Your router is the gateway to your whole network — and the manufacturer's stock firmware is usually abandoned, closed and badly configured. Open firmware hands control back to you. Here's why OpenWRT, and how it compares to the alternatives.
Well-supported examples: GL.iNet (e.g. Flint 2 / MT6000 — OpenWRT out of the box, the easiest start), selected Linksys/Belkin, some TP-Link, and x86 (a mini-PC = the most power). Before buying, check the OpenWRT Table of Hardware — not every model and hardware revision is supported.
| Solution | For whom / notes |
|---|---|
| OPNsense / pfSense | x86 firewalls (Free/HardenedBSD). Far more power (Suricata IDS/IPS, advanced routing, VPN). Needs a mini-PC; won't replace a Wi-Fi AP (add a separate access point). |
| AsusWRT-Merlin | Semi-open, on Asus routers. The easiest entry, lots of features (WireGuard, adblock). Less "pure" than OpenWRT (some closed code). |
| DD-WRT / FreshTomato / Gargoyle | Other home-router firmwares. FreshTomato is light, Gargoyle has QoS. Smaller communities/hardware support than OpenWRT. |
| VyOS / MikroTik RouterOS | Advanced/enterprise, strong CLI. VyOS is open-source; RouterOS is not open-source but very capable. Learning curve. |
| OpenBSD (pf) / Linux + nftables | A DIY router on your own hardware — maximum control and transparency, the most work. |
In short: home/small office → OpenWRT (or Merlin for convenience). Demanding network / IDS-IPS / many VLANs → OPNsense on a mini-PC + a separate AP. Enterprise/CLI → MikroTik/VyOS.
BASIC
A router with OpenWRT out of the box (GL.iNet). Change default passwords, enable automatic patches, turn on ad-blocking, set up a guest network. Result: a safer, cleaner network right away.
ADVANCED
VLANs (IoT / guests / trusted separated), WireGuard (client for the whole network or a server for home access), DNS over DoH/DoT, SQM to kill lag, AdGuard Home.
EXPERT
OPNsense on a mini-PC (Suricata IDS/IPS, granular firewall, multi-WAN) + a separate Wi-Fi AP. Segmentation and monitoring (ntopng), your own resolver (unbound), per-VLAN rules, alerts.
We'll pick and configure a router for privacy: OpenWRT (or OPNsense for bigger needs) with WireGuard, ad-blocking, VLANs and a sane firewall — without the usual mistakes that turn a router into a hole.
Related articles
PivLab informational material. The right solution depends on your network and threat model — if in doubt, get it reviewed individually.