Back to articles
Technology Insight

Stealth VPN Architecture: Implementing OpenVPN over HTTPS (TCP 443) with Stunnel on Cloud VPS

May 28, 2026

Introduction to Stealth VPN Architecture

In an era of increasing network surveillance, sophisticated firewalls, and stringent Deep Packet Inspection (DPI) algorithms, standard Virtual Private Network (VPN) protocols often face severe throttling or outright blocking. Traditional OpenVPN traffic, while highly secure, exhibits distinct cryptographic signatures that corporate firewalls and national gateways can easily identify and terminate.

To overcome these challenges, network engineers and privacy advocates deploy a Stealth VPN architecture. This advanced guide demonstrates how to combine OpenVPN with Stunnel on a Linux-based Cloud VPS. By wrapping OpenVPN traffic within a secondary layer of standard SSL/TLS encryption and routing it through TCP port 443, the resulting traffic becomes virtually indistinguishable from legitimate HTTPS web browsing. This effectively masks your VPN infrastructure from DPI systems.


The Mechanics: Why OpenVPN Alone Is Not Enough

OpenVPN is a robust, open-source tunneling protocol. However, its default handshake configuration uses explicit headers that firewalls can fingerprint. Even if you switch OpenVPN from UDP to TCP port 443, sophisticated firewalls utilizing DPI can look past the port number, analyze the packet structure, and determine that the payload is not genuine web traffic.

This is where Stunnel becomes indispensable. Stunnel is a proxy designed to add TLS encryption functionality to existing clients and servers without any changes to the program's code. By placing Stunnel in front of OpenVPN, we achieve a dual-layer encapsulation model:

  • Inner Layer: OpenVPN handles user authentication, IP routing, and robust data encryption.
  • Outer Layer: Stunnel wraps the entire OpenVPN stream inside a standard TLS tunnel, mimicking a secure session with a regular web server.
By utilizing this architecture, a firewall inspecting the connection only sees a standard TLS handshake directed at port 443, which is identical to someone accessing an online banking portal or a secure e-commerce website.

Prerequisites and Environment Setup

Before initiating the installation, ensure you have the following components ready:

  1. A Cloud VPS running a clean installation of Ubuntu 22.04 LTS or Ubuntu 24.04 LTS.
  2. Root access or a user account with comprehensive sudo privileges.
  3. A static public IPv4 address assigned to your VPS.
  4. Basic familiarity with the Linux command-line interface (CLI) and text editors like Nano or Vim.

First, update your system repository index and upgrade existing packages to their latest versions to ensure security stability:

sudo apt update && sudo apt upgrade -y

Step 1: Installing and Configuring OpenVPN

To streamline the deployment and minimize human error in generating the Public Key Infrastructure (PKI), we will use a secure, well-vetted OpenVPN installation script. Run the following command to download and execute the setup installer:

wget [https://raw.githubusercontent.com/angristan/openvpn-install/master/openvpn-install.sh](https://raw.githubusercontent.com/angristan/openvpn-install/master/openvpn-install.sh)
sudo chmod +x openvpn-install.sh
sudo ./openvpn-install.sh

During the interactive installation process, you must specify precise configurations to accommodate the Stunnel proxy layer:

  • IP Address: Select the public IPv4 address of your VPS.
  • Protocol: Choose TCP. This is critical because Stunnel operates strictly over TCP.
  • Port: Enter an alternative internal port, such as 11940. Do not use 443 here, as Stunnel will bind to port 443 later.
  • DNS Resolvers: Choose a secure option like Cloudflare (1.1.1.1) or Google Public DNS.
  • Encryption Settings: Accept the default modern cryptographic recommendations (AES-256-GCM, SHA256).

Once the script completes, it will generate a client configuration file (e.g., client.ovpn) in your home directory. We will modify this file later.


Step 2: Installing and Configuring Stunnel on the Server

With OpenVPN listening locally on TCP port 11940, we will install Stunnel to act as our external-facing secure gateway on port 443.

Install Stunnel4 via the official package manager:

sudo apt install stunnel4 -y

Generating a Self-Signed TLS Certificate

Stunnel requires an SSL/TLS certificate to establish the outer cryptographic layer. Generate a self-signed certificate using OpenSSL:

sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/stunnel/stunnel.pem -out /etc/stunnel/stunnel.pem

Provide the requested organizational details when prompted. Since this certificate is used solely to establish a private encrypted tunnel between your own devices, a self-signed certificate is completely adequate and highly secure.

Configuring the Stunnel Daemon

Create and edit the primary Stunnel configuration file:

sudo nano /etc/stunnel/stunnel.conf

Populate the file with the following configuration directives:

pid = /var/run/stunnel4.pid
cert = /etc/stunnel/stunnel.pem
output = /var/log/stunnel4/stunnel.log

[openvpn_stealth]
accept = 0.0.0.0:443
connect = 127.0.0.1:11940
client = no

This configuration instructs Stunnel to accept incoming TLS connections globally on port 443, decrypt the TLS envelope using the specified certificate, and forward the raw OpenVPN traffic locally to port 11940.

To ensure Stunnel starts automatically on system boot, enable the service daemon:

sudo systemctl enable stunnel4
sudo systemctl start stunnel4

Step 3: Optimizing Firewall and Network Routing

To ensure traffic flows seamlessly through the dual-layer tunnel, we must verify the Linux kernel routing parameters and adjust the Uncomplicated Firewall (UFW).

Confirm that IP forwarding is enabled within the kernel:

sudo sysctl net.ipv4.ip_forward

If it returns 1, forwarding is active. If not, edit /etc/sysctl.conf, uncomment net.ipv4.ip_forward=1, and apply changes using sudo sysctl -p.

Next, configure UFW to allow traffic on port 443 while maintaining a strict default-deny posture for unauthorized ports:

sudo ufw allow 443/tcp
sudo ufw allow OpenSSH
sudo ufw enable

Step 4: Client-Side Configuration (Windows, macOS, Linux)

To connect to your stealth server, your client device needs both an OpenVPN client and a Stunnel client application installed.

1. Setting Up Stunnel on the Client

Install the Stunnel client application on your local machine. Edit its local configuration file (stunnel.conf) to include the following block:

[openvpn_stealth_client]
accept = 127.0.0.1:1194
connect = YOUR_SERVER_IP:443
client = yes

Launch the local Stunnel application. It will now listen locally on port 1194, waiting to wrap outbound traffic and securely forward it to your VPS over port 443.

2. Adjusting the OpenVPN Profile

Locate the client.ovpn profile generated during Step 1. Open it with a text editor and modify the target remote server pointer. Change the remote line to point directly to your local Stunnel listener:

# Find the existing remote line and comment it out
# remote YOUR_SERVER_IP 11940 tcp

# Redirect traffic through the local Stunnel proxy
remote 127.0.0.1 1194 tcp
route YOUR_SERVER_IP 255.255.255.255 net_gateway

Crucial Security Step: The route command added above instructs your operating system to route the core Stunnel connection directly through your actual local network gateway rather than looping it back into the VPN, preventing a catastrophic routing loop.


Verification and Performance Optimization

Import your modified client.ovpn profile into your OpenVPN client application (such as OpenVPN Connect) and initiate the connection. Once established, verify your configuration by visiting an external IP checking service. Your apparent location should match your Cloud VPS IP address.

To monitor logs on the server for auditing or troubleshooting purposes, use the following tracking utilities:

sudo tail -f /var/log/stunnel4/stunnel.log
sudo tail -f /var/log/openvpn/openvpn.log

Performance Tuning

Because TCP-over-TCP encapsulation can introduce a phenomenon known as "TCP meltdown" under poor network conditions, consider adding the following parameters to your server's OpenVPN configuration file (/etc/openvpn/server.conf) to optimize throughput:

  • sndbuf 393216
  • rcvbuf 393216
  • push "sndbuf 393216"
  • push "rcvbuf 393216"

Conclusion

By obfuscating OpenVPN traffic inside a legitimate TLS layer via Stunnel, you create a robust, highly resilient cryptographic tunnel capable of bypassing advanced corporate firewalls and deep packet inspection systems. This deployment balances enterprise-grade security with sophisticated traffic camouflage, ensuring unhindered and private network accessibility from any location globally.

Stealth VPN Architecture: Implementing OpenVPN over HTTPS (TCP 443) with Stunnel on Cloud VPS | DPTCloud