Protocol reference

Lightway

A VPN protocol developed by ExpressVPN, with a publicly available core.

Three checks when reading a VPN or proxy protocol: identity and keys, data transfer, and traffic and DNS policy.
Check authentication, data transfer, and traffic/DNS policy separately. VPNs and proxies can cover different traffic; routing and DNS depend on the protocol and client.
Transport
Provider implementation
Protocol reference
Tunnel protocol
Address scope
Current reference

How the connection works

The provider publishes Lightway documentation and describes its client integrations. The protocol core being available for review is different from every application component being open source. Read the implementation and audit scope separately.

Configuration checkpoints

  • Identify the actual ExpressVPN client version and selected transport. A published protocol core is not a complete description of every app component.
  • Check the current Lightway repository and the version covered by each audit. Reports for an earlier C implementation do not automatically establish the scope of a later Rust implementation.
  • Use the platform instructions for protocol selection and network changes. Verify reconnection and traffic behavior on your own device before relying on a provider performance claim.

Verify the traffic path

  • Check IPv4 and IPv6 routes separately. A route for one address family does not demonstrate coverage of the other.
  • Check the resolver used by the operating system and by applications that select their own DNS service. A public DNS lookup on this site does not test your device for DNS leaks.
  • Observe a controlled disconnect on your own device. Protocol support does not establish a client kill switch or application-specific routing policy.

Diagnose a connection problem

Separate endpoint reachability, authentication, route selection and DNS resolution. Record the client version and the exact error; change one setting at a time. A handshake with no working traffic often needs route or resolver investigation, while an authentication error needs credentials or certificate checks.

Scope and limitations

Provider performance claims require independent measurements in the relevant network. Protocol design alone does not establish a universal speed winner or uninterrupted roaming.

This page explains a mechanism and a verification approach. It contains no original speed, regional-access or leak measurements. Throughput depends on the implementation, device, path and server; a protocol name cannot identify a universal winner.