What Is VPN Passthrough? How It Works and When You Need It

Share

If you've ever poked around your router's admin page, you've probably seen settings like "PPTP Passthrough," "IPsec Passthrough" or simply "VPN Passthrough." This post helps demystify VPN passthrough.

If you've ever poked around your router's admin page, you've probably seen settings like "PPTP Passthrough," "IPsec Passthrough" or simply "VPN Passthrough." Most people only go looking for them after a VPN refuses to connect from home.

VPN passthrough is a router feature that lets VPN traffic from a device on your network pass through the router's network address translation (NAT) to a VPN server on the internet. It exists because some older VPN protocols don't work well with NAT. Passthrough adds special handling so those protocols can still connect.

Below, we explain why that's needed, which protocols depend on it, and why OpenVPN generally doesn't need it at all.

What VPN passthrough is (and why NAT gets in the way)

Almost every home and small-office router uses NAT. All the devices on your local network share one public IP address, and the router keeps track of which outbound connection belongs to which device. It usually does this using port numbers: when a reply comes back, the port tells the router which laptop or phone should get it.

That works well for ordinary TCP and UDP traffic. It breaks down for protocols that either:

  • don't use ports at all, so the router has nothing to track, or
  • cryptographically protect the packet headers, so the router's address rewriting makes the packet look tampered with.

VPN passthrough is the router's workaround. It's usually an application-level gateway (ALG) that understands a specific VPN protocol well enough to track its sessions and forward the traffic correctly.

One common misunderstanding: passthrough doesn't make your router a VPN. It doesn't encrypt anything. It just stops the router from getting in the way of a VPN connection that starts on a device behind it.

Which VPN protocols need passthrough?

PPTP

PPTP uses a TCP control connection on port 1723, plus a separate data channel carried in GRE (IP protocol 47). GRE has no port numbers, so a basic NAT router can't tell which internal device a GRE packet belongs to. PPTP passthrough tracks the session so the GRE traffic gets to the right place. (PPTP is also considered cryptographically broken and shouldn't be used for anything sensitive today.)

IPsec

IPsec negotiates keys with IKE over UDP port 500 and then carries traffic in ESP (IP protocol 50), which also has no ports. IPsec's AH mode authenticates the IP header itself, so it fundamentally can't survive NAT. IPsec passthrough helps older clients get ESP traffic through the router.

Most modern IPsec implementations use NAT Traversal (NAT-T) instead. NAT-T detects NAT on the path and wraps ESP inside UDP port 4500, which ordinary NAT handles fine. With NAT-T on both ends, IPsec passthrough is rarely needed.

L2TP/IPsec

L2TP is tunneled inside IPsec, so it has the same NAT issues and the same fix: NAT-T on modern systems, or IPsec passthrough on older ones.

Does OpenVPN need VPN passthrough?

No. OpenVPN runs over standard UDP (port 1194 by default) or TCP, as a normal connection with normal port numbers. Any NAT router handles it the same way it handles web browsing or video calls, with no special ALG required.

OpenVPN can also run over TCP port 443, the same port as HTTPS. That helps on restrictive networks such as hotels, airports and some corporate guest Wi-Fi, which often allow little besides web traffic. It's one of the reasons OpenVPN connects reliably in places where older protocols struggle.

So if you're connecting with OpenVPN and the connection fails, the passthrough setting on your router is almost certainly not the cause. Skip to the troubleshooting section below.

Should you turn VPN passthrough on or off?

  • Home users and remote workers: Leaving passthrough enabled (the default on most routers) is generally fine. It only matters if you or someone in your home uses a PPTP, L2TP or older IPsec VPN.
  • IT and network admins: Some organizations disable PPTP and IPsec passthrough on guest or office networks to discourage unapproved VPN use. That won't block VPNs that run over ordinary UDP or TCP, so it isn't a complete control on its own.
  • If something seems broken: ALGs occasionally misbehave. If an IPsec VPN with NAT-T fails to connect, try turning IPsec passthrough off as well as on. On some routers the ALG interferes with NAT-T traffic.

Passthrough on its own carries little security risk. It only applies to connections that start inside your network, and it doesn't open any inbound ports to the internet.

How to enable VPN passthrough on your router

The exact menu names vary by manufacturer, but the steps are usually the same:

  1. Sign in to your router's admin page, usually at an address like 192.168.0.1 or 192.168.1.1, or through the manufacturer's mobile app.
  2. Look under Security, Firewall, WAN or Advanced settings for "VPN Passthrough," "ALG" or the individual protocol names.
  3. Enable the protocols you need (PPTP, L2TP and/or IPsec) and save.
  4. Reboot the router if prompted, then test your VPN connection again.

Some routers, especially mesh systems and ISP-supplied gateways, don't expose these settings at all and have passthrough permanently on. That's normal.

Hosting a VPN server at home is a different setting. Passthrough is for outbound connections. If you're running a VPN server behind your router, you need port forwarding instead: for OpenVPN, forward the UDP or TCP port the server listens on to the server's local IP address.

Troubleshooting: VPN still won't connect

  • Double NAT: If your ISP's modem is also a router and you've added your own router behind it, traffic passes through NAT twice. Put the ISP device in bridge mode or check settings on both devices.
  • Blocked ports or protocols: Firewalls may block UDP 500 and 4500 (IPsec), TCP 1723 and GRE (PPTP), or non-standard UDP ports. Switching OpenVPN to TCP 443 often gets around this.
  • Carrier-grade NAT (CGNAT): Many ISPs, especially mobile and some fiber providers, put customers behind a shared public IP. That doesn't usually affect outbound VPN clients, but it can make hosting a VPN server at home impossible without help from the ISP or a cloud-hosted alternative.
  • Misbehaving ALGs: As mentioned above, try toggling passthrough and any SIP or IPsec ALG settings. Update the router's firmware too.

VPN passthrough FAQ

Is VPN passthrough safe?

Yes, for most networks. It only helps outbound VPN sessions get through NAT and doesn't expose your network to inbound traffic. The bigger security question is which VPN protocol you use: PPTP should be avoided.

Do I need VPN passthrough for a VPN app on my phone or laptop?

Only if the app uses PPTP, L2TP or IPsec without NAT-T. Apps built on OpenVPN, and most modern IPsec/IKEv2 clients, work without it.

Does VPN passthrough slow down my internet?

No. It doesn't affect traffic that isn't a matching VPN session, and the processing overhead for VPN sessions is negligible.

Is VPN passthrough the same as a VPN router?

No. A VPN router runs a VPN client or server itself and encrypts traffic. Passthrough only lets VPN traffic from other devices get through the router.

Skip the passthrough headaches with OpenVPN

OpenVPN runs over standard UDP and TCP, so it gets through NAT, firewalls and restrictive networks without router tweaks. Run your own VPN server with Access Server, or use the cloud-delivered CloudConnexa.

Get started with Access Server

 

Related posts from OpenVPN

Subscribe for Blog Updates