ABOUTVPNS / FIELD NOTE 03
Personal, Remote-Access and Site-to-Site VPNs
Match the kind of VPN to the problem: an internet exit, access to work, or a link between networks.
Personal VPN: a different internet exit
A consumer VPN typically sends selected or all device traffic through an operator's server before it reaches the internet. Websites often see the exit address instead of your connection's public address. That can change the apparent network location, but an address is not proof of physical location or anonymity. The operator's application, handling of data and service terms become part of your decision.
Remote access: a person reaches work resources
A remote-access VPN connects a user or device to an organization. The important question is not simply whether the tunnel connects, but which resources that identity may reach. A managed laptop accessing a document system may need different permissions from a contractor maintaining one application. Device checks, MFA and timely access removal belong in the design.
Site-to-site: gateways connect networks
A site-to-site VPN links gateways, such as a branch office and a central location. Devices behind those gateways may use the connection without running individual VPN clients. Routing must agree on which networks belong at each end. Overlapping address ranges, firewall rules and gateway availability can affect the result. The tunnel alone does not authorize every device on one network to reach everything on the other.
Self-hosted is an operating responsibility
Running your own VPN on a router or server can provide access to your own network or a chosen exit. It also gives you patching, key management, firewall, monitoring, backup and recovery work. It does not make traffic invisible to the server's hosting provider or eliminate trust in the infrastructure. Do not buy a server merely because the word private appears in VPN.
Choose from the actual requirement
For a family device on travel Wi-Fi, evaluate client behavior and privacy terms. For staff reaching internal systems, start with identity and resource access. For two offices, plan addressing and gateway resilience. Application-specific access may be a better fit than broad network access in some business designs. These are different requirements, not a ranking of which category is best.
Sources and Further Reading
Sources support the technical concepts. Examples and checklists are our educational synthesis, not a provider review or a substitute for current deployment guidance.