Router for VPN client

anaphylaxus

Active Member
Joined
Aug 23, 2017
Messages
32
Reaction score
0
Location
Cape Town
Major brainache from trying to research this on my own and hoping for some useful insight from the forum:

I've just upgraded my fibre line from 20Mbps to 100Mbps. Now I'm looking to set up router-level vpn.

I've been down this road before with an Asus RT-N18U that just isn't powerful enough to deliver reasonable speeds with VPN client active. I didn't pursue this further at that time because my line wasn't fast enough to make it worthwhile anyway.

So I'm trying to figure out what my options are going forward, ideally something cost-effective.

I live in a small flat, and coverage isn't really an issue, so I'm just looking for the most practical but workable solution. There also aren't millions of devices connected to the network at once. Often just an android box and two phones, sometimes a computer/laptop or the PS4.

I figure I can shell out on a good consumer grade router - this is probably going to cost minimum R2999 for something like a Netgear R7000 or Asus AC68U, unless I've missed a better option?

Alternatively, I could go with something business-grade, like an EdgeRouter and then use one of my myriad other routers as an AP (or upgrade to a Unify AP eventually). I can't find a whole lot of info on the EdgeRouter's performance as a VPN client. I also have not been able to figure out whether I'd be looking at an EdgeRouter X or an EdgeRouter X SFP, or if neither of those are even up to the task at all.

Any wiser souls out there who can help a gal out?
 
Major brainache from trying to research this on my own and hoping for some useful insight from the forum:

I've just upgraded my fibre line from 20Mbps to 100Mbps. Now I'm looking to set up router-level vpn.

I've been down this road before with an Asus RT-N18U that just isn't powerful enough to deliver reasonable speeds with VPN client active. I didn't pursue this further at that time because my line wasn't fast enough to make it worthwhile anyway.

So I'm trying to figure out what my options are going forward, ideally something cost-effective.

I live in a small flat, and coverage isn't really an issue, so I'm just looking for the most practical but workable solution. There also aren't millions of devices connected to the network at once. Often just an android box and two phones, sometimes a computer/laptop or the PS4.

I figure I can shell out on a good consumer grade router - this is probably going to cost minimum R2999 for something like a Netgear R7000 or Asus AC68U, unless I've missed a better option?

Alternatively, I could go with something business-grade, like an EdgeRouter and then use one of my myriad other routers as an AP (or upgrade to a Unify AP eventually). I can't find a whole lot of info on the EdgeRouter's performance as a VPN client. I also have not been able to figure out whether I'd be looking at an EdgeRouter X or an EdgeRouter X SFP, or if neither of those are even up to the task at all.

Any wiser souls out there who can help a gal out?

I have the ASUS AC87U (older model) and is working great with VPN client.
It has a bit more power than the AC68U but speaking in today's routers I would go for an AC88U
 
Edgerouter X has some nice VPN capabilities in as stock, and many have reported success with it


They also have a very active community on their own forums and on Reddit in case you need help. I asked around on the latter before I bought my ERx and the guys there were really a great help
 
Edgerouter X has some nice VPN capabilities in as stock, and many have reported success with it


They also have a very active community on their own forums and on Reddit in case you need help. I asked around on the latter before I bought my ERx and the guys there were really a great help
Thanks, I'm gonna go check this out!
 
I'd personally look at one of the Mikrotik routers. You should be able to get something for <R1000 and it will do anything and more that you might want to do. They are not the most user friendly devices to setup but once you get your head around it, the possibilities are endless with them! It's amazing how much these Mikrotik home/sme based routers can do. Wifi range is always decent and as I say, the customization on them is amazing!!!
 
I'd personally look at one of the Mikrotik routers. You should be able to get something for <R1000 and it will do anything and more that you might want to do. They are not the most user friendly devices to setup but once you get your head around it, the possibilities are endless with them! It's amazing how much these Mikrotik home/sme based routers can do. Wifi range is always decent and as I say, the customization on them is amazing!!!

You need to consider the router's ability to encrypt/decrypt traffic, and AES-NI (or ARM equivalent) is essential. I don't know of any under R1000 that can do that on 100Mbit.
 
Edgerouter X has some nice VPN capabilities in as stock, and many have reported success with it


They also have a very active community on their own forums and on Reddit in case you need help. I asked around on the latter before I bought my ERx and the guys there were really a great help


Can the new EdgeRouters with 4 cores handle routing for gigabit connection and the OpenVPN tunnel at, at least, 500mbit?


There's another poster on here today who reported 25 Mbps throughput over OpenVPN between two ER-4s.
 
I would just run my own, over Wireguard on the client.
 
I wonder if that is with HW offloading enabled? I know the ER-4 has a Cavium-based SoC and the ERx uses a MTK chipset, so there may be some differences there too.

 
I wonder if that is with HW offloading enabled? I know the ER-4 has a Cavium-based SoC and the ERx uses a MTK chipset, so there may be some differences there too.


OP uses OpenVPN, not IPsec. There's many benchmarks and performance testing on Google to compare the two, that's why I asked the protocol in the first reply.
 
28ff6b6f-4638-40e2-b528-d6dbf5e22c8d
 
You need to consider the router's ability to encrypt/decrypt traffic, and AES-NI (or ARM equivalent) is essential. I don't know of any under R1000 that can do that on 100Mbit.
Would this not do what the OP needs? I know of people running massive VPN's using these things at various high sites...

 
Would this not do what the OP needs? I know of people running massive VPN's using these things at various high sites...




I understand that the hEX is supposed to have hardware encryption to allow up to 400+mbps. The VPN server is a dedicated x86 machine with a 1gbps connection, so it should easily handle 300mbps. CPU usage on the server side only goes up to 5% or so when bandwidth testing the VPN to it
Where am I going wrong?

Only IPsec is hardware accelerated.
 
OP what are you trying to do that 20mbps is too slow? I'm asking more out of curiosity than for any other reason.
 
OP what are you trying to do that 20mbps is too slow? I'm asking more out of curiosity than for any other reason.
20mbps isn't too slow. But with hardware vpn client running, that drops off quite hard to 3 or 4mbps on my RT-N18U at best, or often less.
 
Top
Sign up to the MyBroadband newsletter
X