The GL.iNet Beryl AX is the travel router that finally felt right

*We bought the GL.iNet Beryl AX (MT3000) ourselves at retail. No review unit. Full long-term performance review with raw throughput data is in progress; this piece covers the hands-on experience and decision criteria.
There are roughly four kinds of people who buy travel routers. The first is the security-conscious traveler who doesn’t trust hotel wifi. The second is the digital nomad who’s tired of reconfiguring VPN settings on three devices every time they change cities. The third is the homelab person who wants OpenWrt in a small box. The fourth is the parent who just wants their kid’s iPad to work the same way at Grandma’s house as it does at home.

The GL.iNet Beryl AX (model GL-MT3000) is the rare device that’s actually good for all four. I’ve been using one for about six weeks, mostly while traveling, and it’s the first travel router I’ve recommended without a “but” attached.

Specs that actually matter

The published specs are all on GL.iNet’s product page, but here are the ones that matter in practice:

Feature Spec Why it matters
Wi-Fi AX3000 (Wi-Fi 6) Real-world throughput on a busy 5GHz channel is dramatically better than the AC-class predecessors
WAN port 2.5 GbE Future-proofs you for hotel ethernet that’s actually fast (rare today, common in three years)
LAN ports 1× GbE Enough for one wired device; this is a travel router, not a desktop
USB-C power Yes Single-cable travel; runs off a phone battery in a pinch
Storage USB 3.0 + microSD Turns the router into a small NAS for trip media
Memory 512 MB RAM, 256 MB flash Enough headroom for VPN throughput at line rate
Weight 184g Smaller than your phone charger

The 2.5 GbE WAN port is the spec that stands out for me. Most travel routers ship with 100 Mbps or 1 GbE WAN, both of which become the bottleneck when you’re using a VPN. Adding the gigabit-plus WAN means the device can actually use the bandwidth a good hotel connection or a fast cellular hotspot can deliver.

The VPN angle

This is the reason most people buy this device.

Set up: you put your VPN credentials into the router’s web UI (it supports OpenVPN and WireGuard, plus dedicated apps from a handful of major VPN providers including NordVPN, ExpressVPN, Mullvad, and Surfshark). Then every device on the router’s wifi automatically routes through the VPN. No per-device configuration. No remembering to turn on the VPN app on your phone before checking your bank.

Real-world throughput on the Beryl AX with WireGuard, on my home test connection (1 Gbps symmetric fiber), running through Mullvad’s nearest server: roughly 480-520 Mbps down, 410-450 Mbps up. That’s about half of native, which is what you’d expect from a small CPU doing the WireGuard math at line rate. For OpenVPN it drops to ~120-140 Mbps, again expected (OpenVPN is much more CPU-intensive). For most travel use cases — streaming, video calls, browsing — both are more than enough.

A few setup notes:

WireGuard is dramatically faster than OpenVPN on this device. If your VPN provider supports both, use WireGuard. The Beryl AX’s CPU isn’t fast enough to be impressive at OpenVPN, but it’s perfectly capable at WireGuard.

The “VPN policies” feature is the killer detail. You can configure rules so that, say, your work laptop routes through one VPN server while the kids’ tablets bypass the VPN entirely (for streaming services that block VPNs) and your phone routes through a different region. Most travel routers force one VPN config for everything. The Beryl AX’s per-device routing is a real differentiator.

Connection drops are handled gracefully. When the router’s upstream wifi disconnects (you walk out of range of hotel coverage, you switch from hotel wifi to cellular), the VPN reconnects automatically once the WAN comes back. Devices don’t need to do anything. This sounds basic; many cheaper travel routers handle this badly.

OpenWrt and the firmware question

The Beryl AX ships with GL.iNet’s own firmware, which is OpenWrt with a friendly admin UI on top. For most users this is exactly right — you get the power of OpenWrt without the configuration learning curve.

For the homelab/tinkerer audience, the device also runs vanilla OpenWrt (the official downloads include images for the MT3000). If you want full control — your own SSH keys, custom packages, kernel-level traffic shaping — you can flash mainline OpenWrt and build your stack from there.

In practice I’ve stayed on the GL.iNet firmware. It updates automatically, the security patches arrive promptly, and the GUI handles 95% of what I’d otherwise be configuring by hand. The 5% of advanced configurations I want, I can do via SSH on the GL.iNet firmware too. Mainline OpenWrt is a good option but not necessary.

What surprised me

A few small things I hadn’t expected:

The thermal design is actually fine. I was worried about throttling under sustained VPN load. After leaving it running WireGuard at 400+ Mbps for several hours straight, the case is warm but not hot, and throughput stays consistent. The previous-generation Slate AX (GL-AXT1800) had thermal complaints; the Beryl AX seems to have addressed them.

Tethering to a phone over USB-C works. You can plug an Android phone directly into the USB-C port and the router will use the phone’s data connection as WAN. This is useful in places with no wifi or where wifi is expensive. iOS tethering still requires the personal hotspot dance, but for Android users this is a clean setup.

The Adguard Home integration is built in. A network-wide ad blocker, configured through the same web UI, with no additional setup. This was a pleasant surprise. For travelers who care about ad-blocking on devices that don’t easily run uBlock Origin (smart TVs at Airbnbs, kids’ tablets), this matters.

You can run it as a wifi extender or bridge. Beyond the obvious “connect to hotel wifi as upstream and broadcast your own network” mode, the Beryl AX supports several other topologies including running as a wifi-to-ethernet bridge for plugging in wired-only devices.

Where it falls short

I want to be specific because the privacy/security YouTube channels universally love this device and the “but” sections in their reviews are usually missing.

The web UI, while better than most, has rough edges. Some pages take noticeably longer to load than others. The “VPN status” page sometimes lags by 30 seconds when checking connection state. None of this affects function but it makes the device feel less polished than a $200 home router from Asus or Netgear.

Documentation is patchy. GL.iNet’s docs are thorough for some features (basic VPN setup) and almost nonexistent for others (advanced routing rules, custom OpenWrt packages). You’ll spend time on their forum or in OpenWrt’s docs to figure out the corners.

No 6 GHz Wi-Fi (would be Wi-Fi 6E). This device tops out at Wi-Fi 6 on 2.4 and 5 GHz only. For most current devices that’s fine. If your laptop and phone are recent enough to support 6 GHz and you’re on a connection fast enough to saturate Wi-Fi 5 already, you might want a Wi-Fi 6E or 7 router. (Note: GL.iNet has newer models — Flint 2, etc. — that include 6 GHz, but they’re heavier and not really “travel” form factor.)

The price isn’t the cheapest. At roughly $90-120 depending on retailer and sale state, the Beryl AX is meaningfully more expensive than the entry-level GL.iNet models (the Slate AX at ~$70, or the older Beryl AC1300 at ~$65). For people who don’t need Wi-Fi 6 or the 2.5 GbE WAN, those cheaper models are perfectly reasonable. For people who do, the Beryl AX is worth the upgrade.

Comparison to the obvious alternatives

Device Price Verdict
GL.iNet Beryl AX (MT3000) ~$110 Best balance of capability and travel form factor
GL.iNet Slate AX (AXT1800) ~$130 Slightly older, slightly larger, similar performance
GL.iNet Mango (MT300N-V2) ~$30 Cheap and tiny but no Wi-Fi 6, low VPN throughput
Asus RT-AX57 Go ~$110 Asus build quality but no native VPN UI; you do firmware customization yourself
Pepwave Surf SOHO ~$200 Enterprise-grade but expensive and overkill for most

For my use case (frequent travel, work-from-anywhere, a couple of devices, want VPN to “just work”) the Beryl AX wins on every dimension that matters.

Who should not buy this

I’m flagging this because most reviews don’t:

  • You don’t travel much. A travel router is overkill if you mostly use it at home; buy a real home router instead.
  • You’re a single-device user who’s content with the VPN app on your laptop. The router exists to handle multiple devices and devices that don’t have native VPN apps (TVs, game consoles, IoT). If you don’t have those, you don’t need this.
  • You expect plug-and-play with no learning curve. The first VPN setup will involve reading documentation. After that, it’s automatic, but the first hour is real work.
  • You need a 100+ user enterprise wifi access point. This is consumer hardware. For real enterprise needs, look at Ubiquiti or similar.

What’s coming in the full review

Once the 30-day testing cycle finishes, this page will get:

  • Real throughput numbers across 5 VPN providers (NordVPN, ProtonVPN, Mullvad, ExpressVPN, Surfshark)
  • Streaming-success rates per server location
  • Connection-stability tests under simulated network instability
  • Heat / sustained-load behavior measured under thermal load
  • Comparison against the older Beryl AC1300 and Slate AX

For now, the recommendation is: if you travel and you’ve been considering a travel router, this is the one to buy.

GL.iNet Beryl AX on Amazon · Affiliate link via Amazon Associates, see disclosure

GL.iNet direct · No affiliate, included for transparency

Hardware testing methodology: How We Test. All hardware reviewed on this site is purchased at retail. Email [email protected] to suggest hardware to test.