The Architecture of Dedicated VPN Infrastructure

Four key principles that separate dedicated infrastructure from shared VPN platforms

Single-Tenant Node

The server running your VPN is not shared with any other organisation. No other customer's processes run on your node.

Dedicated Egress IP

All outbound traffic from your node exits through a fixed IP that is registered and reserved for your organisation only.

Isolated Routing

Traffic paths between your node and target resources do not cross other tenants' routing tables.

RADIUS Authentication

User access is authenticated via RADIUS, allowing PrivyNet to integrate with your existing identity and directory infrastructure.

How a Dedicated VPN Node Is Provisioned

From account creation to live team connections - the complete provisioning sequence

  1. Organisation creates an account and selects a deployment region.
  2. PrivyNet provisions a dedicated VPN node in that region.
  3. A static IP is allocated exclusively to that node - reserved at the network level.
  4. VPN service is configured on the node with the organisation's settings.
  5. RADIUS authentication is configured, connecting PrivyNet to the organisation's identity infrastructure.
  6. Admin credentials are generated and the dashboard becomes the control plane.
  7. Admin creates user credentials and distributes them to team members.
  8. Team members connect - sessions are logged in real time.

What Node Isolation Means in Practice

Four specific isolation guarantees that dedicated infrastructure provides - and shared VPN cannot

Process Isolation

Your VPN service runs in its own dedicated VPN environment. Other tenants' processes cannot access your session state.

Traffic Isolation

Packets from your team's sessions do not share network paths with other tenants' traffic at the node level.

Credential Isolation

Authentication is handled per-tenant. A credential breach in one organisation does not affect others.

Log Isolation

Access logs are scoped to your organisation. There is no cross-tenant log contamination.

How Static IPs Are Assigned and Maintained

Your IP is reserved at the network layer - it does not rotate, and it does not change

IP Reservation

The IP is allocated at the network layer and is not shared with any other node or tenant. It is registered to your organisation from the moment of provisioning.

No Rotation

Your IP does not change between sessions, reboots, or maintenance windows. Once assigned, it remains yours.

Permanent Allowlisting

Because the IP never changes, it can be added once to a firewall allowlist, cloud security group, or SaaS IP restriction and relied upon indefinitely.

IP Reputation - Why It Matters and How PrivyNet Maintains It

IP reputation hygiene is one of the most overlooked benefits of dedicated infrastructure

Why Shared VPN IPs Have Poor Reputation

  • Thousands of users - including bad actors - connect through the same IP pool
  • A single abuse event (spam, scraping, credential stuffing) can get the entire pool blocklisted
  • Blocklisted IPs trigger CAPTCHAs, access denials, and false-positive security alerts for every user on that pool
  • You have no control over how other users on the shared pool behave

How Dedicated IPs Maintain Clean Reputation

  • Only your organisation's traffic exits through your IP - no third-party behaviour can taint it
  • Your IP's reputation is entirely within your control
  • PrivyNet allocates IPs with a clean provenance - new IPs are verified before assignment
  • Consistent, predictable egress builds trust with SaaS platforms and security tools over time

Frequently Asked Questions

Common questions about how dedicated VPN infrastructure works

How does dedicated VPN infrastructure differ from a shared VPN service?

In a shared VPN service, many customers use the same servers and share a pool of IP addresses. In dedicated VPN infrastructure, each organisation gets its own private server and a static IP address reserved exclusively for them - providing traffic isolation, a clean IP reputation, and a clear audit trail that shared services cannot offer.

How long does it take to provision a dedicated VPN node?

PrivyNet provisions new nodes quickly after account creation. Contact us for current provisioning times for your preferred region.

What happens to my static IP if my node is restarted or migrated?

The static IP is reserved at the network level independently of the node. A restart or maintenance migration does not change your IP - your firewall allowlists remain valid.

What VPN protocols does PrivyNet's dedicated infrastructure use?

PrivyNet uses IKEv2 - a secure, widely supported protocol that provides fast reconnection and strong encryption, well suited for both team and mobile use cases.

Can I integrate PrivyNet with our existing identity provider?

Yes. PrivyNet supports RADIUS authentication, allowing integration with your existing directory and identity infrastructure. See our dedicated RADIUS authentication page for further detail.

Ready to See It Working?

Your organisation gets its own dedicated node, static IP, and full session audit trail - provisioned and ready for your team.

Dedicated node
Static IP
Full isolation