// Engineering Log

Keenetic: Part 3 — VPN client for the entire network

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

Why a VPN client on the router

Configuring a VPN on each device is inconvenient, and TVs, game consoles and smart home devices often don’t support it at all. If the router becomes the VPN client, the tunnel can be used by all devices on the network — or only selected ones.

A second common scenario is connection to the office: the branch router or an employee’s home router is constantly connected to the corporate network, and its resources are available without running software on the computers.

Supported connections

  • WireGuard — a fast modern protocol; suitable both for connecting to a VPN service and for linking to another router.
  • IKEv1/IKEv2 — client for corporate and commercial IPsec servers.
  • L2TP/IPsec and PPTP/L2TP — for compatibility with existing servers; do not use PPTP for new setups.
  • SSTP — connection over HTTPS, including to another Keenetic via the KeenDNS cloud.
  • OpenConnect — client for servers compatible with Cisco AnyConnect.
  • OpenVPN — the most flexible option, but with configuration requirements (below).
  • Proxy client — since KeeneticOS 3.9 the router can access the Internet via HTTP, HTTPS or SOCKS5 proxy. The manufacturer recommends enabling DNS-over-TLS or DNS-over-HTTPS, otherwise some sites may render incorrectly.
  • ZeroTier — connecting the router to a ZeroTier mesh network (more — in the first part of the series).
  • Tunnels GRE, IPIP, EoIP — for connecting networks between routers. IPIP and GRE do not encrypt traffic by themselves. An example use — redirecting subnet traffic through a remote server via IPIP.

OpenVPN specifics on Keenetic

  • Configuration — a single file, certificates and keys embedded in it.
  • Parameters from OpenVPN 2.4 documentation are supported; parameters related to IPv6 are not supported.
  • The private key must be unencrypted (no passphrase): there is nowhere to enter it in the interface.
  • The OpenVPN file is not stored in the router’s main settings file, so its backup must be kept separately.
  • On older models all VPN configurations together must not exceed 24 KB; on modern models with index KN-XXXX storage is larger.

A step-by-step example — OpenVPN server on Ubuntu and Keenetic client.

Which tunnel for whom: connection policies

The router’s main capability as a VPN client is connection policies (rule-based routing). A policy is a set of connections with priorities, to which devices or network segments are bound. You can create up to 16 policies.

Example: the whole house uses the Internet via the ISP, while the game console uses the VPN.

  1. Configure the VPN connection on the “Other connections” page and enable “Use for Internet access” for it.
  2. On the Connection Policies page, on the policy settings tab, click “Add policy” and select only the VPN connection.
  3. On the policy bindings tab drag the desired device to the new policy. The device must be registered in the clients list.

All unregistered devices in the home and guest segments remain in the default policy. You can check which policy applies to a device in the clients list.

In addition to device bindings, there are domain-name based routes: traffic to specific sites can be directed to the desired connection.

What happens when the tunnel drops

Behavior is determined by the policy composition; there is no separate “Kill Switch” toggle in the Keenetic documentation.

  • In the default policy if the higher-priority connection fails the router switches to the next available. If VPN is first and the ISP is second, when the tunnel drops traffic will go directly.
  • In a VPN-only policy there are no other Internet paths. Until the tunnel is restored, devices in that policy remain without Internet — traffic does not go around it.

The choice depends on the task: for work devices that must not access the Internet outside the VPN — a VPN-only policy; for convenience — a VPN with a backup ISP.

DNS and policies

Only DNS servers of connections included in a policy are added to that policy. This protects against the situation where traffic goes via VPN but DNS queries go via the ISP. But if the VPN service does not provide DNS servers, devices in the policy may be left without name resolution — in that case add a DNS server manually bound to the interface.

Common mistakes

  • Internet access is not enabled for the VPN connection. The tunnel is up, but it does not participate in policies.
  • The device is not registered. An unregistered client remains in the default policy and rules are not applied to it.
  • No backup of the OpenVPN configuration. After resetting the router you will have to restore it from scratch.
  • Overlapping subnets. If the network on the other side of the tunnel matches the home network, routes conflict. More typical issues — in the analysis of the MikroTik and Keenetic setup.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply