Breaking Lab srl
I Built My Own VPN. Here Is the One Thing It Cannot Do
I run my own VPN. It sits on a small server I control, separate from the machines that host my websites, and for the reason I built it, it works exactly as intended.
There is one thing it cannot do, and it took me a while to accept that no amount of configuration was going to fix it: streaming services refuse it. Not because I am in the wrong country — I am in the right country, with a subscription I pay for every month. They refuse it because of what the connection is.
That distinction is the whole point of this page, and almost nobody writes about it honestly, because almost everybody writing about VPNs is selling one.
Why build your own at all
The honest reasons are unglamorous. Traffic encrypted up to a server that belongs to you rather than to a company whose logging policy you have to take on trust. No third party keeping records of where you go. Access to your own network from outside it. A fixed address you know, rather than one shared with strangers. And the running cost of a small server instead of a subscription.
What it is not is anonymity. Anyone promising you that is selling something. A VPN moves the point at which your traffic becomes visible; it does not make it disappear. Moving that point from your internet provider to a machine you own is a real improvement, and it is a modest one.
A word on how, because it explains a choice that would otherwise look strange. The tunnel is L2TP/IPsec — not the protocol anyone would pick today on technical merit alone. It is what my router speaks. The router is a Huawei, and L2TP is the only VPN client it supports, so the decision was made for me.
That constraint turned out to be the best thing about the setup. Because the router holds the connection rather than each device, everything in the house is on the VPN without installing anything on anything. Phones, a television, a printer that will never in its life run a VPN client — they inherit it from the network they join. There is no profile to configure on a new device and nothing to remember to switch on. If you are choosing between putting a VPN on your machines or on the box they all connect through, this is the argument for the box.
What it does well
Everything it was built for. Browsing, work, reaching internal services, keeping the connection private from the network you happen to be sitting on. If you are on hotel or airport wifi, the difference is not theoretical.
It is also cheap in a way that surprises people who only know commercial VPNs. The server costs what a small server costs, and the traffic is yours.
The wall
Streaming does not pass. And here is the detail that reframes the entire problem: it is not geography.
The usual assumption is that these services check where you appear to be and block you if it is the wrong place. That is part of what they do, but it is not what happens here. Right country, paid subscription, and the connection is refused anyway.
What is being rejected is the address itself.
The message is worth quoting exactly, because it contains the whole misunderstanding. In large type: “Disable your VPN to continue.” Underneath, smaller: “Using a VPN may disrupt your DAZN experience. For uninterrupted access, please disable your VPN and reload or restart DAZN.”

Read it twice. It does not say I am in the wrong country. It does not say the content is unavailable in my region. My tunnel comes out in Italy, on an Italian address, on an Italian account, watching something Italian. None of that is in dispute. What is being refused is the tunnel itself, and the message says so without pretending otherwise.
The tone tells you what kind of rule this is. Nobody is accused of anything. The VPN may disrupt your experience; switching it off is offered as the path to uninterrupted access. It is written as advice for my own good rather than as enforcement — which is a courteous way of saying the decision is not open to discussion.
Once you read it that way, the instruction is not a workaround to be defeated. It is a statement of policy, and it is accurate.
Why it happens, in plain terms
Every address on the internet belongs to a network that can be identified — an autonomous system, in the jargon, which is essentially a registered block of addresses with an owner. Those networks are catalogued. It is well known which blocks belong to datacentres and which belong to domestic broadband lines, and there are commercial databases that do nothing but maintain that classification and sell it as a service.
A server lives in a datacentre. That is what a server is. So the moment your traffic arrives from it, the address announces itself: this connection came from a machine in a rack, not from a house.
This is not something configuration can hide. You can change port, protocol, cipher suite, tunnel one thing inside another — the address still belongs to a datacentre block, and the classification is made on the address, before your traffic is even examined. It is not a mistake on your part and it is not a weakness in your setup. It is structural.
It is also worth being clear about a related point: having your own address rather than one shared with hundreds of other people does not help. Sharing makes things worse, certainly — an address that a thousand people have already burned is blocked faster. But a pristine address used by exactly one person is still a datacentre address, and that is the property being tested.
Why sport is the hardest case of all
Sports platforms are the strictest, and there is a specific reason that is rarely explained.
Sports rights are the most rigidly territorial product in media. They are sold country by country, competition by competition, often season by season, and the contracts are explicit about the territory in which the buyer may show the matches. For a general entertainment service, someone watching from the wrong place is a commercial annoyance. For a sports platform it is potential contractual exposure with a rights holder who has sold the same matches to somebody else next door.
That produces a blunt policy: when in doubt, block. The cost of wrongly refusing a paying customer in the correct country is a support ticket. The cost of wrongly allowing a viewer the contract does not cover is a legal problem. Given that asymmetry, any rational operator over-blocks.
So you end up refused not because you did anything wrong, but because you are collateral damage from a rule written about somebody else.
What commercial VPNs do differently
This is where it is tempting to write something dishonest, so let me be precise.
Commercial providers are not doing something technically clever that you failed to think of. They are spending money continuously. They acquire addresses that are classified as residential rather than datacentre, they rotate them, and they replace them as they get recognised and blocked. That procurement and replacement is the product. It is why they cost a monthly subscription rather than the price of a small server: you are paying for an operational treadmill, not for software.
Providers like ExpressVPN and NordVPN are the mainstream of that market, and they are a reasonable purchase if what you want is somebody else running that treadmill for you.
But here is the part their own marketing will not tell you plainly: sometimes it works and sometimes it does not, and none of them can promise you a specific service. Any page that guarantees you a named streaming platform is lying, or is about to be out of date. The classification databases update, addresses get burned, and the platform pushes back. It is a moving contest, and you are buying a position in it, not an outcome.
So what do you actually do
The honest answer, and the one that sells nothing: for streaming, the VPN comes off.
That sounds like a defeat and it is really a clarification. A private VPN and a commercial VPN are not the same category of product, even though they share a name. One gives you a private path to a machine you own. The other rents you a rotating supply of addresses that look domestic. If you built the first expecting the second, you will be disappointed — not because you built it badly, but because you built a different thing.
Two tools, two jobs. There is no configuration that collapses them into one.
Who should build one, and who should buy one
Build your own if you want privacy from your internet provider, access to your own network from outside, a fixed address you control, and you find running a small server interesting rather than tedious. It will do all of that well and cost very little.
Buy a commercial one if your goals include streaming, if you need to appear in several different countries, or if you would rather not maintain anything. You are paying somebody to fight a fight you cannot win alone — with no guarantee attached.
Build one and accept the limit if, like me, the privacy was the point and the streaming was a hope. That is a perfectly good outcome, as long as nobody sold you the hope.
There is a postscript to this, on the other side of the same market. If commercial providers buy residential addresses, somebody is selling them: we did, for twelve months, and wrote down what it paid and what you are really giving up.



