
Whole-home VPN router with kill switch. OpenWrt + WireGuard + AmneziaWG. Protects every device, no VPN apps needed.
Whole-home VPN router with network-level kill switch - Protect every device on your network with OpenWrt, WireGuard, and AmneziaWG. No apps required.
🤖 Using an AI coding agent? Give it access to this entire repo and read AGENTS.md for guided deployment. Supports Claude, GPT, Gemini, and other frontier models.
Turn a Raspberry Pi or mini PC into a VPN gateway that protects your entire home network:
Works with: Any WireGuard-compatible VPN provider (Mullvad, IVPN, AirVPN, etc.)
AmneziaWG obfuscation: Works with any standard WireGuard server (client-side obfuscation)
2025 is a turning point for online privacy:
What this means for you:
This stack solves all of these problems - every device on your network routes through an encrypted tunnel. No browsing history for your ISP. No identity verification per-site. No apps to install or forget to enable.
When you install a VPN app like Mullvad, NordVPN, or ProtonVPN on your phone or laptop, you're only protecting that single device. This leaves gaps:
| Device | VPN App Support | Risk |
|---|---|---|
| Smart TV | ❌ None | ISP sees all streaming |
| Gaming Console | ❌ None | IP exposed to game servers |
| IoT Devices | ❌ None | Smart home traffic visible |
| Guest Devices | ❌ Can't control | No protection |
| Work Laptop | ⚠️ May conflict | Corporate policy blocks VPN |
| Kids' Devices | ⚠️ Can be disabled | Protection bypassed |
VPN apps also:
This privacy router sits between your modem and your existing router. Every device on your network automatically routes through the VPN - no apps, no configuration, no exceptions.
┌─────────────────────────────────────────────────────────────────────┐
│ YOUR HOME NETWORK │
│ │
│ ┌──────────┐ ┌─────────────────┐ ┌──────────────────────┐ │
│ │ MODEM │───▶│ PRIVACY ROUTER │───▶│ YOUR EXISTING ROUTER│ │
│ │ (ISP) │ │ (This Stack) │ │ (WiFi/Switch) │ │
│ └──────────┘ └─────────────────┘ └──────────────────────┘ │
│ │ │ │
│ ┌─────┴─────┐ ┌──────┴──────┐ │
│ │ ENCRYPTED │ │ ALL DEVICES │ │
│ │ TUNNEL │ │ PROTECTED │ │
│ └───────────┘ └─────────────┘ │
└─────────────────────────────────────────────────────────────────────┘
Every device is protected: Phones, tablets, laptops, smart TVs, gaming consoles, IoT devices, guests - everything. Individual devices can be bypassed for direct WAN access when needed.
Great question. Mullvad's QUIC tunnels and WireGuard apps are excellent for individual device protection. Here's when each approach makes sense:
Here's something most people don't realize: VPN app kill switches often fail.
When a VPN app crashes, loses connection, or during the moments between connection drops and reconnection, your traffic can leak to your ISP. App-based kill switches try to prevent this, but they operate at the application level - if the app itself crashes, the kill switch dies with it.
This stack implements a firewall-based kill switch:
Normal Operation:
Device → Privacy Router → VPN Tunnel → Internet ✓
VPN Down (App-based kill switch):
Device → [App crashed] → ISP sees traffic ✗
VPN Down (This stack):
Device → Privacy Router → [No route exists] → Traffic blocked ✓
The kill switch is implemented in the firewall and routing table, not in software. If the VPN tunnel goes down, there is literally no route for traffic to take - it's not blocked by a rule that might fail, it simply has nowhere to go.
See OPTIONAL_ADDONS.md for installation and configuration.
The kill switch is the most important security feature. Here's exactly how it works: