Gert Doering <[email protected]> writes:

> On Thu, Mar 19, 2026 at 10:12:53AM -0400, Greg Troxel wrote:
>> I would also like the TLS connection from openvpn to appear to any
>> networks in between just like web traffic, at least until you look at
>> timing and data sizes.  I am finding that many wifi networks purportedly
>> for customer convenience at businesses are blocking openvpn's udp/1194.
>
> OpenVPN TCP is not "looks like web traffic TLS" and will never be.

Thanks.  My wording was not careful enough.   I did not mean to ask to
change the normal mode.   I was expressing that for me, one of the main
uses is to be able to use a network when various things are blocked, and
that I am frequently encountering not just filtering of 1194/udp, but
apparently everything except 80/443.

I would like to have a vpn server on machines that are already running
nginx on 443.

So therefore it would be nice if openvpn had a mode where it could
connect via an nginx reverse proxy somehow, that did not demand a
particular place in the web namespace, or to be primary on the port.

> The feature request to "run openvpn via a https proxy" has been voiced
> here and there, but nobody really felt like implementing it.

Are you simply saying "nobody's done it yet" or is there some kind of
philosophical or other objection to adding things  like that, for
getting around blocking?

Sooner or later I will be able to report back on how openvpn on just 443
works in blocked networks.  I checked my notes and of 5 fairly-blocked
networks, 4 of them blocked 1194/udp, and those 4 also blocked
submission, imaps, xmpp, and Tor (over 443!).


_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to