Skip to content

VPN for work and office wifi

Office networks block VPNs the same way school networks do: by reading the shape of your traffic, not by matching a list of addresses. A firewall built for deep packet inspection drops a VPN handshake on sight, and a network that intercepts HTTPS for security scanning does the same regardless of which server you connect to. Pangea disguises its traffic as ordinary HTTPS across five transports until one holds.

Try free for 5 days

then from £2.33/mo · cancel anytime

What actually blocks you

Deep packet inspection

Enterprise firewalls read the shape of the connection, not an address list. A plain WireGuard or OpenVPN handshake has a recognisable fingerprint and gets dropped on sight, whatever server it points at.

TLS inspection

Many corporate networks issue their own certificate to company-managed devices so they can read HTTPS traffic for security scanning. On a device carrying that certificate, this happens regardless of the VPN.

Forced proxies

Some networks route all traffic through a proxy or require a PAC file before anything reaches the internet. A VPN client that expects a direct connection can be blocked by this alone, independent of any VPN-specific filtering.

Port and protocol allowlists

Outbound traffic is often restricted to the ports specific business tools use, closing everything else including the ports VPNs default to. Only traffic that looks like ordinary web browsing gets out.

What the app does instead

Five transports, tried in order. The first one that holds is the one you keep. There is nothing to configure; auto mode does this on every connection.

Auto mode finds the way

The app tries each transport in order until one connects. Or pin one in the Connection Method setting.

  1. 1VLESS+REALITYBorrows a real site's handshakeBlocked in this example
  2. 2CloakHides in ordinary HTTPSBlocked in this example
  3. 3ShadowsocksNo TLS to inspectBlocked in this example
  4. 4Hysteria2Built for throttled networksBlocked in this example
  5. 5NaiveProxyIndistinguishable from ChromeConnected. Open internet.
Connected. Open internet.

Before you start

  • Windows and macOS apps. On iPhone you connect through Shadowrocket, a £2.99 App Store app; Android is on the waiting list.
  • Three server locations: London, Amsterdam and New York. More on request.
  • On a laptop your employer owns and manages, IT can see what is installed. That comes down to the device, not the network.
  • Using a VPN is legal in the UK and most other places. Your employer will have its own acceptable use policy, which is a separate matter, and we cannot tell you what it says.

Questions

Why won't my VPN connect on the office network?
Almost always deep packet inspection, sometimes combined with TLS inspection on managed devices. The firewall recognises the handshake pattern of common VPN protocols and drops the connection, so switching servers or ports does not help.
Will IT know I am using a VPN?
From network traffic alone, our transports are built not to be identifiable as a VPN. A company-managed device is a different question — IT can see installed software there whatever the network sees.
Is it against company policy to use a VPN at work?
Often yes, under an acceptable use policy, even where it is entirely legal. Read your employer's policy. We cannot tell you what it says, and a VPN does not change what happens if you breach it.
Does it work through a corporate proxy that requires sign-in?
That depends on the proxy. Our five transports are built to survive deep packet inspection and TLS inspection, not to authenticate through a proxy that demands a login before anything else connects.

If you are somewhere else

Try it on the network that is blocking you

Five days free, no card needed. Try it on the network you actually need it for.