Yes. Put a VPN-capable router downstream of your existing WDS link, then use its WireGuard or OpenVPN client to send traffic from the devices behind it through a VPN. The right setup depends on whether the new router can join the WDS network as a transparent bridge or only connect as a routed wireless client.
Choose the right connection mode
The secondary router needs two separate capabilities: a wireless uplink to the primary router, and a VPN client that can route traffic from its downstream devices. Check the exact model and hardware revision: WDS, wireless-client mode, VPN protocols, and policy-routing features vary by product and firmware. A device advertised as having a VPN server does not necessarily support connecting to a third-party VPN as a client.
| Design | Addressing | LAN transparency | VPN placement | Best suited to |
|---|---|---|---|---|
| WDS bridge | One LAN subnet; the primary router supplies DHCP | Highest when both devices’ WDS implementations interoperate | On the secondary router, routing selected clients or their traffic through its VPN | Extending the same LAN with compatible hardware |
| Routed wireless client | Separate downstream subnet; the secondary router supplies DHCP and usually NAT | Limited across the router boundary | On the secondary router as the gateway for its downstream clients | Cross-vendor setups and predictable network isolation |
| OpenWrt relayd fallback | Relayed/routed behavior; details depend on configuration | Less predictable than a true Layer-2 bridge | On the OpenWrt router | When the primary access point lacks WDS or 802.11s |
Option 1: Transparent WDS bridge
Use this when both routers support compatible WDS or four-address mode. WDS connects access points wirelessly, but vendors can implement it differently; compatibility is not guaranteed just because both products use the WDS label. TP-Link notes that compatible wireless MAC-address formats are required, and OpenWrt explains that the IEEE four-address mechanism leaves implementation details unspecified.
Match the wireless settings on both ends: SSID, band and channel, channel width, encryption, and WDS settings. Keep the secondary router’s management address reachable on the primary LAN, and disable DHCP on the secondary so the primary remains the address authority. OpenWrt’s repeater guidance likewise calls for matching radio settings, enabling WDS on the access point and station, disabling DHCP on the repeater LAN, and placing the access point in the LAN firewall zone.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Check the exact security-mode limitations before choosing this design. ASUS’s WDS support page documents Open System with NONE or WEP authentication; do not assume that a particular ASUS model and firmware can bridge a WPA2- or WPA3-protected network using WDS. Verify the specific devices and firmware before changing your existing Wi-Fi security.
Option 2: Routed wireless client
Choose this if the secondary router can join the upstream Wi-Fi as a client but cannot bridge it transparently. Configure the wireless connection as the secondary router’s WAN or uplink, give its LAN a different subnet from the primary router, and let it provide DHCP, firewalling, and NAT to its own clients. Then configure the VPN client on that router as the gateway for the downstream LAN.
Rank #2
- 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
- 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
- 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
- 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.
This arrangement usually makes the traffic path easier to reason about, particularly across different vendors. The trade-off is that devices on the primary LAN may not be able to discover or connect directly to devices behind the secondary router without additional routes or relay mechanisms.
Option 3: OpenWrt relayd fallback
If the primary router does not support WDS or 802.11s, OpenWrt documents relayd as a way to connect a wireless client uplink to a LAN. Treat it as a routed compatibility fallback, not as a transparent Layer-2 bridge. Broadcast-dependent discovery, multicast, and some management protocols can behave differently from devices on one bridged LAN.
Rank #3
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
Set up the wireless link before the VPN
- Record the current network. Note the primary router’s LAN subnet and DHCP range, Wi-Fi SSID, band, channel, encryption, and the secondary router’s supported operating modes. Keep a way to restore the primary configuration if needed.
- Verify model and firmware support. Confirm that the secondary router supports the specific WDS or wireless-client mode you need and has a VPN client for your provider’s protocol. Support can differ by model, hardware revision, and firmware. Install firmware only from the vendor’s instructions for the exact hardware revision.
- Establish the uplink first. For WDS, match the radio settings and enable the WDS/four-address option on both the access point and station. For routed client mode, configure the wireless interface as the WAN/uplink and join the upstream SSID.
- Set addressing for the chosen design. With transparent WDS, keep one LAN subnet and disable DHCP on the secondary router. With routed client mode, use a separate downstream subnet and leave DHCP enabled on the secondary router.
- Confirm ordinary connectivity. Before enabling the VPN, check that the secondary router associates with the upstream network, downstream devices receive the expected addresses, and they can reach the Internet.
- Configure the VPN client. Import the VPN provider’s WireGuard or OpenVPN profile. On supported TP-Link models, the documented path is Advanced > VPN Client. ASUS instructs users to confirm the VPN server’s protocol before selecting the client type.
- Choose which traffic uses the tunnel. Route all downstream traffic through the VPN or, if supported, select devices or traffic using policy-routing rules. GL.iNet documents policies based on domain/IP or MAC address. A router-level VPN can spare downstream devices from needing individual VPN apps, but only traffic assigned to the tunnel will use it.
- Check the firewall and leak behavior. Confirm that forwarding from the downstream LAN to the VPN interface is configured. If the firmware supports a kill switch, decide whether traffic should be blocked when the VPN disconnects rather than fall back to the ordinary uplink.
- Test each layer in order. Check upstream association, client IP assignment, ordinary Internet access, VPN handshake, public IP, DNS resolution, and any local services the clients must reach. A successful WDS association alone does not prove that VPN routing or downstream firewall rules are working.
What to verify before buying or reusing a router
- Exact hardware revision and firmware support for WDS, four-address bridging, or wireless-client mode.
- Whether the intended mode works with the primary router’s vendor, wireless security, band, and firmware.
- VPN-client support for the protocol and configuration file your provider supplies; server support alone is not enough.
- Whether the VPN can cover the whole downstream LAN or select clients through policy routing.
- Whether the firmware provides a kill switch and the firewall controls needed to keep traffic from bypassing the VPN.
- For same-LAN access, whether transparent WDS is genuinely supported end to end; for routed mode, whether devices across the subnet boundary need to communicate.
Search product specifications for terms such as “WDS client mode,” “wireless client,” “WireGuard client,” “OpenVPN client,” and “policy routing.” TP-Link distinguishes VPN-server and VPN-client functions; OpenWrt documents WireGuard client operation. Confirm the feature on the exact model and firmware rather than relying on a product family name.
Quick Recap
Best Value
- Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
- A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
- Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
- Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
- Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Rank #4
- 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
- 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
- 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
- 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
- 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

