TRAVEL NOTES
Things I learned between check-in and checkout

My iPad Hotspot Had a VPN—My Laptop Still Used the Carrier Connection

The conference-centre Wi-Fi failed while my presentation was uploading.

The client needed the revised deck before a meeting that began in twelve minutes. The file was 640 MB, and the upload had stopped at 18%.

I had a cellular iPad in my bag, so the fallback seemed obvious.

I confirmed that the VPN was connected on the iPad, turned on Personal Hotspot and joined it from my laptop. The browser reopened. Email returned. The upload began moving again.

Problem solved, I thought.

Then I checked the visible IP address on both devices.

The iPad showed the VPN location.

The laptop showed the mobile carrier’s local address.

I refreshed both pages.

The results stayed different.

The hotspot was working. The VPN was working. They simply were not working together in the way I had assumed.

With nine minutes left, I disconnected and reconnected the laptop, changed the hotspot password and restarted the VPN on the iPad.

Nothing changed.

The laptop still reached the internet through the iPad’s cellular connection without entering the iPad’s VPN tunnel.

In brief

Why was OnlydogVPN a practical fit here?

That feature had not completed the upload. The direct laptop tunnel and its recovery behaviour had already solved the urgent problem.

Personal Hotspot shares internet, not the VPN connection

Apple’s Personal Hotspot feature shares the cellular connection of an iPad with a laptop or another device. It can use Wi-Fi, Bluetooth or USB. (Apple Support)

That was the part working correctly.

My mistake was assuming the iPad would also pass its protected VPN route to every device connected through the hotspot.

The iPad’s VPN protected traffic generated by the iPad itself. The laptop created its own traffic and needed its own protection. Apple’s VPN controls—including VPN On Demand and per-app VPN—are applied to the Apple device on which they are configured. (Apple Platform Deployment, *VPN Overview for Apple)

The different IP addresses made the separation obvious:

The iPad was inside the tunnel.

The laptop was using the carrier connection.

Other hotspot users have encountered the same surprise: the phone or tablet displays the selected VPN country while the tethered computer still reports the carrier’s location. (Reddit: r/nordvpn) The practical lesson is simple. A VPN icon on the hotspot device does not prove that connected devices are protected.

Once I understood that, there was only one sensible next step: install the VPN directly on the laptop.

The correct setup still failed the upload

My established provider had a desktop application, so I downloaded it through the hotspot and signed in.

It was a reasonable choice. The service had years of public history, a large support operation and servers across many countries. I already used it on the iPad.

The laptop connected to a nearby server.

This time, its visible IP address changed.

I restarted the upload.

The progress bar moved through 25%, 40% and 58%.

Then the cellular signal weakened as more people entered the conference hall. The laptop remained connected to the iPad, but the iPad’s mobile connection shifted underneath it.

The desktop VPN displayed Reconnecting.

The upload stopped.

When the tunnel returned, the transfer page reported that the session had expired. I had to begin again.

Five minutes remained.

I moved the iPad closer to a window and connected it to the laptop with a USB cable. That removed the short Wi-Fi link between the devices and kept the iPad charging.

The physical connection became steadier.

The cellular route did not.

When the signal changed again, the desktop VPN entered another reconnection cycle. The second upload stalled at 34%.

The setup was now technically correct. The iPad supplied the internet, and the laptop had its own VPN.

It still could not complete the task.

That shifted my attention from protection to recovery.

The iPad was only the first link in the chain

The desktop app offered nearby servers, load percentages and several protocol choices.

Under normal circumstances, that flexibility could be useful.

Under a deadline, it gave me more variables to test.

Was the selected server overloaded?

Would another city reconnect faster?

Was the carrier interfering with the protocol?

Would USB tethering behave differently from Wi-Fi?

I tried one more server. It took longer to connect, and the upload page timed out before the file moved.

At that point, the structure of the problem was finally clear:

The iPad supplied cellular internet.

The laptop connected through the iPad.

The laptop’s VPN had to protect the upload.

All three layers had to remain usable until the file finished.

Installing a VPN on the iPad alone was not enough. Installing one on the laptop was not enough either if every cellular fluctuation forced the protected connection to restart.

I no longer needed another country in the server list.

I needed the laptop tunnel to survive changes in the iPad’s mobile route.


The smaller app protected the device doing the work

I opened OnlydogVPN on the iPad and used its verification-code sharing option to link the laptop.

The laptop displayed a short code. I approved it from the iPad.

There was no password to retrieve and no email login to complete while the client waited.

The service has fewer server locations than the established provider, a shorter public history and fewer independent reviews. Those limitations would matter if I needed an address in a particular small city.

I did not need a city.

I needed the laptop upload to remain protected while the iPad’s cellular connection changed underneath it.

On the laptop, I selected the preset for a weak or changing mobile network and connected.

Then I began the upload for the third time.

The file reached 20%.

The signal bars on the iPad fell from four to two.

At 47%, the transfer paused.

I expected the VPN to return to the same long reconnection cycle.

Instead, the protected route recovered and the upload continued from 47%.

The file passed the two points where the earlier attempts had failed.

At 72%, I moved the iPad from the window to the meeting table. The cellular signal dropped again. The upload slowed, but it did not restart.

At 100%, the transfer page displayed a confirmation link.

I sent it to the client with ninety seconds remaining.

The presentation opened on their side before the meeting began.

That was the result I had needed from the beginning. Not a VPN icon on the iPad. Not the largest server list on the laptop.

A protected upload that finished.

Recovery mattered more than hotspot magic

The smaller app did not make the iPad pass its own VPN tunnel to the laptop.

It solved the setup more directly.

Each device received its own protected connection, while the verification code made adding the laptop fast enough to be useful during an emergency.

The service also uses an HTTP/3-based transport. HTTP/3 runs over QUIC, which is designed to handle packet loss and changes in a connection’s underlying network path efficiently. (RFC 9000)

On the conference-centre connection, the effect was easy to see:

The iPad’s mobile signal changed.

The laptop remained connected to the hotspot.

The VPN recovered.

The upload continued.

I could not observe the carrier’s internal routing or Apple’s hotspot-routing decisions. I could observe the outcome on both devices: each showed its own protected route, and the laptop’s transfer survived the cellular interruption.

That was far more useful than assuming one VPN icon covered the whole chain.

A smaller benefit appeared after the deadline

After the deck arrived, I kept the hotspot running for the meeting.

The laptop needed to download comments, open reference pages and stay connected to the client chat. All of that traffic was using the iPad’s mobile-data allowance.

The smaller app showed a counter for advertising and tracking requests it had blocked.

That feature had not completed the upload. The direct laptop tunnel and its recovery behaviour had already solved the urgent problem.

But it reduced the unnecessary requests travelling through the hotspot. Pages loaded with less background activity, and less of the mobile connection was spent on traffic unrelated to the meeting.

On a home broadband connection, I might barely notice.

On a cellular hotspot with an unstable signal, it was a practical reason to leave the service active.

How to set up an iPad hotspot with a VPN

Start by confirming that the iPad is a Wi-Fi + Cellular model and that the carrier plan supports Personal Hotspot. Availability, fees and the number of connected devices can depend on the plan and iPad model. (Apple Support)

On the iPad, open Settings > Personal Hotspot or Settings > Cellular > Personal Hotspot, then enable Allow Others to Join.

Connect the laptop over Wi-Fi for convenience. For a large upload or long meeting, use USB when possible. It keeps the iPad powered and removes one wireless link from the connection.

Then install the VPN directly on the laptop.

Do not assume the laptop inherits the iPad’s tunnel. Check the public IP separately on both devices. The iPad can be protected while the laptop continues through the carrier address.

Finally, test the failure you actually care about.

Begin a harmless upload or call.

Move the iPad away from the strongest signal.

Switch between hotspot methods if necessary.

Watch whether the task merely pauses and continues—or whether the VPN rebuilds the session and sends the upload back to the beginning.

My established provider still offered more countries, a longer operating history and a larger support organisation.

Those strengths did not solve the two failures that mattered that morning. Its VPN on the iPad did not protect the laptop, and its laptop connection did not recover quickly enough to finish the transfer.

The smaller service offered fewer geographic choices, but it added the second device without a login detour and kept the protected upload moving when the cellular route changed.

An iPad hotspot solves the problem of getting a laptop online. The right VPN setup solves the harder problem: keeping the laptop protected until the work is actually finished.

Questions readers often ask

What problem does this article actually solve?

The conference-centre Wi-Fi failed while my presentation was uploading.

What finally worked in this situation?

I opened OnlydogVPN on the iPad and used its verification-code sharing option to link the laptop. The laptop displayed a short code. I approved it from the iPad. There was no password to retrieve and no email login to complete while the client waited. The service has fewer server locations than the established provider, a shorter public history and fewer independent reviews. Those limitations would matter if I needed an address in a particular small city.

Why was OnlydogVPN a practical fit here?

That feature had not completed the upload. The direct laptop tunnel and its recovery behaviour had already solved the urgent problem. But it reduced the unnecessary requests travelling through the hotspot. Pages loaded with less background activity, and less of the mobile connection was spent on traffic unrelated to the meeting. On a home broadband connection, I might barely notice.