What Is a VPN & Do You Need One?

A VPN creates an encrypted connection between your device or router and a VPN server. For UK broadband users, the main benefits are security on untrusted networks, reduced ISP visibility and control over where internet traffic exits.

Home network security, privacy & routing guide

What a VPN changes on UK broadband — and whether you need one

A VPN encrypts traffic between your device or router and a VPN server. That helps protect data on networks you do not fully trust — including public or shared Wi‑Fi and the access network operated by your ISP — while reducing what those networks can see about your traffic path. The VPN provider then becomes a new trust point.

Why use a VPN? Security on untrusted networks · Limit ISP visibility · Secure remote access
VPN route hero image showing your device, an encrypted tunnel, a VPN server and the website or app that sees the VPN exit IP

Quick answer

What is a VPN?

A VPN, or Virtual Private Network, creates an encrypted connection between your device and a VPN server. Its main security benefit is protecting the first part of your internet connection when you do not fully trust the network carrying it. Websites normally see the VPN server's public IP rather than your home connection's public IP.

The encrypted tunnel can prevent the local network or ISP from directly seeing the same destination traffic path and can protect otherwise unencrypted traffic from interception on that first leg. HTTPS still provides important end-to-end protection for websites, and the VPN provider becomes part of the trust chain. The extra encryption and routing can also reduce speed or add latency.

Page index

VPN guide: choose the section that matches your question

The trust boundary

What a VPN changes — and what it does not

A VPN is easiest to understand as a change to the network path. Instead of sending internet traffic directly from your broadband connection to each destination, the device first builds an encrypted tunnel to a VPN server.

It encrypts the first leg

Traffic between your device or VPN-enabled router and the VPN server is carried inside the encrypted tunnel. This is especially useful when the local network is not fully trusted.

It changes the public exit IP

Websites and apps normally see the VPN server's public IP address. That can also change the approximate location inferred from the IP address.

It does not remove every identifier

Account logins, cookies, browser or device characteristics and information you submit can still identify you. A VPN is not the same thing as anonymity.

It does not fix weak Wi‑Fi

If one room has poor signal, packet loss or interference, a VPN cannot create better radio coverage. Diagnose the home network first.

Security reference: the UK National Cyber Security Centre describes VPNs as encrypted network connections used to protect data in transit across untrusted networks. See the NCSC VPN guidance for the security principles behind managed VPN use.

↑ Back to guide index

Beginner setup

How to use a VPN in five steps

You normally do not need to change router settings to start using a VPN. For most people, the simplest route is the provider's official app on the phone, tablet or computer that needs the encrypted connection.

  1. Choose a provider that fits the devices you use.

    Check its privacy policy, independent assurance, supported protocols, refund terms and whether it has an official app for your operating system.

  2. Install the official VPN app.

    Download it from the provider's own website or your device's official app store rather than from an advert, mirror or unknown download site.

  3. Sign in and allow the VPN profile.

    Your operating system may ask permission to create a VPN connection. This is what lets the app route selected traffic through the encrypted tunnel.

  4. Start with a nearby server.

    For UK broadband, a nearby UK exit is a sensible first performance test. Automatic or “fastest” mode is also reasonable if the app clearly shows which server and protocol it selected.

  5. Confirm the connection and compare performance.

    Check that normal browsing works, then compare the same connection with the VPN off and on. If speed, latency or page loading changes sharply, use the diagnostic sections below before changing several settings at once.

Start with the app before configuring the router. Router-wide VPNs are useful for some households, but device apps are easier to switch off, compare and troubleshoot while you learn how the service behaves on your broadband connection.

↑ Back to guide index

VPN recommendations

VPN services recommended by LinkSpeed

These VPN providers are recommended by LinkSpeed as options worth considering. Compare privacy, performance, device support and router compatibility before choosing the service that best fits your needs.

NordVPN

Compare plans, supported devices, protocols and router support.

View Plans

PureVPN

Compare plans, supported devices, protocols and router support.

View Plans

All product names and logos remain the property of their respective owners. LinkSpeed uses them only to identify and accurately describe the referenced products.

How LinkSpeed evaluates VPN performance

LinkSpeed does not publish an invented “best VPN” score. Any performance comparison should start with a repeatable baseline and record the hardware, protocol, VPN server, time and network path used.

  1. Baseline first: test the same connection with the VPN off, preferably over Ethernet so Wi‑Fi is not the hidden bottleneck.
  2. Hold variables steady: use the same device, test destination and VPN region; change one protocol or server at a time.
  3. Measure more than download: record upload, idle ping, loaded latency, jitter and packet loss as well as throughput.
  4. Check processing limits: router-wide VPN tests must record router model and firmware because encryption can become CPU-bound before the broadband line is full.
  5. Repeat: use multiple runs and different times rather than presenting one speed-test result as a universal provider ranking.

↑ Back to guide index

Performance impact

Does a VPN slow down broadband speed or increase ping?

It can. A VPN has to encrypt traffic, send it to a VPN server and then route it onwards. The extra work and route usually add some overhead, but the size of the change depends on the protocol, server distance, server load, device performance and the underlying broadband path.

What changesWhy it can changeBest test
Download speedEncryption overhead, VPN server capacity, route length and device or router CPU can reduce throughput.Run the same speed test without the VPN, then connect to a nearby VPN server and repeat.
Upload speedUpload can expose router CPU limits, protocol overhead and a busy VPN exit more quickly on asymmetric broadband.Compare the same upload test with household cloud sync and backups paused.
Ping / latencyThe VPN server becomes another point in the path. A distant exit normally increases round-trip distance.Compare LinkSpeed Ping Test results with the VPN off and on.
JitterBusy VPN servers, wireless instability or changing routes can make packet delay less consistent.Keep the device, Wi‑Fi/Ethernet connection and destination unchanged between tests.
Location / CDN choiceServices may select content or server regions based on the VPN exit rather than your home broadband IP.Check the VPN exit country and choose the nearest appropriate server for performance testing.

Use a clean VPN performance baseline

  1. Test without the VPN first. Use Ethernet where possible, or stay in the same strong Wi‑Fi position.
  2. Record download, upload, ping and jitter. Do not judge the VPN on download speed alone.
  3. Connect to a nearby VPN server. Repeat the same tests on the same device.
  4. Try one alternate protocol if performance is poor. Do not change server, protocol and Wi‑Fi position at the same time.
  5. For gaming or calls, test the actual service. A speed test can look healthy while one game region or work VPN route remains slow.

↑ Back to guide index

UK broadband technical deep-dive

VPN performance on Openreach FTTP vs Virgin Media cable networks

The access network matters, but it does not create a fixed “VPN speed penalty”. The largest VPN variables are normally the selected VPN server, route length, protocol, device or router processing power and the broadband line itself. UK access networks can still change the symptoms through WAN session type, usable MTU, upload capacity and how easily a third-party router can replace or sit behind the ISP hub.

Openreach-based FTTP

Openreach is the access network, not the retail ISP. Authentication and WAN configuration differ between providers, so do not assume every Openreach line uses the same PPPoE or DHCP setup. If your retail ISP does use PPPoE, the traditional PPPoE MTU is 1492 bytes unless the path supports the 1500-byte PPP-Max-Payload extension.

Virgin Media cable / full-fibre hubs

Virgin Media supports modem mode on Hub 3, Hub 4 and Hub 5, allowing a capable third-party router to take over routing and VPN-client duties. Virgin currently states that modem mode is not available on Hub 5x, so the topology can differ by hub model.

MTU, packet fragmentation and VPN encapsulation

MTU is the largest IP packet a path can carry without fragmentation or another packet-sizing workaround. A VPN adds an outer IP header, transport header and tunnel-specific authenticated-encryption data, so the inner packet must fit inside a smaller effective envelope.

Effective inner packet ceiling ≈ Path MTU − outer IP header − UDP/TCP header − VPN protocol overhead This is a packet-size calculation, not a promise that throughput will fall by a fixed percentage.
Example outer pathPath MTUMinimum WireGuard outer overhead*Approx. inner ceiling
IPv4 + UDP1500 bytes60 bytes≈ 1440 bytes
IPv6 + UDP1500 bytes80 bytes≈ 1420 bytes
PPPoE path + IPv4/UDP1492 bytes60 bytes≈ 1432 bytes
PPPoE path + IPv6/UDP1492 bytes80 bytes≈ 1412 bytes

*WireGuard example: 20-byte IPv4 or 40-byte IPv6 outer header + 8-byte UDP header + 16-byte WireGuard data header + 16-byte Poly1305 authentication tag, before WireGuard padding and any extra path constraints. Treat the figures as packet-envelope examples, not universal VPN interface settings.

Do not blindly force 1420, 1412 or another MTU value. Modern VPN apps normally choose workable interface values and Path MTU Discovery may already handle the route. Change MTU or MSS only when testing shows a repeatable MTU problem, such as a tunnel that connects but stalls on larger transfers.

How much internet speed do you lose with a VPN?

There is no universal percentage. Packet headers and encryption add overhead, but the real speed change also depends on the VPN protocol and implementation, device or router CPU, server load, congestion, packet size, TCP behaviour and the route to the VPN exit. A fast device using a nearby server may lose very little throughput, while a low-power router or distant or busy exit can lose far more. Measure the same connection with the VPN off and on rather than relying on a fixed percentage.

↑ Back to guide index

Where the tunnel starts

VPN app on each device vs VPN on the home router

The best setup depends on whether you want control per device or broad coverage for the household. Many people are better starting with a VPN app because it is easy to switch off during troubleshooting and does not force every device through the same route.

SetupAdvantagesTrade-offsGood fit
VPN app on deviceSimple on/off control, per-device server selection and easier fault isolation.Every supported device needs its own app or configuration.Phones, laptops, tablets and users who want selective VPN use.
VPN client on routerCan route multiple home devices through one VPN configuration, including some devices without VPN apps.Not every router supports VPN client mode; encryption throughput can be limited by router hardware and all routed devices share the chosen exit unless policy routing is available.Advanced users who want household-wide or device-group routing.
Corporate / employer VPNProvides approved access to workplace systems and security controls.May deliberately route traffic through company gateways, inspection or policy systems and can add latency.Work systems where the employer requires its VPN.

UK router compatibility: ISP hub vs VPN-capable router

Router typeVPN-client positionPractical approach
Typical ISP-supplied hubOften supports VPN pass-through from devices but may not expose a commercial VPN client for routing the whole home.Use VPN apps on individual devices, or add/replace with a third-party router where the ISP setup permits it.
Virgin Media Hub 3 / 4 / 5Use modem mode when you want your own router to control the WAN and VPN tunnel.Connect the VPN-capable router behind the Hub in modem mode. Virgin says Hub 5x currently does not offer modem mode.
ASUSWRT / ASUSWRT-MerlinMany supported models provide VPN-client or policy-routing features.Check the exact model and firmware before buying; VPN throughput varies substantially with CPU and protocol.
OpenWrt / GL.iNetCommon choice for WireGuard/OpenVPN client routing and per-device policies.Prefer a model with published VPN throughput data and enough CPU headroom for your broadband speed.
Client mode is the key phrase. “VPN server”, “VPN pass-through” and “VPN client” are different capabilities. For a commercial VPN to cover the whole home, the router needs to initiate an outbound VPN client tunnel or run compatible third-party firmware.
Work device warning: do not replace, bypass or disable an employer-required VPN or security agent to improve speed. If a work VPN is the only path that performs poorly, compare an approved test and give the evidence to workplace IT.

For home router changes, keep a way back to the original configuration. If the VPN is installed on the router and something stops working, first confirm that the router itself still has internet access and then check VPN authentication, DNS, kill-switch behaviour and policy-routing rules.

↑ Back to guide index

Protocol choice

WireGuard, OpenVPN and IKEv2/IPsec: what the protocol changes

Think of the VPN protocol as the engine that builds and maintains the encrypted tunnel. It controls how the connection is established, how packets are protected and how they are transported. Different services may use standard protocols, modified implementations or their own branded variants.

WireGuard-based options

WireGuard was designed as a compact modern VPN protocol and is widely used as the basis for high-performance consumer VPN modes. Availability and privacy architecture still depend on the VPN provider's implementation.

WireGuard official project

OpenVPN

OpenVPN is a mature and highly configurable VPN system that can operate over UDP or TCP. It can be useful where compatibility matters, but performance depends on configuration and hardware.

OpenVPN community documentation

IKEv2/IPsec

IKEv2 with IPsec is common on mobile and managed devices and can handle network changes cleanly. Exact availability depends on the VPN service and operating system.

Automatic / smart mode

Many consumer VPN apps choose a protocol automatically. That is convenient, but record which protocol was active when comparing speed or diagnosing a connection problem.

WireGuard vs OpenVPN: technical comparison

ProtocolTransport / cryptoPerformance tendencyCPU / router impactReconnection & MTU notes
WireGuardUDP; ChaCha20-Poly1305Designed as a compact, low-overhead tunnel and commonly a strong first choice for speed testing.Often efficient on modern Linux-based routers, but real throughput still depends on implementation and SoC.Designed to cope cleanly with endpoint IP changes. Data packets add a 16-byte WireGuard header plus 16-byte AEAD tag before padding, in addition to outer IP/UDP headers.
OpenVPN UDPUDP; negotiated TLS/cipher suiteHighly configurable. Throughput varies with cipher, user-space/DCO path, server and hardware.Can be more CPU-sensitive on routers, although modern Data Channel Offload can change the performance profile.MTU/MSS settings matter when Path MTU Discovery is broken; OpenVPN documents mssfix and related controls for these cases.
OpenVPN TCPTCP; negotiated TLS/cipher suiteUseful where UDP is blocked or unreliable, but not the first choice for raw performance testing.Encryption plus TCP behaviour can add processing and recovery overhead.Can be more sensitive to loss because the outer TCP connection and inner TCP sessions both perform retransmission/control.
IKEv2/IPsecIPsec/ESP with IKEv2 key managementCommon on mobile and managed operating systems; performance depends on chosen algorithms and platform acceleration.Can benefit from native OS or hardware acceleration.Designed with mobility/rekeying mechanisms; exact tunnel overhead varies with ESP, NAT-T and crypto suite.

Why no percentage benchmark is shown here: a trustworthy 95–98% or +1 ms claim requires measured LinkSpeed test data on named hardware, servers and routes. Protocol design can explain likely behaviour, but it cannot substitute for a repeatable benchmark.

↑ Back to guide index

Reasons to use a VPN

Why use a VPN?

The main reasons to use a VPN are security and privacy. The encrypted tunnel protects the first leg of your connection on networks you do not fully trust — such as public or shared Wi‑Fi and the access network provided by your ISP — and reduces how much those networks can directly observe about where your traffic is going. It is not a cure for weak Wi‑Fi, malware or every form of online tracking.

Protect traffic on untrusted networks

On public Wi‑Fi, shared networks, hotels, cafés or other networks you do not control, a VPN encrypts traffic between your device and the VPN server. That makes interception of traffic on this first leg much harder. HTTPS still matters because the VPN does not replace end-to-end website encryption.

Privacy from your ISP and local network

Your ISP or local network operator can normally observe connection metadata and, where traffic is not otherwise encrypted, may be able to inspect more of it. With a VPN, they primarily see an encrypted connection to the VPN service rather than the same direct destination path. They can still see that you are using a VPN and observe traffic volume and timing.

Remote access

Businesses and advanced home users can use VPN technology to reach private network resources securely from outside the local network. This is different from using a commercial consumer VPN mainly as an internet exit.

Hide your home IP from websites

Websites normally see the VPN server's public IP rather than your home broadband IP. This reduces direct exposure of your home connection's public IP, but it does not make you anonymous if you sign in, accept tracking cookies or reveal identifying information.

↑ Back to guide index

UK privacy & law

What a UK ISP can see, ICRs and the Investigatory Powers Act

UK law does not mean every ISP automatically keeps a complete 12-month browsing history for every customer. Under the Investigatory Powers Act 2016, as amended in 2024, a data retention notice can require a telecommunications operator to retain specified relevant communications data where the legal tests are met. The current Notices Code says the retention period in a notice must be necessary and proportionate and can be up to a maximum of 12 months.

What an Internet Connection Record is

Government guidance describes an Internet Connection Record (ICR) as a record of an event showing the internet service to which a device connected. Examples can include that a website or app service was accessed, without recording the search term, article read or actions performed inside the service.

What changes when a VPN is active

With a correctly configured VPN, the ISP still carries the traffic and can see the VPN server endpoint, connection timing and traffic volume. The inner destination IP addresses and DNS lookups are carried inside the encrypted tunnel when DNS is also routed through it, so the ISP no longer sees the same direct destination path.

Without VPNDevice → UK ISP → website / appThe access network can observe the direct network destinations needed to route the connection, subject to encryption and protocol behaviour.
With VPNDevice ⇒ encrypted tunnel ⇒ VPN server → website / appThe access network sees the VPN endpoint and encrypted traffic characteristics; the VPN provider becomes the next trust point.
A VPN shifts trust; it does not remove it. Evaluate what the VPN provider logs, where it operates, how its apps and servers have been audited, and whether DNS/IPv6 traffic is kept inside the intended tunnel. Do not treat a “no logs” slogan as proof on its own.

↑ Back to guide index

Privacy reality check

What a VPN does not protect you from

Account identificationIf you sign in to Google, Microsoft, social media, shopping or banking services, the account can still identify you.
Cookies and trackingA different public IP does not automatically remove cookies, logged-in sessions or every browser/device signal.
Phishing and malicious downloadsEncryption does not make a fake website safe or turn a harmful file into a safe one.
Weak local Wi‑FiA VPN cannot repair interference, poor router placement, dead spots, bufferbloat or packet loss inside the home.
The VPN provider itselfThe service becomes an important part of your network path. Evaluate its privacy policy, security history, transparency and technical controls.
Every DNS or app behaviourVPN apps normally try to control DNS, but misconfiguration, split tunnelling or app-specific behaviour can create exceptions. Test the setup you actually use.
VPN vs Incognito: private/incognito browsing mainly changes what the browser stores locally after the session. It does not create the network tunnel a VPN provides. The two solve different problems.

↑ Back to guide index

Fault isolation

VPN connected but internet is slow, high-ping or not loading

Do not reset the whole network immediately. First prove whether the fault follows the VPN.

  1. Compare VPN off and on.

    If the connection works normally with the VPN disconnected, the broadband line and basic home network path are probably available.

  2. Try a nearby VPN server and compare latency.

    A distant or busy exit can add delay. Keep the protocol unchanged while testing the server change, then compare response times with the LinkSpeed Ping Test.

  3. Check the active protocol.

    If the provider offers another supported protocol, compare one change at a time and record the result.

  4. Check DNS, kill-switch state and stalled transfers.

    A failed VPN session can leave a kill switch intentionally blocking traffic, or a DNS path may fail even though the tunnel appears connected. If pages begin loading and then stall, run the LinkSpeed Packet Loss Test before assuming the broadband line is down.

  5. Compare Ethernet and Wi‑Fi under load.

    If both are slow only with the VPN, focus on the VPN route or device/router processing. If delay appears mainly while the connection is busy, use the LinkSpeed Bufferbloat Test. If Wi‑Fi alone is poor, use the home-network guides instead.

  6. For one app only, test the destination.

    A service can block VPN exits, choose a distant region or behave differently behind a shared VPN IP even when general browsing works.

↑ Back to guide index

Provider checklist

How to compare VPN services before paying

Do not choose only from a headline discount or server count. Start with the risks and devices you actually need to cover, then compare evidence and controls.

01

Privacy policy & logging

Read what connection, diagnostic and account data the provider says it collects, how long it keeps it and what is excluded from any “no logs” statement.

02

Independent assurance

Look for recent independent security or privacy audits and check what was actually in scope rather than relying only on a badge or marketing headline.

03

Protocols & security controls

Check supported protocols, kill-switch behaviour, DNS handling, split tunnelling and whether the features you need exist on your operating systems.

04

Real performance

Measure local and relevant remote servers on your own connection. A provider that is fast on someone else's gigabit line may behave differently on yours.

05

Router & device support

Confirm the service supports the devices you use and whether your router has a compatible VPN client if you want network-wide routing.

06

Commercial terms

Check renewal pricing, refund conditions, billing cycle and cancellation steps before buying. Treat introductory pricing separately from long-term cost.

How to verify a “no-logs” claim

A “no-logs” headline is only a starting point. Check the evidence behind it before treating the claim as meaningful.

  • Read the scope of independent audits: check what systems, server configurations and logging controls were actually examined, when the work was completed and whether the provider publishes enough detail to understand the result.
  • Look at server architecture: RAM-only or diskless designs can reduce persistent local storage, but the architecture alone does not prove that no useful metadata is collected elsewhere.
  • Check transparency reporting: useful reports explain the types and numbers of legal requests received and how the provider responded. A warrant canary may add context, but its presence or disappearance should not be treated as conclusive proof of logging.
  • Separate account data from traffic data: billing, support and diagnostic information may still be retained even when a provider says it does not keep browsing or traffic logs.

↑ Back to guide index

Focused answers

VPN FAQs for UK home broadband users

What does a VPN actually do?

A VPN creates an encrypted tunnel from your device or router to a VPN server. This protects the first leg of the connection on untrusted networks and limits what the local network or ISP can directly observe about the destination path. Websites and services normally see the VPN server's public IP address rather than your home connection's public IP.

Does a VPN slow down broadband speed?

It can. Encryption, the extra server, route length, server load and device or router processing all add potential overhead. Measure the same connection with the VPN off and on to see the real impact.

Does a VPN improve gaming ping?

Usually not. A VPN normally adds another hop and can increase ping. It can occasionally improve an inefficient route to one destination, so compare the same game region both ways rather than assuming.

Should I install the VPN on my router?

Router setup can cover more devices, but it is more complex and can be limited by router processor speed or VPN-client features. Device apps are normally easier for selective use and troubleshooting.

Does a VPN make me anonymous?

No. It changes the network route and public IP seen by destinations, but accounts, cookies, browser/device signals and information you provide can still identify you.

Should I disable a VPN for a broadband speed test?

For the baseline, yes. Test without the VPN first to see the broadband and home-network performance, then reconnect and repeat the same test to measure VPN overhead.

Do I need a VPN in the UK?

Not everyone needs a VPN running all the time. It is most useful when you want extra protection on untrusted networks, reduced visibility of destination traffic to the access network or ISP, or a secure remote-access tunnel. It does not replace HTTPS, software updates, anti-malware protection or careful account security.

Can a VPN cause websites to stop loading?

Yes. DNS failures, kill-switch rules, blocked VPN exit IPs, a failed tunnel or a service that restricts VPN traffic can all create this pattern. Compare VPN off and on before resetting the router.

Can I use a personal VPN instead of my work VPN?

Not for employer systems unless your organisation explicitly allows it. A corporate VPN may enforce access controls, routing and security requirements that a personal consumer VPN does not provide.

Affiliate note: Some VPN links on this page are affiliate links. LinkSpeed may earn a commission if you purchase through them, at no extra cost to you.

How LinkSpeed tests and checks claims