Keyboard keys spelling security on a red surface

GL.iNet Travel Router Review: Slate AX vs Beryl AX for Secure Hotel Wi-Fi

·

·

A GL.iNet travel router is the one piece of gear I never leave off a packing list, hotel conference or otherwise. This is a head-to-head between the Slate AX and the Beryl AX — two models that solve the same problem from slightly different angles, and picking wrong just means you paid for capability you didn’t need.

Affiliate disclosure: this post contains affiliate links. As an Amazon Associate, RMF Insider earns from qualifying purchases — at no extra cost to you.

Why a practitioner carries a travel router at all

Hotel and conference Wi-Fi is a shared, unmanaged network you don’t control, full of other guests’ devices you know nothing about. Every laptop, phone, and tablet you connect directly to that network is exposed to whatever else is sitting on it.

A travel router changes the topology. The router joins the hotel network and deals with the captive portal exactly once. Every device you own then connects to the router’s own private network instead, riding a VPN tunnel out to the internet. Your laptop, phone, and tablet never actually touch the hotel’s shared segment.

That one-time captive portal login is a bigger deal than it sounds. Anyone who’s tried to get a work laptop, a personal phone, and a tablet all through a hotel’s janky sign-in page separately knows the router paying that tax once, for everything, is worth the price by itself.

GL.iNet Slate AX (GL-AXT1800)

The Slate AX runs about $100 and is built around a quad-core IPQ6000 chip with Wi-Fi 6 AX1800. It has three gigabit Ethernet ports and a USB 3.0 port, running OpenWrt 23.05 under the hood.

Throughput is the headline feature here. In real-world testing it pushes roughly 550 Mbps over WireGuard and about 560 Mbps over OpenVPN using DCO (Data Channel Offload). That’s fast enough to actually use a hotel’s gigabit-class connection instead of bottlenecking it through VPN overhead, which is the single biggest complaint about budget travel routers.

Three Ethernet ports also means you can hardwire a device — a conference room switch, a hotel ethernet jack instead of Wi-Fi, or a secondary access point — without giving up ports for basic connectivity.

GL.iNet Beryl AX (GL-MT3000)

The Beryl AX runs about $90–99 and trades some horsepower for size. It’s genuinely pocket-sized in a way the Slate AX isn’t, with Wi-Fi 6 AX3000 and a 2.5 Gbps WAN port.

The catch is WireGuard throughput caps around 300 Mbps in real-world use. That’s the CPU, not the WAN port, being the bottleneck — the 2.5 Gbps WAN port is there for a fast unencrypted connection, but the moment you push everything through a VPN tunnel, the processor becomes the limit.

For most hotel and conference Wi-Fi, which rarely delivers a stable few hundred Mbps to begin with, 300 Mbps of VPN throughput is not a practical limitation. It becomes one if you’re on a fast home connection or a well-provisioned conference network and want to actually use all of it.

Slate AX vs Beryl AX: head-to-head

SpecSlate AX (GL-AXT1800)Beryl AX (GL-MT3000)
Price~$100~$90–99
Wi-FiWi-Fi 6 AX1800Wi-Fi 6 AX3000
CPUQuad-core IPQ6000Lower-power chip, smaller footprint
Ethernet3x Gigabit + USB 3.02.5 Gbps WAN port
WireGuard throughput~550 Mbps~300 Mbps
OpenVPN throughput~560 Mbps (DCO)Lower than Slate AX
SizeStandard travel routerPocket-sized
Best forMax VPN throughput, wired portsPacking light, still fast enough for hotel Wi-Fi

How I actually use one

Repeater mode is the feature that makes hotel Wi-Fi tolerable. The router connects to the hotel network as a client, handles the captive portal, and rebroadcasts a private SSID that only my devices join. Everything behind that SSID rides the VPN tunnel automatically — I don’t have to remember to turn a VPN app on for each device separately.

GL.iNet’s firmware ships with integrations for more than 30 VPN providers, so setup is generally pasting in a config file or a few credentials rather than hand-building WireGuard configs on each device.

Honest downsides worth knowing before you buy either one:

  • CPU throttles under sustained VPN load on both models — the rated Wi-Fi speed and the actual VPN throughput are two different numbers.
  • The Beryl AX’s ~300 Mbps WireGuard ceiling will cap you if you’re on a genuinely fast ISP or conference connection.
  • The admin UI has real depth — VLANs, firewall rules, multiple VPN clients — that a non-technical user will never touch and may find intimidating on first boot.

Your first hotel deployment, step by step

Do the setup work at home, not in a hotel lobby at 11pm after a travel day. Here’s the order that avoids a bad first trip with either router.

  • Flash the latest firmware before you leave. GL.iNet ships updates regularly, and a router sitting in a box since purchase is usually a version or two behind. Do this on your home network where a failed update just means trying again, not scrambling on hotel Wi-Fi.
  • Set your own Wi-Fi credentials on the router’s private SSID. Don’t leave the default admin password or a default network name — this is the network your devices will actually trust and connect to automatically, so treat its credentials like you would your home router’s.
  • Load your WireGuard config before you travel. Whether it’s from your own self-hosted WireGuard server or one of the 30+ supported VPN providers, paste in the config file and confirm the tunnel comes up while you’re still on a network you understand.
  • Test the whole chain at home first. Connect a laptop and a phone to the router’s SSID, confirm the VPN tunnel is actually active (check your IP address matches the VPN exit, not your home ISP), and confirm you can still reach the sites you need. Finding a misconfigured WireGuard peer at home costs you five minutes. Finding it in a hotel room costs you the evening.
  • Simulate the captive portal step if you can. Not every home setup can replicate a hotel captive portal, but if you have access to any network with a browser-based login page — a coffee shop, an airport lounge — do a dry run of joining that kind of network as the router’s WAN connection before you’re relying on it for real.

Once you’ve done this once, the actual hotel routine is fast: plug the router in, join the hotel Wi-Fi as the WAN, clear the captive portal on the router’s own connection, and every device you own is already configured to join the router’s private SSID it’s used at home. No repeating the captive portal per device, no re-pasting VPN configs on the road.

Newer models if you want more: Puli AX and Slate 7 Pro

If you want more than either the Slate AX or Beryl AX offers, GL.iNet’s newer lineup includes the Puli AX (GL-XE3000), which adds 5G dual-SIM connectivity and a built-in battery for fully mobile use where you’re not relying on hotel or venue Wi-Fi at all — useful if you travel to locations where the local Wi-Fi is unreliable or you don’t trust it even behind a VPN tunnel.

The Slate 7 Pro (GL-BE10000) brings Wi-Fi 7 to the lineup, aimed at anyone future-proofing a hardware refresh rather than solving an immediate throughput problem — Wi-Fi 7 client devices are still catching up in the market, so the near-term benefit is smaller than the spec sheet suggests. Neither is necessary for standard hotel or conference use, but they’re worth knowing about if your travel pattern is heavier than a few trips a year or you’re deploying routers for a team rather than just yourself.

Which one to buy

Buy the Slate AX if you want the highest realistic VPN throughput and don’t mind a slightly bigger unit, or if you’ll actually use the extra Ethernet ports. Buy the Beryl AX if packing size is the deciding factor and 300 Mbps is plenty for what you’ll actually be doing on hotel Wi-Fi — which, for most conference and travel scenarios, it is.

A travel router solves the network isolation half of the travel security problem. The device authentication half is still on you — I don’t travel without a hardware security key for exactly that reason, which I cover in the YubiKey 5 NFC review. And if you’re carrying sensitive files on the trip itself, pair the router with a FIPS-validated drive rather than trusting laptop disk encryption alone — see our hardware encrypted drives comparison.

If you’re documenting remote access controls as part of continuous monitoring, our ConMon checklist is a useful reference for how travel and remote work scenarios typically get captured.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

One response

  1. Best VPN for Security Professionals in 2026: NordVPN vs Surfshark vs Proton VPN – RMFInsider

    […] you’re running a VPN client on a travel router rather than per-device, our GL.iNet travel router review covers how that setup actually performs under real hotel and conference […]

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading