14 models compared
Routers with a built-in VPN server
Routers that can host a VPN server on the device — WireGuard, OpenVPN, or both. Sorted by total wireless bandwidth; for VPN speed, look at the processor on each product page and read the section below.
| Model | Wi-Fi | Total speed | WAN | Wired ports | USB | Year | Price |
|---|---|---|---|---|---|---|---|
| ASUSROG Rapture GT-BE98 ProBE30000 · Router | Wi-Fi 7Quad-band | 30,198Mbps | 10G | 2×10G + 4×2.5G + 1×1G | 2 | 2024 | $699.99 |
| ASUSRT-BE96UBE19000 · Router | Wi-Fi 7Tri-band | 18,669Mbps | 10G | 2×10G + 4×1G | 2 | 2024 | $699.99 |
| TP-LinkArcher BE800BE19000 · Router | Wi-Fi 7Tri-band | 18,656Mbps | 10G | 2×10G + 4×2.5G | 1 | 2023 | $599.99 |
| ASUSZenWiFi BT8BE14000 · Mesh system | Wi-Fi 7Tri-band | 13,654Mbps | 2.5G | 2×2.5G + 2×1G | 1 | 2024 | $279.99 |
| UbiquitiDream Router 7Router | Wi-Fi 7Tri-band | 10,688Mbps | 10G | 1×10G + 4×2.5G | — | 2025 | $279.00 |
| ASUSZenWiFi XT9AX7800 · Mesh system | Wi-Fi 6Tri-band | 7,780Mbps | 2.5G | 1×2.5G + 3×1G | 1 | 2022 | $239.99 |
| ASUSRT-AX92UAX6100 · Router | Wi-Fi 6Tri-band | 6,071Mbps | 1G | 4×1G | 2 | 2019 | $229.99 |
| GL.iNetFlint 2AX6000 · Router | Wi-Fi 6Dual-band | 5,952Mbps | 2.5G | 2×2.5G + 4×1G | 1 | 2024 | $169.99 |
| ASUSRT-AX57AX3000 · Router | Wi-Fi 6Dual-band | 2,976Mbps | 1G | 5×1G | — | — | $129.99 |
| GL.iNetBeryl AXAX3000 · Travel router | Wi-Fi 6Dual-band | 2,976Mbps | 2.5G | 1×1G | 1 | 2023 | $99.90 |
| GL.iNetPuli AXAX3000 · Travel router | Wi-Fi 6Dual-band | 2,976Mbps | 2.5G | 1×1G | 1 | 2023 | $459.90 |
| GL.iNetSpitz AXAX3000 · Modem-router | Wi-Fi 6Dual-band | 2,976Mbps | 2.5G | 1×2.5G + 1×1G | 1 | 2023 | $379.99 |
| GL.iNetSlate AXAX1800 · Travel router | Wi-Fi 6Dual-band | 1,800Mbps | 1G | 3×1G | 1 | 2022 | $119.99 |
| GL.iNetOpalTravel router | Wi-Fi 5Dual-band | 1,167Mbps | 1G | 3×1G | 1 | — | $39.99 |
Browse the full catalog with all filters →
Two jobs, often confused
"VPN router" is used for two opposite setups, and a router can be good at one and useless at the other.
Remote access — a VPN server on your router. You connect back to your home network from anywhere: reach a NAS, a home lab, a printer, or a security camera without exposing any of it to the internet. This is what the list above filters on.
Whole-network tunnelling — a VPN client on your router, sending outbound traffic through a commercial VPN provider. Everything behind the router is covered, including devices that can't run VPN apps. That's a different feature flag; filter for it on the catalog page.
WireGuard or OpenVPN
WireGuard is newer, dramatically faster on the same hardware, and simpler to configure — a keypair and an endpoint. It reconnects near-instantly when a phone changes networks. Prefer it where both ends support it; the WireGuard-only list is narrower and better.
OpenVPN is older and slower — expect roughly a third of the WireGuard throughput on identical hardware — but it's supported nearly everywhere and can run over TCP on port 443, which gets through restrictive networks that block WireGuard's UDP outright. Worth having as a fallback.
IPsec/L2TP shows up on some models. Native client support on phones and laptops is its main advantage; performance and configuration are worse than either of the above.
The number nobody prints
VPN throughput is set by the router's CPU, not its Wi-Fi rating, because encryption runs in software on the main processor. A router advertising 5,400 Mbps of wireless may move 80 Mbps through a VPN tunnel. Neither figure is wrong; they measure unrelated things.
Rough current-generation expectations for WireGuard: 50–100 Mbps on entry-level dual-core ARM, 150–400 Mbps on quad-core mid-range and flagship parts. Divide by about three for OpenVPN. Where a manufacturer publishes the processor, it's on the product page under Processor — and it is a better predictor of VPN performance than everything else on that page combined.
Finally: a server needs to be findable. Home connections usually have changing IP addresses, so check for a dynamic DNS client, and check whether your ISP puts you behind CGNAT — if it does, inbound connections won't reach you at all without a relay, whatever the router supports.