VPN Protocols

    OpenVPN for VPN Resellers: UDP and TCP

    OpenVPN is a mature, widely supported VPN protocol that can run over UDP or TCP. It is available in all ready-made VPNclient apps and remains a dependable choice when compatibility and flexibility matter.

    Transport
    UDP or TCP
    Apps
    all VPNclient platforms
    Track record
    mature and widely used
    Managed VPN infrastructure
    Included VPNclient apps
    REST API
    Pay only for active accounts
    21+ years in infrastructure

    What Is OpenVPN?

    OpenVPN is an open source VPN protocol that secures traffic with TLS-based key exchange. It has been in wide use for many years and is supported by a large ecosystem of clients and operating systems.

    Its main practical strength is flexibility. OpenVPN can run over UDP, which is usually the more efficient option, or over TCP, which can help on networks where UDP traffic is blocked or unreliable. Running over TCP adds overhead, so UDP is generally preferred when it works.

    UDP and TCP modes

    Customers can switch transport when a network blocks or degrades UDP.

    Broad compatibility

    OpenVPN is supported across desktop, mobile and TV platforms.

    Proven and flexible

    A long track record and many configuration options make it a dependable fallback.

    When OpenVPN Is a Good Choice

    • Networks where WireGuard's UDP traffic does not get through: try OpenVPN TCP.
    • Customers or teams who already know and trust OpenVPN.
    • A reliable second option alongside WireGuard in every app.

    Practical Limitations

    • Usually more overhead than WireGuard, especially in TCP mode.
    • Standard OpenVPN is not designed to disguise VPN traffic. Some networks can still identify and block it.
    • TCP mode can feel slower on unstable connections because of TCP-over-TCP retransmissions.

    OpenVPN Availability

    OpenVPN UDP and TCP are included in all ready-made VPNclient apps.

    OpenVPN availability in VPNclient apps
    PlatformOpenVPN
    Windows app Available
    macOS app Available
    iOS app Available
    Android app Available
    Linux app Available
    Android TV / Fire TV app Available

    Download links for every platform are on the white label apps page. Setup help is in the Help Center.

    OpenVPN in a White Label VPN Offering

    Offering OpenVPN next to WireGuard gives your support team a simple answer when a customer cannot connect: switch protocol, or switch OpenVPN to TCP. Both are already in the included VPNclient apps, so there is nothing extra to build.

    OpenVPN vs Stealth: Stealth is not a different encryption protocol. In the Windows and macOS apps, Stealth runs a local OpenVPN connection and pushes it through stunnel. Regular OpenVPN connects directly and is available on every VPNclient platform.

    OpenVPN FAQ

    Does VPNresellers support OpenVPN over both UDP and TCP?

    Yes. OpenVPN UDP and TCP are available in the ready-made VPNclient apps for Windows, macOS, iOS, Android, Linux and Android TV / Fire TV.

    Should customers use OpenVPN UDP or TCP?

    Start with UDP, which is usually more efficient. Switch to TCP if UDP traffic is blocked or unreliable on the network the customer is using.

    What is the difference between OpenVPN and Stealth?

    Stealth is not a separate encryption standard. It runs an OpenVPN connection locally and pushes it through stunnel, which can help on some networks where many ports are blocked. Stealth is available only in the Windows and macOS apps; regular OpenVPN is available on all VPNclient platforms.

    Is OpenVPN better than WireGuard?

    Neither is best for every situation. WireGuard is our recommended default for everyday use, while OpenVPN adds TCP support and broad compatibility. Offering both gives customers a practical fallback.

    Background reading: OpenVPN 2.6 manual

    Build with VPNresellers

    Offer OpenVPN Without Running Servers

    OpenVPN UDP and TCP are included in the ready-made VPNclient apps, on managed VPNresellers infrastructure.

    Read the VPNresellers API documentation →