Mbps over WireGuard. If your line is fast, run the client app on devices that can take one and keep the router tunnel for the ones that cannot.
Does the router VPN protect me on mobile data?
No. It only covers devices while they are connected to that network. Your phone loses the protection the moment it leaves the house and switches to mobile data, which is why the app matters on devices that can run it.
Can some devices bypass the router VPN?
Yes, with policy-based routing on OpenWrt or pfSense you can send specific devices or VLANs straight out while everything else stays tunnelled. Useful for a work laptop with its own corporate VPN, or a TV that refuses to work behind a foreign IP address.

One config, the whole house

Unlimited devices on every plan, so the router tunnel and the client apps come out of the same subscription.