OpenVPN appeared in 2001 and for two decades became what people mean by "VPN" by default. It still runs in thousands of corporate networks — and there are reasons for that, just as there are reasons why new services increasingly choose something else.
The short answer
OpenVPN is an open protocol that builds an encrypted tunnel on top of the OpenSSL library. It works over UDP or TCP on any port. It is reliable and proven, but bulky and easily recognized under traffic analysis.
How the connection is built
- The client contacts the server and begins a TLS handshake — the same mechanism as HTTPS.
- The parties verify each other: the server presents a certificate, the client presents a certificate or a login and password.
- Encryption algorithms are negotiated and session keys are generated.
- A virtual network interface comes up, and traffic goes into the tunnel.
Keys are refreshed periodically: even if one session key is compromised, it only opens a small stretch of the exchange.
UDP or TCP
A practically important fork.
- UDP — the default mode. Faster, because it does not resend lost packets: the protocol inside the tunnel handles that.
- TCP — the fallback option. It works where UDP is closed and passes through most proxies. But you end up with "TCP inside TCP": both layers start recovering losses at the same time, interfere with each other, and on a poor connection the speed drops more than you would expect. The phenomenon is known as TCP meltdown.
Hence the rule: UDP by default, TCP only when nothing else gets through.
Strengths
- Open source and two decades of independent review.
- Works on any port, including 443 — the same one as HTTPS.
- Supported almost everywhere, including routers.
- Flexible configuration: routes, DNS, access rules.
Weaknesses
- Size. Hundreds of thousands of lines of code together with dependencies. A full audit is an expensive task.
- Speed. User space and heavy per-packet processing put it noticeably behind WireGuard.
- Recognizability. Even on port 443 the OpenVPN handshake differs from ordinary HTTPS. Where traffic is analyzed deeply, this is visible.
Why "works on 443" is not the same as disguise
A common misconception. Port 443 is indeed used by HTTPS, and a connection on it does not look suspicious by port number. But when the handshake content is analyzed, OpenVPN differs from browser TLS. Protocols like VLESS Reality solve exactly this problem, while changing the port does not.
Where OpenVPN still fits today
Corporate networks where compatibility and fine-grained access configuration matter. Connecting to equipment that supports nothing else. Scenarios where no one filters the traffic and the task is simply a secure channel.
Why it is not in VolnaLink
For the networks the service is designed for, recognizability matters more than compatibility. We use VLESS Reality, Trojan and Hysteria 2; the app picks the suitable option on its own.