Skip to content
VPNmine
SECURITY

Corporate VPN versus consumer VPN

A corporate VPN routes your traffic into the company network so you can reach internal systems and so security controls can inspect what leaves. A consumer VPN routes your traffic out through a provider so your local network cannot see where you go. Opposite purposes, same word.

4 min read

Illustration of a briefcase and a house, joined by a dashed tunnel line on a dark grid.

Both are called a VPN and both build an encrypted tunnel. Everything else about them differs, including who benefits and who is being protected from whom.

Corporate VPN: getting in

The original purpose. Before cloud services, a company's systems lived on its own network, and a remote employee needed to be on that network to reach them. The tunnel puts them there.

Direction: your traffic goes into the corporate network.

Who it protects: the company. It authenticates you, gives you access to internal resources, and lets security controls inspect traffic.

Who runs it: your employer's IT department.

What it sees: in a full-tunnel configuration, everything you do while it is connected, including personal browsing.

That last point is worth dwelling on. Many corporate deployments route all traffic through the company gateway, where it passes through inspection systems. That is a deliberate security design and it means the company sees your destinations.

Consumer VPN: getting out

Direction: your traffic goes out through a provider's server.

Who it protects: you, from the network you are sitting on.

Who runs it: a company you chose and pay, or do not pay.

What it sees: your destinations, which is why what it records matters and why a specific retention policy is the thing to read. VPNmine's privacy policy states what is kept.

Side by side

Corporate Consumer
Purpose Reach internal systems Hide destinations from the local network
Traffic goes Into the company network Out through a provider
Configured by IT department You
Sees your browsing Often, by design Yes, subject to its policy
Protocol IPsec, or a vendor SSL VPN WireGuard, OpenVPN
You can turn it off Usually not, on a managed device Yes

Running both

Technically awkward and usually pointless.

On most platforms only one tunnel can hold the default route, so a consumer VPN and a corporate VPN will fight. On Android only one VpnService is active at a time, so installing a second displaces the first.

More importantly, a personal VPN on a work laptop achieves almost nothing, because monitoring on a managed device runs on the device itself, above any tunnel. It is also visible in software inventory and usually breaches an acceptable use policy.

Where the corporate model is going

Zero trust architecture, described in NIST SP 800-207, is replacing the network-perimeter model in many organisations. Instead of putting a device on the trusted network, each request to each application is authenticated and authorised individually.

Practically that means fewer full-tunnel corporate VPNs and more per-application access brokers. For an employee it usually means less of their personal traffic passing through company inspection, which is a privacy improvement arriving as a side effect of a security redesign.

The practical advice

Use the corporate VPN for work, on the work device. That is what it is for and it is not optional on most managed hardware.

Use a consumer VPN on your own devices, where the threat is the network you are on rather than access to internal systems. The download page covers the clients.

Do not mix them. Not because it is forbidden, though it often is, but because it does not accomplish what people expect.

Keep personal activity on personal devices. That single habit resolves the entire category of questions about what an employer can see, more cleanly than any configuration.

Split tunnelling means different things in each

On a corporate VPN, split tunnelling is a decision the organisation makes about which destinations must traverse the company gateway. It is usually configured to route internal ranges through the tunnel and let everything else go direct, which reduces load on the gateway and incidentally keeps personal browsing out of the inspection path.

On a consumer VPN, split tunnelling is a decision you make about which of your own traffic is protected. The mechanism is similar and the intent is inverted: one is about what the company needs to see, the other about what you want hidden.

Reading a support article about one while configuring the other is a reliable route to confusion.

Why the corporate one is often slower

A company gateway serves everyone at once, sits in one location, and inspects traffic as it passes. All three cost throughput and latency, and none of them are things the IT department is doing wrong.

A consumer provider optimises for exactly the opposite: many locations, no inspection, and capacity scaled to the number of subscribers. That is why a personal VPN often feels faster than a work one, and it is a difference in purpose rather than in competence.

The one legitimate reason to run a personal VPN on a work network

Not on a work device — on a personal device connected to a workplace guest network. There the employer's network sees your destinations and the device is yours, so a tunnel does exactly what it does on any untrusted network.

That is a normal use and is usually permitted, though the guest network's acceptable use policy still applies.

Sources

  1. NIST SP 800-77 — Guide to IPsec VPNs
  2. NIST SP 800-207 — Zero Trust Architecture
  3. Android Enterprise — always-on VPN

Try it on the network this was written from

VPNmine is a free no-logs VPN running its own WireGuard servers, with native apps for Windows, macOS, Android, iOS, Android TV and Apple TV. No ads, no card.

Get VPNmine