Whole house WiFi VPN?

I just subscribed to the Secure+ service through Eero. I have the Eero 6 mesh network in my house (main and two satellites).

I thought that the VPN service would have been at the router-level. Like a firmware flash upgrade. No, it’s apparently just a gateway to subscribe for VPN through encrypt.me. While, I do want VPN for my mobile devices outside the home, I was pretty disappointed with what Eero offers.

I have now found a bunch of other brands of routers that offer VPN built in to protect your WiFi from brands like Asus, Netgear, Linksys, and other quality names.

Has anyone tried hardwiring the VPN boxes via WAN/LAN connections between their modem and the Eero? I was really hoping to not have to trash my eero, but if I want WiFi VPN to secure all my smart devices (TV, stove, smart switches, etc.) what options are out there? I was hoping for maybe just a small, hardwired VPN box that doesn’t have it’s own WiFi that I can stick between the modem and router. The guides I have seen around show putting a WiFi-enabled VPN router after the Eero, not before. Which seems to defeat the purpose of a mesh network.

I get that this dual-WiFi set-up allows you to have the choice of VPN or non-VPN connectivity. Not sure why you wouldn’t want everything to go through the VPN, so long as you have fast internet (I have 1GB) and the VPN service doesn’t have any throttle bottlenecks for your speed.

Appreciate any (constructive) feedback.

Firewalla Gold in router mode with eero’s in bridge mode behind it is a popular combination for this.

I don’t really follow the requirement for a whole network VPN specific to smart devices, typically you want to isolate those from your local network, not sure what benefit you think a VPN would provide with these specifically.

If you’re using a third-party VPN service, you’d better trust that service as you’re just shifting trust from your ISP to VPN provider. If you’re running your own VPN endpoint, that’s different. Expect issues with streaming services and geolocation regardless.

OpenVPN and third-party VPN services aren’t going to come anywhere close to gigabit throughput in my experience. WireGuard will come close though.

What exactly are you securing by putting your whole network through a VPN? The best use case for consumer VPN services like encrypt.me are to spoof your location for content only available in a specific country.

Securing your traffic from your ISP is one. It could also allow you to securely access your home network when you’re not at home without having to configure another VPN device.

It’s an effective way to not be able to access any online streaming services which will all block you when they detect access from a VPN.

Securing your traffic from your ISP is one

You should really be working towards moving away from HTTP traffic in your regular usage. Using a VPN hides the traffic from your ISP, sure, but there are larger concerns that need attention if you have that much unencrypted traffic.

It could also allow you to securely access your home network when you’re not at home

Sure, but I would rather put that load on a dedicated device. Let eero handle the routing and SQM, let another piece of hardware handle the VPN and its required encryption - I highly recommend and use WireGuard everywhere I can.