Which Kind of VPN Do You Actually Have?

The word “VPN” is attached to at least three unrelated products: the connection your employer issues so you can reach internal systems, the subscription service you install for privacy and access, and browser add-ons that borrow the label while handling only what happens inside that browser. They solve different problems, they behave differently when you travel, and two of them will fight each other on the same device.

If a VPN is behaving strangely abroad, the first useful question is not which server you are on. It is which of these you are actually running.

The employer’s VPN: a route into somewhere specific

A corporate VPN exists to put your device inside the organisation’s network so you can reach systems that are not published to the public internet. Its purpose is arrival, not concealment. It is administered by someone else, it may be mandatory, and it usually logs — properly and by design, because the organisation is accountable for what happens on its network.

What that means for travel:

  • It is not there for your privacy. Your employer’s network operators can see your activity on it. That is the arrangement you agreed to.
  • It may route everything or only some things. If it routes everything, your personal browsing goes through your employer while it is up.
  • It often refuses to run alongside anything else. Two tools both claiming to handle all your traffic is a conflict, not a configuration.
  • It may be geofenced or flagged by location. Connecting from an unexpected country can trip a security control rather than simply working.

The rules and etiquette around carrying one across a border are their own subject, in travelling with a work laptop.

The consumer VPN: a route out of wherever you are

This is the product the rest of this site is about. You pay a provider, install its app, and your traffic leaves through a server you choose. Its purpose is to take visibility away from the network you happen to be on and to give you an apparent origin somewhere else.

It is the opposite orientation from the employer’s tool. One is about getting in to a named network; the other is about getting out of an unnamed one. The general shape is in what a VPN is.

The browser add-on that calls itself a VPN

Most extensions marketed as VPNs are not tunnels for your device. They redirect the traffic of one browser, and often only some of it. Everything else on the machine — other browsers, mail clients, messaging apps, updaters, anything running in the background — carries on using the local network directly.

That is not automatically useless. It is genuinely convenient for changing which regional edition of a website you see. But it is a much smaller claim than the name implies, and the difference matters most exactly where people rely on it: on a network they do not trust, believing the whole device is covered when only one window is. The general distinction is in VPN versus proxy on a network you do not control.

How to tell which one you have, in about a minute

  • Where did it come from? Pushed onto your device by an employer or school, or installed by you from a provider you pay?
  • Can you choose the exit country? A long country list is a consumer service. A single named location, or none, is a corporate route.
  • Does it live in the system settings or in the browser? A device-wide profile behaves very differently from an extension inside one application.
  • Who can turn it off? If you cannot, someone else administers it — and someone else’s policy governs it.
  • What happens to other applications when it is on? If only web pages change behaviour, it is not covering the device.

The conflict travellers actually hit

The common mess is a work VPN and a personal VPN on one laptop. Both want to be the thing that handles your traffic. Symptoms vary — one silently loses, both connect and nothing routes, the work tool refuses to start, or a security agent objects to the other tool’s presence.

There is no clever configuration that makes this comfortable. The workable habits are:

  1. Use one at a time, deliberately. Bring one down before raising the other.
  2. Do work on the work route and personal browsing on the personal one. Mixing them is how you end up routing private traffic through an employer or work traffic through a provider your employer never approved.
  3. Prefer separate devices if the trip is long. A phone for personal use and the laptop for work removes the conflict entirely.
  4. Check the employer’s policy before you leave, not from a hotel room. Some organisations prohibit any other tunnel on a managed device, and finding out abroad is the expensive way.

Two more things sold under the same word

Router-level tunnels. Some home and travel routers can hold the tunnel themselves, so every device behind them is covered without installing anything. Convenient, and a different set of tradeoffs from an app on one device.

Services that only redirect name lookups. Sold for unblocking regional catalogues, these change how your device resolves certain addresses without encrypting anything. Whatever they are, they are not tunnels, and they do nothing for you on an untrusted network.

Bottom line

Three different products share one name. The employer’s tool gets you into a specific network and is logged on purpose. The consumer service gets you out of whatever network you are standing on. The browser add-on covers one window. Identify yours before you spend any time on settings — and never run two device-wide tunnels at once and expect the result to make sense.