The moment you turn on a VPN, your device follows a different route while the apps you use keep working normally. Traffic first enters an encrypted connection to a VPN server, which forwards requests to online destinations.
Once the VPN connection is established, your operating system sends protected traffic along the VPN route, DNS requests can follow that path, and destination websites receive the VPN server’s public IP address instead of yours.
What Your Traffic Looks Like Before the VPN
Normally, your device sends internet-bound traffic to your home Wi-Fi, office networks, mobile tower, or another access point. Routers and internet providers then move those packets toward the services you want to reach.
Domain-name lookups are part of that process because DNS translates names into IP addresses. Unless you use encrypted DNS or another resolver, requests may go to one specified by your router, ISP, browser, network operator, or device settings.
Upon receiving your requests, online services record transmission details, which include your public IP address. That address can reveal your network and an approximation of your geographic location. Consequently, a public IP address lookup can show common network and location details associated with your IP.
For example, when you’re at an airport, your phone may use the local DNS resolver while websites receive the airport connection’s public IP address. Even if HTTPS encrypts your web content, your network path and source IP remain observable.
The Handshake Creates a Secure Session
The moment you tap Connect, your VPN app initiates a handshake with the selected VPN server. In this handshake, both sides authenticate the connection, agree on security settings, and establish cryptographic material for succeeding traffic.
For the VPN tunnel, ApexGuard uses IKEv2/IPsec, with IKEv2 managing negotiation and IPsec protecting data once connection is established. Together, they create the protected channel between your device and the VPN infrastructure.
That setup process performs several distinct tasks before traffic goes through the tunnel:
- Authentication: Checks that a valid device is connecting to the intended VPN endpoint.
- Security negotiation: Both sides agree on compatible cryptographic parameters that will protect the connection.
- Session key creation: A fresh set of cryptographic keys is created for the new session.
- Tunnel preparation: The app and server prepare the security state required to protect traffic while the tunnel remains active.
As soon as the setup is complete, traffic can start moving through the VPN instead of its usual route. ApexGuard, in particular, uses Double VPN by default, so protected traffic passes through an additional server before reaching the public internet.
Session Keys Protect the Tunnel
The handshake process does not encrypt or decrypt transmitted packets. Rather, it creates the session keys for those encryptions and decryptions later on. Once the tunnel is active, those keys are used as your data moves between the device and VPN server.
Outgoing packets are encrypted before entering the tunnel, and incoming packets are decrypted after returning. This keeps the protection tied to the active session while AES-256 encryption handles the traffic itself.
The Operating System Changes the Route
After the tunnel is ready, your device adjusts network routing so supported traffic uses the VPN path instead of going directly to the internet. The exact method depends on the operating system and protocol implementation, and can involve routing rules, a virtual interface, or IPsec security policies.
Your applications function as they normally do because the VPN operates underneath them at the network layer. A browser still requests pages, an email app still contacts its server, and other software still reaches APIs the way they normally do.
In IPsec tunnel mode, original traffic is protected inside packets addressed to the VPN server. The server processes those packets and forwards the original traffic toward its destination, without the associated apps ever noticing.
With split tunneling, you have the option to exempt certain traffic from the VPN connection. When you exclude a supported app or destination, it can use the regular connection while selected traffic remains inside the VPN.
Websites See the VPN Server Instead
From a website’s POV, the most noticeable change is your public IP address. Requests that once arrived from your home, office, carrier, or public network now reach them through VPN infrastructure and carry a VPN server’s IP address.
Because public IPs are often associated with certain regions, IP-based location estimates change with your exit point. More so with ApexGuard, which provides VPN locations/exit points across more than 125 countries.
That said, changing your IP does not make you anonymous to every service. Account logins, cookies, browser fingerprints, and other identifiers can still connect activity to you. A VPN may change the network route and source address, but not every form of identification.
DNS Follows the Protected Route
DNS resolution also matters because if DNS requests leave through an unencrypted path, they can reveal browsing metadata. Thus, when your VPN is active, DNS should also go through the protected route.
Requests that go through the usual resolver can reveal which domains your device is trying to reach, even when HTTPS is used. ApexGuard routes DNS requests through its own Private DNS infrastructure, reducing the type of exposure we just described.
Additional leak controls help keep DNS, IP, and WebRTC information from bypassing your intended path. They do not replace the tunnel, but they reduce the chance that network details leave through another interface or resolver.
One Request Takes Two Different Paths
One way to understand the change a VPN makes is by comparing one web request before and after connection. Your browser or application can send the same type of request in both cases, but its transport path, DNS handling, and the public IP visible at the destination change.
| Change | Without VPN | With VPN |
|---|---|---|
| Network path | Normal device route | VPN-protected route |
| Packet handling | Direct network forwarding | Protected through VPN |
| Address seen by destination | Connection’s public IP | VPN exit server IP |
| Name resolution | Configured DNS resolver | DNS through VPN |
| VPN transport | None | Protected path to VPN infrastructure |
Despite those changes, the destination still receives the same request from your browser or app. Software can keep using normal web, messaging, and API protocols because the VPN alters the transport path rather than the application itself.
Inside the default Double VPN model, protected traffic takes one extra step. Your traffic reaches one VPN server and then a second server, which then becomes the exit point websites see.
What Keeps Working After the Handshake
Once the VPN tunnel is established, several processes begin working in the background. Your VPN app applies routing rules, handles network changes, and helps prevent traffic from leaving through the regular connection.
Beyond the core tunnel, several features work with or alongside the encrypted connection during everyday use:
- Connection safeguard (Kill Switch): This blocks unprotected traffic if the VPN connection drops, helping prevent an unexpected return to the normal route.
- Network leak controls: These safeguards help keep DNS, IP, and WebRTC information from bypassing the intended protected connection.
- ThreatShield: This protection can block harmful websites, phishing pages, trackers, and suspicious destinations before you reach them.
- Selective routing (Split Tunneling): This lets you choose which supported apps or services use the VPN and which continue over the regular connection.
- Exposure alerts (Dark Web Monitor): This can alert you when monitored account details appear in known leak sources associated with exposed data.
- Consistent address (Dedicated IP): This gives you a stable VPN address when you need a fixed source IP.
These tools do not all perform the same role as the VPN protocol itself. The Kill Switch and leak controls affect network behavior, while ThreatShield and Dark Web Monitor provide additional security functions alongside the protected connection.
Why the Connection Feels Fast
Although the handshake takes several steps, a stable network can complete them quickly enough that connecting feels nearly instantaneous. And once your session is established, most ongoing work processes focus on protecting traffic instead of repeating the full negotiation for every request.
On mobile devices, IKEv2 can work with MOBIKE to handle certain changes in the underlying IP address more efficiently. That can help maintain or quickly restore connectivity when you move between Wi-Fi and mobile data, although behavior depends on the client, server, and operating system.
Several practical factors influence how your VPN performs after the session has been established:
- Server distance: A more distant VPN server can increase round-trip time because your traffic has to travel farther.
- Network route: Congestion or inefficient routing between your device and the VPN server can add noticeable delay.
- Server load: A heavily used VPN endpoint may have fewer available resources for processing your traffic efficiently.
- Local stability: Packet loss, weak Wi-Fi, or an unreliable mobile connection can affect performance before the tunnel adds overhead.
- Available bandwidth: Your VPN cannot exceed the practical limits of the internet connection and network path available to you.
Good infrastructure and routing can keep added delay at a minimum, but no VPN can guarantee faster performance than the underlying path allows. That said, ApexGuard provides 3.2 Tbps of total network capacity and 10 Gbps-class connectivity, with independent tests exceeding 800 Mbps.
What Happens to Data After the Session Ends
VPN encryption protects information in transit, but privacy also depends on what data the provider retains afterward. The main question is whether operational data is quickly discarded or kept long enough to create a record of your browsing activity.
ApexGuard uses a strict no-logs architecture that does not retain browsing history, visited websites, DNS requests, traffic content, or VPN activity profiles as routine usage records. Its infrastructure also uses RAM-only servers, where operational data stays in volatile memory rather than being stored permanently on server disks, and thus clears when servers restart.
And because ApexGuard is a Swiss-built VPN, its privacy practices are shaped by Swiss standards, while ISO 27001 security controls and PCI-audited processes support the handling of account, operational, payment, and other sensitive data.
What a VPN Changes
When you tap ‘Connect’, several network-level changes happen beneath your apps. Your device establishes a secure session, adjusts the route for supported traffic, protects traffic in transit, and can send DNS requests along the same path while destination websites receive the VPN exit address.
Your mobile applications also continue performing their usual tasks. Browsers still use HTTP or HTTPS, apps still authenticate normally, and APIs still receive familiar requests, all because the VPN protects the path underneath those protocols.
Together, these changes give you a protected connection without changing how you use apps or websites. The VPN reduces what the local network can observe and prevents websites from receiving your usual public IP address directly. And with ApexGuard, the same account can protect unlimited supported devices, extending that protection across the phones, computers, and other compatible devices you use.
Comments
Loading comments…