If TCP only lives in a Zendesk macro, you do not have a fallback. You have a rumor.

OpenVPN TCP Fallback on a White-Label Stack

When UDP dies, OpenVPN TCP 443 is either a named mode in the app or a 2am support paste. Operator copy, defaults, and screenshots — not a consumer TCP-versus-UDP primer.

KloxVPN Team
22 min readPublished 2023-02-12Updated 2024-04-18
OpenVPN TCP Fallback on a White-Label Stack
If TCP only lives in a Zendesk macro, you do not have a fallback. You have a rumor.

UDP dies in hotels, schools, and offices more often than founders admit on a sales call. The handshake hangs. The user stares at Connecting. Your brand is on the icon. Someone has to tell them what to do next.

There are two honest ways to ship OpenVPN over TCP, usually on port 443. One is a product story: a labeled mode in settings, helper text, a screenshot that shows the control, an onboarding line that says restricted networks exist. The other is an escape hatch: nothing in the UI a tired person can find, and an agent who pastes switch to OpenVPN TCP at 2am. Both can keep a paying user online. They are not the same brand.

This is not the consumer primer on TCP versus UDP. That piece already exists. Speed tables, TCP-over-TCP stalls, when a home fiber user should stay on UDP — go read it if you need the physics. This is not inherit-versus-own as a stack diagram. You already know the client can speak protocols you did not write. This is not the UDP-blocks article, which is the filter and the in-app error. Here the question is narrower: when UDP is dead, did you offer TCP as something a user can choose, or did you hide it until support is awake?

A VPN is a tunnel. Wikipedia's virtual private network page will not tell you what to put on the protocol picker. RFC 8446 is TLS 1.3 for the web. OpenVPN on TCP 443 is not TLS 1.3. Saying the traffic looks like HTTPS because of the port is a half-truth you should not print as undetectable.

Klox ships WireGuard, OpenVPN, OpenConnect, and Shadowsocks. That is the set for this article. I will not invent IKEv2, Shadowsocks, OpenConnect, or a stealth wrapper so your comparison table looks thicker. If a white-label packet adds protocols, confirm it on a call. Consumer Klox is five devices, yearly from $2.83 a month, seven-day money-back. Your brand sets retail and the words on the glass.

I have a bias. I would rather a slightly uglier settings screen than a pretty screenshot that omits the only control that works on a campus AP. You can disagree. You cannot disagree in the app and agree in the macro. That split is how one-star reviews get written.

Related reading: Hystart: Not a VPN Setting and White-Label VPN and Vs Building From Scratch. White-Label VPN and Vscode on a branded site and White-Label VPN and Vscodium on a branded site. What is a VPN? and Download KloxVPN.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

TCP 443 is a product, not a ticket paste

A fallback that only exists in a helpdesk article is not a fallback for the user who never opens Help. They retry WireGuard. They toggle airplane mode. They refund. The agent who would have saved them is asleep, or the brand never hired one.

Name the job. Restricted network. Hotel Wi-Fi after the splash page. School filter that allows the web and hates UDP. Office that inspects everything except 443 because payroll still has to load. TCP on 443 is how OpenVPN often survives those rooms. UDP is still the right default when the path is open. Default and fallback are two settings. Treat them as two settings.

If you refuse to put a control in the app, say that out loud in the launch checklist. Then staff the inbox like a product. Most founders do neither. They ship WireGuard-only screenshots and a buried OpenVPN toggle, then act shocked when tickets say the VPN does not work in the Marriott.

WireGuard versus OpenVPN
Klox ships four protocols: WireGuard by default, OpenVPN when UDP fails.

    How to read this page

  1. 1Skim the seating / order diagram.
  2. 2Do the numbered steps once on your real network.
  3. 3Use the FAQ if a sentence was too long.
  4. 4Follow one related article — not ten tabs.
Same OpenVPN TCP listener. Three ways a brand treats it. Not a Klox SLA.
PostureWhat the user seesWhat support doesWhat breaks
Product storyNamed mode: Restricted network / OpenVPN TCPPoints at the control; rarely pastes stepsCopy overclaims stealth; TCP feels slow on bad Wi-Fi
Quiet defaultAutomatic tries WireGuard then OpenVPN TCPAlmost nothing if Auto worksUser cannot tell which protocol stuck; tickets stay vague
Escape hatchWireGuard only in the UI they noticePaste: Settings, OpenVPN, TCPAfter-hours refunds; reviews that say it never connects

If TCP only lives in a Zendesk macro, you do not have a fallback. You have a rumor.

— KloxVPN operator notes

Cloudflare Learning: What is a VPN?

Wikipedia: Virtual private network

IETF RFC 8446 (TLS 1.3)

NordVPN: TCP or UDP (competitor specimen)

Automatic is a product too

Auto that tries WireGuard, then OpenVPN UDP, then OpenVPN TCP can be adult. It is still a product decision. Print what Auto means in one sentence under the picker. If Auto is a black box, every timeout ticket starts with I already tried Automatic. You cannot debug a slogan.

Do not sell TCP as faster

TCP 443 is the path that still opens. It is not a speed SKU. The consumer primer already covered TCP-over-TCP. Your white-label site should not put Turbo next to TCP. I have seen it. It is a lie with a rocket emoji.

What you inherited versus what you named

The platform can listen on TCP 443. That is inheritance. The string Restricted network is ownership. Mix those up and marketing will announce Stealth Protocol 2.0 for a port bind you did not invent.

Ask, in writing, whether OpenVPN TCP is actually up on the nodes your users hit. A client toggle that points at a dead listener is cruelty. Confirm ports. Confirm that WireGuard UDP is the default. Confirm that OpenVPN UDP exists if you mention it. Then write names that match.

I do not need you to become a protocol author. I need you to stop renaming TCP 443 as military-grade obfuscation. The inherit-versus-own essay is the two-column list. This paragraph is the one row that belongs on the homepage: we offer OpenVPN over TCP when UDP will not pass.

Consumer Klox versus a custom packet

Klox consumer apps speak WireGuard, OpenVPN, OpenConnect, and Shadowsocks. This article stays inside that pair. If your white-label contract adds other protocols, do not paste this post into a store listing as if those protocols shipped. Confirm the matrix per OS.

The operator does not write your settings labels

Unless the SOW says they own copy, the labels are yours. A platform default of Protocol: OpenVPN (TCP) is a starting string, not a brand. Translate it. Shorten it. Do not invent physics.

A labeled mode users can find

Put the control where a person with wet hands in an airport can find it. Settings, connection, protocol. Not a nested Advanced that looks like a developer menu. Travelers do not feel like developers at 23:40.

I like plain names. OpenVPN (TCP). Restricted Wi-Fi. If you need a short label, the helper text does the work: Use this when the VPN will not connect on hotel or school networks. Helper text is not optional. A toggle without a sentence is a future macro.

Do not hide TCP behind a support PIN or a secret gesture. That is how you create a caste of users who were taught the trick in a Facebook group. The rest refund.

White-label branding versus the VPN tunnel
Your logo is packaging. The tunnel is still WireGuard, OpenVPN, OpenConnect, and Shadowsocks.

Onboarding can mention it once

One line in first-run: If you cannot connect, try OpenVPN TCP in settings. Then stop. A three-screen lecture on transports is how people skip everything. The UDP-blocks post is the error string when they fail. Onboarding is the hint that a second mode exists.

Remember the last successful mode

If TCP saved them at the hotel, do not reset to WireGuard at 06:00 because a job woke the phone. Sticky last-good is kindness. Sticky TCP forever on home fiber is how you teach them the app is slow. Home should prefer WireGuard again when UDP works. That is product, not a daemon Easter egg. Confirm what the client actually does. Do not promise sticky if it is not sticky.

The escape-hatch brand

Some brands keep the UI clean and accept the ticket load. That can be rational if your buyers are home fiber and a campus is a rounding error. Say the bet. Measure switched to OpenVPN tickets per week. If that count is not boring, your clean UI is a tax on the inbox.

Escape-hatch copy in email should still match the glass. If the control is named OpenVPN and the macro says stealth mode, you trained them to search for a button that does not exist. I would rather an ugly label than two names for one socket.

After-hours is the tell. If your only path to TCP is a human, you are closed when the hotel is open. Hotels do not wait for your morning stand-up.

Macros are still copy

Write the paste as if it will be screenshotted in a review. Numbered steps. The exact words on the screen. Platform notes: iOS versus Android versus Windows. Five devices means five places the user might be stuck. The macro that says open the app is not a macro.

Do not upsell TCP

TCP is not a paid add-on. Charging extra for the only mode that works on a filter is how you get a regulator letter and a deserved one. If you ship OpenVPN, TCP is part of the subscription they already bought.

Copy that does not say undetectable

Forbidden: undetectable, invisible to firewalls, bypass any block, military-grade stealth, guaranteed on every hotel. Port 443 helps against dumb port filters. Deep inspection can still fingerprint VPN. You do not have a Klox spec that says otherwise. I will not mint one so your ads feel brave.

Allowed: OpenVPN over TCP, often on port 443, is the usual fallback when WireGuard cannot complete a handshake. It can be slower. Use it when UDP is blocked. That paragraph is enough for a help article and a settings footer.

NordVPN's public TCP-versus-UDP explainer is a competitor specimen. Read how they frame transport. Do not clone their brand voice onto an ISP add-on or a campus SKU. Your buyer may be a night auditor. Your string has to survive them.

Store listings

Apple and Google have seen every bypass censorship claim. If your screenshot caption says Works on any Wi-Fi, you invited a rejection and a user who will test the claim in China, on a school filter, and in a courtroom. Say WireGuard, OpenVPN, OpenConnect, and Shadowsocks. Say TCP for restricted networks if you actually ship the control. Stop.

Homepage versus settings

The homepage can lead with WireGuard. Settings must still admit OpenVPN TCP exists. I have watched brands bury TCP because it sounded old. Old is what still connects. Pride is a ticket.

Default order: WireGuard, then OpenVPN, then TCP

A sane order for a consumer-shaped white-label app: try WireGuard first. If the handshake dies, offer OpenVPN. If OpenVPN UDP dies, offer TCP. You can automate that ladder. You can make the user climb it. What you cannot do is skip naming the rungs.

I am opinionated about the first hop. WireGuard as commonly deployed is UDP. It is the right default on home broadband and most phones on LTE. OpenVPN TCP as the global default makes every review about speed. Do not punish the majority to save the hotel minority, and do not pretend the hotel minority does not exist.

If Auto is on, log which protocol won, at least on the device. Support that cannot see last protocol is guessing. Guessing becomes reinstall. Reinstall does not change a UDP filter.

Do not invent a fourth protocol in the ladder

This post's ladder is WireGuard, OpenVPN, OpenConnect, and Shadowsocks. No Shadowsocks chapter. No OpenConnect surprise. If your packet includes more, that is a sales conversation, not a sentence I will put in your mouth.

MTU and TCP are different tickets

A stall on TCP might be loss plus TCP-over-TCP. It might be MTU. Do not let agents mix those macros. The consumer UDP/TCP guide can train them. Your white-label runbook should still split: cannot connect versus connects and crawls.

Port 443 is not TLS 1.3

Port 443 is where browsers speak HTTPS. OpenVPN can bind there so a lazy firewall lets it through. The bytes inside are still OpenVPN. RFC 8446 describes TLS 1.3. Citing RFC 8446 as if it were your VPN protocol is a category error. I have seen it in white papers partners wanted to publish. Strike it.

You may say TCP 443 is often allowed because blocking it breaks the web. You may not say therefore we are indistinguishable from Chrome. Simple port filters are not all filters. Corporate SSL inspection is a different animal. The UDP-blocks article is where I talk about the office more. Here: do not print camouflage claims you cannot demonstrate.

What a new hire should read

Cloudflare's VPN explainer and Wikipedia's VPN page are enough for a first week. Then show them the settings screen. Then have them fail WireGuard on a guest network and succeed on OpenVPN TCP. If they cannot do that in your own office, you do not have a fallback. You have a slide.

DPI honesty

If a buyer asks whether you beat DPI, the answer is not a blog adjective. It is a scoped test and a contract line. Most consumer white-label brands should say we do not promise to defeat inspection. That sentence loses some deals. It saves you from the deals you would lose in week two anyway.

When TCP should stay off the homepage

If your buyers are home ISP add-on customers on fiber, leading with TCP 443 is a self-own. They will hear slow. Keep TCP in settings and in the hotel paragraph of the help center.

If your buyers are campus or travel, TCP can be a homepage bullet. Still do not make it the only bullet. WireGuard remains the default for a reason.

If you do not actually listen on 443, it must stay off every page. I am repeating myself because someone will publish the blog post before the node config.

ISP and hotel SKUs

An ISP add-on might never leave the home prefix. TCP still matters when a teenager takes a phone to school. Five devices means the account leaves the house. The hotel amenity article is a different product. This is the consumer-shaped brand whose users travel without telling you.

Gaming cafes and UDP

A cafe that already allows game UDP may allow WireGuard. A cafe that only allows web may not. Do not copy cafe copy from a different post and stamp TCP on it without asking what the floor network permits.

Macros that match the glass

Write three macros and freeze the nouns. Cannot connect: captive portal first, then WireGuard, then OpenVPN UDP, then OpenVPN TCP. Connects but slow: leave TCP, try WireGuard, do not promise Mbps. App has no protocol picker: tell the truth and file a product bug, do not invent taps.

Match kill-switch copy if the user has fail-closed on. TCP will not save a machine that blocks all traffic until a handshake that cannot start. Point at the kill-switch article. Do not debug transports while the switch is strangling the portal.

Hours: if you send users to TCP only via chat, publish hours next to the help article. A 24/7 hotel and a 9–5 inbox is a refund machine.

Screenshots in the help center

Shoot the real build, not a Figma of a picker you meant to ship. iOS and Android will not match. Update the PNGs when you rename the mode. Stale screenshots are how users say your help is fake.

Language

If you sell in more than one language, translate the protocol names with a glossary. OpenVPN stays OpenVPN. TCP stays TCP. Restricted network can be localized. Do not let a translator turn TCP into stealth security layer.

Store screenshots and five devices

A family plan with five devices is five chances to hit a filter. The laptop at the office. The phone at the hotel. The tablet at school. The fifth device on home Wi-Fi that never needed TCP. Your screenshot that only shows Connected on a sofa is not a lie. It is incomplete in a way reviewers punish.

You do not need a screenshot of a protocol picker in the first store slot. You do need the picker to exist before you spend on travel keywords. Travel ads plus WireGuard-only UX is how you buy refunds.

Klox consumer is five devices. Your white-label brand may choose another cap. The point stands: device count is how many networks you silently agreed to support.

Router users

A router on OpenVPN TCP can sit behind a filter the phones never see. Document whether your router build includes TCP. If it does not, say so before the Amazon review.

Do not screenshot a protocol you disabled on that OS

Per-platform protocol matrices exist on white-label for a reason. If iOS does not ship OpenVPN in your packet, the iPhone screenshot cannot show it. The inherit article already scolded this. I am scolding it again because TCP is the usual lie.

How to decide before launch

Write a one-page decision. Default protocol. Auto behavior, if any. Where TCP lives in the UI. Exact label. Helper sentence. Help URL. Three macros. Who confirms 443 is open. Who owns store screenshot captions. Who measures weekly TCP tickets.

If you cannot fill that page, you are launching an escape hatch by accident. Accidental hatch is fine for a private beta. It is not fine for ads.

I would pick product story for any brand that mentions travel, campus, or hotel on the site. I would pick quiet Auto plus a visible picker for a general consumer brand. I would pick hatch-only only if the buyer never leaves a known network and you are willing to say that. Few VPN brands are willing to say that. They still ship hatch-only. That gap is the review.

Test it yourself

Before launch, fail WireGuard on purpose. Guest VLAN. Phone hotspot that is fine, then a network that is not. If you have never watched OpenVPN TCP save the session, you are shipping folklore.

Refunds when TCP was the answer

If they refunded inside seven days because nobody told them about TCP, that is not a protocol bug. That is a copy bug you paid for. Klox consumer money-back is seven days on first purchase. Your brand may copy that window or not. Either way, a hatch that arrives after the refund is a hatch that did not exist.

QA that proves TCP exists

A settings row is not proof. Proof is a phone on a network that drops UDP, a tap on OpenVPN TCP, and a handshake that finishes. Do that on iOS, Android, and Windows if you ship them. Do it on the same node hostname a customer would pick, not on a lab IP that always allows 443. I have watched brands pass QA on the office fiber and fail on the first hotel.

Record a two-minute clip for the help center. No music. Finger on the picker. Home card showing OpenVPN TCP after connect. That clip is worth more than a protocol white paper. Put the date in the filename so you know when it went stale.

If TCP fails in QA, you do not have a product story. You have a lying toggle. Take the row out until the listener is up. Shipping a dead TCP control is worse than shipping hatch-only, because the user did the thing you asked and still sat in Connecting.

Who signs off

Not marketing. An engineer or an operator who can read a packet capture if it comes to that. Marketing can watch the clip. They cannot declare 443 open because the Figma said so.

After a node change

When you add a region or rebuild images, TCP 443 is the thing that gets forgotten. Add it to the launch checklist next to DNS. The server-placement article is where nodes live. This is the port that has to listen when WireGuard UDP is dead.

Key Takeaways

OpenVPN TCP 443 is how many branded apps survive a network that hates UDP. WireGuard stays the default. OpenVPN stays the adult fallback. Klox does not invent a third protocol in this article to make the sentence prettier.

Decide whether TCP is a named mode, a quiet Auto rung, or a paste. Put the same nouns on the glass, in the store, and in the macro. Do not call it undetectable. Do not cite TLS 1.3 as if it were OpenVPN. Do not hide the control and then blame the hotel.

If you want a branded VPN whose protocol picker you actually own, start from white-label. Five devices. WireGuard, OpenVPN, OpenConnect, and Shadowsocks. A price you set. A seven-day window if you copied Klox consumer, or another window if you did not. UDP will still die somewhere. The only question is whether the user can find TCP without waiting for you to wake up.

Ship a brand whose fallback is on the glass

White-label gives you branded apps on a stack that speaks WireGuard, OpenVPN, OpenConnect, and Shadowsocks. You still write the protocol labels, the default order, and the macros. Klox consumer remains from $2.83 a month with five devices and a seven-day money-back — that SKU is not your settings copy.

See white-label VPN

Frequently Asked Questions

No. RFC 8446 is TLS 1.3 for the web. OpenVPN can use TCP on port 443 so simple firewalls allow it. That is a port choice, not TLS 1.3.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.