Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
privacy-first-network — Whole-home VPN router with kill switch. OpenWrt + WireGuard + AmneziaWG. Protects every device, no VPN apps needed. | Kitploit
Tools/GitHubGitHub/yoloshii/privacy-first-network
Encryption/Decryption ToolsIoT SecurityNetwork SecurityWireless SecurityPrivacyDNS Analysis
GitHubyoloshii/privacy-first-network

privacy-first-network

Whole-home VPN router with kill switch. OpenWrt + WireGuard + AmneziaWG. Protects every device, no VPN apps needed.

View Repository
612613 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Privacy Router Stack

Whole-home VPN router with network-level kill switch - Protect every device on your network with OpenWrt, WireGuard, and AmneziaWG. No apps required.

License: MIT OpenWrt WireGuard AmneziaWG Raspberry Pi PRs Welcome

🤖 Using an AI coding agent? Give it access to this entire repo and read AGENTS.md for guided deployment. Supports Claude, GPT, Gemini, and other frontier models.


TL;DR

Turn a Raspberry Pi or mini PC into a VPN gateway that protects your entire home network:

  • ✅ All devices protected - Smart TVs, consoles, IoT, phones, laptops, guests
  • ✅ Firewall kill switch - Router-level failsafe blocks traffic if VPN drops
  • ✅ DPI bypass - AmneziaWG defeats VPN blocking in restrictive networks
  • ✅ DNS encryption - AdGuard Home with DNS-over-HTTPS
  • ✅ Auto-recovery - Watchdog restarts tunnel on failure
  • ✅ AI-deployable - Full agent instructions included

Works with: Any WireGuard-compatible VPN provider (Mullvad, IVPN, AirVPN, etc.)

AmneziaWG obfuscation: Works with any standard WireGuard server (client-side obfuscation)


Why Now? The Privacy Landscape Is Changing

2025 is a turning point for online privacy:

  • UK Online Safety Bill - Age verification now required for adult content. Third-party services verify your identity and track what you access.
  • Australia Social Media Ban - Age verification requirements taking effect December 2025. Platforms must verify user ages.
  • US State Laws - Multiple states passing age verification bills for various content categories.
  • EU Digital Services Act - Expanded platform accountability with data retention requirements.

What this means for you:

  • Your ISP can see every site you visit
  • Age verification services build profiles of your browsing
  • Data retention laws store your history for years
  • Per-device VPN apps don't protect smart TVs, consoles, or IoT devices

This stack solves all of these problems - every device on your network routes through an encrypted tunnel. No browsing history for your ISP. No identity verification per-site. No apps to install or forget to enable.


Why Network-Level VPN?

The Problem with Per-Device VPN Apps

When you install a VPN app like Mullvad, NordVPN, or ProtonVPN on your phone or laptop, you're only protecting that single device. This leaves gaps:

DeviceVPN App SupportRisk
Smart TV❌ NoneISP sees all streaming
Gaming Console❌ NoneIP exposed to game servers
IoT Devices❌ NoneSmart home traffic visible
Guest Devices❌ Can't controlNo protection
Work Laptop⚠️ May conflictCorporate policy blocks VPN
Kids' Devices⚠️ Can be disabledProtection bypassed

VPN apps also:

  • Drain battery on mobile devices
  • Can be forgotten or disabled
  • Require updates on every device
  • May leak traffic during app crashes
  • Don't protect devices that can't run apps

The Network-Level Solution

This privacy router sits between your modem and your existing router. Every device on your network automatically routes through the VPN - no apps, no configuration, no exceptions.

┌─────────────────────────────────────────────────────────────────────┐
│                        YOUR HOME NETWORK                            │
│                                                                     │
│   ┌──────────┐    ┌─────────────────┐    ┌──────────────────────┐  │
│   │  MODEM   │───▶│ PRIVACY ROUTER  │───▶│  YOUR EXISTING ROUTER│  │
│   │  (ISP)   │    │  (This Stack)   │    │  (WiFi/Switch)       │  │
│   └──────────┘    └─────────────────┘    └──────────────────────┘  │
│                           │                        │               │
│                     ┌─────┴─────┐           ┌──────┴──────┐        │
│                     │ ENCRYPTED │           │ ALL DEVICES │        │
│                     │  TUNNEL   │           │  PROTECTED  │        │
│                     └───────────┘           └─────────────┘        │
└─────────────────────────────────────────────────────────────────────┘

Every device is protected: Phones, tablets, laptops, smart TVs, gaming consoles, IoT devices, guests - everything. Individual devices can be bypassed for direct WAN access when needed.


Why Not Just Use Mullvad QUIC or WireGuard Apps?

Great question. Mullvad's QUIC tunnels and WireGuard apps are excellent for individual device protection. Here's when each approach makes sense:

VPN Apps Are Better When:

  • You only need to protect 1-2 devices
  • You travel frequently and use different networks
  • You want per-app split tunneling
  • You're on a network you don't control

Network-Level VPN Is Better When:

  • You have many devices (especially ones that can't run VPN apps)
  • You want "set and forget" protection for your entire household
  • You need to protect smart home/IoT devices
  • You want a kill switch that actually works (more on this below)
  • You're in a region with VPN blocking/deep packet inspection

The Kill Switch Problem

Here's something most people don't realize: VPN app kill switches often fail.

When a VPN app crashes, loses connection, or during the moments between connection drops and reconnection, your traffic can leak to your ISP. App-based kill switches try to prevent this, but they operate at the application level - if the app itself crashes, the kill switch dies with it.

This stack implements a firewall-based kill switch:

Normal Operation:
  Device → Privacy Router → VPN Tunnel → Internet ✓

VPN Down (App-based kill switch):
  Device → [App crashed] → ISP sees traffic ✗

VPN Down (This stack):
  Device → Privacy Router → [No route exists] → Traffic blocked ✓

The kill switch is implemented in the firewall and routing table, not in software. If the VPN tunnel goes down, there is literally no route for traffic to take - it's not blocked by a rule that might fail, it simply has nowhere to go.


Features

Core Protection (Required)

  • Network-wide VPN - All devices protected automatically
  • Firewall kill switch - No traffic leaks, ever
  • IPv6 leak prevention - IPv6 completely disabled

Reliability (Required)

  • Automatic recovery - Watchdog restarts tunnel on failure
  • Boot persistence - VPN starts automatically on power-up
  • Connection monitoring - Continuous health checks

Optional Security Addons

  • AdGuard Home - DNS-over-HTTPS encryption, ad/tracker blocking
  • BanIP - Threat intelligence, malicious IP blocking
  • HTTPS for LuCI - Encrypted admin interface

See OPTIONAL_ADDONS.md for installation and configuration.

Advanced (For Technical Users)

  • DPI bypass - AmneziaWG obfuscation defeats deep packet inspection
  • Flexible deployment - Dedicated hardware or VM
  • Full observability - Detailed logging and diagnostics

How the Kill Switch Works

The kill switch is the most important security feature. Here's exactly how it works:

Firewall Zones

Download Tool