VolnaLink VPN

OpenVPN — how it works

OpenVPN appeared in 2001 and for two decades became what people mean by "VPN" by default. It still runs in thousands of corporate networks — and there are reasons for that, just as there are reasons why new services increasingly choose something else.

The short answer

OpenVPN is an open protocol that builds an encrypted tunnel on top of the OpenSSL library. It works over UDP or TCP on any port. It is reliable and proven, but bulky and easily recognized under traffic analysis.

How the connection is built

  1. The client contacts the server and begins a TLS handshake — the same mechanism as HTTPS.
  2. The parties verify each other: the server presents a certificate, the client presents a certificate or a login and password.
  3. Encryption algorithms are negotiated and session keys are generated.
  4. A virtual network interface comes up, and traffic goes into the tunnel.

Keys are refreshed periodically: even if one session key is compromised, it only opens a small stretch of the exchange.

UDP or TCP

A practically important fork.

  • UDP — the default mode. Faster, because it does not resend lost packets: the protocol inside the tunnel handles that.
  • TCP — the fallback option. It works where UDP is closed and passes through most proxies. But you end up with "TCP inside TCP": both layers start recovering losses at the same time, interfere with each other, and on a poor connection the speed drops more than you would expect. The phenomenon is known as TCP meltdown.

Hence the rule: UDP by default, TCP only when nothing else gets through.

Try it on your device

8 hours free, no card required. Full access to all servers.

Strengths

  • Open source and two decades of independent review.
  • Works on any port, including 443 — the same one as HTTPS.
  • Supported almost everywhere, including routers.
  • Flexible configuration: routes, DNS, access rules.

Weaknesses

  • Size. Hundreds of thousands of lines of code together with dependencies. A full audit is an expensive task.
  • Speed. User space and heavy per-packet processing put it noticeably behind WireGuard.
  • Recognizability. Even on port 443 the OpenVPN handshake differs from ordinary HTTPS. Where traffic is analyzed deeply, this is visible.

Why "works on 443" is not the same as disguise

A common misconception. Port 443 is indeed used by HTTPS, and a connection on it does not look suspicious by port number. But when the handshake content is analyzed, OpenVPN differs from browser TLS. Protocols like VLESS Reality solve exactly this problem, while changing the port does not.

Where OpenVPN still fits today

Corporate networks where compatibility and fine-grained access configuration matter. Connecting to equipment that supports nothing else. Scenarios where no one filters the traffic and the task is simply a secure channel.

Why it is not in VolnaLink

For the networks the service is designed for, recognizability matters more than compatibility. We use VLESS Reality, Trojan and Hysteria 2; the app picks the suitable option on its own.

Ready to connect?

Try VolnaLink VPN free for 8 hours without a card, or pick a plan right away.

FAQ

Yes. It uses proven cryptography, is open and has been reviewed many times. Its weak spot is not the strength of the encryption but the recognizability of the traffic and performance.
UDP by default: it is faster. TCP only if UDP does not get through — on a poor connection the TCP mode noticeably loses speed because two retransmission mechanisms overlap.
Only simple filtering that looks at the port number. When the content is analyzed, the OpenVPN handshake differs from browser TLS, and changing the port does not change that.
OpenVPN is more flexible and compatible with almost everything, WireGuard is noticeably faster and more compact. Both are recognizable under traffic analysis.
No. The service runs on VLESS Reality, Trojan and Hysteria 2.