LeoTun

Internet Freedom Alliance

2026-10 sing-box upgraded: old configs no longer work. Sign in and re-scan the code on the sing-box page, once per device.
2026-09 New router firmware is out — please update. OpenVPN is back: download a profile, import it, and connect in one tap.
2026-09 New Personal plan: 4 USD/month for 2 devices, routers included — everyone should have a VPN router.
HomeRouterOpenVPNCiscoHiddifyProxyPrivateContact

Related guides

What Is OpenWrt? Soft Routers, Bypass Gateways and VPN Routers for China

Updated 2026-10-08

The short answer: a “soft router” (软路由) is general-purpose hardware running a router operating system, and that system is usually OpenWrt. Its strength is that you install whatever features you want; its cost is that you configure and maintain all of it. If the goal is simply to put every device at home on a VPN, building one from scratch is unnecessary — an ordinary OpenWrt-capable router with purpose-built firmware does the same job without the configuration and upkeep. This guide sorts out the concepts: soft router versus ordinary router, what OpenWrt is, main router versus bypass gateway, which hardware details matter, and who should build and who should buy. For choosing a model, flashing and split routing, it links to the dedicated guides.

Soft router versus ordinary router

An ordinary router is a finished product: the manufacturer pairs dedicated hardware with its own system. The maker decides the features. It is stable and undemanding, and there is little you can change.

A soft router originally meant general-purpose hardware — a mini PC, an industrial box, a development board, even an old computer or a virtual machine — with a router operating system installed. The hardware is powerful and has plenty of ports, the system can be swapped freely, and features are added as software.

In everyday Chinese usage the term has widened: an ordinary router flashed with a third-party system such as OpenWrt is often called a soft router as well. What the two share is a system you can replace and features you can add, and that is exactly what running a VPN on a router requires. Stock firmware rarely includes it.

What OpenWrt is

OpenWrt is an open-source operating system for routers, built on Linux and available for a large number of brands and models. Like a phone system, it takes installable packages: split routing, ad filtering and the various VPN protocols are all added that way.

OpenWrt firmware is built per model. Each model, and each hardware revision of it, has its own image, and images are not interchangeable.

  • Official builds: released by the OpenWrt project with basic functions only. Everything else you install and configure yourself.
  • Community bundles: images passed around forums and file-sharing links with dozens of add-ons preinstalled. Who built them and what went in cannot be verified.
  • Purpose-built firmware: compiled on top of OpenWrt by a service for its own routes, with the connection and split routing already in place.
  • Every byte the household sends passes through the router, so the origin of its firmware should be something you can account for. For how to judge, see How to Recognise a Risky VPN App.

Main router, bypass gateway, or a second router

Main router: the soft router connects straight to the modem, handles the broadband login and hands out addresses, so all household traffic passes through it by construction. It is the simplest layout and nothing can go around it. The cost is that when it fails the whole home is offline, and so is everyone else while you tinker with it.

Bypass gateway (旁路由): the existing main router stays as it is. The soft router hangs off it on a single cable, and devices are pointed at it as their gateway and DNS server, so traffic detours through it before leaving. The appeal is that the existing network is untouched and only some devices need to use it. The costs are worth knowing in advance:

  • When the bypass box is off or has crashed, every device pointed at it is offline. If the gateway was changed for the whole home on the main router, the whole home is offline while the main router is perfectly healthy, which makes the fault confusing to trace.
  • IPv6 goes around it: the main router still hands IPv6 addresses to devices, and whatever a device sends over IPv6 leaves through the main router without touching the bypass box. The symptom is that things work some of the time. The usual remedy is to turn IPv6 off on the main router.
  • Traffic takes an extra hop, and with imperfect settings you get slow uploads or individual apps misbehaving — faults that are hard to pin down.
  • The gateway and DNS have to be changed, either by hand on each device or in the main router’s address-assignment settings. Both need some networking knowledge.

The simpler layout: behind the router you already have

The third layout is a second router. A router with the firmware installed plugs in behind the existing modem or main router and broadcasts its own Wi‑Fi. Devices that should use the route join it; everything else stays on the original network, and neither side affects the other.

If it fails, only the devices on it are affected and everyone else stays online. Devices on it have no exit that goes around it, so the IPv6 problem of a bypass gateway does not arise. The cost is one more layer of address translation, and the odd application that needs port forwarding has to be set up separately.

A router running our firmware can serve as the main router or sit behind one in this way. For the layout used for parents and a TV, see For the TV and the Grandparents at Home.

Which hardware details matter

The more flash and RAM a router has, the more headroom is left once the VPN components are installed and the easier later upgrades are; models with only 16 MB of flash leave too little, and our firmware does not support them. Whether a particular model can take our firmware is answered by the support list on the router page.

  • Flash storage: where the system and packages live. With too little, newer firmware will not fit, let alone extra features.
  • RAM: split-routing lists and connection tracking are held in memory. With too little, the router stutters or reboots once enough devices are connected.
  • Processor: it does the encryption. The faster the broadband and the more devices in use at once, the more it matters. When route speed will not go any higher, the limit is often here and not in the broadband.
  • Hardware revision: one model name often covers v1, v2 and so on, with different chips and flash inside, and their firmware is not interchangeable. Read the label on the underside, and check with particular care when buying second-hand.
  • Ports and wireless: for broadband above one gigabit, look for a 2.5G port. A mini PC usually has no Wi‑Fi and needs a separate access point.
  • Carrier-supplied modem/router combos usually cannot be flashed. Put a second router behind them.

Build a soft router, or use a router with purpose-built firmware

For what the firmware does once installed, see What the Router Firmware Does. For what good split routing has to achieve, see How split routing works on a VPN router.

  • Build it yourself: buy hardware, install the system, install add-ons, enter the route configuration, write split-routing rules, then handle updates and faults from then on. It gives the most freedom, and the same box can also run ad filtering, downloads and other services. Every problem is also yours to solve.
  • Purpose-built firmware: the connection and split routing are already in the image. Here that means building the firmware online for your model — more than 600 OpenWrt models are supported — or buying a unit with it installed. The connection components and split lists update themselves, with no re-flashing.
  • The two paths do not differ in hardware. They differ in who configures it, who maintains it, and who you turn to when something breaks.

Who should choose which

  • You want the household covered and no maintenance: buy a router with the firmware installed. For picking a model, see Choosing a VPN Router.
  • You already own an OpenWrt-capable router: flash our firmware yourself, following Flashing the Router Firmware.
  • You enjoy tinkering and want other services on the same box: build a soft router and import an OpenVPN profile for the route. See How to Use OpenVPN and When to Choose It.
  • For parents, a TV or a streaming box: a ready-made router behind the existing network. See For the TV and the Grandparents at Home.
  • A rented room or dorm where the main router is off limits: a portable router behind it, as a second router.
  • One or two phones and laptops: no router needed; a client is lighter. See Which connection method fits which scenario.

FAQ

Is a soft router always faster for a VPN than an ordinary router?

No. Speed is set jointly by the broadband, the route and the router’s processor. Powerful hardware shows a clear advantage with broadband above one gigabit and many devices. For most homes an ordinary router of suitable specification with the firmware flashed is enough.

Bypass gateway or main router: which is better?

For a simple layout that nothing can go around, make it the main router. To leave the existing network alone and route only some devices, use a bypass gateway, but deal with IPv6 and accept that those devices go offline whenever it is off. To avoid those settings altogether, a second router behind the existing one is the least effort.

How do I set up a VPN on a router?

With purpose-built firmware there is almost nothing to set. Firmware you build yourself is generated for your account and connects by itself after flashing; with a pre-flashed unit you log in once on the admin page. After that, every device on that router uses the route. Steps are in Flashing the Router Firmware.

Can my router run OpenWrt?

It depends on whether the model and the hardware revision are on the support list; both have to match. The models we support are listed on the router page, and anything selectable on the build page can be flashed.

Where do I download OpenWrt firmware?

Official builds come from the OpenWrt website, by model. Our purpose-built firmware is built per model on the router page and downloaded from there. Leave bundles of unknown origin alone.

Is building a soft router difficult?

Installing the system is the easy part. The work comes afterwards: route configuration, split rules, DNS and IPv6 can each go wrong, and all of it needs ongoing maintenance. It suits people willing to spend time learning networking; people who just want it to work should take purpose-built firmware.

Related pages

  • Choosing a VPN Router →
  • Flashing the Router Firmware: From Stock to Ours, Step by Step →
  • What the Router Firmware Does →
  • How split routing works on a VPN router →
  • For the TV and the Grandparents at Home →
  • Tencent Video or iQIYI Blocked Abroad? Fix It in 5 Steps →
  • How to Choose a China VPN →
  • Does Cisco AnyConnect Work in China? →
  • How to Import a Hiddify Subscription →
  • China VPN for Students Abroad →
  • What a Web Proxy Is and When to Use One →
  • Free or Paid China VPN? →
  • What the Private Network (Tailscale) Is →
  • How to Use OpenVPN and When to Choose It →
  • How to Reach Us and Never Lose Contact →
  • Where We Beat Other VPNs →
  • How to Recognise a Risky VPN App →
  • Which connection method fits which scenario →
  • Which Region Is Fastest from Inside China →
  • Watching Home Cameras and a NAS in China from Abroad →
  • What to Do When iOS Cannot Install an App →
  • Cannot Connect, Slow, or Dropping: What to Check →
  • Setting Up for Business Trips and Travel →
  • On a Company Laptop: No Admin Rights, Corporate VPN Already On →
  • Many Devices, One Setup, No Redo on a New Phone →
  • Routing a Synology or QNAP NAS →
  • Routing a Linux Server and Command-Line Tools →
  • “Damaged” on a Mac, and how to verify the installer →
  • Using RustDesk for remote help →
  • What macOS's Network Extension Approval Is →
  • Not enough device slots? Temporary vs long-term fixes →
  • Dropbox and other apps want an HTTP / SOCKS proxy — what to do →
  • How to Get Good Answers from the AI Support →
  • How to manually uninstall the Cisco client on a Mac →
  • Cisco error “remote user is disabled” →
  • Refund Policy and Feedback →
  • What a VPN is, what it is used for, and how to connect →
  • VPN vs “airport” proxy subscriptions vs accelerators →
  • VPN protocols compared: WireGuard, OpenVPN, AnyConnect, Hysteria2 →
  • Is a VPN Safe to Use? Who Can See What →
  • VPN Slow? How to Run a Speed Test and Find the Cause →
  • DNS Leak vs DNS Poisoning: How to Check and Fix →
  • VPN on iPhone: which method to use and how to set it up →
  • VPN on Android: which client to use and how to set it up →
  • VPN on a computer: which method for Windows and Mac →
  • Using ChatGPT in China: Why It Fails and What Matters →
  • No Verification Code for an Overseas App? Telegram, Instagram and TikTok in China →
  • How to Use a VPN in China: Set Up Before You Land →
  • VPN Not Working in China? Why, and What to Try →
  • Best VPN for China: How to Judge One Yourself →
  • Do VPNs Work in China? What NordVPN, ExpressVPN and Others Say Themselves →
  • eSIM vs VPN in China: Which One Do You Need? →
  • Travel VPN Router for China: Setup and Who Needs One →
  • WhatsApp in China: Does It Work and How to Set It Up →
  • Google in China: Gmail, Maps and Google Play Explained →
  • YouTube in China: How to Watch, and Why Netflix Refuses →

Flags by Twemoji (CC-BY 4.0)·IP Geolocation by DB-IP

AboutGuidesContact

© 2007–2026LeoTun