VPN gateway hardening: running a GL.iNet Brume 2 as your always-on home VPN endpoint
VPN gateway hardening: running a GL.iNet Brume 2 as your always-on home VPN endpoint
Most home VPN setups fail quietly. A laptop's VPN app gets switched off and stays off; a smart TV never had a VPN option at all; a guest's phone connects and goes straight out through your raw IP. A dedicated VPN gateway — a device like our GL.iNet Brume 2 (GL-MT2500A) — fixes this with architecture rather than discipline: a small, silent, always-on box between your modem and your router, through which every device on your network is tunnelled automatically — including the devices that cannot run VPN software at all. This guide covers the threat model, the setup, and the hardening details that turn a stock GL.iNet Brume 2 into a gateway you actually rely on.
Why a gateway, not per-device apps
The problem a VPN gateway solves is coverage, not encryption. Per-device VPN apps encrypt what they can reach, and their coverage is full of holes: devices that cannot run apps (TVs, consoles, IoT gear, printers), devices whose users forget to enable the app, and split moments during sleep, roaming, or reboot when the tunnel drops silently. On an Australian home network with a dozen devices, "everyone uses a VPN app" is really "three devices are protected and the rest leak".
The GL.iNet Brume 2 (GL-MT2500/MT2500A) is designed for exactly this role. It has no Wi-Fi at all — a deliberate limitation that confuses some buyers and is actually the point. (If you need portable Wi-Fi protection on hostile networks instead of a fixed home gateway, our GL.iNet Beryl AX travel router covers that use case; the two products complement rather than replace each other.) It sits inline: WAN port to your modem, LAN port to your existing router, and it tunnels everything crossing it. The vendor rates it at up to 355 Mbps WireGuard client throughput and 150 Mbps OpenVPN, which comfortably covers typical Australian NBN plans. A recent third-party review of the Brume 2 as a VPN gateway measured real-world WireGuard throughput around 300–350 Mbps and concluded it is the right fit for connections under roughly 300 Mbps — for symmetric gigabit fibre, faster hardware exists, but that is not most homes.
Underneath, it is OpenWrt, which means the vendor's friendly panel sits on top of a full Linux router you can harden as deeply as you like.
The threat model it addresses
Be precise about what an inline gateway buys you:
- Leak-proof by default. Every device behind the router is tunnelled, with no per-device configuration and no per-device failure. Configure a kill switch and a dropped tunnel means blocked traffic rather than leaked traffic — the gateway turns VPN lapses from silent leaks into visible outages, which is exactly the trade you want.
- DNS control at one point. With DNS-over-TLS configured on the gateway (Cloudflare and Quad9 both run open DoT endpoints), no device on the network can quietly query a resolver you did not choose. Combined with the built-in AdGuard Home toggle, ad and tracker domains are dropped for the whole household at the resolver.
- One place to audit. Firmware updates, tunnel status, and connected-device lists live in one admin panel instead of a dozen VPN apps.
It is equally important to state what it does not do: it does not anonymise you from the VPN provider itself, it does not protect devices when they leave your network (your phone on 5G is outside this architecture), and it does not defend the devices themselves — patching and OS hardening remain your job. For portable protection on hostile networks, that is the travel-router job, which we covered separately in our OpenWrt travel router guide.
Setup, in the order that matters
1. Update firmware before anything else
The Brume 2 ships running OpenWrt with a GL.iNet panel on top; first action is to update to the current firmware release, because a gateway that sits inline 24/7 is part of your network's attack surface and needs to run patched software. Set a strong admin password while you are in there, and disable remote administration unless you specifically need it.
2. Choose client, server, or cascading
The Brume 2's distinctive feature is VPN cascading: it can run a WireGuard or OpenVPN server (so you can reach home resources from the road) and a VPN client (so outbound traffic rides a provider tunnel) simultaneously. Most home users want one of two shapes:
- Client gateway — all home egress through a commercial provider. WireGuard client configs from providers like Mullvad or IVPN import directly; the vendor supports 30+ providers out of the box.
- Self-hosted server — for remote access back into your home network. A detailed hands-on Brume 2 review with VPN server testing covers the server path in depth, including the caveat that matters in Australia: if your ISP does not give you a public IP (increasingly common on CGNAT-heavy plans), you will need a relay service or VPS endpoint for inbound connections. Prefer WireGuard over OpenVPN — reviewers consistently report materially better throughput, and independent Brume 2 security gateway testing verified the advertised speeds with WireGuard well ahead of OpenVPN.
3. Enforce the kill switch
Enable the kill-switch option so that if the tunnel drops, traffic is blocked instead of falling out through the raw WAN. This is the single setting that separates a hardened gateway from a decorative one. Then verify it: disconnect the tunnel deliberately, run an IP lookup from a client, and confirm it fails rather than silently reverting. A kill switch you have not tested is a rumour.
4. DNS-over-TLS and AdGuard Home
Set DNS to DoT (the vendor supports Cloudflare DoT natively) and confirm clients actually resolve through it — query a domain from a device and check the panel's DNS statistics. Then enable AdGuard Home if you want network-wide tracker blocking. The two together mean every device behind the router — including the smart TV — gets encrypted resolution and filtered domains with zero per-device work.
5. Segment the LAN
The Brume 2 exposes one LAN port, typically feeding your existing router — so put your segmentation at the downstream router or use the gateway as the upstream of a VLAN-capable switch. At minimum, keep guest devices and IoT gear off the same segment as work machines; the gateway enforces egress policy, while the downstream network enforces isolation.
Hardening beyond the defaults
- Disable GoodCloud (the vendor's remote management platform) unless you genuinely use it. Every cloud management channel is a door you do not need.
- SSH discipline. If you SSH into the box, use keys, disable password authentication, and close the WAN side entirely.
- Scheduled reboots. A weekly unattended reboot clears memory pressure and re-establishes tunnels cleanly — the gateway is meant to be forgotten, so make forgetting safe.
- Monitor tunnel uptime. The panel's VPN dashboard shows tunnel status; if your provider tunnel drops more than occasionally, switch endpoints. Chronic instability is a provider problem, not a gateway problem.
- Physical placement. It draws under 2.6 watts and runs silent, but it is passively cooled — do not bury it in an enclosed cabinet; the aluminium MT2500A case is the version worth having for 24/7 duty.
Honest limits and who should skip it
The gateway is the wrong tool if you want per-device flexibility (sometimes bypassing the tunnel for banking apps that dislike VPNs — though the Brume 2's per-device policy routing can exempt specific devices), if your connection exceeds ~300 Mbps and you refuse to bottleneck it, or if you cannot tolerate one more box in the signal chain. It also does not replace good endpoint security; it is a network boundary, not an antivirus.
For everyone else, it delivers the most valuable property in home privacy: protection that does not depend on anyone remembering anything. Once the kill switch is tested and the tunnel is enforced, every device in the house — including the ones that will never run VPN software — rides encrypted egress by default, and your raw IP address stops being the default route for your entire household.
This article is general technical information, not legal advice. Using a VPN is lawful in Australia; ensure any service you choose complies with the terms of the platforms you use it with.