VPN app, FRITZ!Box, or travel router? Which setup is right for you?
If you run your own WireGuard VPN server, you can use it not only at home. You can also route your Internet connection through your own VPN server while on the go—for example, via cellular data, hotel Wi-Fi, public hotspots, or the Wi-Fi at a vacation rental.
The key question, therefore, is:
Which VPN configuration is best for you?
For some users, simply installing WireGuard directly on their iPhone, Android smartphone, or Windows PC is perfectly sufficient. However, if you want to protect multiple devices, your children’s devices, smart TVs, or game consoles, a router-based solution is often a better option.
In this article, we compare four typical configurations:
-
WireGuard directly on the device
-
WireGuard Centralized on a Router
-
FRITZ!Box as a WireGuard Client
-
Travel router with separate VPN and regular Wi-Fi
In this article, we'll look at the pros and cons, as well as the risk of bypassing the VPN.
Configuration 1: WireGuard directly on iPhone, Android, or Windows
The simplest solution is to install the WireGuard app directly on the device in question.
The device will then establish the encrypted connection to your VPN server on its own.
For example:
iPhone via 5G → WireGuard → personal VPN server → Internet
or:
Windows laptop connected to the hotel Wi-Fi → WireGuard → my own VPN server → Internet
So WireGuard doesn't just work on your home Wi-Fi network. You can also connect via cellular data or public Wi-Fi networks.
Advantages
-
No additional hardware required
-
Very easy to set up
-
Works via cellular network
-
Works on hotel and public Wi-Fi networks
-
Ideal for individual devices
-
Very low additional costs
-
WireGuard is fast and resource-efficient
Disadvantage: The user may turn off the VPN
The main drawback of this solution is also its biggest security issue:
The VPN runs on the same device that the user controls.
Depending on the operating system and user permissions, the user could, for example:
-
Disable WireGuard
-
Delete the app
-
Remove the VPN configuration
-
Change Network Settings
-
Use a different connection
For example, if the VPN must remain active for children or managed devices, simply installing WireGuard is not enough.
Securing WireGuard on Android Against Bypass Attempts
Android offers some very interesting features for this use case.
These include, in particular:
Always-on VPN
and
Block Connections Without a VPN
If this combination is enabled, Android can prevent the device from continuing to communicate over the regular Internet connection if the VPN tunnel is interrupted.
This creates a kind of kill switch:
VPN active → Internet is working
VPN not active → no Internet
For devices used by children or managed smartphones, additional measures should be taken to prevent users from changing these settings on their own.
Device management, family features, or MDM systems, for example, can be used for this purpose.
WireGuard on iPhone and iPad
WireGuard also works very well on the iPhone and iPad.
However, Apple devices require a little more attention if you want to ensure that users cannot bypass the VPN.
WireGuard can be combined with the following mechanisms:
-
Equipment Monitoring
-
Family Restrictions
-
MDM
-
Restrictions on Deleting Apps
-
Restrictions on System and Network Settings
One technical detail is particularly important here:
Apple's native Always On VPN for fully managed or "supervised" devices is based on IKEv2, not WireGuard.
That's why, when it comes to WireGuard on Apple devices, it's better to think of it in terms of the following concept:
WireGuard + Device Management / Monitoring
The WireGuard app alone does not automatically make the VPN impossible to disable.
WireGuard on Windows
WireGuard can also be started automatically and used continuously on Windows.
For a personal computer, that's usually more than enough.
However, if you do not want the user to be able to disable the VPN, you should also restrict the user's permissions.
For example:
-
The user is working without administrator privileges
-
Network changes will be restricted
-
WireGuard services must not be terminated
-
The software must not be uninstalled
The same applies here:
Anyone with full administrator privileges can usually find a way to disable local VPN software at some point.
Configuration 2: WireGuard on a Router
A much more powerful option is to run WireGuard not on each individual device, but directly on a router.
The router itself then becomes a WireGuard client.
For example, the connection looks like this:
Hotel Wi-Fi / Cell Service / Internet
↓
Travel Router
↓
WireGuard Tunnel
↓
Personal VPN Server
↓
Internet
All devices that connect to this router can then be automatically routed through the VPN tunnel.
These may include:
-
Smartphones
-
Tablets
-
Windows PCs
-
Macs
-
Smart TVs
-
Streaming Devices
-
Game Consoles
-
Children's Equipment
-
IoT devices
-
Parents' Devices
WireGuard itself does not need to be installed on these devices.
Why a VPN router is harder to bypass
The key difference lies in where the VPN rule is enforced.
For an app:
Device → WireGuard App → VPN Server
The user controls the device and possibly the app as well.
For a router:
Device → Secure Wi-Fi → VPN Router → VPN Server
The VPN runs outside the device.
For example, a child cannot simply open the WireGuard app and tap “Disconnect” because the WireGuard app doesn’t even need to be installed on their device.
As long as the device is connected to the secure Wi-Fi network, the router monitors the data traffic.
Advantages
-
A VPN for Multiple Devices
-
No app is required on every device
-
Smart TVs and game consoles can also be protected
-
Central Administration
-
More difficult to bypass from the device
-
Especially interesting for families
Disadvantages
-
Additional Hardware
-
The router needs to be set up
-
Another device to take on trips
-
The kill switch should be configured correctly
Configuration 3: FRITZ!Box as a WireGuard client
Even modern FRITZ!Box models can establish WireGuard connections.
Examples include, among others:
-
FRITZ!Box 7530 AX
-
FRITZ!Box 7590 AX
-
FRITZ!Box 4060
-
FRITZ!Box 6850 LTE / 4G
-
FRITZ!Box 6850 5G
-
Other current models with corresponding FRITZ!OS support
The FRITZ!Box establishes the connection to your VPN server on its own. The devices connected to it do not need their own WireGuard installation.
Here's an example of what that might look like:
Smartphone / Laptop / TV
↓
FRITZ!Box
↓
WireGuard
↓
Your own VPN server
↓
Internet
Advantages of the FRITZ!Box
-
User-friendly interface
-
WireGuard Can Be Configured Centrally
-
No VPN app on every device
-
Protection for Multiple Devices at Once
-
Very interesting for existing FRITZ! environments
-
A good solution if the entire network needs to go through the VPN
The main drawback of the FRITZ!Box
However, there is one important limitation for our specific use case.
Let's say you want two Wi-Fi networks:
Wi-Fi 1 – Children
Family VPN → WireGuard → My Own VPN Server
Wi-Fi 2 – Parents
Normal → directly to the Internet
This is exactly where things get tricky with a FRITZ!Box.
Although the FRITZ!Box has a standard Wi-Fi network and a guest network, it is not designed as a freely configurable policy-routing platform where individual SSIDs can be assigned to different VPN or WAN routes as desired.
If your goal is:
All devices should connect through the same VPN
A FRITZ!Box is a good solution.
If, on the other hand, your goal is:
Kids with VPN, Parents without VPN
A flexible travel router is usually the better choice.
Configuration 4: Separate VPN Wi-Fi and Regular Wi-Fi
This option is often particularly appealing to families.
A suitable travel router can, for example, provide two different networks:
Secure Wi-Fi
Kids' Devices → WireGuard → Your Own VPN Server
and at the same time:
Standard Wi-Fi
Parent Devices → Directly to the Internet
This gives you two clearly separate networks.
The router determines which devices or which Wi-Fi network are routed through the VPN tunnel.
GL.iNet Travel Router
GL.iNet is particularly appealing for this application.
The routers are designed for travel, VPN, and OpenWrt applications and can, for example, connect to a hotel's Wi-Fi network and provide your own private Wi-Fi network behind it.
Depending on the model and firmware, VPN rules can be created based on various criteria, such as:
-
Visitor Network
-
Terminal
-
IP address
-
VLAN
-
Some domains or target rules
This allows for configurations such as:
Children's Devices → WireGuard
Parental Control Devices → Regular Internet
or:
All Devices → WireGuard
Selected Devices → Exception Without VPN
GL.iNet Beryl AX
The GL.iNet Beryl AX (GL-MT3000) is one of the most interesting all-around travel routers.
It offers:
-
Wi-Fi 6
-
WireGuard
-
OpenVPN
-
compact housing
-
2.5-Gigabit WAN
-
Flexible VPN Rules
As a rough estimate, the price is currently around 90–100 euros or dollars, depending on the country, retailer, and taxes.
Suitable for
-
Families
-
frequent travel
-
Hotel Wi-Fi
-
Smartphones and Tablets
-
small to medium quantities of equipment
GL.iNet Slate AX
The Slate AX (GL-AXT1800) is also a high-performance Wi-Fi 6 travel router.
It offers:
-
WireGuard
-
OpenVPN
-
Wi-Fi 6
-
Good VPN performance
-
Extensive routing options
Price-wise, it typically ranges from about 100 to 130 euros/dollars, depending on the market.
GL.iNet Beryl 7
If you're looking to switch to a newer Wi-Fi 7 platform, check out the Beryl 7.
It is more modern, but not strictly necessary for a pure WireGuard application.
Price-wise, you should expect to pay roughly 120 to 150 euros or dollars.
GL.iNet Flint 2
The Flint 2 is less of a classic pocket travel router and more of a high-performance router designed for:
-
Vacation Homes
-
Second Homes
-
larger families
-
Faster VPN speeds
-
many devices
Price-wise, it is typically significantly more expensive than the smaller travel models.
ASUS RT-AX57 Go
Another very interesting alternative is the ASUS RT-AX57 Go.
The router was specifically designed for portable or travel use.
Among other things, he supports:
-
Wi-Fi 6
-
WireGuard
-
OpenVPN
-
VPN Client
-
Public Wi-Fi / WISP
-
USB Tethering
-
multiple network profiles
One particularly interesting feature is the ability to set up your own VPN network or VPN Wi-Fi on compatible firmware.
This makes it possible to implement the following scenario, for example:
SSID: FAMILY-VPN
→ WireGuard
→ own VPN server
and:
SSID: NORMAL
→ direct Internet connection
It is precisely this flexibility that is missing from a traditional FRITZ!Box configuration.
Depending on the retailer and market, the price ranges from about 80 to 120 euros.
TP-Link Travel Router
TP-Link now also offers a variety of portable routers with VPN client support.
The corresponding product families include, for example, models such as:
-
TL-WR1502X
-
TL-WR1512X
-
TL-WR3002X
-
TL-WR3602BE
Depending on the model, WireGuard is also supported.
Before making a purchase, however, you should check whether the specific model actually offers the advanced features you want:
-
separate SSIDs
-
VPN Policy Routing
-
Rules per device
-
Kill Switch
-
Hotel Wi-Fi/Repeater Mode
When it comes to these advanced features, GL.iNet and ASUS are often more transparent and flexible.
Which configuration is right for you?
Option A: Just a personal smartphone or laptop
Recommendation: WireGuard app
Suitable for:
-
you are the only user
-
you check the device yourself
-
you don't want any additional hardware
-
you want to secure your cell phone connection and hotel Wi-Fi
Costs
Virtually 0 euros in additional hardware costs.
Option B: All devices should always connect through the VPN
Recommendation: FRITZ!Box or VPN router
Suitable for:
-
Apartment
-
Vacation Rental
-
Family with a Single VPN Rule
-
Smart TVs
-
Consoles
-
many devices
These devices do not require a separate WireGuard app.
Option C: Children via VPN, Parents without VPN
Recommendation: GL.iNet or ASUS Travel Router
This is the most interesting option for families.
Example:
Kids VPN Wi-Fi
→ WireGuard
→ your own VPN server
Parents: Wi-Fi
→ regular Internet
The router handles the disconnection.
Option D: Frequent Travel and Hotel Wi-Fi
Recommendation: Travel Router
A travel router can connect to the hotel's Wi-Fi and then set up your own private Wi-Fi network.
This means:
Hotel Wi-Fi
↓
Travel Router
↓
Your Private Wi-Fi
↓
WireGuard
↓
Your Own VPN Server
That way, you won't have to connect each of your family's devices to the hotel's Wi-Fi one by one.
The kill switch is crucial
Regardless of which router you're using, you should definitely check what happens if the WireGuard connection drops.
A poorly configured system might react as follows:
WireGuard is down → The router automatically switches to the regular Internet
This would allow the protection to be circumvented without anyone noticing.
A better option is:
WireGuard active → Internet available
WireGuard is down → Protected devices have no Internet access
This behavior is often referred to as:
-
VPN Kill Switch
-
Block Non-VPN Traffic
-
Fail Closed
is referred to as.
This feature is especially important for children's devices or managed devices.
Comparison of Solutions
| Solution | Additional Hardware | Mobile Communications | Hotel Wi-Fi | All devices protected | Separate VPN and Regular Wi-Fi | Anti-circumvention protection |
|---|---|---|---|---|---|---|
| WireGuard App | No | Yes | Yes | No | No | depending on the device |
| FRITZ!Box | Yes | depending on the model | limited / depends on the configuration | Yes | limited | good |
| GL.iNet Travel Router | Yes | Depending on the model/tethering | Yes | Yes | very good | very good |
| ASUS RT-AX57 Go | Yes | About Tethering | Yes | Yes | very good | very good |
| TP-Link Travel Router | Yes | depending on the model | Yes | Yes | depending on the model | depending on the model |
Our Recommendation
If you just want to protect your own smartphone or laptop, the WireGuard app is probably the best solution.
If you want all devices on a network to connect through the same VPN and you're already part of the FRITZ! ecosystem, a WireGuard-enabled FRITZ!Box is a very convenient solution.
If, on the other hand, you want maximum flexibility—especially for a family—a travel router from GL.iNet or ASUS is usually the better choice.
For example, you can use it to:
Children → Secure VPN Wi-Fi
and
Parents → Regular Wi-Fi
use.
Ultimately, the most important difference isn't whether WireGuard works.
WireGuard works with all of these solutions.
What is crucial, rather, is:
Where is the security rule enforced, and who can change it?
The more you shift control away from the end device and toward the router, the harder it becomes for a typical user to bypass the VPN, whether accidentally or intentionally.