Nodetonet started as a proxy platform — routing individual requests through real mobile proxies, rotating pools and HTTP tunnels. Today we're rounding out the platform with the other half of the connectivity picture: a full VPN. You can now route an entire device — laptop, desktop, or phone — through Nodetonet using WireGuard or OpenVPN, exiting from an IP that is genuinely yours and yours alone.
TL;DR: issue a VPN profile, pick a mobile-carrier or dedicated edge exit, scan a QR or import the config, and your whole device's traffic goes through a real IP you control — no shared pool, no new subscription, same prepaid credit.
Why add a VPN when you already have proxies?
Proxies and VPNs solve related but distinct problems, and knowing the difference tells you exactly when to reach for each one. A proxy intercepts individual application requests: one browser tab, one scraper thread, one API call. You can run dozens of proxy sessions simultaneously from different IPs, apply per-request rotation, and keep full per-client quota and auth controls. That is the right tool when you need parallel, per-request control.
A VPN routes everything on the device — browser, app, background process, system update — through a single encrypted tunnel to a single exit IP. There is no per-app configuration: it is a blanket network-level change. That is the right tool when you need:
- A work laptop to appear in a consistent geographic location regardless of where you physically are.
- A phone on untrusted public Wi-Fi to have all its traffic encrypted at the device level.
- A server or VM to carry a fixed mobile identity for every outbound connection it ever makes.
- A client who does not want to configure a proxy in every application they use.
For a full breakdown of the tradeoffs, read our companion post VPN vs proxy — which do you actually need? The short version: use a mobile proxy for per-request control and rotation; use the VPN when you need the whole device under one identity.
VPN vs proxy — a quick comparison
| Feature | Nodetonet Proxy | Nodetonet VPN |
|---|---|---|
| Scope | Per-app or per-request | Whole device |
| Simultaneous IPs | Yes — run many in parallel | One exit IP per tunnel |
| Protocols | SOCKS5 and HTTP/HTTPS | WireGuard or OpenVPN |
| Rotation | Per-request or sticky-session | Fixed for the tunnel lifetime |
| Exit IP type | Mobile carrier, upstream residential | Mobile carrier or dedicated edge |
| Per-client controls | Quota, expiry, IP whitelist, thread limits | Per-profile revocation |
| Billing | Prepaid credit (same balance) | Prepaid credit (same balance) |
A dedicated exit IP, not a shared VPN pool
Consumer VPN services pack thousands of subscribers behind a handful of datacenter addresses. Those addresses spend their lives getting flagged — by streaming platforms, banks, fraud-detection systems and enterprise firewalls — because every bad actor on the same server poisons the same reputation. You share the pain of strangers.
Nodetonet's approach is the opposite. When you issue a VPN profile, you pick your own exit:
- Mobile-carrier IP — the exit is a paired Android phone on a real SIM. The public IP comes from carrier-grade NAT, shared among thousands of genuine paying subscribers on that carrier. Anti-bot systems treat that address as a normal phone; banning it risks blocking every real customer on the same range. For hardened targets this is the highest-trust exit available anywhere. See how it compares against datacenter-VPN exits in Nodetonet vs Bright Data.
- Dedicated edge IP — the exit is an edge server IP assigned exclusively to you. Stable, fast, predictable geolocation. The right choice for services that need a fixed inbound allowlist entry or consistent TLS certificate.
Either way, no other Nodetonet user shares your exit IP at the same time. Clean slate reputation, no noisy-neighbour bans, no surprises.
WireGuard or OpenVPN — which to pick
Both protocols are fully supported. The choice comes down to your environment:
- WireGuard — the modern standard. A lean kernel-level implementation delivers lower latency, faster handshakes and noticeably better battery life on mobile devices. Reconnects after a network change are nearly instant. This is the recommended default for most users.
- OpenVPN — the broadly compatible classic. Every commercial router, corporate firewall and enterprise MDM system that supports a VPN protocol has an OpenVPN client. The TCP/443 transport mode works on networks that block UDP (hotel Wi-Fi, strict corporate proxies, airport hotspots). If your users live on managed devices or locked-down networks, OpenVPN travels where WireGuard sometimes cannot.
You can issue profiles for both protocols from the same panel without choosing one globally. A developer testing on their laptop might use WireGuard while distributing OpenVPN profiles to less technical clients.
Everything in one panel, one balance
The VPN does not live in a separate product, billing account or dashboard. It is a native feature inside the same panel that manages your mobile proxies, rotating proxy pools, SOCKS5 endpoints, HTTP tunnels and reseller accounts.
It runs on the exact same prepaid credit balance. There is no monthly VPN subscription, no separate purchase, no second invoice. Idle VPN profiles cost nothing — you are billed for usage, not availability. That is the same model that makes our pay-as-you-go pricing predictable for proxy users, and it carries over directly.
If you are a reseller managing VPN + proxy access for multiple clients, see reseller and white-label for how to provision all of this under your own brand through WISECP.
TCP/IP fingerprint spoofing
Nodetonet's platform supports TCP/IP fingerprint spoofing to make your connections look like a specific operating system or device profile at the packet level. When paired with a VPN tunnel exiting from a mobile-carrier IP, this creates a consistent, believable mobile identity from the network layer up — carrier range at the IP level, real mobile device fingerprint at the TCP level.
How to set up the VPN
- Open the panel and navigate to the VPN section.
- Create a profile. Name it, select WireGuard or OpenVPN, and pick your egress: a paired phone for a mobile-carrier IP, or an edge server for a dedicated stable IP.
- Download or scan the config. On desktop, import the file into the WireGuard or OpenVPN client. On mobile, scan the QR code directly from the panel.
- Connect. The tunnel is up. All traffic on that device now exits from your chosen IP.
You can issue as many profiles as your fleet requires and revoke any of them instantly from the panel without touching the client device. Full client-setup walkthroughs are on the VPN feature page.
Geo-targeting within the VPN
Because the VPN exit is a real device or a real edge server, the exit IP carries a genuine location and carrier attribution — not a spoofed location claim that geo-databases routinely debunk. If you pair the VPN to a phone on Turkcell in Istanbul, the exit IP is registered to Turkcell in Istanbul. That is the same geo-accuracy that makes our geo-targeting reliable for proxy users, now available at the device-tunnel level.
Get started
The VPN is available to all Nodetonet accounts today. Create a free account to issue your first profile, or read the VPN feature overview for details on profile limits, supported clients, and egress options. Questions? Reach us at support@nodetonet.com, on Discord discord.gg/nodetonet, or on X x.com/nodetonet.
Not sure whether you need a VPN or a proxy for your specific workflow? Start with VPN vs proxy, then check out what a mobile proxy actually is — the two posts together cover the full decision tree.