It seems like Mullvad, Proton, IVPN, Obscura, and many others are working on beefing up their apps, which is great, don’t get me wrong. However, most of these features are not usable on a router. I can only import the WireGuard configuration file.
Is there a limit to what can be done to enhance the privacy and security of using these VPNs at the router level?
Would you guys agree that using these VPNs at the router level may be less feature-rich and potentially less private and secure at the router level?
Why are you conflating less feature rich to inferior privacy/security?
You still get that encrypted tunnel for what VPNs provide. If you want the bells and whistles, the apps have always been the way to go.
Privacy is the same as on the app as it is if set up on the router. I don’t think you should consider additional GUI features as an improvement on the same because it’s just a feature. The core tech of what a VPN is still provided at equivalent quality (encrypted tunnel) if using the app or on the router.
Some of those additional features are just better obfuscation methods to get connected in highly restrictive regions. But generally speaking, I see them as the same.
Proton also has their netshield aka tracker and malware blocker in the Wireguard options when you generate a new profile 
OpenWRT is the top shelf router firmware for privacy & security. It is pretty feature-complete
At the router level, a single wireguard tunnel effectively hides all internet traffic from any adversaries between your LAN and the VPN server. Your traffic is private from the ISP, and your IP is private from the endpoint webserver
Why do you imply that this single wireguard config is insufficient? What do you think would be gained by a phone-like VPN config app at the router level?
I’d rather not use that, so disable it when I generate the configuration file.
I believe Mullvad’s DAITA (Defense Against AI Traffic Analysis) feature is only available through their app.
A single wireguard tunnel obscures your traffic from your ISP, but your ISP may not be the only party you care about. If you’re trying to compartmentalize different parts of your life (like for example you want to have a work identity and a personal identity and you don’t want anyone to infer that the two are the same person) then it helps if each identity’s traffic is entering the clearnet from a different IP.
A router that supports Policy-Based Routing (PBR), like OpenWRT, can allow you to direct traffic through different tunnels depending on a variety of factors, such as the source device, time of day, etc…
At the end of the day, a router is just a computer. Most of what you can do with the VPN on a phone/laptop could feasibly be done on the router too, though VPN providers tend to put their energy into apps because that’s approachable from most people’s technical ability.
Is there a compelling reason you’d want to manage this at the router level? Id be inclined to think you’d minimize the risk of leakage by assigning each “persona” to a dedicated tunnel at the lowest level possible, ie on the pc/device itself
All the functionality and security that the plain wireguard-go package on openWRT misses compared to what Mullvad offers for starters. Have you even used OpenWRT?
Android’s always on VPN blocks LAN traffic, aggregating multiple devices into a segmented VPN VLAN saves everyone’s CPU cycles, centralizes the management, saves up devices slots and allows unsupported devices to use the VPN connection.
Mullvad’s DAITA multihop, QUIC, LWO obfuscation are indeed vendor locked in. iVPNs V2Ray is vendor agnostic, but no user friendly way of setting up a router exists, so yeah, i’d agree. The good news are, they’re in the process of developing an OpenWRT package.
Security wise, even stock settings OpenWRT has a large attack surface for an attacker
* **dnsmasq:** backport six upstream CVE-fix patches to dnsmasq 2.91:
* CVE-2026-2291: heap buffer overflow in DNS domain-name handling.
* CVE-2026-4890 / CVE-2026-4891: DNSSEC crashes via crafted NSEC bitmaps / RRSIG packets.
* CVE-2026-4892: buffer overflow on large DHCPv6 CLIDs (only with `--dhcp-script`).
* CVE-2026-4893: broken EDNS Client Subnet validation.
* CVE-2026-5172: buffer overflow in `extract_addresses()` on crafted resource records.
I’d say this is a perfectly valid question. NordVPN for example developed NordLynx as a way to bolster WireGuard security (or at least that is what they claim, I’m not knowledgable enough to confirm or deny this) but this feature is only available through their own tools / apps. Officially they no longer even support WireGuard router profiles.
You mean Mullvad or IVPN is developing an OpenWRT package? Where can I get the details?
I should’ve clarified i meant Mullvad. Their mullvadvpn-app has a couple of openwrt development branches you can take a look at.
I haven’t seen anyone talking about it. Is it close to being released, or is it far off in the future?
While router-level VPNs sound great for total privacy, they come with some serious downsides that make them a bad fit for most people, especially if you use location-based services.
The Hardware Headache Most home routers just aren’t built for it. They usually have weak CPUs and limited RAM, which leads to massive speed drops and overheating issues. Plus, let’s be real: even if you find a router that can handle a VPN, are you actually going to bother updating the firmware every time a security patch drops? Probably not.
The “Real Location” Nightmare This is the big one. Banks and government sites often flag logins from foreign IPs or data centers as suspicious. You could end up locked out of your own accounts because your router is masking your location.
The Verdict Unless you have a specific need to protect dumb IoT devices that can’t run VPN apps themselves, the performance hit and setup complexity usually aren’t worth the trouble for the average user.
MT7621, a 2013 era chip, can hit 400mbps+ Wireguard.
outbound rotations are possible with every mainstream cores like sing-box/xray.
“Location based services”… Well, you didn’t realize that the primary usecase for routers is policy based routing when promoting.