If you work with multiple advertising accounts, manage client accounts, or connect to corporate resources — a single VPN no longer provides the necessary level of protection. Platforms have learned to recognize VPN addresses, and corporate networks require an additional layer of anonymity. The solution is the double-hop scheme: proxy + VPN in one chain. In this article, we will explore how it works, who needs it, and how to set it up without technical knowledge.
What is double-hop and why is it needed for business
Double-hop (literally — "double jump") is a scheme where your traffic passes through two independent anonymization nodes sequentially. In the classic version, it looks like this: your computer → proxy server → VPN server → target website or service. Each of these nodes sees only its "neighbor" in the chain but does not see the final source of the request.
Why is this important right now? Because large platforms — Facebook, TikTok, Google, Wildberries — are actively developing systems to detect proxies and VPNs. They analyze not only the IP address but also traffic behavior, the ASN number of the provider, and connection time patterns. A single VPN or proxy is easily detected today. The double chain significantly complicates this task.
For businesses, double-hop solves several tasks at once:
- Protection of corporate data — employees connect to the company's internal resources through a corporate VPN, while their real IP is hidden behind a proxy server.
- Working with multiple accounts — arbitrage specialists and SMM professionals can use different proxies for each account, adding a VPN as an additional layer of protection.
- Bypassing regional restrictions — a proxy in the required country + corporate VPN = the ability to work with local content without the risk of revealing the real location.
- Protection against DNS and WebRTC leaks — with proper configuration, double-hop completely eliminates leaks that often occur when using only one tool.
It is important to understand: double-hop is not paranoia, it is a working tool for those who take the security of their business on the internet seriously. Especially when it comes to advertising budgets in the tens of thousands of rubles or client accounts, the loss of which is more expensive than any setup.
Who needs the proxy + VPN scheme: real scenarios
Before setting up double-hop, it is worth understanding whether you really need this scheme or if something simpler is sufficient. Here are specific scenarios where the double chain is justified.
Arbitrage specialists and media buyers
If you work with Facebook Ads or TikTok Ads and manage 10–30 advertising accounts simultaneously, each account must "see" a unique IP address. But that is not enough: Facebook analyzes the IP history, the ASN of the provider, and behavior patterns. The proxy scheme (unique IP for each profile in Dolphin Anty or AdsPower) + corporate VPN as an external layer provides additional protection for the entire infrastructure. Even if one account comes under scrutiny, the others remain safe — they are connected through different proxies, and the VPN hides that they originate from the same network.
SMM agencies with a team
When several employees work with client accounts on Instagram or TikTok from one office — this poses a huge risk. Instagram sees that dozens of different accounts are managed from one subnet and begins mass blocking. The solution: each employee works through their proxy in an anti-detect browser (Multilogin, GoLogin), and all office traffic additionally goes through a corporate VPN. This creates double isolation.
Marketplace sellers
Monitoring prices on Wildberries, Ozon, or Avito from multiple accounts is a task that requires different IPs. If you use a parser or monitoring service and want requests not to be associated with your company, double-hop is the right choice. The proxy hides the real IP, and the VPN adds another layer of masking.
Remote teams with access to corporate resources
Remote employees connect to the corporate VPN to access internal systems — CRM, ERP, internal dashboards. However, their home IP remains visible to the corporate server. Adding a proxy before the VPN connection hides the employee's real location and protects the corporate network from attacks through compromised home networks.
How the proxy → VPN chain works technically
Let's break down the scheme without unnecessary technical jargon — as it is important to understand for practical setup.
In a standard scheme without protection, your request goes directly: Your computer → Website. The website sees your real IP.
When using only a VPN: Your computer → VPN server → Website. The website sees the IP of the VPN server. But the VPN provider knows your real IP. Moreover, the IPs of large VPN providers (NordVPN, ExpressVPN, and others) have long been blacklisted on Facebook and other platforms.
When using only a proxy: Your computer → Proxy server → Website. The website sees the proxy's IP. This is better, especially if the proxy is residential (real home IP). But your provider and the proxy service know your real IP.
With double-hop (proxy + VPN): Your computer → Proxy server → VPN server → Website. The following occurs:
- The website sees the IP of the VPN server (or proxy, depending on the order of the chain).
- The VPN server sees only the IP of the proxy server, but not your real IP.
- The proxy server sees your real IP but does not know what you are doing next (traffic is encrypted by the VPN).
- Your provider sees only encrypted traffic up to the proxy server.
💡 Key principle of double-hop:
No node in the chain has both your real IP and information about what you are doing on the final site. This is maximum anonymity.
There are two possible orders for the chain: Proxy → VPN and VPN → Proxy. For most business tasks (working with advertising accounts, multi-accounting), the first option is used: first proxy, then VPN. This allows using different proxies for different profiles, while all traffic is additionally encrypted by the corporate VPN.
What type of proxy to choose for double-hop
Not all proxies work equally well in the double-hop scheme. The choice depends on your task. Let's break down three main types.
| Proxy Type | Suitable for | Risk of Blocking | Speed |
|---|---|---|---|
| Residential | Facebook Ads, Instagram, TikTok, social networks | Minimal | Average |
| Mobile | TikTok Ads, mobile apps, warming up accounts | Minimal | Average |
| Datacenter | Parsing, price monitoring, corporate access | Medium | High |
Residential proxies in double-hop
Residential proxies are the optimal choice for working with social networks and advertising platforms in the double-hop scheme. They use real IP addresses of home users, so platforms perceive them as regular user traffic. In conjunction with a corporate VPN, they provide maximum masking: the platform sees a "home" IP, while the real origin of the traffic is hidden behind two layers.
Mobile proxies in double-hop
Mobile proxies are especially valuable for working with TikTok Ads and mobile versions of applications. They use IP addresses from mobile operators (4G/5G), which platforms perceive as the "cleanest" type of traffic. Mobile IPs rarely end up in blocklists, as one IP can be used by thousands of real users through the operator's NAT. In the double-hop scheme, this creates virtually impenetrable protection for advertising accounts.
Datacenter proxies in double-hop
If your task is corporate access to internal resources or data parsing, datacenter proxies are the best fit. They provide high connection speed and stability, which is critical for working with corporate VPN tunnels. The risk of blocking for corporate tasks is negligible — no one blocks access to their own servers.
Step-by-step setup of double-hop for anti-detect browser
Let's break down the setup using Dolphin Anty — one of the most popular anti-detect browsers among arbitrage specialists and SMM professionals. The principle is similar for AdsPower, GoLogin, and Multilogin.
What you will need:
- Anti-detect browser: Dolphin Anty, AdsPower, GoLogin, or Multilogin
- Proxy (residential or mobile) — details: IP, port, username, password
- Corporate VPN — client and connection details
- Computer with Windows, macOS, or Linux
Step 1. Set up the proxy at the operating system level or in the browser
The first option is to set up the proxy directly in the anti-detect browser profile. Open Dolphin Anty → click "Create Profile" → in the "Proxy" section, select the type (SOCKS5 is recommended for maximum compatibility) → enter the proxy IP address, port, username, and password → click "Check Proxy." Make sure the correct country and city are displayed.
The second option is to set up the proxy at the system level through system settings. This allows all traffic from the computer to be routed through the proxy, not just the traffic from a specific browser. For Windows: Settings → Network & Internet → Proxy → Use a proxy server → enter the proxy details.
Step 2. Connect to the corporate VPN
After setting up the proxy, launch the VPN client (Cisco AnyConnect, OpenVPN, WireGuard, or your company's corporate client) and connect to the corporate server. An important point: the VPN client should be launched AFTER the proxy is already set up and active. This is how the chain is formed: traffic goes first through the proxy and then through the VPN.
If the VPN client is configured to use the system proxy (most corporate clients support this), it will automatically connect through the proxy server.
Step 3. Check that the chain is working correctly
After connecting both levels of protection, open the browser and go to an IP check website (for example, whoer.net or ipleak.net). You should see the IP of the VPN server — not your real IP and not the proxy IP. Also check:
- DNS leaks — DNS servers should correspond to the VPN provider, not your real provider.
- WebRTC leaks — your real IP should not be displayed in the WebRTC section on ipleak.net.
- IPv6 leaks — if your provider supports IPv6, make sure it is also hidden.
Step 4. Launch the profile in the anti-detect browser
Now open the desired profile in Dolphin Anty or AdsPower. If the proxy is set at the system level, you can select "No Proxy" in the profile itself — all traffic is already routed through the system proxy and VPN. If the proxy is set in the browser profile — make sure the VPN is active, and launch the profile as usual.
Features of working with corporate VPN
Corporate VPNs have a number of features that need to be considered when building a double-hop scheme. Unlike commercial VPN services (NordVPN, ExpressVPN), corporate solutions are usually configured by the company's administrator and may have restrictions.
Split tunneling — an important setting
Most corporate VPNs support split tunneling mode — traffic separation. In this mode, only traffic to corporate resources goes through the VPN tunnel, while all other traffic goes directly (or through the proxy if it is configured). This is convenient: work tasks are protected by the corporate VPN, while work with advertising accounts goes through the proxy.
If split tunneling is disabled (all traffic goes through the VPN), to work with advertising platforms, you need to set up the proxy at the level of a specific profile in the anti-detect browser, not at the system level. Then the scheme will be: Anti-detect browser (with proxy) → VPN → Internet.
Authentication and certificates
Corporate VPNs often require two-factor authentication or corporate certificates. This does not interfere with the operation of double-hop — just make sure the VPN client is installed and configured before you start building the chain with the proxy. Certificates and 2FA work independently of which proxy the connection is established through.
VPN protocols and compatibility with proxies
Not all VPN protocols work equally well through proxies. Here is a brief guide:
- OpenVPN (TCP mode) — works great through SOCKS5 proxies. This is the most compatible option.
- WireGuard — works through proxies but requires additional configuration. Some corporate clients support this out of the box.
- Cisco AnyConnect / SSL VPN — works through HTTP/HTTPS proxies. Proxy configuration is usually available in the client settings.
- IPSec/IKEv2 — the most difficult to configure through a proxy. Requires specific configuration at the system level.
Common mistakes and how to avoid them
Even with a correct understanding of the double-hop scheme, many make mistakes that nullify all protection. Here are the most common ones.
Mistake 1: Incorrect connection order
The most common mistake is to connect to the VPN first and then set up the proxy. In this case, the proxy will work inside the VPN tunnel, and the scheme will look like this: Your computer → VPN → Proxy → Website. This is not double-hop in the classic sense: the VPN provider sees your real IP, and the proxy sees the IP of the VPN server.
The correct order: first set up and activate the proxy, then connect to the VPN.
Mistake 2: Using one proxy for all accounts
If you use one proxy server for all profiles in Dolphin Anty or AdsPower, platforms will still see that many accounts are working from one IP. Double-hop does not solve this problem — it adds protection on top but does not replace the rule "one account — one IP." Use different proxies for each profile.
Mistake 3: Ignoring DNS leaks
Even with a correctly configured double-hop, DNS requests may go through your real provider, revealing your location. Always check DNS on ipleak.net after setup. In the VPN client settings, enable the "DNS through VPN" or "Prevent DNS leaks" option.
Mistake 4: Mixing profiles
If you use an anti-detect browser but sometimes access work accounts through a regular browser (Chrome, Firefox) — this destroys the entire protection scheme. Facebook and other platforms use cookies, localStorage, and other identifiers that can link the "protected" profile to your real account. A strict rule: each account — only through its profile in the anti-detect browser.
Mistake 5: Saving on proxy quality
Free or very cheap proxies from public lists are not just a risk of blocking. They are a security risk: such proxies may log your traffic, inject ads, or intercept authentication data. In the double-hop scheme, the proxy is the first node through which all your traffic passes. Use only trusted providers with a clear privacy policy.
Comparison of protection schemes: VPN, proxy, double-hop
To finally understand when double-hop is needed and when a simpler solution is sufficient, let's compare all three approaches by key parameters.
| Parameter | Only VPN | Only Proxy | Double-hop |
|---|---|---|---|
| Hiding real IP | ✅ | ✅ | ✅✅ |
| Traffic encryption | ✅ | ❌ | ✅ |
| Working with social networks without blocking | ⚠️ Risk | ✅ (residential) | ✅✅ |
| Multi-accounting | ❌ | ✅ | ✅✅ |
| Protection against DNS leaks | ✅ (with setup) | ❌ | ✅✅ |
| Corporate access | ✅ | ❌ | ✅✅ |
| Connection speed | High | Average | Average |
| Setup complexity | Low | Low | Medium |
The conclusion from the table is obvious: double-hop wins on all security parameters, only lagging slightly in speed (insignificantly with good proxies) and ease of setup. For serious work with advertising accounts and corporate resources, this is a justified choice.
📋 Checklist: when to switch to double-hop
- You manage more than 5 advertising accounts simultaneously
- You work with client accounts, the loss of which is critical
- Several employees work with the same platforms
- You have already received blocks when using only VPN or only proxy
- You need access to corporate resources while protecting your real IP
- You work with financial or confidential data over the internet
Conclusion
The double-hop scheme (proxy + corporate VPN) is not an excessive precaution but a practical tool for those working with multiple accounts, advertising accounts, or corporate resources. It addresses the main problem of modern internet marketing: platforms are becoming smarter, and a single level of protection is no longer sufficient.
Key takeaways from the article: the correct connection order (proxy first, then VPN) is critically important; the type of proxy should be chosen based on the task (residential for social networks, mobile for TikTok, datacenter for corporate access); always check for DNS leaks after setup; each account must work through a separate proxy even in the double-hop scheme.
If you plan to build a reliable infrastructure for multi-accounting or protecting corporate traffic, start by choosing the right type of proxy. For working with Facebook Ads, Instagram, and TikTok, we recommend considering residential proxies — they provide minimal risk of blocking and work excellently in the double-hop scheme with corporate VPN.