GL.iNet Flint 2 Review: ISP Router Replacement

I replaced a client's ISP router last week with a GL.iNet Flint 2, and it's become my default recommendation when someone asks what router to buy. The complaint that started the job was ordinary — dead spots at the back of the building. But the fix I recommended wasn't a wifi extender, and the reason has less to do with signal than with who owns the box sitting in the closet.

This is the long version of the answer I give clients around Hopewell and Princeton when they ask whether it's worth replacing the router their internet provider handed them. Short version: yes, and not mainly for the speed.

What your ISP's router actually tracks

You're probably renting it, usually somewhere between $10 and $15 a month. That part most people know. What gets missed is what the box actually does while it sits there.

Every device on your network asks that router where to find things. Every domain — every site, every app's backend, every smart TV phoning home — passes through it as a DNS lookup. By default your internet provider sees all of it, and in the United States there's nothing stopping them from building a profile out of it. The federal rules that would have required your permission were repealed in 2017.

Then there's the control problem. The firmware is managed remotely, and you don't decide when it changes. Settings you'd expect to own — DNS servers, port forwarding, what the guest network does, sometimes even the admin password — are either hidden or locked. Some providers broadcast a second public hotspot off your hardware, on your electricity, for other customers to use. You can usually opt out. You have to know to go looking first.

This is true in the same general shape whether you're on Xfinity, Verizon Fios, Optimum, or Spectrum. The details differ. The arrangement doesn't: it's a box that answers to somebody else, installed at the exact point where all of your traffic converges.

Why Google, Amazon, and Netgear routers aren't the fix

The instinct is to buy a nice consumer router and be done. But most of the popular ones now sit inside somebody's ecosystem. Nest Wifi is Google. Eero is Amazon. Netgear's Orbi and Nighthawk lines push you into their app, and some of the security features live behind a subscription.

In each case setup requires an account, your configuration lives on the manufacturer's servers, and the company is not fundamentally in the router business — it's in the data and services business, and the router is the doorway in. Trading your ISP's visibility for an advertising company's visibility isn't much of a trade.

What I wanted for this client was boring: a router that works for a living and doesn't have a second job.

The GL.iNet Flint 2: an OpenWrt router with no account

The GL.iNet Flint 2, model GL-MT6000, runs OpenWrt — open-source router firmware maintained by an independent community since 2004. The admin panel is served from the router itself, on your own network. There's no account to create, no phone app required, and no cloud service holding your configuration. Remote management exists, it's opt-in, and it's off unless you deliberately turn it on.

Three features do the actual work:

Network-wide adblocking. AdGuard Home is built in, filtering ads and trackers at the DNS level for every device at once. The smart TV, the tablet the kids use, the guest phones — all covered, without installing anything on any of them. A browser extension can't do that, and neither can anything you configure per-device.

A real VPN router, not a per-device app. WireGuard runs at about 900 Mbps and OpenVPN at about 880 with hardware acceleration, fast enough to route an entire office through it without noticing. It also works as a VPN server, so you can reach your office network from the road without paying a service to broker the connection.

Encrypted DNS. DNS-over-HTTPS and DNS-over-TLS are toggles in the interface, so those lookups stop being readable by your provider in the first place.

GL.iNet Flint 2 specs

  • Wifi: Wi-Fi 6 (AX6000) — 4804 Mbps on 5 GHz, 1148 Mbps on 2.4 GHz
  • Antennas: four dual-band 2.4/5 GHz
  • Processor: quad-core MediaTek at 2.0 GHz
  • Memory: 1 GB DDR4 RAM, 8 GB eMMC storage
  • Ports: 2.5 Gbps WAN, a second 2.5 Gbps WAN/LAN, four gigabit LAN, one USB 3.0
  • VPN: WireGuard up to 900 Mbps, OpenVPN up to 880 Mbps
  • Security: WPA3, DNS-over-HTTPS/TLS, DFS certified
  • Power: 12V/4A, under 20 W in use
  • Size: 233 × 137 × 53 mm, 761 g
  • Price: $169.99

Against a $15/month rental that's roughly a year to break even, and then it keeps going.

Range: how far the Flint 2 actually reaches

I test this stuff in real buildings, and older construction around Hopewell and Flemington is unkind to wifi — plaster over lath, brick interior walls, additions with foil-backed insulation buried in them. The Flint 2 covered more of this client's building from a single unit than anything else I've put in the same spot. The back rooms that started the whole conversation are now fine, and I didn't have to run a cable or add an access point.

That said: it's one router, not a mesh kit. If you're covering a large footprint, multiple floors, or a layout with a detached section, you'll still want proper access points — which is usually the real fix for a network that's been degrading for years. A strong single unit buys you a lot of headroom. It doesn't repeal physics.

What you give up when you stop using the ISP router

Worth being straight about this, because it's the part that gets glossed over in most recommendations.

You still need the modem. Replacing the router doesn't replace whatever brings the internet into the building — a cable modem, or the ONT on fiber. If your provider gave you a combined modem-router gateway, you keep that box and put it in bridge mode so it stops routing and just passes the connection through to the Flint 2.

That matters for the math. If the gateway stays, so does the rental fee, and the win is control and coverage rather than money. To actually drop the fee on cable you'd need to buy your own compatible modem too, which is a separate purchase and worth confirming against your provider's approved list first. On fiber the ONT typically isn't a separate rental, so the picture is simpler.

You also give up ISP tech support for anything wifi-related. They'll support the line up to their box and stop there. In practice that's less of a loss than it sounds — the answer was usually "restart it" — but it's real, and it's the reason some people would rather hand the whole thing off.

And if your provider bundles phone service through that gateway, check how it's wired before you buy anything. That's the one case where this gets genuinely fiddly.

Downsides: what the Flint 2 isn't

GL.iNet is based in Hong Kong. If your instinct is to ask what that means for a device handling all your traffic, that's the right instinct. My answer is that the firmware is OpenWrt underneath and open to inspection, you can flash upstream OpenWrt if you'd rather not run their build at all, and nothing requires an account or a callback to their servers. That's a materially better position than a closed box from a company whose business model depends on knowing things about you — but it's a judgment call, and you should make it knowingly rather than because I said so.

It's also Wi-Fi 6, not Wi-Fi 7. That's the right call at this price, and Wi-Fi 7 buys most small offices nothing today, but you should know which you're getting.

And the settings page, while genuinely approachable, is a settings page. If the phrase "bridge mode" made you tense up, this is a router you'd want installed rather than one you'd want to unbox.

How to replace your ISP router, and where to buy the Flint 2

The Flint 2 is on Amazon here, and GL.iNet sells it directly. (That Amazon link is an affiliate link — if you buy through it I earn a small commission at no cost to you. Nobody paid me to write this and I bought the units I've tested with my own money.)

The install itself is four steps: put the ISP gateway into bridge mode, plug its ethernet into the Flint 2's WAN port, run the setup wizard, then turn on AdGuard Home and encrypted DNS. Most people who are comfortable in a settings page can do it in an afternoon.

If you'd rather not — or if the bridge-mode phone call with your provider sounds like a bad evening — that's a normal thing to hand off. I install these for small businesses and homes around Hopewell, Princeton, Flemington, and Yardley, and it's usually a single visit. Get in touch and I'll tell you plainly whether it's worth doing in your building, including when it isn't.

← Back to Insights