VPN on a router: set it up once and the whole apartment works

A VPN on a router is set up when there are more devices in the home than you feel like configuring one by one: a television on Tizen, a games console, a speaker, a work laptop and guests' phones. The router brings the connection up once and hands it to the whole apartment, and the devices have no idea a tunnel exists. Let us be honest straight away: we do not release firmware of our own. Our protocols are VLESS and ShadowSocks, so everything comes down to a single question: can your firmware run a compatible client.

See pricing

The router connects as a single device, and the equipment behind it needs no client of its own.

Setting a VPN up on a router: the order of work

The exact menu items differ from firmware to firmware, so the steps are described by meaning. It is always worth starting by checking the router itself.

  1. 1

    Check what the router can do

    Look up the model and the firmware. What you need is the ability to install third-party packages: the OpenWrt repository, components and OPKG on Keenetic, or a full Linux on a mini PC. Factory firmware on mass-market models usually gives no such option.

  2. 2

    Pick up the connection key

    Get access in your dashboard or in the Telegram bot: one trial access is due to every user, and plans are arranged in the same place. Copy the connection key — you will need it in full, together with every parameter that follows the server address.

  3. 3

    Install a compatible client

    Through the firmware's package manager install a client on the XRay core for VLESS or a ShadowSocks package. Make sure there is enough room in the flash memory: on routers with 8 MB of storage the package often simply does not fit.

  4. 4

    Enter the key and bring the tunnel up

    Import the key or transfer its parameters into the client's configuration, then start the service and check its log. At this stage it helps to leave one test laptop on the network for a while, so that you see the result straight away.

  5. 5

    Decide who goes through the VPN

    Set up the routing rules: some firmware can send only selected devices or domains into the tunnel. That way the TV and the console work through the VPN, while the banking apps on your phone stay on the ordinary channel.

  6. 6

    Check the speed under load

    Start a video in high quality and a file download alongside it, then look at the temperature and the processor load of the router. If the speed drops by half or more, the bottleneck is the processor, and that is cured by changing the device.

Why a VPN on a router is worth having at all

The main reason is the devices a client cannot be installed on. Samsung televisions on Tizen and LG on webOS, games consoles, smart speakers, operators' TV boxes, printers and cameras: none of them has an app store or any way to add a connection key. The router removes the question entirely, because it works a level below — it hands the devices a ready-made route. The second reason is the number of settings: instead of ten installations you do one. The third is guests and temporary devices, which simply join your network and get the same access. Finally, the router connects to the service with a single connection, and how many machines sit behind it is a matter for your home network; the device limit itself is set by the plan and is visible in the dashboard. There is one price for the convenience: everything depends on a single device, and if that device is weak, everyone suffers.

Which routers can work with a VPN at all

Here it matters to tell two different statements apart. Almost any modern router can bring some form of VPN connection up: the factory firmware of TP-Link, Xiaomi, Mercusys and the like usually has PPTP, L2TP, sometimes OpenVPN or WireGuard. But those are other people's protocols, not ours: RobinGood VPN works over VLESS and ShadowSocks, because as a rule they cope better with modern filtering methods. So what the router needs is not abstract VPN support but the ability to run a client on the XRay or Mihomo core. That ability comes from firmware that has a package manager and enough memory. This is a fact about routers and their firmware, not our own development: we do not release firmware, we do not supply images and we do not sell ready-made devices.

Firmware or deviceWhat to check before setting up
OpenWrtWhether the repository has an XRay or Mihomo package and whether there is enough flash memory
KeeneticThe presence of components for third-party packages and of an OPKG partition on a USB drive
Asuswrt-Merlin, PadavanThe ability to run third-party binaries and the amount of free memory
Factory firmware on mass-market modelsUsually only PPTP, L2TP, OpenVPN or WireGuard — our protocols are not supported
A mini PC or single-board computer as a routerFull Linux, with practically no limits on the choice of client

What the device has to be capable of: XRay or Mihomo

We issue a connection key, not firmware, so the compatibility question runs like this: can the firmware start a process that understands VLESS or ShadowSocks. With ShadowSocks it is simpler — packages for it have existed for a long time and are found in the repositories of many firmwares. With VLESS it is harder: you need XRay or a compatible core such as Mihomo, and that is a separate binary file, one that requires room in storage and free RAM. Hence the practical rule: before buying a router for this task, look not at the number of antennas but at the amount of flash memory, the amount of RAM and the presence of a USB port for an external drive. A budget router with 8 MB of flash memory physically cannot hold the package it needs, however many Wi-Fi bands are listed on the box.

An alternative: a separate access point or a mini PC

Reflashing the main home router is not compulsory and often not needed: it holds the whole network, and a failed experiment will leave the entire apartment without internet. The calmer option is a second device. It can be an inexpensive router with suitable firmware placed at a second level: it takes internet from the main one and hands out a Wi-Fi network of its own, in which the traffic already goes through the tunnel. You connect the TV and the console to that network and leave everything else on the main one. More flexible still is a mini PC or a single-board computer with ordinary Linux: there is several times more performance there, the client installs in the standard way, and updates do not turn into a quest. That scenario is especially fitting when the main router was issued by the internet provider and its firmware cannot be changed at all.

Limits: the speed runs into the router's processor

This is rarely warned about honestly. The encryption is done by the router's processor, and the processors of home models are weak: usually one or two cores at around a gigahertz with no hardware acceleration for cryptography. Such a router pushes the provider's direct channel through thanks to hardware packet processing, but that processing does not work for traffic that has to be decrypted and encrypted again. As a result, on a budget model noticeably less passes through the tunnel than over the direct channel, and what it runs into is not our server but the hardware in your home. It is easy to check: measure the speed on a computer with the client directly and then through the router. If it is significantly slower through the router, the router is the cause. That is cured either with a more powerful device or with split routing.

  • A weak router processor limits the speed more than the tunnel itself does
  • Hardware packet acceleration is not applied to encrypted traffic
  • Compare the speed directly and through the router to find the bottleneck
  • A mini PC or single-board computer removes the processor limit

Split routing: only what is needed goes through the tunnel

Wrapping all of the home traffic into the tunnel is usually unnecessary and even harmful. Russian websites, banking apps, government services and local services work faster and more predictably over the direct channel, and some refuse outright to admit requests from foreign addresses. Firmware with a full client can divide traffic by rules: by device, by domain or by address lists. A practical scheme looks like this: the TV, the box and the console always go through the VPN, the laptop goes by domain, and the phones with banking apps stay on the direct channel. The side benefit is obvious: less encrypted traffic passes through the router's processor, which means the speed ceiling from the previous section stops being a problem in everyday use.

If the router does not support the protocol you need

This is the most common outcome, and there is nothing frightening about it. The factory firmware of most models will not let you install XRay or Mihomo, and not everyone wants to change the router for the sake of one task. Then the usual scheme works: the client is installed on the devices themselves. Phones, tablets, computers and Android boxes are set up in a couple of minutes, the device limit on your plan is usually enough for a home's fleet of equipment, and a television on Tizen or webOS is helped by an inexpensive Android box. An intermediate option is a second router or a mini PC used only for the devices a client cannot be installed on. The choice here is purely practical: the router is more convenient, the devices are simpler, and both methods coexist calmly in one apartment.

Start with the key, not with the firmware

First pick the access up in your dashboard or in the Telegram bot and check the connection on a computer, and only then move it to the router. That way you see straight away where the bottleneck is — in the channel or in the hardware.

Frequently asked questions

Can a VPN be set up on a Keenetic router?

Yes, if the model can install third-party packages: KeeneticOS supports installing additional components and an OPKG repository on a USB drive, which means a client that supports our protocols can be put on it. There is no ready-made firmware from us — we give a connection key, and the setup is carried out with the firmware's own means. The order and the presence of menu items depend on the model and the version.

Will an ordinary router from the internet provider do?

As a rule, no. Provider and mass-market factory firmware is closed to the installation of third-party packages, and the built-in VPN clients are meant for PPTP, L2TP or OpenVPN, which we do not have. The practical way out is to put a separate router with suitable firmware at a second level, or to run the client straight on the devices.

Do you release firmware of your own for routers?

No. We provide access over the VLESS and ShadowSocks protocols and support the Happ, Koala Clash and Outline clients, but we neither develop nor distribute firmware for routers. Whether it works on a router depends entirely on whether its firmware can run a compatible client.

How much will the speed drop with a VPN on a router?

It depends on the router's processor, not on our server. On budget models encrypted traffic is processed in software, and the speed ceiling turns out noticeably lower than the direct channel. Compare the speed on a computer with the client and through the router: if it is slower through the router, the bottleneck has been found.

Can I send only the TV through the VPN?

Yes, that is standard practice. Firmware with a full client lets individual devices, domains or address lists be directed into the tunnel, so the TV and the console go through the VPN while everything else stays on the direct channel. It also takes load off the router's processor.

How is the router counted against the device limit?

The device limit is set by your plan, and the figure in force is visible in the dashboard. The router connects to the service with a single connection and hands access on, so the equipment behind it needs no client of its own. For the exact terms on device numbers, see the description of your plan.

Which is better: setting the router up or installing a client on every device?

The router is more convenient when the home has a lot of equipment with no client support — televisions, consoles, speakers. A client on the device is simpler and faster, and it also gives protection away from home, in cafes and on public Wi-Fi. Many people use both options at once, and that is fine.

Do I need a separate plan for the router?

No, there is one account. The same connection key works on the router, on computers and on phones within the shared device limit. Plans are arranged in the dashboard or through the bot, and the available payment methods are shown on the payment page.

Will access to Russian websites remain?

Yes, if split routing is set up: local sites, banking apps and government services go over the direct channel, and only what is needed leaves through the tunnel. If you wrap all the traffic up entirely, some Russian services may restrict access from foreign addresses.

Do you keep logs of home traffic?

No. We do not record visited addresses and do not store the contents of traffic — neither for a router nor for individual devices. All the service needs to work is information about the active subscription and the technical load on the servers.

One tunnel for the whole apartment

Check whether your firmware can run a client with VLESS or ShadowSocks. If it can, set the router up; if not, install the client on the devices or add a second access point.

Updated August 21, 2026