What you gain
Every device on the network is covered without installing anything, including hardware that has no VPN client available. The whole router counts as one connection against your provider’s limit, which is the standard way around a five-device cap.
It also covers guests and anything that joins the network later, which is either a feature or a problem depending on your household.
What you lose
Throughput, usually a lot of it. Consumer routers have modest processors and encryption is the most demanding thing you can ask of them. A router that routes a gigabit unencrypted may manage a small fraction of that through a tunnel.
Control, entirely. Everything is tunnelled or nothing is. Your banking app now arrives from another country, your smart speaker cannot find local devices, and troubleshooting any of it means changing the setting for the whole house.
Avoid
- Router-only setups on a fast line — you will cap your connection at the router’s encryption speed
- Flashing custom firmware without checking your exact hardware revision is supported
- Assuming a kill switch exists; on many router configurations, if the tunnel drops, traffic simply goes out unprotected
The setup most people should actually use
Run VPN clients on the devices that support them, where you get per-app control and full speed. Use the router only for the devices that cannot: the TV, the console, the IoT hardware.
Many routers support a second network for exactly this. Devices that need the tunnel join that one; everything else uses the ordinary network and its own client.
Choosing hardware
Check three things before buying: that the router supports WireGuard rather than only OpenVPN, that your provider publishes configuration for it, and that the processor is rated for VPN throughput near your line speed.
Some providers ship purpose-built firmware, which removes the configuration work at the cost of tying you to that provider. Others document manual configuration, which is more work and more portable.