Why enterprise CAD portals drop your login every three clicks abroad, and how sticky egress routing preserves your security token.
Need an egress connection with strict IP stickiness that stops ProjectWise Web tokens from looping?
You are on assignment at an overseas site office, a regional contractor branch, or an international hotel room. Back home, the project delivery deadline for a major civil infrastructure package is ticking down.
Your lead structural engineer pings you on Teams: they need you to review the latest federated 3D model, approve drawing revisions, and check out a set of iModels on Bentley ProjectWise Web.
You open your browser, enter your Bentley IMS (Identity Management System) corporate credentials, pass the Microsoft Entra ID or Okta multi-factor push on your mobile phone, and the ProjectWise Web work area opens. You click into the discipline folder. The file tree begins to expand.
Then, the moment you click on a drawing to check its document properties or open an asset view, the interface pauses. A modal dialog snaps onto the screen: "Your session has expired. Please log in again."
You sigh, re-enter your password, approve another 2FA notification, and get back to the dashboard. You click a file. Two seconds later: "Your session has expired. Please log in again."
You can loop through this authentication cycle five times in ten minutes without making a single edit.
The default reaction is almost always the same. You assume Bentley’s cloud services or IMS federation are having an outage. You check the corporate intranet status boards—everything is green, and colleagues sitting at the home headquarters are checking out design files without a hitch.
Next, you figure the local branch Wi-Fi or hotel internet is dropping packets. You fire up a generic commercial VPN you normally use to stream football games or check email while traveling, choose a server back in your home country, and refresh the browser.
Instead of fixing the loop, the problem gets worse. Now ProjectWise doesn't even make it past the initial token exchange: it throws an immediate "Invalid Grant," "Access Denied," or a blank redirect loop that bounces endlessly between login.microsoftonline.com and projectwise.bentley.com.
The problem is not a software crash, and it is not a Bentley server outage. It comes down to how enterprise Zero Trust architectures continuously monitor your session fingerprint, and why standard consumer VPNs actively break those security contracts.
## Why ProjectWise Web Loops on Overseas Connections
Bentley ProjectWise Web is not an ordinary document store. It houses billion-dollar engineering assets, proprietary BIM coordinate databases, and regulated public infrastructure data. Because of this, enterprise clients protect it with strict Conditional Access Policies tied to corporate Identity Providers (IdPs).
When you authenticate, your identity provider issues an OAuth2/OIDC bearer token and an active session cookie. These tokens are not static tickets; they are bound to a composite device and network context.
On overseas branch connections, three specific network behaviors constantly trigger token revocations:
First, multi-homed ISP load balancing and dynamic NAT rotation. Many international hotels, satellite branch offices, and regional business parks run dual-WAN or multi-carrier SD-WAN links that balance outbound traffic per-connection. When your browser opens three concurrent HTTPS requests to fetch the ProjectWise UI, an iModel graphics pipeline, and an IMS keep-alive ping, those requests might exit across two different public IP addresses or subnets. To an enterprise security gateway, a single authenticated session token suddenly presenting requests from alternating IP addresses within three seconds looks like an active session-hijacking attack. The server instantly revokes the session.
Second, digital fingerprint and header inconsistencies. Modern enterprise Conditional Access engines inspect network transport headers alongside client fingerprints. When local carrier proxies abroad intercept, cache, or re-route web assets through regional proxy appliances, the TCP/TLS parameters shift mid-stream. If the gateway senses an unexpected route deviation while you are navigating confidential project folders, it forces an immediate session expiration as a defensive precaution.
Third, aggressive session-timeout enforcement on foreign ASNs. Corporate IT security teams often configure policies that permit domestic staff 8-to-12-hour session lifespans, but enforce aggressive 5-minute re-authentication thresholds on traffic originating from overseas autonomous system numbers (ASNs) unless the session proves sustained route consistency.
## Why Generic Consumer VPNs Make the Session Loop Worse
Toggling on a standard consumer VPN seems like an obvious way to bring your connection "back home," but generic consumer VPN architecture is fundamentally misaligned with enterprise identity systems.
The core business model of popular commercial VPNs relies on massive, oversaturated server farms. Their infrastructure balances load dynamically by shifting client connections between dozens of different physical blades or IP ranges within the same city.
For streaming movies or browsing news, dynamic load-balancing is invisible. For ProjectWise Web, it is catastrophic:
- Rapid IP churn: A consumer VPN app might rotate your public IP address slightly every few minutes, or route API polling calls and WebSocket streams through different egress gateways in its cluster. Every time the IP rotates, Bentley’s identity gate sees a token used from a brand-new IP and revokes it, sending you back to the login screen.
- High-reputation risk scores: Consumer VPN nodes host thousands of simultaneous users, many of whom may be running scrapers, bots, or unauthorized traffic. Enterprise firewalls subscribe to automated threat intelligence feeds. When your engineering login originates from an IP block flagged for high abuse velocity, the IdP marks the session as high-risk and triggers continuous step-up authentication.
- Broken persistent WebSockets: Viewing large CAD models and synchronization status in ProjectWise Web requires stable, persistent bi-directional communication channels. Oversubscribed consumer servers frequently reset idle TCP sockets, severing the keep-alive loop and tricking the web app into believing you have disconnected.
To do serious engineering work from abroad, you don’t need an entertainment tool with server locations in ninety countries. You need an egress route that delivers absolute IP stickiness, clean reputation, and consistent transport state.
## What an Engineer Needs to Stop the Authentication Loop
When you need to review construction deliverables, sign off on submittals, or access ProjectWise design environments outside the country, evaluate your VPN by these criteria:
### 1. Strict IP Stickiness
Your connection must maintain a single, unvarying public IP address throughout the entire duration of your workday. It must never load-balance individual browser sockets across multiple egress endpoints or switch IPs mid-session.
### 2. Clean, Low-Noise Egress Nodes
The egress endpoint must not be an overused, public proxy hub saturated with automated traffic. A quiet, enterprise-friendly server range ensures corporate security filters and Microsoft Entra ID conditional access evaluate your session as low-risk.
### 3. Transparent TLS and Header Integrity
The network tunnel must cleanly encapsulate all outbound TCP traffic without injecting non-standard proxy certificates, altering headers, or breaking the cryptographic trust chain required for seamless SSO federation.
### 4. Low-Jitter Connection Persistence
Handling heavy vector geometry, DGN references, and live document state requires rock-solid network stability. Low-jitter transit prevents micro-disconnects that cause the web application to lose its place in the project directory.
## Where ONLYDOGSVPN Fits for Remote Infrastructure Teams
This is where ONLYDOGSVPN serves a dedicated, practical function for traveling engineers, technical consultants, and field managers who cannot afford to waste half their day fighting login screens.
Rather than cluttering its platform with consumer privacy gimmicks, ONLYDOGSVPN focuses on disciplined, resilient routing engineered specifically to survive restrictive travel internet and preserve mission-critical web application sessions.
For engineers battling ProjectWise Web session loops overseas:
- Persistent Egress Paths: ONLYDOGSVPN locks your outbound traffic to a stable, dedicated egress route. By ensuring your IP address never changes while you are working, it stops the constant token-revocation triggers that cause the endless session expired loop.
- Clean Route Reputation: Because its network is maintained for stable professional use rather than mass abuse, its server nodes avoid the automated blacklists that flag corporate SSO sessions as suspicious.
- Resilient Protocol Tunneling: It maintains persistent, low-jitter tunnels over volatile hotel Wi-Fi, site-trailer connections, and foreign cellular hotspots, keeping your ProjectWise WebSockets and background syncs intact.
- Straightforward Deployment: Whether you are running a company-approved Windows workstation or a field laptop, it connects in seconds without fragile manual configuration or complex registry changes.
It turns an erratic overseas connection into a dependable, domestic-grade pipeline, allowing Bentley’s identity services to verify your session once and leave you alone to do your work.
## What a VPN Cannot Fix
To keep your troubleshooting realistic, recognize the boundaries of what network routing can accomplish:
- Explicit Device Compliance Blocks: If your enterprise IT department mandates that ProjectWise Web can only be accessed from laptops with an active Microsoft Intune compliance certificate, a corporate Zscaler client running, or specific BitLocker encryption keys, a VPN cannot substitute for a non-compliant machine.
- Revoked Project Permissions: If your Bentley user account has had its Bentley IMS role unassigned, its license expired, or your access to a specific ProjectWise Connected Project removed by the administrator, fixing your network will not grant you file permissions.
- Browser Cache and Cookie Desynchronization: If you have been caught in a login loop for an hour, your browser is likely holding a chaotic tangle of half-valid OAuth tokens, stale cookies, and failed redirection URLs. Always clear your browser cache or test in a clean Incognito/Private window after establishing a new connection.
If your corporate credentials are valid and your laptop is compliant, but the web interface simply refuses to keep you logged in over foreign Wi-Fi, the root cause is network IP instability tripping enterprise token defenses.
## Field Protocol for Stable ProjectWise Access Abroad
Before you attempt to open your project folders on unfamiliar networks:
1. Connect to ONLYDOGSVPN Before Opening the Browser: Establish your secure, sticky connection to your home region first. Opening ProjectWise only after your egress route is anchored prevents your browser from establishing session cookies across mismatched network interfaces.
1. Launch a Clean Incognito/Private Browsing Window: This ensures you start with zero expired tokens, clean localStorage, and fresh authentication headers.
1. Complete the SSO and 2FA Challenge: Complete your multi-factor approval cleanly. The sticky IP ensures the token received from the identity provider matches the token used across every subsequent ProjectWise sub-domain.
1. Keep Background Cloud Backups Paused: If you are working on massive local CAD exports, pause background cloud syncs (like OneDrive or Dropbox) so they do not saturate your upstream bandwidth and induce packet jitter while browsing live models.
Infrastructure projects operate on tight margins and unforgiving deadlines. With a clean, stable network tunnel, you can check out your files, complete your reviews, and keep the design team moving forward no matter which site office you are working from.