NetworkThreat ModelConfigurationsdVPN · single exitdVPN · single exit ✅IP hidden · P1@L2❌Req-unlink · P2@L2❌Local net · P1@L3L❌Global net · P1@L3G✅FastL2The destination✅P1❌P2SeesExit gateway IPAll requests and contentsCan't seeClient IPResidual / countermeasureP2 fails within a session: the tunnel delivers one NATed flow. Across sessions, linkage depends on crowding at the exit IP.Rotate the exit per request to restore P2. See the multi-exit configuration.L3LLocal network observerSeesActivity fingerprint: WireGuard adds no cover and preserves packet timingL3GGlobal network observerSeesEnd-to-end flow correlationResidual / countermeasureThe 2-hop route stops a single gateway linking client to destination, but both gateways colluding, or a global observer, can still correlate.ProsFastDeployable todayCons / mitigationsA fixed exit is a linking key: rotate per requestFitThe minimum: hides IP; add exit rotation and baseline hygieneVerdicts and the latency implied by the path are an illustrative model, not measured values.VPNdVPN · multi-exit