Skip to main content
Connection Drops during Rekeying using TCP with OpenVPN c... - KH2183

Frequently Asked Questions

Connection Drops during Rekeying using TCP with OpenVPN connections
 
  1. What are connection drops during rekeying?

    Connection drops during rekeying occur when the VPN connection is interrupted during the key update (rekeying). This causes traffic to not be processed for a short period, which is particularly problematic for stable connections such as video conferences.

  2. Why does the problem occur during rekeying?

    The problem arises because, when using TCP with OpenVPN, the firewall does not accept any traffic during the rekeying process. This leads to an interruption of the traffic.

  3. What impact do connection drops have on a video conference?

    During a video conference, connection drops during rekeying can result in a complete interruption of the traffic. This causes the connection to break, disrupting or even ending the video conference.

  4. Why is TCP susceptible to this problem?

    According to OpenVPN, TCP is problematic for VPN connections because it is more sensitive to traffic congestion during network disruptions or the rekeying process. OpenVPN therefore recommends using UDP instead, as it can better handle rekeying processes.

  5. What solution does VPN Tracker provide for the problem?

    VPN Tracker offers a particularly user-friendly solution: when establishing a connection, VPN Tracker automatically sets the rekeying timer to 24 hours. This significantly minimizes connection drops due to rekeying processes, keeping the connection especially stable. Additionally, VPN Tracker supports switching to UDP, which allows for an even more reliable connection.

  6. Why should the rekeying timer be set to 24 hours?

    A longer rekeying cycle reduces the frequency of connection drops. By setting the timer to 24 hours— as VPN Tracker does by default— the likelihood of the rekeying process being triggered during a critical phase, such as a video conference, is decreased.

  7. What advantages does VPN Tracker have when using UDP over TCP?

    VPN Tracker makes it easy to configure UDP, which offers faster connections and less sensitivity to packet loss. UDP is more efficient and resilient to interruptions during the rekeying process, which is particularly beneficial for bandwidth-intensive applications like video conferencing or streaming.

  8. What recommendations does VPN Tracker provide for companies to optimize their VPN connections?

    For companies relying on stable connections, VPN Tracker offers simple and effective solutions:

    • By default, the rekeying timer is set to 24 hours to minimize connection drops.
    • It is recommended to use UDP instead of TCP whenever possible to further enhance performance.

Privacy Settings / Datenschutz-Einstellungen