Is a VPN router the same thing as a VPN concentrator or VPN passthrough?

Summary

No, they share a word but do different jobs, and the quickest way to tell them apart is to ask where the VPN tunnel ends. With a VPN router, the router is the end of the tunnel and every device behind it can use the VPN. A VPN concentrator sits at the other end, taking in tunnels from dozens of sites or many users at once. VPN passthrough is just a router setting that lets a VPN app on your laptop reach a VPN server outside, with the router playing no part in the tunnel itself.

Where does the tunnel end?

A tunnel always has two ends. For a VPN router, one end is the router. For a concentrator, it's the central box or cloud service that many tunnels connect to. With passthrough, the end is the laptop or phone behind the router, and the router only forwards the traffic.

VPN routers cover every device behind them

Some home routers can act as a VPN server, so you can connect back to your home network from outside. ASUS lists PPTP, OpenVPN and IPsec as the server options on its routers, each with its own ports.

Others work as a VPN client for a commercial service. GL.iNet routers have built-in WireGuard support for providers including Mullvad, NordVPN and Surfshark. Their VPN dashboard can apply a rule to "All Clients," meaning every device on the router, or to specified devices only, with everything else going out over the normal connection. A smart TV or games console that can't run a VPN app gets covered this way. Our home router VPN article goes further into home setups.

Concentrators take in many connections at once

A company with dozens of branch offices needs each branch router to hold a tunnel back to headquarters or the cloud. The device or service that terminates all of those tunnels is the concentrator. AWS sells one as a cloud service.

AWS's Site-to-Site VPN Concentrator is aimed at customers "who need to connect 25+ remote sites to AWS, with each site needing low bandwidth (under 100 Mbps)." It handles 5 Gbps in total across all sites, with a 100 Mbps ceiling per site. It only works with Transit Gateway, not Cloud WAN or a virtual private gateway, and it supports BGP routing only.

AWS bills it per concentrator-hour plus a connection-hour charge for each site. Headcount never enters the calculation, which is why concentrators don't appear in per-user price tables. The actual rates and a 50-site example are in our AWS VPN pricing article.

Passthrough only opens the door

Picture someone working from home. The VPN app on their laptop builds a tunnel to the company's VPN server, and the home router just lets that traffic out.

Cisco's documentation for its small business routers explains why the setting exists. Home and small office routers share one public IP address among the devices behind them, a technique called NAT, and "Point-to-Point Tunneling Protocol (PPTP) and Internet Protocol Security (IPSec) VPN do not support NAT." Passthrough lets that VPN traffic through anyway. On Cisco's RV34x routers there are separate checkboxes for IPsec, PPTP and L2TP passthrough, and all three are on by default.

So a box labeled "VPN support" might mean it can be a VPN server, it can be a VPN client for a service, or it only does passthrough. Those are three different capabilities, and a router that only does passthrough won't put your smart TV on a VPN.

Sources

Related on this site


Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.