VPN
Virtual Private Network
In short
A VPN is a technology that creates an encrypted tunnel between a device and another network, so traffic can travel privately across the public internet.
What is a VPN?
A VPN, or Virtual Private Network, creates an encrypted connection, often called a tunnel, between your device and another network over the public internet. Everything sent through the tunnel is encrypted, so others on the same network, such as a public Wi-Fi hotspot, cannot read it. To the outside world, your traffic appears to come from the VPN server's IP address rather than your own.
A VPN client on your device wraps each outgoing packet inside another, encrypted packet and sends it to a VPN server. The server decrypts it and forwards it to its real destination, and replies travel back the same way. Common VPN protocols include WireGuard, IPsec, and TLS-based protocols, which differ in speed, ease of setup, and how they handle encryption.
Picture a private, opaque tunnel running alongside a busy public highway: the cars inside use the same route, but no one outside can see who or what is traveling through it. Companies use VPNs so employees can securely reach internal tools from home, and to connect office networks to each other or to cloud networks, a setup called a site-to-site VPN. Individuals often use VPN services to protect their traffic on untrusted networks or to hide their IP address from the websites they visit.
A VPN is often mistaken for complete anonymity or security. It hides your traffic from your local network and your internet provider, but the VPN provider can see it instead, and websites can still identify you through logins and cookies. Many organizations are also moving from VPNs toward zero trust access, which checks every request individually instead of trusting everyone who is inside the network.
Key takeaways
- A VPN creates an encrypted tunnel between a device and a remote network.
- Traffic appears to come from the VPN server's IP address instead of your own.
- Companies use VPNs for remote access and to connect networks site-to-site.
- Common protocols include WireGuard and IPsec.
- A VPN improves privacy on untrusted networks but does not make you fully anonymous.
Example
# WireGuard client config: route traffic through a VPN server
[Interface]
PrivateKey = <client-private-key>
Address = 10.8.0.2/32
DNS = 10.8.0.1
[Peer]
PublicKey = <server-public-key>
Endpoint = vpn.example.com:51820
# 0.0.0.0/0 sends all IPv4 traffic through the tunnel
AllowedIPs = 0.0.0.0/0Readers ask
Does a VPN make me anonymous?
No. A VPN hides your traffic from your local network and your internet provider and masks your IP address, but the VPN provider can see your traffic, and websites can still track you through accounts, cookies, and browser fingerprinting.
What is the difference between a VPN and a proxy?
Both route your traffic through another server, but a typical proxy handles a single application, like a browser, and often does not encrypt traffic. A VPN usually covers all traffic from the device and encrypts everything between your device and the VPN server.
Is a VPN the same as zero trust?
No. A traditional VPN grants access to a whole network once you connect, while zero trust verifies each user, device, and request before allowing access to a specific resource.
Often compared
See also
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- IP AddressNetworking, p. 10An IP address is a numeric label assigned to each device on a network so that data can be routed to it, much like a postal address for a house.
- FirewallNetworking, p. 8A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- PacketNetworking, p. 20A packet is a small, formatted unit of data sent across a network, made of a header with addressing information and a payload that carries the actual data.
- Proxy ServerNetworking, p. 23A proxy server is an intermediary that receives network requests on behalf of clients or servers and passes them on, adding control, caching, or privacy.
Spotted a mistake or something missing on this page?Suggest an edit