A company VPN and a personal VPN are different tools that happen to share a name.
The company VPN connects your laptop to the office network so you can reach internal systems, and it's configured and monitored by your employer's IT department. A personal VPN protects your own traffic from the network you're on and from your ISP, and you control it. Both may live on the same laptop, but they shouldn't run at the same time without a plan, and understanding what each one sees prevents both privacy mistakes and support tickets.
Company Personal
reaches office net ✓ ✗
hides from the cafe ✗ ✓
IT controls it ✓ ✗
works abroad ask IT ✓
└─ two tunnels at once rarely workWhat a workplace VPN does
It creates a tunnel to the employer's network. Depending on how IT set it up, either only traffic to internal systems goes through it (split tunnel) or everything does (full tunnel). In a full-tunnel setup, your employer's gateway sees all your traffic while connected, including personal browsing, and can log or filter it. That's normal and usually stated in the acceptable-use policy. The practical rule: while on the company VPN, treat the laptop as being in the office.
Company VPNs typically use IKEv2, IPsec, SSL VPN clients, or increasingly zero-trust access tools that aren't tunnels at all.
company VPN └─ gets you into their network └─ their admins see the traffic personal VPN └─ hides traffic from the network you happen to be sitting on
The model that vendors propose as the replacement for the corporate VPN is covered in VPN vs ZTNA.
What a personal VPN does
It encrypts all the device's traffic to a server you chose, hiding site names and your address from the local network and the ISP. Your employer's gateway isn't involved. What it protects and doesn't is in what is a VPN.
each wants to be the default route ├─ whichever wins takes all └─ the other silently does nothing on most systems only one tunnel can hold the default route
Can you use a personal VPN with a work VPN?
Two active tunnels stack: the personal VPN's traffic goes inside the company tunnel or the other way around, depending on which started first and how each sets routes. Results range from "internal systems unreachable" to "personal traffic visible to the employer after all" to "nothing works." Some corporate clients refuse to connect if another VPN is active. The clean approaches:
- Sequential. Personal VPN for everything, disconnect it, connect the company VPN when you need internal systems, disconnect, reconnect the personal one. Simple and predictable.
- Split tunnel on the company side. If IT configured the company VPN to carry only internal traffic, the personal VPN can handle the rest, but only if the personal app is set to exclude the company's address ranges; ask IT for those. This is fiddly and easy to get wrong.
- Two devices. Work laptop on the company VPN, personal device on the personal VPN. The least elegant and the most reliable.
Never assume the two coexist correctly without testing: connect both, open What Is My IP, and check which address appears; then check that an internal system still loads.
employer personal
provider
work traffic yes no
personal traffic maybe yes
which sites yes yes
└─ "maybe" is why you do not
browse personally on itWorkplace VPN on hotel Wi-Fi and in coworking spaces
The company VPN protects the path to the office; on a full tunnel it also covers the rest of your traffic while connected. But between sessions, or on a split tunnel, your personal browsing on hotel Wi-Fi is exposed like anyone else's. The routine that works: personal VPN on by default with a kill switch, off only for the duration of a company VPN session. Why hotel networks deserve this is in is public Wi-Fi safe.
Some hotel and conference networks block the ports company VPNs use. If the corporate client won't connect, mobile data or a hotspot usually will; a personal VPN can't fix a blocked corporate protocol.
tell IT before you go some systems flag a new country some contracts restrict where work may happen └─ a tunnel hides the country from the network, not from your employer's records
Using a work VPN from abroad
Two separate issues. First, your accounts: banks, email and some work tools flag logins from a new country. A personal VPN server in your home country keeps sessions looking normal; the checklist is in do I need a VPN when traveling. Second, your employer's policy: many companies restrict where work may be done for legal and tax reasons, and a VPN doesn't change where you physically are. Ask before you go, not after.
What your employer and the network see
| Company VPN (full tunnel) | Company VPN (split) | Personal VPN | |
|---|---|---|---|
| Employer sees personal browsing | yes, while connected | no | no |
| Local network sees site names | no | yes, for non-work traffic | no |
| Internal systems reachable | yes | yes | no |
| Controlled by | IT | IT | you |
[ ] work traffic on the work tunnel [ ] personal traffic on yours [ ] never both at the same moment [ ] personal browsing off work kit [ ] ask before working from abroad
The rules depend on what your employer actually requires. Get them straight first.
Help me separate work and personal VPN use.
My employer gives me: (a VPN client / a managed
laptop / nothing).
I work from: (home / cafés / abroad sometimes).
My personal VPN: (name, or none).
Devices: (work laptop, personal phone, etc.)
Tell me which traffic belongs on which tunnel,
what happens if both are on, and what I should
ask my IT team before traveling.
Do not advise me to bypass a company policy.
Rules for running a work VPN and a personal VPN
- Personal VPN by default, company VPN on demand, never both without testing.
- Don't do personal things on a full-tunnel company VPN; it's the office.
- Don't install a personal VPN on a managed work laptop without checking policy; IT may prohibit it or it may be removed automatically.
- Keep the personal VPN's kill switch on for the gaps between sessions.
404 VPN is a personal VPN: VLESS in the apps or a WireGuard config for Istanbul or Marseille, DNS inside the tunnel, a kill switch in the Android app, split tunneling to exclude address ranges where you need to, and seven locations from Amsterdam to Tokyo for home-country logins from abroad when home is one of them. Get started here.