OrbConnect Protocol
OrbConnect Protocol
OrbVPN's own HTTPS-tunnel protocol. FIPS 140-3 cryptography, deep anti-censorship, and Cloudflare CDN fronting — engineered in pure Go for users in the most hostile networks on earth.
What Is OrbConnect?
OrbConnect is OrbVPN's proprietary VPN protocol, written from the ground up in pure Go. It is not OpenVPN, and it is not Cisco AnyConnect — it is OrbVPN's own engine, purpose-built to keep working in Iran, Russia, and China where ordinary VPN protocols are detected and dropped within seconds.
OrbConnect tunnels your traffic inside a standard HTTPS session. To any firewall or deep-packet-inspection (DPI) system on the path, your connection looks like an ordinary visit to a secure website. Because it carries traffic over TCP 8443 and can be wrapped in Cloudflare CDN fronting, it survives in networks that blackhole UDP and fingerprint every other transport.
OrbConnect, not OpenConnect
OrbConnect is OrbVPN's own protocol. It is named OrbConnect because it is ours — there is no third-party Cisco/OpenConnect dependency. If you have read about "OpenConnect" elsewhere, that is a different product. OrbConnect's design goals are anti-censorship and standards-grade cryptography, not enterprise AnyConnect compatibility.
Why OrbConnect?
FIPS 140-3 Cryptography
OrbConnect uses standards-validated cryptographic primitives, giving you the same caliber of encryption trusted in regulated and high-assurance environments.
Looks Like Plain HTTPS
Your VPN session is carried inside a real TLS/HTTPS tunnel on port 8443. To a censor, it is indistinguishable from normal encrypted web traffic.
Region-Aware Connect Hints
Before connecting, OrbConnect can fetch anti-censorship hints from the server — TLS fingerprint, fake SNI, traffic padding, and fallback servers tuned to your region.
Built in Pure Go
A single, auditable, cross-platform engine powers OrbConnect on every device — no fragile native dependencies, fast to ship security fixes.
Transport Options
OrbConnect ships with two transports. Pick the one that survives your network — or let Smart Connect choose automatically.
Direct HTTPS Tunnel
The default. A standard HTTPS tunnel straight to the OrbConnect server on port 8443. Fast and secure for unrestricted and lightly filtered networks.
CDN Fronting (Cloudflare)
Routes OrbConnect through Cloudflare's CDN via a WebSocket bridge to TCP 8443. Maximum stealth — a censor cannot block it without blocking millions of websites that share the same CDN. Deployed on all 33 servers.
When to use CDN Fronting
In Iran, Russia, and China, where direct ports are routinely blocked, choose CDN Fronting. Your traffic enters Cloudflare on the ubiquitous HTTPS port and is bridged to the OrbConnect server, so the only way to block it would be to block Cloudflare itself.
Anti-Censorship Engineering
OrbConnect was designed for the hardest networks. Its connection layer adapts to what the network allows.
uTLS Fingerprinting
The TLS Client Hello can be shaped to match a real browser (Chrome, Firefox, iOS Safari), so your handshake blends in with genuine HTTPS clients.
Traffic Padding
Optional packet padding hides the size and timing signatures that DPI systems use to fingerprint tunnels.
Fake SNI & Domain Fronting
Connection hints can supply an innocuous SNI value, so the visible hostname in your handshake reveals nothing about OrbVPN.
Region-Tuned Fallbacks
When a region is supplied, the server returns a curated list of fallback endpoints, so a single blocked IP never ends your session.
How It Connects
Fetch Connection Hints (optional)
For restricted regions, OrbConnect first asks the server for anti-censorship hints: which TLS fingerprint to imitate, whether to enable WebSocket, padding, and fake SNI, plus a list of fallback servers.
Authenticate
OrbConnect authenticates with the server over HTTPS and receives session credentials and an allocated client IP.
Establish the Tunnel
The HTTPS tunnel is brought up — directly to the server, or through Cloudflare's CDN when CDN Fronting is selected — using FIPS 140-3 cryptography.
Route & Verify Traffic
Your device traffic is routed through the tunnel. Smart Connect can then verify that real traffic flows and your public IP has actually changed.
When to Use OrbConnect
Best For
Heavily censored networks (Iran, Russia, China), networks that block UDP or fingerprint WireGuard/VLESS, and any situation where you need a standards-grade, HTTPS-disguised tunnel that can fall back to Cloudflare CDN fronting.
Considerations
OrbConnect runs over TCP inside HTTPS, so on a completely open network WireGuard will usually give you lower latency and higher raw throughput. OrbConnect's advantage is resilience: it keeps working when faster protocols are blocked. If you are unsure, let Auto (Smart Connect) decide.
Stay Connected Where Others Can't
OrbConnect is OrbVPN's answer to state-level censorship: FIPS 140-3 cryptography wrapped in ordinary HTTPS, with Cloudflare CDN fronting as a last resort. Download OrbVPN and break through.