Configure a dedicated router so that all Internet traffic goes through your VPN service
In this test we are going to configure an independent router at home, in which we will guarantee that only the traffic to the internet goes through VPN.
Looking for gigabit ethernet hardware, with wireless and constant upgrades, we experimented with a MikroTik hAP ac2 device.
There are many more devices with RouterOS and also the possibility to virtualize RouterOS on a computer with several network interfaces. You can also do it with openWRT without any problem, but not on this model.
About the VPN service compatible with Wireguard, say that there are many, in this example we are going to do it with Mullvad, there are many other services that I have not tested like iVPN, lnvpn.net that are also compatible.
Requirements por this test:
MikroTik router / RouterOS installed Mullvad VPN service or another
#Advantages:
-Wired and wireless network with output to the internet via VPN.
-Being able to have several devices connected with the same VPN account.
-Low cost and consumption.
-Improve the performance and stability of the VPN connection, avoid problems with kill-switch, leaks in the internet traffic, etc. .......
Remember that this example is for having a second router, but there are many more configuration options!
#Getting Started:
The first thing to do is to access the Mullvad VPN service platform and download the configuration files for wireguard. Example:
Open the file with a text editor and configure the variables.
We can save it as 'configuration.rsc' to load it later.
Access the router through WinBox and upgrade to RouterOS 7 if it is not already installed. Once inside, we reset the router without any default configuration in System - Reset Configuration:
![](
The router will reboot and boot without any factory settings.
Go to Winbox, Files and upload the file with the Upload button. Access Winbox TERMINAL and type the following command:
/import file=configuration.rsc
Once imported we would already be connected.
*Important to have the ethernet1 port connected to our router.
We can connect via WiFi to our new router, or even to ports 2,3,4 and 5. This is a very basic configuration, from here you can do much more.
Enjoy it!
Speed tests...
It all depends on your connection, your VPN service, the distance, etc... But it is not bad to get about 300Mbps symmetrical in almost any location, even much more. The advantage of being able to connect several mobile devices to a new wifi network with VPN is very convenient.
reply
Bookmarked and added to ToDo-list, thanks.
reply
Second that!
reply
Excellent! So many new things to learnt
reply
Privacy 🔏 and security of your browsing experience at its best
reply
GL-iNet routers are also great for this, even easier to set up.
They support Mullvad out the box (as well as custom Wireguard and OpenVPN configs).
reply
If I'm not mistaken you can also install openwrt on those devices, I don't know if they come with other custom firmware out of the box. About the type of VPN, wireguard is much faster and easier to configure than OpenVPN, but yes, both are good ;)
The idea is that each user takes his necessary hardware and installs a suitable OS that allows many configurations and upgrades and personally I think there is more variety in MikroTik than in GL.inet:
I would very much like to do more testing with other hardware.
We continue to contribute ;)
reply
Great info! 👏 👏 👏
reply
Thanks a lot.
I have a few questions:
1. Does this still require the main ISP Router to work? 2. Is MikroTik recommended, or can I use other routers like Xiaomi? 3. What is the watt consumption? 4. If I use Proton VPN, how can I easily change to a different country or make other configurations easily?
reply
Thanks a lot. I have a few questions:
  1. Does this still require the main ISP Router to work?
This test is to have it as a secondary router connected to your router. You could use it perfectly well as a main router, even if you have FTTH you can connect it through an ONT such as the 'Alcatel G-010G-P'. It all depends on how your connection is
  1. Is MikroTik recommended, or can I use other routers like Xiaomi?
If you have the opportunity to try MikroTik I recommend it, there are no limits in the configuration and you will have many updates
  1. What is the watt consumption?
I'm no expert on this, but the specs are: DC jack input Voltage 12-30 V Max power consumption 21 W Max power consumption without attachments 16 W PoE in input Voltage 18-28 V
  1. If I use Proton VPN, how can I easily change to a different country or make other configurations easily?
I think if you use a free service like ProtonVPN you don't get configuration data for Wireguard, I haven't used it in a while but I think it was APP only.
Thanks ;)
reply
Not worth for me. Having an extra router (which can cost a lot to buy), plus 21 W is quite high for a device that will be running 24/7/365. I have ProtonVPN premium, but i don't see how can i easily change VPN configurations with no Proton VPN app UI.
reply
Regarding the consumption you have equipment that works with 5V, which even allows you to have a great portable tool, even with LTE modules.
In order not to increase the consumption you could change it for your current router (I do not know which one it is) choosing the hardware that suits you best.
Some devices can also lower the processor frequency to lower their consumption in a very easy way.
About the VPN service try to contact support because I do not know if it is possible to manually configure your service with wireguard.
Thank you very much.
reply
deleted by author
reply
yes proton vpn please
reply
I think it is necessary to have a Premium account. In the link there is a WireGuard configuration with the necessary data to be able to import by changing the variables that I put in the script.
Any doubt you tell me!
reply
Invizbox router is miles away easier to setup for Proton VPN.
reply