FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Chromebook VPN Choice That Protected More Than the Browser

The upload stopped at 84 percent.

I was in an airport lounge with forty minutes before boarding, trying to send a signed contract and two identification documents to an accountant. The files were open in Chrome, while the confirmation code was waiting in an Android messaging app on the same Chromebook.

The lounge Wi-Fi had already made me accept its terms twice. I did not want to send anything sensitive over it without a VPN.

ChromeOS offered an Add built-in VPN button, which sounded like the safest choice. “Built-in” suggested protection for the entire Chromebook. An Android VPN app sounded as though it might protect only Android apps.

So I chose the native option.

Instead of a connect button, ChromeOS asked for a server hostname, provider type, authentication method, certificates, usernames and keys. I downloaded the configuration supplied by my regular VPN provider and looked for a simple way to import it.

There was not one.

The upload deadline had not moved. I had simply replaced an unfinished document transfer with a networking form.

The short answer

The result made the architecture easier to understand than any settings page had. The smaller app was not behaving like a browser extension. It was creating a system VPN connection that ChromeOS could use across the browser and compatible Android apps.

Why the labels are misleading

Chromebooks are no longer just lightweight browser machines. They are now primary computers for students, travellers, freelancers and small businesses that work through cloud services. Worldwide Chromebook shipments rose in the third quarter of 2025, helped by education deployments across several major markets. (Informa)

That broader use has made one ChromeOS peculiarity more important: a Chromebook can run several kinds of software at once.

Chrome handles ordinary websites and installed web apps. Google Play provides Android apps. Supported models can also run Linux applications. All three may appear side by side, making the device feel unified until a security tool asks which environment it should protect.

That is where the labels create the wrong expectation.

“Built-in VPN” sounds like whole-device coverage. “Android VPN app” sounds confined to the Android layer. In practice, a compatible Android VPN can be integrated into ChromeOS networking and route traffic from both Chrome and Android apps through the same tunnel. (Google)

The word “Android” describes how the client is delivered, not necessarily where its protection ends.

That was the first assumption I needed to discard.

The built-in client expected information I did not have

ChromeOS’s native VPN support is useful. It supports common configurations including L2TP over IPsec, OpenVPN and WireGuard on compatible devices. When an employer or school provides the server details, certificates and authentication requirements, the built-in client can be exactly the right tool.

In that setting, an administrator already understands the network. The user may only need to select a prepared connection.

I was in a different situation. I was trying to use a commercial privacy service on airport Wi-Fi.

My provider had supplied an OpenVPN configuration file, but ChromeOS’s native OpenVPN support is designed around more basic configurations. Google itself directs users toward an Android OpenVPN application when they need direct .ovpn imports or more advanced settings. (Google)

That explained why a valid subscription had left me staring at empty certificate and server fields.

I tried entering one server manually. Authentication failed. A second attempt stopped at certificate validation. ChromeOS offered a way to bypass that check, but weakening certificate verification while uploading identity documents on public Wi-Fi would have defeated the purpose.

The built-in client had not malfunctioned. It was waiting for a complete network configuration that I did not have in a usable form.

That changed the question. I no longer cared which option appeared more deeply integrated into Settings. I needed the option that could establish a properly configured connection before boarding began.

The Android app protected the task, not just one app

I opened the Play Store and installed OnlydogVPN.

ChromeOS displayed its normal system request asking whether I trusted the app to create a VPN connection. I approved it, selected the browsing situation and connected.

Then I returned to Chrome.

The contract upload resumed.

I refreshed the accountant’s portal, opened an IP-check page in another tab and retrieved the confirmation code from the Android messaging app. Both Chrome and the Android app were using the new route.

I entered the code. The progress bar moved from 84 percent to complete.

The receipt arrived before the first boarding announcement.

The result made the architecture easier to understand than any settings page had. The smaller app was not behaving like a browser extension. It was creating a system VPN connection that ChromeOS could use across the browser and compatible Android apps.

A browser extension may affect only browser activity. It does not automatically protect a messaging app, cloud-storage client or another application on the same Chromebook. A full VPN tunnel does.

That difference mattered because my task crossed environments. The documents were in Chrome, but the authentication code was in an Android app. Protecting only one side would have left half the workflow outside the tunnel.

The app also handled its own server and connection details. I did not have to translate a commercial subscription into certificate fields, hostnames or peer settings. Instead of asking how the network should be built, it asked what I was trying to do.

Google’s Android documentation identifies the same practical advantages: VPN apps can support their own connection methods and hide complex setup from the user. (Google) At the airport, that was not merely convenient. It was the difference between finishing the upload and continuing to troubleshoot it.


Closing the lid did not end the protection

With the files sent, I closed the Chromebook and walked toward the gate.

Ten minutes later, the accountant replied with a question about the contract date. I opened the Chromebook near the boarding area, beyond the lounge Wi-Fi’s range. The machine joined my phone’s hotspot instead.

The VPN returned without asking me to rebuild the connection.

I opened the document, checked the date and replied.

The service uses an HTTP/3-based transport designed to recover efficiently when a device wakes, loses packets or changes networks. That suited the way a Chromebook is actually used: close the lid, move, reopen it somewhere else and continue working.

I could not inspect the airport network’s internal filtering or traffic-management rules, so I cannot identify every reason the two attempts behaved differently. The observable result was clear. The manual connection never completed the original task. The app completed it and returned after the Chromebook moved onto another network.

That recovery turned out to be more than a technical detail.

A desktop computer may remain on the same Ethernet or Wi-Fi connection for hours. A Chromebook moves between a kitchen table, classroom, train, airport, hotel and phone hotspot. Sleep and network changes are part of its normal day.

A VPN that requires manual repair after each transition is poorly matched to the device, even if its first connection looks impressive.

Public Chromebook discussions reflect the same confusion. Users regularly ask whether an Android VPN covers Chrome traffic and why a VPN running inside the Linux container does not protect the rest of the system. (Reddit) The recurring mistake is treating every visible environment as a separate computer.

For the browser-and-Android workflow in front of me, the full tunnel removed that problem.

Always-on protection finished the setup

After the trip, I opened ChromeOS’s Android VPN settings and enabled Always-on VPN. I also selected the option to block connections when the VPN was unavailable.

ChromeOS supports these controls for compatible Android VPN apps. If the tunnel drops, the system can warn the user and prevent traffic from quietly returning to a direct connection. (Google) (Google)

That solved the final weakness in my airport setup.

During the document upload, I had watched the VPN indicator because the files mattered. On an ordinary morning, I would not necessarily notice that the Chromebook had awakened before the secure connection was ready.

Always-on protection moved that responsibility from memory into the operating system.

It also made the built-in-versus-app distinction feel even less useful. The client came from Google Play, but ChromeOS controlled its permission, displayed its status and could stop traffic from bypassing it.

The protection did not become less system-wide because its interface was an Android app.

When the built-in option still makes sense

I would still choose ChromeOS’s native VPN configuration when an employer or school supplied the exact server address, certificates and authentication details. In that situation, the organisation controls the network and may require a specific configuration.

I would not replace a company-mandated VPN with a consumer service simply because the consumer app was easier to use. They solve different problems.

The built-in option can also work well for someone running a straightforward personal WireGuard or OpenVPN server and comfortable entering the configuration manually.

But that was not my situation at the airport.

I had a personal Chromebook, an unfamiliar public network and one urgent task spread across Chrome and an Android application. The smaller app solved that problem without requiring me to become the network administrator first.

Its task-based interface removed the configuration delay. Its full tunnel covered both parts of the workflow. Its transport recovered when the Chromebook moved from lounge Wi-Fi to a phone hotspot.

It also includes traffic obfuscation, making the connection less obvious to networks that identify familiar VPN patterns. That adds value on airports, hotels, campuses and other shared networks where a conventional tunnel may connect inconsistently.

There is one limitation worth noting. The service has fewer server locations, a shorter public history and fewer independent reviews than the largest established providers. Someone who needs a specific national endpoint may place more weight on those factors.

None of them changed the result of this test.

The native client offered a secure framework but expected configuration I could not complete. My regular provider supplied files that did not fit neatly into that framework. The smaller app created the system-wide connection, completed the upload and remained useful after the Chromebook changed networks.

On a personal Chromebook, the better VPN is not the one that looks most native in Settings. It is the one that protects the entire task before the progress bar stops moving.

Questions this experience may leave you with

What was actually causing the problem?

The result made the architecture easier to understand than any settings page had. The smaller app was not behaving like a browser extension. It was creating a system VPN connection that ChromeOS could use across the browser and compatible Android apps.

Why did the obvious fixes fail?

A browser extension may affect only browser activity. It does not automatically protect a messaging app, cloud-storage client or another application on the same Chromebook. A full VPN tunnel does.

What should you check first?

During the document upload, I had watched the VPN indicator because the files mattered. On an ordinary morning, I would not necessarily notice that the Chromebook had awakened before the secure connection was ready.

What finally changed the result?

Its task-based interface removed the configuration delay. Its full tunnel covered both parts of the workflow. Its transport recovered when the Chromebook moved from lounge Wi-Fi to a phone hotspot.

What is worth remembering?

There is one limitation worth noting. The service has fewer server locations, a shorter public history and fewer independent reviews than the largest established providers. Someone who needs a specific national endpoint may place more weight on those factors.