Noob here. This is probably the most repeated question, but I don’t know the technical terms to make the appropiate digging online, and thought of asking humans before slopping my way around.
I don’t trust my ISP or the government above it.
The ISP remotely manages the local network! So I installed a router of my own and my devices only to that one.
I would like to encrypt (?) anything that goes out of my own router, so my ISP doesn’t evesdrop what I’m doing even if they want to (I know I know… if they really wanted, they could just send friends to my house).
Using Linux, Android GOS, and Pihole. They live under a “picked-up-from-a-shelf” router; and that router under theirs.
(I cannot get a different ISP)
Thanks


You can run your VPN on your firewall (mine is opnsense, behind a cable modem in bridge mode). E.g. wireguard with Mullvad is a good option. Or you can set up a VPN client on your end devices – Mullvad gives you 5 endpoints for one account.