Anyone comparing gateways and VPNs, or trying to understand what TYO Reach actually does.

What is a smart internet gateway?

Not a VPN. Not just a proxy. A selective routing layer that sends only the apps and domains you choose through a remote exit — and leaves everything else completely alone.

The problem with full-tunnel VPNs

Traditional VPNs route everything — and that's the problem

A full-tunnel VPN sends 100% of your traffic through a remote server. That design made sense when remote workers needed to reach a private corporate network from outside the office. For everyday mixed use, it creates real friction.

Video calls degrade

Every packet in a VPN tunnel travels to the VPN server and back before reaching the other person. On a video call that needs sub-100 ms round-trip latency, the added hop shows immediately — pixelated video, dropped audio, lag.

Local devices stop working

While a full-tunnel VPN is active, traffic destined for your local network — a shared printer, a NAS, a Chromecast — goes into the tunnel instead. The printer disappears. Home devices become unreachable.

Everything slows down

Your upload and download speed is capped by the VPN server's bandwidth, not your ISP's. Large file uploads, 4K streams, and cloud backups all compete for that one bottleneck.

Kernel drivers and admin rights

Most VPN clients install a TUN or TAP adapter — kernel-level software that intercepts all traffic system-wide. Installing one requires administrator rights and can conflict with corporate endpoint protection tools.

A better model

A smart internet gateway routes only what needs routing

Instead of tunnelling everything, a smart gateway applies selective routing rules: nominated apps and domains exit through a remote gateway; everything else goes direct — full speed, no disruption.

A smart internet gateway sits between your device and the internet. It watches outbound connections and applies a routing policy you define:

  • A request to a streaming service that's geo-blocked in your region? Goes through the gateway's exit node in another country.
  • A Teams video call? Goes direct to Microsoft's servers — no gateway hop, no added latency.
  • Your local network printer? Untouched. The gateway never sees traffic that isn't destined for the public internet.

Your local devices keep working, video calls stay sharp, and only the connections that benefit from the gateway actually use it.

Static egress IP

One consistent address for your outbound traffic

Every time you connect, the destination server sees the same IP address — the gateway's exit IP, not your home or office IP.

Your ISP assigns you a dynamic IP address that changes each time your modem reconnects. That's fine for casual browsing, but it causes real problems in specific situations:

  • SaaS firewall rules. If a corporate tool restricts logins to a known IP allowlist, you must update that list every time your IP rotates.
  • Banking and government portals. Some portals treat a sudden IP change as suspicious and force re-authentication or lock the account.
  • Geo-access. Streaming services and news archives check your IP to decide what content is available. A shifting IP can cause inconsistent access.

A static egress IP solves all three. You get a single address — hosted in a specific region — that you add to an allowlist once and rely on indefinitely.

Team policy

Admins define routing; employees just install the client

In a team context, an administrator configures which apps use the gateway, which exit region to use, and whether MFA is required. Every member's device picks up that policy automatically on sign-in.

This is meaningfully different from running a team VPN:

  • Traditional team VPN: provision a server, distribute credentials to every employee, redeploy config when a rule changes.
  • Policy-driven gateway: configure routing rules once in a dashboard; employees install a lightweight client and sign in with SSO; policy changes propagate to every device without any per-machine action.

For small and mid-sized teams, this removes an entire category of IT work.

How it works

No kernel driver — works at the OS proxy level

Because a smart gateway routes only selected traffic, it doesn't need to intercept everything at the kernel level. No TUN driver, no administrator rights to install, no conflict with existing endpoint tools.

TYO Reach configures your operating system's built-in proxy settings and a PAC (Proxy Auto-Config) file. A PAC file is a small script — natively supported by every major OS and browser — that tells your device which connections to send through the gateway and which to leave direct.

This means Reach:

  • Works on machines where users don't have administrator rights.
  • Runs alongside endpoint protection software without conflict.
  • Uninstalls cleanly with no driver residue.
  • Never touches local network traffic.
Honest comparison

When to use a gateway, and when to use a VPN

Both tools serve real purposes. Here's a straightforward look at which fits which situation.

Use a smart internet gateway when you want to:

  • Unblock specific streaming services, archives, or region-locked tools without affecting your whole connection.
  • Give your team a static egress IP for SaaS allowlisting and corporate firewall rules.
  • Route only selected apps through a remote exit — not your entire network traffic.
  • Install something on a managed or locked-down machine without administrator rights.
  • Keep local devices (printers, NAS, smart home hubs) working normally while the gateway is active.

Use a traditional VPN when you want to:

  • Access a private internal network — such as your company's office LAN — from outside.
  • Tunnel all traffic through a single encrypted connection when working from an untrusted public network and you need blanket coverage.
  • Conceal all traffic metadata from your ISP (an OS-level proxy gateway does not add encryption below the application layer).

Neither is universally better. A gateway is lighter, more selective, and easier to deploy. A VPN is more comprehensive but more disruptive to everyday use.

APAC
Gateway network
AU · HK · SG and more
0
Kernel drivers
no TUN, no admin rights
1
Static egress IP
per team, per region
500 MB
Free to try
no card needed
1

Create a free account

Sign up with email or Google. No card required. Your first 500 MB is included so you can try the service before committing to anything.

2

Download the client

Install the Reach app on Windows, macOS, or Linux. It configures your browser proxy automatically — nothing else to set up.

3

Switch it on

Toggle from the system tray. The apps you've selected route through the Australian exit node. Everything else goes direct.

Does a smart gateway encrypt my traffic?

Traffic between your device and the Reach gateway travels over HTTPS — the same TLS encryption used by any secure website. The gateway does not add a second encryption layer below the application level. If end-to-end encryption of all traffic is your goal, a full-tunnel VPN provides that; Reach is optimised for selective routing, not blanket encryption.

Will it slow down my internet connection?

Only the traffic you've selected to route through the gateway is affected. A connection from Sydney to our Sydney exit node adds roughly 5–15 ms of extra latency under normal conditions. Everything else — video calls, file uploads, local network access — goes direct and is completely unaffected.

Does it work on managed or locked-down machines?

Yes. Reach installs without administrator rights on Windows using a standard user-level NSIS installer. It relies on OS-level proxy settings rather than a kernel driver, so it runs comfortably alongside most corporate endpoint protection tools.

What happens to traffic that isn't selected for routing?

It goes direct — straight from your device to the internet, with no involvement from the Reach gateway at all. The Reach client only touches traffic it has been explicitly told to route.

Try TYO Reach free — 500 MB, no card needed