OpenVPN for VPN Resellers: UDP and TCP
OpenVPN is a mature, widely supported VPN protocol that can run over UDP or TCP. It is available in all ready-made VPNclient apps and remains a dependable choice when compatibility and flexibility matter.
- Transport
- UDP or TCP
- Apps
- all VPNclient platforms
- Track record
- mature and widely used
What Is OpenVPN?
OpenVPN is an open source VPN protocol that secures traffic with TLS-based key exchange. It has been in wide use for many years and is supported by a large ecosystem of clients and operating systems.
Its main practical strength is flexibility. OpenVPN can run over UDP, which is usually the more efficient option, or over TCP, which can help on networks where UDP traffic is blocked or unreliable. Running over TCP adds overhead, so UDP is generally preferred when it works.
UDP and TCP modes
Customers can switch transport when a network blocks or degrades UDP.
Broad compatibility
OpenVPN is supported across desktop, mobile and TV platforms.
Proven and flexible
A long track record and many configuration options make it a dependable fallback.
When OpenVPN Is a Good Choice
- Networks where WireGuard's UDP traffic does not get through: try OpenVPN TCP.
- Customers or teams who already know and trust OpenVPN.
- A reliable second option alongside WireGuard in every app.
Practical Limitations
- Usually more overhead than WireGuard, especially in TCP mode.
- Standard OpenVPN is not designed to disguise VPN traffic. Some networks can still identify and block it.
- TCP mode can feel slower on unstable connections because of TCP-over-TCP retransmissions.
OpenVPN Availability
OpenVPN UDP and TCP are included in all ready-made VPNclient apps.
| Platform | OpenVPN |
|---|---|
| Windows app | Available |
| macOS app | Available |
| iOS app | Available |
| Android app | Available |
| Linux app | Available |
| Android TV / Fire TV app | Available |
Download links for every platform are on the white label apps page. Setup help is in the Help Center.
OpenVPN in a White Label VPN Offering
Offering OpenVPN next to WireGuard gives your support team a simple answer when a customer cannot connect: switch protocol, or switch OpenVPN to TCP. Both are already in the included VPNclient apps, so there is nothing extra to build.
OpenVPN vs Stealth: Stealth is not a different encryption protocol. In the Windows and macOS apps, Stealth runs a local OpenVPN connection and pushes it through stunnel. Regular OpenVPN connects directly and is available on every VPNclient platform.
OpenVPN FAQ
Does VPNresellers support OpenVPN over both UDP and TCP?
Yes. OpenVPN UDP and TCP are available in the ready-made VPNclient apps for Windows, macOS, iOS, Android, Linux and Android TV / Fire TV.
Should customers use OpenVPN UDP or TCP?
Start with UDP, which is usually more efficient. Switch to TCP if UDP traffic is blocked or unreliable on the network the customer is using.
What is the difference between OpenVPN and Stealth?
Stealth is not a separate encryption standard. It runs an OpenVPN connection locally and pushes it through stunnel, which can help on some networks where many ports are blocked. Stealth is available only in the Windows and macOS apps; regular OpenVPN is available on all VPNclient platforms.
Is OpenVPN better than WireGuard?
Neither is best for every situation. WireGuard is our recommended default for everyday use, while OpenVPN adds TCP support and broad compatibility. Offering both gives customers a practical fallback.
Background reading: OpenVPN 2.6 manual
Offer OpenVPN Without Running Servers
OpenVPN UDP and TCP are included in the ready-made VPNclient apps, on managed VPNresellers infrastructure.
Read the VPNresellers API documentation →