Put the VPN on your router
A console, a smart TV and a set-top box have one thing in common: none of them will ever run a VPN app. Configure the tunnel on the router instead and every device behind it is covered, whether or not it knows what a VPN is.
Get a router configThe devices that cannot help themselves
PlayStation and Xbox consoles have no VPN app and no way to install one. The same is true of most Samsung and LG smart TVs, Roku, Chromecast, older streaming boxes, e-readers, printers, smart speakers and essentially every piece of IoT hardware in the house.
Putting the tunnel on the router moves the problem up one level. The router holds the WireGuard connection, and every device on the network gets the tunnel simply by being connected — no app, no configuration, nothing to install on hardware that would not accept it anyway.
It also covers guests, and it survives a device being factory reset. If the goal is that everything on this network goes through the tunnel, the router is the only place that reliably delivers it.
Router or per-device?
Neither is simply better. Most households end up doing both — router for the devices that cannot run an app, client apps on the ones that can.
| On the router | On each device | |
|---|---|---|
| Covers consoles and TVs | Yes | No |
| Switch country quickly | No | Yes |
| Per-app split tunneling | No | Yes |
| Protects you away from home | No | Yes |
| Speed ceiling | Router CPU | Device CPU |
| Setup difficulty | Moderate | Trivial |
| Kill switch | Firewall rules | Built in |
What your router needs
OpenWrt
The best-supported option. WireGuard is available as a package, configuration is straightforward, and you get full control over routing and firewall rules. If your hardware can run OpenWrt, this is the path with the fewest surprises.
pfSense
Native WireGuard support and the routing flexibility to send only some VLANs or some clients through the tunnel while everything else goes direct. The right answer if you already run pfSense as your gateway.
AsusWRT
Many Asus routers support WireGuard client mode in the stock firmware, which means no flashing and no warranty questions. Check your model — support varies across the range and across firmware versions.
Most ISP routers
The box your provider supplied almost certainly cannot do this. It typically has no VPN client mode, no way to add one, and locked firmware. The usual solution is to put a capable router behind it and let the ISP box act only as a modem.
Router CPU is the real limit. Encryption is arithmetic, and a consumer router has a fraction of the processing power of a phone. A device that routes 900 Mbps unencrypted may manage 100–200 Mbps through WireGuard, and considerably less through OpenVPN. WireGuard is substantially lighter, which is why it is the only protocol we recommend for router use. If your connection is fast and the router is modest, expect the router to become the ceiling.
Roughly how it goes
Exact menus differ by firmware, but the shape is the same everywhere.
Confirm your router supports WireGuard
Check for a WireGuard or VPN client section in the firmware. If there is none and the device cannot be flashed with OpenWrt, no amount of configuration will help — you need different hardware.
Download a config file
Get a WireGuard configuration for the country you want from the download page. It is under 1 KB and contains the keys, endpoint and allowed IPs.
Import it and bring the tunnel up
Paste or upload the config into the router’s WireGuard client section and enable it. The router now holds the tunnel on behalf of everything behind it.
Set DNS to route through the tunnel
This is the step people skip. If the router keeps handing out your ISP’s resolver over DHCP, every device leaks its lookups even though traffic is tunnelled. Point DNS at the tunnel.
Add a firewall kill switch
Write a rule that drops WAN-bound traffic that is not going through the tunnel interface. Without it, a dropped tunnel silently means the whole house is browsing unprotected and nothing tells you.
Verify from a device on the network
Open the DNS leak test and what is my IP from a laptop or phone on that Wi-Fi. Both should show the VPN, not your provider.
Common questions
How do I use a VPN on a PS5 or Xbox?
Can I put a VPN on a Samsung or LG smart TV?
Will a router VPN slow down my internet?
Does the router VPN protect me on mobile data?
Can some devices bypass the router VPN?
One config, the whole house
Unlimited devices on every plan, so the router tunnel and the client apps come out of the same subscription.