VPN gateway hardening: running a GL.iNet Brume 2 as your always-on home VPN endpoint


VPN gateway hardening: running a GL.iNet Brume 2 as your always-on home VPN endpoint

Most home VPN setups fail quietly. A laptop's VPN app gets switched off and stays off; a smart TV never had a VPN option at all; a guest's phone connects and goes straight out through your raw IP. A dedicated VPN gateway — a device like our GL.iNet Brume 2 (GL-MT2500A) — fixes this with architecture rather than discipline: a small, silent, always-on box between your modem and your router, through which every device on your network is tunnelled automatically — including the devices that cannot run VPN software at all. This guide covers the threat model, the setup, and the hardening details that turn a stock GL.iNet Brume 2 into a gateway you actually rely on.

Why a gateway, not per-device apps

The problem a VPN gateway solves is coverage, not encryption. Per-device VPN apps encrypt what they can reach, and their coverage is full of holes: devices that cannot run apps (TVs, consoles, IoT gear, printers), devices whose users forget to enable the app, and split moments during sleep, roaming, or reboot when the tunnel drops silently. On an Australian home network with a dozen devices, "everyone uses a VPN app" is really "three devices are protected and the rest leak".

The GL.iNet Brume 2 (GL-MT2500/MT2500A) is designed for exactly this role. It has no Wi-Fi at all — a deliberate limitation that confuses some buyers and is actually the point. (If you need portable Wi-Fi protection on hostile networks instead of a fixed home gateway, our GL.iNet Beryl AX travel router covers that use case; the two products complement rather than replace each other.) It sits inline: WAN port to your modem, LAN port to your existing router, and it tunnels everything crossing it. The vendor rates it at up to 355 Mbps WireGuard client throughput and 150 Mbps OpenVPN, which comfortably covers typical Australian NBN plans. A recent third-party review of the Brume 2 as a VPN gateway measured real-world WireGuard throughput around 300–350 Mbps and concluded it is the right fit for connections under roughly 300 Mbps — for symmetric gigabit fibre, faster hardware exists, but that is not most homes.

Underneath, it is OpenWrt, which means the vendor's friendly panel sits on top of a full Linux router you can harden as deeply as you like.

The threat model it addresses

Be precise about what an inline gateway buys you:

It is equally important to state what it does not do: it does not anonymise you from the VPN provider itself, it does not protect devices when they leave your network (your phone on 5G is outside this architecture), and it does not defend the devices themselves — patching and OS hardening remain your job. For portable protection on hostile networks, that is the travel-router job, which we covered separately in our OpenWrt travel router guide.

Setup, in the order that matters

1. Update firmware before anything else

The Brume 2 ships running OpenWrt with a GL.iNet panel on top; first action is to update to the current firmware release, because a gateway that sits inline 24/7 is part of your network's attack surface and needs to run patched software. Set a strong admin password while you are in there, and disable remote administration unless you specifically need it.

2. Choose client, server, or cascading

The Brume 2's distinctive feature is VPN cascading: it can run a WireGuard or OpenVPN server (so you can reach home resources from the road) and a VPN client (so outbound traffic rides a provider tunnel) simultaneously. Most home users want one of two shapes:

3. Enforce the kill switch

Enable the kill-switch option so that if the tunnel drops, traffic is blocked instead of falling out through the raw WAN. This is the single setting that separates a hardened gateway from a decorative one. Then verify it: disconnect the tunnel deliberately, run an IP lookup from a client, and confirm it fails rather than silently reverting. A kill switch you have not tested is a rumour.

4. DNS-over-TLS and AdGuard Home

Set DNS to DoT (the vendor supports Cloudflare DoT natively) and confirm clients actually resolve through it — query a domain from a device and check the panel's DNS statistics. Then enable AdGuard Home if you want network-wide tracker blocking. The two together mean every device behind the router — including the smart TV — gets encrypted resolution and filtered domains with zero per-device work.

5. Segment the LAN

The Brume 2 exposes one LAN port, typically feeding your existing router — so put your segmentation at the downstream router or use the gateway as the upstream of a VLAN-capable switch. At minimum, keep guest devices and IoT gear off the same segment as work machines; the gateway enforces egress policy, while the downstream network enforces isolation.

Hardening beyond the defaults

Honest limits and who should skip it

The gateway is the wrong tool if you want per-device flexibility (sometimes bypassing the tunnel for banking apps that dislike VPNs — though the Brume 2's per-device policy routing can exempt specific devices), if your connection exceeds ~300 Mbps and you refuse to bottleneck it, or if you cannot tolerate one more box in the signal chain. It also does not replace good endpoint security; it is a network boundary, not an antivirus.

For everyone else, it delivers the most valuable property in home privacy: protection that does not depend on anyone remembering anything. Once the kill switch is tested and the tunnel is enforced, every device in the house — including the ones that will never run VPN software — rides encrypted egress by default, and your raw IP address stops being the default route for your entire household.

This article is general technical information, not legal advice. Using a VPN is lawful in Australia; ensure any service you choose complies with the terms of the platforms you use it with.


← All posts