tcp vs udp configs, which one?

Posted: Fri Jul 06, 2018 3:17 pm
by DVF
The setup guides show connecting to the udp configs so I've been doing that. Is there any reason I should use the tcp config? What's the difference between them? When should I use each one? Is one faster than the other? Does one offer more protection? Does the .onion thing still work? etc..

Posted: Wed Oct 31, 2018 1:08 pm
by df
UDP is always preferred over TCP when used with OpenVPN.
The reliability that TCP offers that UDP doesn't isn't relevant in this context since most of your pre-encrypted traffic will already be using TCP (WWW, email, etc.), so any retransmitting of packets or integrity checking would be done at the OS level of your machine, it's just wrapped up in a UDP packet when OpenVPN encrypts it.
Plus, OpenVPN does it's own integrity checks and retransmitting of packets.
More technical info about why TCP OpenVPN is a bad idea is @
That page talks more about PPP, but OpenVPN could apply to those issues as well.

The only reason we also offer TCP OpenVPN is for those who are behind firewalls that are so restrictive that they don't allow UDP OpenVPN out. There's also a few cases where the ISP mangles or otherwise throttles UDP OpenVPN traffic, but not TCP OpenVPN traffic.

And yes, the .onion thing still works. All of the server-side Tor instances are running the latest version of Tor, which means those new v3 .onion's described @ ... tGenOnions can also be transparently accessed while on cryptostorm.
And just for fun, we've also added our own v3 .onion's to the list @

Posted: Sat Nov 17, 2018 11:58 pm
by DVF
Thanks, I'll delete all the TCP ones then.