By Eric L.
09/08/2026 · 6 MIN READ

A company VPN and a personal VPN are different tools that happen to share a name.

The company VPN connects your laptop to the office network so you can reach internal systems, and it's configured and monitored by your employer's IT department. A personal VPN protects your own traffic from the network you're on and from your ISP, and you control it. Both may live on the same laptop, but they shouldn't run at the same time without a plan, and understanding what each one sees prevents both privacy mistakes and support tickets.

DIAGRAMFIG. 01
                  Company  Personal

reaches office net    ✓        ✗
hides from the cafe   ✗        ✓
IT controls it        ✓        ✗
works abroad          ask IT    ✓
    └─ two tunnels at once rarely work

What a workplace VPN does

It creates a tunnel to the employer's network. Depending on how IT set it up, either only traffic to internal systems goes through it (split tunnel) or everything does (full tunnel). In a full-tunnel setup, your employer's gateway sees all your traffic while connected, including personal browsing, and can log or filter it. That's normal and usually stated in the acceptable-use policy. The practical rule: while on the company VPN, treat the laptop as being in the office.

Company VPNs typically use IKEv2, IPsec, SSL VPN clients, or increasingly zero-trust access tools that aren't tunnels at all.

TWO TUNNELS, TWO JOBSFIG. 02
company VPN
  └─ gets you into their network
  └─ their admins see the traffic
personal VPN
  └─ hides traffic from the network
     you happen to be sitting on

The model that vendors propose as the replacement for the corporate VPN is covered in VPN vs ZTNA.

What a personal VPN does

It encrypts all the device's traffic to a server you chose, hiding site names and your address from the local network and the ISP. Your employer's gateway isn't involved. What it protects and doesn't is in what is a VPN.

WHY BOTH AT ONCE BREAKSFIG. 03
each wants to be the default route
  ├─ whichever wins takes all
  └─ the other silently does nothing
on most systems only one tunnel
can hold the default route

Can you use a personal VPN with a work VPN?

Two active tunnels stack: the personal VPN's traffic goes inside the company tunnel or the other way around, depending on which started first and how each sets routes. Results range from "internal systems unreachable" to "personal traffic visible to the employer after all" to "nothing works." Some corporate clients refuse to connect if another VPN is active. The clean approaches:

  1. Sequential. Personal VPN for everything, disconnect it, connect the company VPN when you need internal systems, disconnect, reconnect the personal one. Simple and predictable.
  2. Split tunnel on the company side. If IT configured the company VPN to carry only internal traffic, the personal VPN can handle the rest, but only if the personal app is set to exclude the company's address ranges; ask IT for those. This is fiddly and easy to get wrong.
  3. Two devices. Work laptop on the company VPN, personal device on the personal VPN. The least elegant and the most reliable.
THREE CLEAN WAYS TO HAVE BOTH1. SEQUENTIALOne at a timesimple and predictable2. SPLIT ON THE COMPANY SIDEEach tunnel its sharefiddly: ask IT for ranges3. TWO DEVICESSeparate machinesleast elegant, most reliablepersonalcompanypersonaldisconnect one,then connect the otherLaptopoffice ranges:company VPNthe rest:personal VPNWork laptopcompany VPNYour phonepersonal VPN
All three avoid the same thing: two tunnels fighting over one laptop without a plan.

Never assume the two coexist correctly without testing: connect both, open What Is My IP, and check which address appears; then check that an internal system still loads.

WHAT EACH SIDE SEESFIG. 04
                employer  personal
                          provider
work traffic      yes        no
personal traffic  maybe      yes
which sites       yes        yes
   └─ "maybe" is why you do not
      browse personally on it

Workplace VPN on hotel Wi-Fi and in coworking spaces

The company VPN protects the path to the office; on a full tunnel it also covers the rest of your traffic while connected. But between sessions, or on a split tunnel, your personal browsing on hotel Wi-Fi is exposed like anyone else's. The routine that works: personal VPN on by default with a kill switch, off only for the duration of a company VPN session. Why hotel networks deserve this is in is public Wi-Fi safe.

A DAY ON HOTEL WI-FI● PERSONAL VPN BY DEFAULT, KILL SWITCH ONpersonal VPNcompany VPNpersonal VPNcompany VPNpersonal● COMPANY VPN ONLYexposedcompany VPNexposedcompany VPNexposedthe dayOn a split company tunnel, personal browsing is exposed even during the session.
The routine closes the gaps between company sessions, which is exactly where hotel Wi-Fi sees your browsing.

Some hotel and conference networks block the ports company VPNs use. If the corporate client won't connect, mobile data or a hotspot usually will; a personal VPN can't fix a blocked corporate protocol.

WORKING FROM ABROADFIG. 05
tell IT before you go
some systems flag a new country
some contracts restrict where work
may happen
   └─ a tunnel hides the country from
      the network, not from your
      employer's records

Using a work VPN from abroad

Two separate issues. First, your accounts: banks, email and some work tools flag logins from a new country. A personal VPN server in your home country keeps sessions looking normal; the checklist is in do I need a VPN when traveling. Second, your employer's policy: many companies restrict where work may be done for legal and tax reasons, and a VPN doesn't change where you physically are. Ask before you go, not after.

What your employer and the network see

Company VPN (full tunnel)Company VPN (split)Personal VPN
Employer sees personal browsingyes, while connectednono
Local network sees site namesnoyes, for non-work trafficno
Internal systems reachableyesyesno
Controlled byITITyou
PRACTICAL RULESFIG. 06
[ ] work traffic on the work tunnel
[ ] personal traffic on yours
[ ] never both at the same moment
[ ] personal browsing off work kit
[ ] ask before working from abroad
Ignore the highlighted rule, and one tunnel silently swallows the other's traffic.

The rules depend on what your employer actually requires. Get them straight first.

Prompt for an AI
Help me separate work and personal VPN use.

My employer gives me: (a VPN client / a managed
laptop / nothing).
I work from: (home / cafés / abroad sometimes).
My personal VPN: (name, or none).
Devices: (work laptop, personal phone, etc.)

Tell me which traffic belongs on which tunnel,
what happens if both are on, and what I should
ask my IT team before traveling.
Do not advise me to bypass a company policy.

Rules for running a work VPN and a personal VPN

  • Personal VPN by default, company VPN on demand, never both without testing.
  • Don't do personal things on a full-tunnel company VPN; it's the office.
  • Don't install a personal VPN on a managed work laptop without checking policy; IT may prohibit it or it may be removed automatically.
  • Keep the personal VPN's kill switch on for the gaps between sessions.

404 VPN is a personal VPN: VLESS in the apps or a WireGuard config for Istanbul or Marseille, DNS inside the tunnel, a kill switch in the Android app, split tunneling to exclude address ranges where you need to, and seven locations from Amsterdam to Tokyo for home-country logins from abroad when home is one of them. Get started here.