A proxy routes one app or one request. A VPN routes the whole device — every TCP and UDP connection from your laptop, phone or server leaves through a single IP. Nodetonet gives you both, in the same panel, on the same prepaid credit: alongside the mobile and rotating proxy engine you can spin up a full WireGuard or OpenVPN tunnel whose exit is a dedicated IP — a real 4G/5G carrier address from a paired phone, or a stable edge-server IP — instead of the shared, recycled pools that consumer VPN services hand you.
TL;DR: if you need one trusted, fixed-identity IP for an entire device or server — without a subscription and without sharing that IP with strangers — Nodetonet VPN is the shortest path there.
What the Nodetonet VPN actually is
It is a self-serve VPN built on the same infrastructure that powers our mobile proxies and rotating proxy pools. You create a VPN profile in the panel, download a config file or scan a QR code, and your device tunnels all of its traffic to a Nodetonet edge node, which then egresses from the IP you chose. Because the exit belongs to you — not 10,000 other VPN customers — you get a clean IP reputation, a stable and predictable geolocation, and no "noisy-neighbour" bans that routinely hit shared VPN ranges.
Consumer VPNs (NordVPN, ExpressVPN, Mullvad, etc.) put hundreds or thousands of users behind each datacenter IP. Those IPs accumulate CAPTCHA triggers, streaming blocks and fraud-score penalties from every user who passed through them before you. Our model is the opposite: one profile, one exit IP, you.
WireGuard or OpenVPN — pick your protocol
Both protocols are first-class citizens on Nodetonet. Your choice usually comes down to where you need to connect from:
- WireGuard — modern cryptography (ChaCha20-Poly1305, Curve25519), tiny attack surface, kernel-level performance, and near-instant reconnects after network changes. Recommended default for laptops, desktops and phones where you control the firewall.
- OpenVPN — battle-tested since 2001, works on the widest range of routers, corporate firewalls and managed devices. The TCP/443 mode makes it look like HTTPS to deep-packet-inspection filters, which is the practical solution for hotels, airports and restrictive enterprise networks.
Both are issued from the same panel. You can have multiple active profiles simultaneously — for example, WireGuard on your laptop and OpenVPN on a router — and revoke any of them instantly without affecting others.
A dedicated egress IP — mobile carrier or edge server
The exit point is what separates Nodetonet VPN from everything else. You choose between two egress types:
- Mobile carrier IP (4G/5G) — your VPN exit is a real phone on a SIM. The IP sits inside carrier-grade NAT (CGNAT), which means it looks identical to millions of ordinary smartphone users to any website or service. Very hard to fingerprint, very hard to ban. Ideal when the target cares about the origin's trust score — streaming services, financial apps, social platforms, anything that dislikes datacenter ASNs.
- Edge server IP — a static, dedicated IP hosted on Nodetonet's edge infrastructure. Predictable, low-latency, and appropriate when you need a fixed outbound identity for a server or CI/CD pipeline without depending on a physical device.
Either way, that IP is not shared with anyone else's session. See how Nodetonet routes traffic for the full data-plane architecture.
VPN vs proxy — when to use which
Both products live in the same Nodetonet panel; knowing when to reach for each saves time. The short answer: use a proxy for per-request control at scale, use the VPN when you need an entire device to behave as if it lives at one IP. The table below gives the full picture:
| Dimension | Nodetonet VPN | Nodetonet proxy (HTTP/SOCKS5) |
|---|---|---|
| Scope | All traffic on the device / OS | Per-app or per-request |
| Protocol | WireGuard / OpenVPN (UDP or TCP) | HTTP/HTTPS and SOCKS5 |
| IP per session | One fixed egress IP | Rotating or sticky |
| Parallel IPs | One per profile | Many — full rotating pool |
| Client setup | Official WireGuard / OpenVPN app | Proxy URL in tool or browser |
| Best for | Remote work, geo-stable access, device identity, server outbound | Scraping, automation, multi-account, price monitoring |
| Billing | Prepaid credit, no subscription | Prepaid credit, no subscription |
Still unsure which fits your use case? Read the full VPN vs proxy guide — it walks through five real scenarios and explains which tool wins each one.
Key capabilities
- Multiple simultaneous profiles — issue separate configs for each device, team member or server, all revocable independently.
- Mobile-carrier egress — tunnel through a paired Android phone on any supported carrier; the exit IP inherits full CGNAT trust. Useful alongside our mobile proxy fleet when you also need whole-device routing.
- Edge-server egress — static, always-on IP at a dedicated node; no phone dependency, sub-10 ms reconnect. See choosing the right edge server.
- TCP/IP fingerprint control — Nodetonet's data plane can adjust TCP/IP stack characteristics on the egress side, so the traffic signature matches the egress environment rather than leaking your real OS.
- Geo-targeting — choose a specific country or carrier for the exit; the same panel username-modifier system as geo-targeting for proxies applies to VPN egress selection.
- No logs, prepaid billing — no monthly subscription; you pay for what you use from the same credit balance as your proxies and HTTP tunnels.
Common use cases
- Remote work with a stable mobile IP — keep your corporate tools, banking apps and internal systems on a fixed, clean IP even when your physical location changes.
- Geo-stable access — watch geo-restricted content, access local government portals or run QA tests from a specific country without physically being there.
- Securing a phone on public Wi-Fi — WireGuard runs efficiently on Android and iOS; all traffic tunnels to your dedicated exit without draining the battery.
- Server with a fixed mobile outbound identity — give a CI/CD pipeline, a scraping worker or an API client a carrier IP as its outbound address, so the downstream service never sees a datacenter ASN.
- Router-level coverage — run OpenVPN on an OpenWrt or DD-WRT router and every device on the network egresses from your dedicated IP, with no per-device setup.
How to set it up (step by step)
- Create an account at /auth/register and add prepaid credit — no subscription required.
- Choose an egress type in the panel: a paired mobile device for a carrier IP, or an edge server for a static dedicated IP.
- Generate a WireGuard or OpenVPN config file; the panel also shows a QR code for mobile clients.
- Import the config into the official WireGuard or OpenVPN client on your device — available for Windows, macOS, Linux, Android and iOS.
- Connect. Every packet from the device now leaves from your chosen egress IP. Verify with our free What is my IP tool.
For router-by-router and OS-by-OS walkthroughs, see the documentation. Questions? Reach us at support@nodetonet.com or on Discord.
How Nodetonet VPN compares with consumer VPNs
Consumer VPN services are built for privacy — hiding your traffic from your ISP and masking your IP from websites — but they rely on shared datacenter IP pools. That design is fine for casual browsing but problematic the moment a website or app decides to trust or block based on IP. Nodetonet VPN is purpose-built for the opposite scenario: you need a trustworthy, consistent identity for a device, not just a mask. For more, see how we compare to similar tools at Cloudflare Tunnel and ngrok for tunnel-adjacent use cases, and our reseller program if you manage VPNs for multiple end customers.