OpenVPN: when WireGuard will not connect

For hotel and office networks that block WireGuard. Slower, and it gets through.

Sign in to download your configuration file, or see plans.

Use WireGuard unless it will not connect. It is faster, and the setup is simpler.

OpenVPN is the fallback. WireGuard only speaks UDP, so a network that blocks UDP blocks it completely — and plenty of hotel, office and public networks do exactly that, often without saying so. OpenVPN can speak TCP, which those networks generally allow.

It is slower. That is the trade, and it is worth it when the alternative is no connection at all.

The difference that catches people out

A WireGuard configuration contains a key and needs nothing else. An OpenVPN configuration asks for your VPN username and password, which are on your account page. The password is shown once when you set it or reset it, so if you do not have it, reset it there first and write it down before you go any further.

1. Get the configuration

On your account:

1. Choose OpenVPN as the protocol. 2. Leave the port on 1194/TCP unless you have a reason not to. It is the one that gets through a network that has blocked WireGuard. 3. Pick a location. 4. Get configuration downloads an .ovpn file.

On ports. There is no TCP 443 on our network, so the classic "make it look like ordinary HTTPS" trick is not available here, and we would rather say so than let you hunt for it. If 1194/TCP is blocked, try 8080/TCP, then 443/UDP — that last one looks like modern web traffic and works where UDP is allowed but WireGuard specifically is filtered.

2. Install a client

  • iPhone / iPad — OpenVPN Connect, free, App Store.
  • Android — OpenVPN for Android (Play Store or F-Droid) or OpenVPN Connect.
  • Windows — OpenVPN Connect or the OpenVPN GUI from openvpn.net.
  • Mac — Tunnelblick (free, open source) or OpenVPN Connect.
  • Linux — sudo apt install openvpn, then sudo openvpn --config veystrix.ovpn.

3. Import and connect

Open the .ovpn file with the client, or use the client's import profile option and choose the file. Then connect, and enter your VPN username and password when it asks. Most clients offer to remember them.

4. Check it worked

Open veystrix.net/tools/ip. It should say you are coming through our network, in the country you picked.

If it does not connect

Try 8080/TCP, then 443/UDP. Download a fresh configuration with the different port. This is the single most effective thing to try, and it is why the port choice is offered at all.

Check the username and password. The most common failure by a wide margin. Reset the password on your account and try again with the new one.

A captive portal is in the way. Hotel and airport networks make you accept terms in a browser before anything else works. Do that first, then connect.

Nothing loads once connected. Usually another VPN or security tool holding the DNS settings. Disconnect the other one and retry.

When to use which

Use it for
WireGuardeverything, unless it will not connect
OpenVPNhotel, office and public networks that block UDP
VLESScountries that filter internet traffic at a national level

If WireGuard fails, try OpenVPN on 1194/TCP. If you are somewhere that blocks VPNs as a matter of state policy, OpenVPN will not help either and VLESS is the answer.

All setup guides Stuck? Ask us