- Transport
- UDP / TCP
- Protocol reference
- Tunnel protocol
- Address scope
- Current reference
How the connection works
OpenVPN supports UDP and TCP transports. Certificates, cipher negotiation, routing and platform DNS integration are distinct parts of a deployment. Consult the manual for the actual Community version rather than mixing it with Connect or Access Server instructions.
Configuration checkpoints
- Match the configuration to the deployed OpenVPN Community version. Product instructions for Connect or Access Server do not automatically apply to Community.
- Verify the server identity, certificate chain and negotiated data-channel settings. Do not solve a certificate failure by disabling server verification.
- Identify UDP or TCP transport, full or selected routes, and how the actual client applies DNS. Save a redacted client log before changing these settings.
Verify the traffic path
- Check IPv4 and IPv6 routes separately. A route for one address family does not demonstrate coverage of the other.
- Check the resolver used by the operating system and by applications that select their own DNS service. A public DNS lookup on this site does not test your device for DNS leaks.
- Observe a controlled disconnect on your own device. Protocol support does not establish a client kill switch or application-specific routing policy.
Diagnose a connection problem
Separate endpoint reachability, authentication, route selection and DNS resolution. Record the client version and the exact error; change one setting at a time. A handshake with no working traffic often needs route or resolver investigation, while an authentication error needs credentials or certificate checks.
Scope and limitations
Choose settings for the network and platform. TCP is not automatically safer, and protocol support alone does not establish service speed or leak protection.
This page explains a mechanism and a verification approach. It contains no original speed, regional-access or leak measurements. Throughput depends on the implementation, device, path and server; a protocol name cannot identify a universal winner.