Setting Up a VPN Before You Travel: The Decisions, Not the Clicks
Installing a VPN client is the easy part and not really the subject. What determines whether the thing works on a hotel network in a fortnight’s time is a set of decisions — which devices, which protocol fallback, what happens when it drops, how names get resolved, when it connects automatically — and each of those should be settled and verified while you still have a connection you trust and accounts that trust you.
This page is about those decisions. It is not a device walkthrough, and it deliberately does not include a click-by-click for any platform.
Why “set up” means more than “install”
An unconfigured client works on the connection you installed it on. That tells you very little, because your home network is not filtering anything, has no captive portal, and does not interfere with your name lookups.
Every setting below is one you will not notice at home and will notice abroad. Getting them wrong produces failures that look like the network being broken, in a place where you cannot easily investigate — which is why the work belongs before departure rather than on arrival.
Decision one: which devices, and which one is the trusted one
Install on everything you are taking, sign in on each, and connect once on each. A client installed on a laptop and not a phone is a client you will not have on the evening it matters.
Then pick one device as the trusted one for banking, identity, and recovery, and keep it patched and encrypted. Having a designated device makes several later decisions obvious.
Check how many simultaneous connections your subscription allows, because discovering the limit by being disconnected is a bad way to learn it.
Decision two: the protocol fallback
Take the default, and separately find out where the protocol setting lives and which option your provider recommends for restricted networks. Switch it once at home so the menu is familiar rather than novel.
This matters because it is the highest-yield fix on guest networks, for reasons in when your VPN protocol choice actually matters. Knowing the path through the menus is most of the value.
Also save a manual configuration or profile if your provider publishes one. It lets you build a connection with the operating system’s own client if the app itself is unavailable or unwelcome.
Decision three: what happens when it drops
Enable the kill switch, then find out whether yours is application-level or system-level, because that predicts how it fails and how hard it will be to get past a captive portal.
Decide knowingly about always-on rather than leaving it as it came. It is the stronger setting and also the one most likely to leave you facing a dead browser in an airport. The whole trade-off is in why a kill switch matters most on travel networks.
Leave per-application exceptions alone unless you have a specific reason for one. Exceptions are the commonest route to being unprotected while believing otherwise.
Decision four: name resolution and auto-connect rules
Two settings that quietly cause most arrival-day confusion.
How names are resolved. Clients typically push their own resolver while connected, which is usually what you want. What matters is knowing how to revert to the network-assigned resolver temporarily, because a captive portal’s own sign-in pages sometimes will not load otherwise.
Automatic connection rules. Many clients can connect automatically on untrusted networks, or on any network not on a trusted list. Useful, and worth configuring deliberately: decide whether your home and office networks are trusted, and understand that auto-connect will fight every captive portal you meet until you have signed in.
Verify each one before you leave
Verification is the step that separates this from a shopping list, and it takes about a quarter of an hour.
- Connect and confirm the exit location is the one you selected.
- Disconnect abruptly — turn off the connection rather than the client — and confirm your traffic actually stops if the kill switch is meant to be on. Then reconnect and confirm it resumes.
- Switch protocol and reconnect, to prove the alternative works and that you know where the setting is.
- Connect to a server in the country you are travelling to, and open the sites and apps you will genuinely need. Complete any verification prompts now, while you are somewhere your accounts trust.
- Reconnect to a home-country server and confirm the services that must look domestic still work.
- Disconnect entirely and confirm everything still works without the tunnel, so you can tell a tunnel problem from a network problem later.
Step four is the highest-value item on this page. A service that will demand extra verification from a new apparent location will do it either way; doing it at home costs you a minute.
What this is not sufficient for
- It does not prepare your accounts. Second factors, recovery contacts, and banking notices are a separate and more important body of work — the pre-departure connectivity checklist.
- It does not decide your mobile connectivity, which affects your apparent country and whether your number keeps receiving codes: roaming vs local SIM vs eSIM.
- It does not choose an exit country per task, which is its own decision: which VPN server country to connect to.
- It does not apply to employer equipment. On a managed device the configuration is not yours to set — travelling with a work laptop.
- It does not change what a tunnel protects, which stays exactly as described in what a VPN does not change about your location.
The one timing rule
Do all of it before you go, not on arrival. Provider websites and app listings are not reachable everywhere, store catalogues differ by market, and a network that filters actively may make obtaining the software difficult once you are inside it. Every item above is trivial from home and potentially impossible from a hotel room.
Bottom line
Installing is not setting up. Decide devices, protocol fallback, drop behaviour, resolver handling, and auto-connect rules deliberately; then verify each by breaking it on purpose while you are still somewhere it is easy to fix. Fifteen minutes at home replaces an unpleasant first evening abroad.