DarkSpace-Harbinger 11 Posted ... I understand the option is being added in a month or two for most servers, but is it a reliable substitute for my current SSL Tunnel setup? Quote Share this post Link to post
zhang888 1066 Posted ... Depends on the use case and the ISP. Works totally different, and looks very different in traffic monitoring devices and software.One is high-entropy data (tls-crypt over UDP usually) while SSL looks and behaves like a regular connection to an HTTPS site, TCP on 443 with proper TLS handshake,which is visible on monitoring devices (handshake part) but cannot be determined as a VPN connection based just on that. Test both and see what works better for you. If both options are available, check which gives you better performance and stick to it. 2 iampd and itsmefloraluca reacted to this Quote Hide zhang888's signature Hide all signatures Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees. Share this post Link to post
Bitmann 0 Posted ... tls-crypt actually encrypts the entire tunnel using a TLS key, making it so that layer-7 DPI cannot identify an OpenVPN handshake or tunnel as such.An SSL tunnel goes one step further than this and makes the OpenVPN tunnel "look like" a https-enabled website or service. Quote Hide Bitmann's signature Hide all signatures 2018 best year for My Crypto Project Ho!ho!ho! Share this post Link to post
go558a83nk 362 Posted ... tls-crypt actually encrypts the entire tunnel using a TLS key, making it so that layer-7 DPI cannot identify an OpenVPN handshake or tunnel as such.An SSL tunnel goes one step further than this and makes the OpenVPN tunnel "look like" a https-enabled website or service. The hope is that tls-crypt UDP sessions can defeat firewalls yet give better performance than the TCP tunnel required with SSL. But, I haven't seen anybody post about their experience in China with tls-crypt yet. Quote Share this post Link to post
amires 10 Posted ... I live in a country which the government censors the internet. Recently they started blocking all kinds of VPN. None of the AirVPN's UDP/TCP/SSH/SSL protocols works anymore however tls-crypt is working perfectly. 2 Staff and go558a83nk reacted to this Quote Share this post Link to post
DUONG NAM PHUONG 0 Posted ... Sorry for being late. I have two VPN servers: 1. VPN server #1 (tls-crypt): I setup a VPN server on my Asus router with tls-crypt enabled. 2. VPN server #2 (no tls-crypt): This is a VPN server the company gave me for teleworking. I can connect to those two from many places. I want to check whether they can be connected from China. It was difficult for me to have an IP in China to test this. Luckily, Astrill VPN has one China IP. My PC connect to it and share a Wifi hotspot to a mobile device. The "OpenVPN Connect" app on the device can establish a connection to #1, but not #2. I am not 100% certain that whether being no tls-crypt is the cause. I think I would edit the #1 to "no tls-crypt" and try it again. If #1 cannot be connected after then tls-crypt would is crucial. However I don't dare to make the Great Firewall know the IP of #1 serves as a VPN server. Quote Share this post Link to post
zsam288 36 Posted ... I don't know the tech of wireguard, but how does it work there? Quote Share this post Link to post
SurprisedItWorks 49 Posted ... It doesn't. Wireguard does not use TLS. Quote Share this post Link to post