eduroam gets you on the SSID. The VPN is a later hop. Stop selling them as the same product.

White-Label VPN for Campuses

A campus VPN is a branded student and staff tunnel, not eduroam. BYOD, who supports (ITS vs vendor), and what you must not claim about FERPA.

KloxVPN Team
22 min readPublished 2021-07-12
White-Label VPN for Campuses
eduroam gets you on the SSID. The VPN is a later hop. Stop selling them as the same product.

Campuses already have a network identity product. It is called eduroam, or a local 802.1X SSID with the same job: prove you are a student or staff member, then join Wi-Fi. A VPN is not that product. A VPN is a tunnel that starts after you already have a path. If your RFP treats them as synonyms, you will spend a year explaining why the residence hall still needs a password and why the library database still blocks a shared exit.

This page is for a CIO, a campus ITS lead, or a vendor trying to put the university name on student and staff apps. It is not the three-niche overview of ISPs, hotels, and MSPs. It is not a consumer essay about cafe Wi-Fi. The buyer already has an identity provider, a help desk that hates September, and a legal office that will ask about student records the moment you say privacy.

White-label means the icon says the campus name, not a platform name. Reseller leaves the upstream brand. Most universities that care about the home screen want the crest on the phone. That is white-label. Confirm the package with sales. Do not screenshot a consumer checkout into a board packet.

KloxVPN's consumer SKU is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, from $2.83/month on yearly, 7-day money-back. A campus should not quote that as a student amenity. Seat models, SSO, graduate revoke, and who answers at 11pm in the dorms are a sales conversation. I will not invent FERPA coverage. I will not invent HIPAA. I will not mint a 99.something SLA. I will not publish city counts or API URLs. The consumer site talks 60+ countries and 100+ locations. Your footprint is the contract.

Cloudflare and Wikipedia still help a new technician explain a tunnel. RFC 8446 is TLS 1.3 on the web path, which is not eduroam and is not your VPN handshake. Encryption is a protocol. Campus Wi-Fi auth is a different protocol. Get the order wrong and ITS will spend August on a poster that lies. I have watched that poster. Students believed it. Tickets followed.

Related reading: Linux imessage_rcs: Not a VPN Setting and White-Label VPN and Builder Io. White-Label VPN and Buildroot and White-Label VPN and Bull Arena (Follow-up). What is a VPN? and Download KloxVPN.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

Campus VPN is not eduroam

eduroam is how a lot of campuses let a visiting researcher join Wi-Fi without a guest form. Local 802.1X is the same idea with a campus-only SSID. You authenticate. The controller lets you on. That is layer two and a RADIUS conversation. It is not a tunnel to an exit node. It does not change the IP the journal publisher sees. It does not encrypt your path across a coffee shop in another city.

A VPN wraps packets and sends them to an endpoint you chose. After that hop, the destination sees the VPN exit, not the dorm NAT. That is useful when a student is on a hotel SSID, on cellular, or on a conference network that is hostile in the boring way (captive portals, broken IPv6, nosy middleboxes). It is not useful as a replacement for joining the campus SSID. If you cannot join Wi-Fi, you cannot start the tunnel unless you already have another path.

I keep seeing procurement language that says deploy campus VPN / eduroam as if the slash meant equals. It does not. Train the help desk on two sentences. Sentence one: eduroam or the campus SSID gets you on the air. Sentence two: the branded VPN app is optional, for when you want a campus-named tunnel off-net or a stable egress for a publisher allowlist. If you merge those sentences, every failed RADIUS ticket becomes a VPN ticket. You do not have the staff for that in week one.

NordVPN's consumer homepage will still tell a traveler to hide on public Wi-Fi. Do not paste that onto a student portal. You are the network in a lot of those sentences. Insulting the house SSID in the house voice is how legal kills the project. Pitch a quieter path off-campus, a staff tool for travel, a way to present a known egress to a vendor. Do not pitch we hide you from ITS.

White-label branding versus the VPN tunnel
Your logo is packaging. The tunnel is still WireGuard, OpenVPN, OpenConnect, and Shadowsocks.

    How to read this page

  1. 1Skim the seating / order diagram.
  2. 2Do the numbered steps once on your real network.
  3. 3Use the FAQ if a sentence was too long.
  4. 4Follow one related article — not ten tabs.
Campus packaging versus consumer SKU. Ops texture, not a Klox rate card.
MotionWhat it isWho authenticatesFailure mode
eduroam / campus 802.1XWi-Fi loginIdP / RADIUSYou sold it as a VPN and the desk cannot tell them apart
Staff travel tunnelBranded app, off-netCampus account in the VPN clientAlways-on fights hotel portals
Student optional amenitySame app, lighter defaultsStudent account, term-scopedFive-device cap vs a laptop pile
Publisher allowlistDedicated egress if contractedITS + vendorYou promised 'anonymous' and the vendor wants a static IP
Consumer 5-device checkoutA card on a websiteWhoever typed the emailYou put it on a residence-hall poster

If the dorm desk has to explain 802.1X and a kill switch in the same breath, you already lost September.

— KloxVPN operator notes

Cloudflare Learning: What is a VPN?

Wikipedia: Virtual private network

IETF RFC 8446 (TLS 1.3)

NordVPN (competitor consumer pitch — not a campus portal)

Order of operations on a freshman laptop

Join the campus SSID or eduroam. Confirm the browser loads the LMS. Then, if the amenity is in scope, open the university-branded app and connect. If the app tries to fail-closed before Wi-Fi auth, the captive portal or the 802.1X dance never finishes. Fail-closed is a privacy mode on a cafe. It is a trap on a move-in weekend. Default the student SKU away from it unless you tested the real SSIDs.

Visiting scholars

eduroam exists so a visitor can get on Wi-Fi. Your branded VPN account probably should not. If you issue VPN seats to every visitor, you will revoke nobody in June. If a lab needs a tunnel for a visiting postdoc, that is a staff exception with an end date. Write the end date. Calendar it. Do not leave it as the PI will remember.

Who actually buys this, and who can veto it

ITS usually owns the network and the identity provider. Student affairs sometimes owns the 'digital campus' story and the app store listing in the student-life bundle. The library owns publisher contracts. Legal owns student-data language. Procurement owns the PDF. If you sell to student affairs only, ITS will veto the client defaults. If you sell to ITS only, student affairs will ship a poster that promises anonymity. Get them in the same room in meeting two.

The From Enterprise Inquiry to a White-Label VPN article is the packet shape: controller, store accounts, support hours, dedicated IP. Use it. A campus that emails we're interested will get a polite stall. A campus that names the IdP, the store publisher, and who revokes graduates will get a real conversation. I would rather lose a fuzzy RFP than win a fuzzy RFP.

Budget is rarely the consumer $2.83/month number. Sometimes the university pays as a site license. Sometimes students opt in. Sometimes a college inside the university pays for staff travel only. Write who pays. If who pays is TBD, the bursar will guess, and guesses become refund theater in October.

The CIO test

If you cannot say in one slide what happens when a student graduates, what happens when a laptop is stolen, and who the student emails at 11pm, you do not have a campus product. You have a consumer app with a crest. The CIO already has enough of those.

Faculty senate and unions

Staff tunnels that inspect traffic are a different political object than student amenity tunnels. If your deck is vague about split tunnel and DNS, someone will fill the gap with a rumor. Write what the client does. Write what it does not do. Rumors are more expensive than a boring PDF.

Student and staff apps under the university name

White-label is the right shape when the home screen should match the ID card. The White-Label VPN and Explained is the model: your brand, platform underneath. This page assumes you picked that model because a reseller icon on a residence-hall flyer teaches students to shop the university. Most campuses will not accept that.

Two audiences, two defaults, same binary if you must. Staff: travel, hotel portals, maybe a publisher allowlist, maybe always-on on university-owned laptops. Students: optional, lighter, no fail-closed on move-in SSIDs, term-scoped accounts. If you ship one default to both, staff will complain the tunnel is timid and students will complain they cannot complete eduroam. You will be right that it is the same protocol. You will still be wrong as an operator.

Store listings are homework. Apple entitlements and Play VPN declarations are their own articles. A campus that already has a student app will want to stuff the tunnel into that binary. Stuffing often dies in review. A small branded VPN app plus a deep link from the campus app is usually faster. Confirm the store plan before you promise one icon to the board. I have watched a September launch slip because someone assumed Network Extension was a checkbox in week three.

WireGuard versus OpenVPN
Klox ships four protocols: WireGuard by default, OpenVPN when UDP fails.

The crest is a trademark, not a skin

Legal will care about the name in the store. So will the foundation that owns the logo. Get written permission. A contractor who 'borrowed' a PNG from the website is how you get a takedown in October. Ugly. Avoidable.

Screenshots must match the desk script

If the store screenshot shows a kill switch and the dorm script says never touch that, you scheduled a fight. The brand-screenshots article is the general wound. Here: one campus, one script, one set of shots. Retake them when defaults change.

BYOD versus a five-device consumer SKU

A freshman shows up with a phone, a laptop, a tablet, maybe a second phone, maybe a console. Klox consumer is five devices. That number is a household SKU, not a dorm census. If you copy it onto a campus amenity without saying so, you will spend move-in weekend on cap tickets. Confirm device caps with sales. If the campus SKU is five, print five. If it is seats that ITS assigns, print that. Caps discovered at 1am are tickets with an audience in the hallway.

University-owned endpoints are easier: image the client, pin the profile, revoke with the asset tag. BYOD is a consent and a mess. You will not MDM every personal phone. Do not pretend. Offer the branded app, a short how-to, and a device list the student can see. If a roommate's laptop is still in the slot after a breakup, the student needs a self-serve kick, not a 48-hour ITS ticket.

IPv6 on residence hall Wi-Fi will leak around a sloppy client. We have a consumer leak article. Do not promise the campus build is leak-proof because a blog said so. Test the real SSID. Test dual-stack. If ITS disabled IPv6, say that in the FAQ so you do not debug a ghost.

Shared dorm rooms

Two humans, eight devices, one account they shared because the poster said family plan. That account will outlive the friendship. Prefer per-student seats bound to the campus ID. Shared passwords are how you get a harassment case with a tunnel still up.

Consoles and TVs

Most consoles will not run your branded app. A router hop in a dorm is a different product and a different complaint (latency, NAT, RA). Do not put console setup on the student VPN FAQ unless you actually support it. Honesty here saves a week of Discord screenshots.

Who supports: ITS, vendor, dorm desk

Dorm desk owns: cannot join Wi-Fi, forgot eduroam password, captive portal on a conference SSID they brought home in their head. ITS owns: identity, revoke, campus SSIDs, whether the VPN is in scope for a given role. Vendor / platform owns: handshake failures, client defects, node-side incidents. Shared: 'the LMS is slow' and 'the journal blocked me.' Shared is a fight unless you timebox it.

The student should not see three teams. They see the campus name. Escalation is back-office. If you SMS a platform name, you taught them to shop the university. White-label means the campus owns the relationship. If that scares ITS, they wanted a consumer QR to someone else's app. That is reseller energy. Most campuses will not put that on a residence-hall poster.

Write the split in the SOW. Cap categories. Review tickets per 1,000 enrolled, not per 1,000 consumer subs. The VPN Support Load: Tickets Per 1,000 Users article is consumer ticket math. Do not clone it. Campus mix is identity, device caps, hotel-portal fights on spring break, and a thin tail of real handshakes. If handshake is the bulk, your SSID or your client default is sick. Fix the house network before you buy more nodes.

After-hours is the honest line. If ITS is not on a night rotation, the script is: Wi-Fi first, then disable the tunnel, then a callback at 8am. Lying about a 24/7 engineering desk you do not have will be discovered once during midterms and remembered in the faculty Slack forever.

A ninety-second desk card

Step one: are they on the campus SSID or eduroam. If no, stop. Step two: is this staff travel or student amenity. Step three: still dead after a reconnect? Collect campus ID, time, device, and whether a personal VPN is also running. Then stop. Do not import OpenVPN profiles at the desk. OpenVPN as a protocol inside the app is fine. OpenVPN as a residence-hall ceremony is how you get a wrong config on a stranger's Mac.

Personal VPNs already installed

Students arrive with a consumer client and always-on. Your script should include: turn that off, join campus Wi-Fi, then use ours or turn theirs back on. You will not win a theology argument in the lobby. You will get them to the LMS.

FERPA and HIPAA are not a VPN feature

I will say this as clearly as I can. Putting a campus name on a tunnel does not make the university FERPA-compliant. It does not make a student health app HIPAA-compliant. It does not replace access control on the SIS. A VPN can encrypt a path and mask an IP behind an exit. Counsel still owns record-handling, BAAs, and what you print in an RFP.

The failure mode is a slide that says encrypted therefore FERPA. A journalist, an auditor, or a faculty member who actually reads will ask who the controller is, where student emails live, and what the admin panel shows. If you cannot answer, you do not have a compliance story. You have a tunnel. Sell the tunnel. Send the questionnaire to counsel and to the platform for the parts only the platform can verify.

Health-adjacent campuses will want a HIPAA sentence. Do not write one from this blog. A counseling-center laptop on a cafe SSID may benefit from a tunnel. That is a path control. It is not a designation. Inventing HIPAA coverage is how you get a worse year than the one where you said we encrypt the path and stopped talking.

Student records in the wrong pile

If the VPN admin shows last-connected next to a campus ID, that is account metadata. Write it in the privacy notice. Do not say we collect nothing next to a portal that lists devices. The privacy-policy mistakes article is the document version of this. Campus legal will find the mismatch before you do if you ship fast.

Research data

A lab that handles human-subjects data needs a protocol, not a consumer VPN slogan. If they need a known egress, that is dedicated IP as a tool. If they need a controlled enclave, that is not this product. Do not let a PI's enthusiasm turn your amenity into a fake enclave.

Split tunnel for the LMS versus full tunnel

Full tunnel is simpler to explain and harder to live with on a campus SSID. Printing, casting, internal-only services, and some lab tools expect to see the campus network. A full tunnel can send that traffic out the exit and back, or drop it. Students will call that the VPN broke Wi-Fi. Staff will call it the VPN broke the copier. Both are your problem if you defaulted full tunnel without a map.

Split tunnel is the adult default for a lot of campus builds: LMS, email, and chosen SaaS through the tunnel, or the reverse — only off-net traffic through the tunnel. There is no universal right list. There is a list ITS wrote and tested. If you do not have that list, you do not have a split. You have a hope.

Kill-switch copy on a campus client needs the same humility as a hotel amenity. Fail-closed plus a captive portal on a conference Wi-Fi is a ticket. The kill-switch naming article is the branded-app version. This page is the campus version: defaults that survive move-in and a faculty trip.

DNS

If campus DNS is required for internal names, the client has to respect that on-net. If you force a public resolver always, internal names die and ITS will blame the vendor. Document on-net versus off-net DNS. Test both. I have seen a 'privacy DNS' default take down a building's printers for a morning. That is not privacy. That is a default you did not walk.

IPv6 again

Split tunnel that forgets IPv6 is a leak with extra steps. Dual-stack campuses need dual-stack policy. If you cannot test it, do not claim it.

Graduates, leavers, guests: session life

I like credentials that die when the campus ID dies. Graduation. Withdrawal. Staff termination. A tunnel that outlives the person is a hole with a crest on it. Bind seats to the IdP. Revoke on the same event that kills email. If that event is flaky, time-box the session to the term and accept that early leavers need an ITS reset. Pick the failure you can staff.

Permanent consumer-style emails for a one-semester guest lecturer become a privacy pile. Prefer campus ID. If the store requires an Apple ID, that is the store, not your SIS. Do not harvest a Gmail to 'simplify' and then build a marketing list. That is how legal has a bad quarter.

Guests are not students. Conference attendees on campus Wi-Fi do not need your branded VPN unless you have a reason and an expiry. Reasons I believe: a known publisher egress for a workshop that lasts three days. Reasons I do not believe: everyone should have a tunnel. Everyone is how you never revoke.

Stolen laptop

ITS needs a revoke that does not wait on a vendor chat. One action in the campus tool, or a named path with a timebox. If revoke is email the platform, you will have an active tunnel on a laptop that is already on a bus.

Alumni nostalgia

Do not leave student VPN seats active as a 'benefit.' Alumni networks are a different product. A leftover seat is not a loyalty program. It is an account you forgot.

Dedicated IP as a library and publisher allowlist

Some journals and some library vendors still allow by IP. A shared VPN exit that twenty campuses use will get blocked, or it will never be listed. A dedicated IP, if your package includes it, is a sales tool: here is the egress we will register. It is not anonymity. It is the opposite. Say that out loud so a privacy working group does not hear dedicated and think invisible.

The White-Label VPN and Dedicated Ip Sla article is the general channel version. Here the buyer is the library plus ITS. Who requests the allowlist change. Who notices when the vendor rotates their ACL and the dedicated IP still works but the content does not. Who pays if you need a second IP because one publisher is allergic to the first. Write it.

I will not print an SLA percentage. I will not invent a city. Assignment details are confirm-with-sales. If a publisher wants a /32 in a specific country, that is a packet, not a blog claim.

Shared exits and reputation

A consumer-shared exit used for torrent-heavy traffic is a bad neighbor for a library allowlist. If students use the same SKU for everything, you mixed a quiet publisher path with a noisy amenity. Split the profile or accept the blocks. I would split.

Do not sell 'unblocks everything'

Geo catalogs, lab licenses, and streaming are not a campus success metric. If a student wants a consumer streaming story, that is a different product. Do not put it on the library FAQ.

Procurement without invented certifications

RFPs will ask for SOC 2, ISO numbers, HIPAA, FERPA 'certification,' penetration-test dates, and a 99.something. I will not put those stamps on this page for Klox. You should not invent them for a campus brand either. Answer what you can verify. Forward what only the platform can verify. Guessing is a three-year lie with letterhead.

The questionnaire should separate: campus as controller for student accounts; platform as operator of nodes; store publishers; subprocessors for email and cards if you take cards. If students never pay, say that. If they pay, the Billing a White-Label VPN: Cards, Tax, and Failed Payments article is the general wound. Campus bursar versus in-app cards is a choice that changes refunds. The consumer 7-day money-back is the wrong policy on a tuition-funded seat. Confirm reversals in the package.

Start with one college, one staff travel group, or one library allowlist. Prove tickets per 1,000. Then expand. Heroic all-campus rollouts in August are how you get a Slack channel named vpn-fire while the residential network is already on fire.

RFPs that want a unicorn

Every device, every TV, dedicated IP in every country, 24/7 phone, next week, $1 a student. Rewrite or walk. A staff-travel pilot with an end date is a win. A signed unicorn is an outage during midterms with a crest.

When to walk

They need you to lie about logs, lie about FERPA, or staff a language and a night desk you cannot staff. There are other campuses. There is not another reputation. If they wanted a consumer plan from $2.83/month, send them to pricing. This aisle is for ITS that already has a line.

What you must not print on the student portal

Do not promise anonymity. Cameras, ID cards, and the SIS still exist. Do not promise FERPA or HIPAA. Do not promise the VPN makes campus Wi-Fi fast. Do not promise every journal. Do not promise a kill switch that never breaks a hotel portal. Do not promise five devices if the campus SKU is different. Confirm with sales.

Do not promise WireGuard will pass every network. Offer OpenVPN in the app as fallback. Test both on residence hall Wi-Fi, on cellular, and on a hotel SSID a faculty member actually uses. Do not promise 24/7 engineering if the night path is a callback. The portal, the store listing, and the desk card should match. Misalignment is a ticket category. Name it before launch.

If this still sounds like your campus, bring a real package: who pays, IdP, store publisher, student versus staff defaults, credential life, desk languages, night path. White-label is the platform conversation. Contact is the meeting. Enterprise VPN is the inquiry shape when procurement is in the room. Consumer download is for people who already have a Klox account, not for a freshman with a move-in checklist.

Pilots that never end

End date. Metric: tickets per 1,000 enrolled, identity-related versus handshake, portal-related on travel. No metric, no all-campus rollout. I have been the free amenity. It is a lousy identity.

The poster test

Read the residence-hall poster out loud. If it uses hide, anonymous, or compliant, rewrite it. If a night student worker cannot follow it in ninety seconds, rewrite it. The protocol can stay WireGuard. The poster has to stay human.

Key Takeaways

A campus-branded VPN is a student and staff tunnel that does not pretend to be eduroam, dies when the campus ID dies, and can be explained by a dorm desk without an OpenVPN ceremony. It is not a consumer subscription funnel and it is not a FERPA stamp. Wi-Fi auth first. Tunnel second. Per-person seats. Staff defaults that differ from student defaults. Dedicated IP only when a publisher actually needs a name.

KloxVPN can put the university name on WireGuard, OpenVPN, OpenConnect, and Shadowsocks. You still have to package the term like an operator. Device caps, SSO, and who answers at 11pm are a sales conversation. Confirm them. Do not paste a five-device consumer SKU onto a board slide and call it a campus program.

If you needed the three-niche map, that article exists. If you needed the MSP playbook, that article exists. This one is ITS plus a poster that does not lie. Bring the IdP and the desk card. Leave the slash that treated eduroam as a VPN at the door.

Put a campus name on a tunnel ITS can actually support

White-label apps, WireGuard, OpenVPN, OpenConnect, and Shadowsocks, and a packaging talk for universities. Confirm seats, SSO, and device caps with sales. This page is not a rate card and not a FERPA opinion.

See white-label VPN

Frequently Asked Questions

No. eduroam and campus 802.1X authenticate Wi-Fi. A VPN is a later encrypted path to an exit. Sell them as two products or the desk will treat every RADIUS failure as a VPN ticket.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.