Let’s be real: half of us are “based” in one country but actually working from a beach, jungle, or rooftop pool in a totally different time zone. And if you’ve ever gotten a Slack message from HR asking, “Hey, quick question—where are you logging in from?” then you already know the problem: you need to hide your location, and your IP address, from your employer. You’re not the only one—it’s one of the most common questions in nomad circles (here’s the r/digitalnomad thread that started us down this path). Here’s the setup that actually works.
So how do you work remotely without your company knowing your location?
We’re not just throwing out the usual NordVPN or Surfshark suggestion—most of us already know that route doesn’t cut it. So here's the better way: set up your own self-hosted VPN, tunneling your internet traffic to where you’re “supposed” to be.
This system isn’t about fooling your boss just for less awkward Zoom meetings—it’s about being able to work and travel without triggering a company compliance panic or getting geo-blocked by your own internal tools. Whether you're working from a coliving space in Mexico or a coworking cafe in Lisbon, this setup keeps your location (and your job) safe.
DIY VPN for Working Abroad: What You’ll Need
Buy two GL.iNet Beryl travel routers:
- One router at your "approved" home base (ex: your parents’ house in California)
- One router travels with you
The home base router acts as a VPN server. The travel router acts as your gateway—connecting to the home router via an encrypted tunnel.
The Best Way to Work Remotely Without Setting Off Security Alerts
GL.iNet routers have a user-friendly interface that makes setting up WireGuard or OpenVPN surprisingly painless. And once you’ve done the initial setup, the hard part’s over. From then on, just connect your laptop to your travel router—ideally via Ethernet for maximum stealth—and you're good to go. All your internet traffic will automatically route through your home base. It’s like your laptop’s chilling in your parents’ living room—even if you’re actually working from a hammock in Bali.
Compared to a standard VPN app:
- You’re using a real residential IP address, which companies trust more
- Your traffic doesn’t go through a commercial VPN that might be blacklisted
- You’re in control—no random server hops or DNS leaks
- Much lower risk of location-based app leaks (if you disable other services properly)
The catch nobody mentions: your home IP address changes
Home internet connections are handed a dynamic IP address that your provider rotates every so often. That’s a problem for a home-hosted VPN: your travel router is trying to “call home,” but the address it’s calling can change without warning, and suddenly your tunnel is dead mid-trip.
The fix is dynamic DNS. A free service like No-IP gives you a fixed hostname (e.g. yourname.ddns.net) and a small client that keeps that hostname pointed at your home’s current IP. Point your travel router at the hostname instead of a raw IP and the connection survives every IP change. If you set it up and find the No-IP client isn’t running after a reboot, this fix for starting the No-IP service on boot is the one you’ll want.
How to Stay Private While Living in a Coliving or Coworking Space
If you're in a shared space—like a hostel, coworking hub, or coliving villa—you’ll want to tighten things up:
- Turn off Wi-Fi on your laptop. Always connect via Ethernet to your travel router.
- Disable location services on your device (and in your browser).
- Run DNS leak tests regularly to make sure nothing’s slipping.
- Don’t mix personal and work logins on the same device. (Don’t order tacos on Uber Eats from your work laptop. Yes, that includes VPNed ones.)
On a budget? Skip the second router and use a Raspberry Pi
You don’t strictly need two GL.iNet routers. If you already have a Raspberry Pi (or don’t mind buying one), you can turn it into the home-base VPN server for a fraction of the cost and just travel with a single travel router—or the client app on your laptop.
The easiest path is PiVPN, a one-command installer that sets up WireGuard on the Pi and walks you through creating client profiles. Pair it with No-IP for dynamic DNS and you have the same residential-IP setup as the two-router build. This step-by-step Raspberry Pi + PiVPN + WireGuard + No-IP guide covers the whole thing end to end.
Which route is right for you:
- Two GL.iNet routers — the plug-and-play option. More expensive, but the least fiddly and the most reliable day to day.
- Raspberry Pi + PiVPN — cheaper and more flexible, but you’ll spend an evening in the terminal. Best if you’re comfortable following a guide.
What Is This Setup Called?
There's no sexy name for this system, but if you want to google it try:
- Privately hosted VPN
- Self-hosted WireGuard/OpenVPN
- Router-based VPN tunnel
- Site-to-site VPN setup
DIY VPN FAQ
Can my employer detect a VPN?
Commercial VPNs, often yes — their IP ranges are known and frequently blacklisted by corporate security tools. That's the whole advantage of the two-router setup: your traffic exits from a normal residential IP at your home base, which looks exactly like you working from home.
Do I need to be technical to set this up?
Less than you'd think. GL.iNet's interface walks you through WireGuard setup with a few clicks — if you can configure a smart TV, you can do this. Budget an afternoon for the initial setup and a test run before you fly.
Is this legal?
The setup itself is just a private VPN — completely legal. Whether working abroad violates your employment contract or creates tax implications is a separate question that depends on your situation; know what you're signing up for before you go. This article covers the technical side, not the legal one.
What internet speed do I need at each end?
Your remote speed is capped by the home base's upload speed, which is usually the bottleneck. 20+ Mbps upload at home is comfortable for video calls. On the travel side, pick accommodation with fiber, not just Starlink — and wire in via ethernet.
Work from Anywhere. Actually.
Look, we’re not encouraging you to break your company’s rules. (Okay, maybe just bend them a little.) But if your job says "remote in the US only" and your soul says “I need tacos and surf,” this setup helps you fly under the radar—safely and smoothly.
It’s not hard to set up, it’s not sketchy, and it works. Hope this helps some fellow remote workers out there! If you pass through Mexico come say hi to us at Amplitude Coliving — the internet setup here was built by people who care about this stuff (see WiFi in Puerto Escondido: Why Starlink doesn't cut it).

