Data Channel Offload: supported features

This page aims at summarizing all data channel features and their support status in the DCO modules across the supported platforms.\ New features may be added over time, therefore keep an eye on this page if interested.

Please, also note that some features, like compression are considered to be legacy and expected to never be implemented in ovpn-dco. This is a design decision aimed at keeping ovpn-dco as simple as possible, while also taking the chance to drop those functionalities that are not consider useful anymore (or even harmful!).

Supported features by platform

This table is constantly work in progress, therefore expect changes over time.

Feature Windows Linux FreeBSD Remark
TUN mode (L3) yes yes yes
TAP mode (L2) no no no not planned
Mode: client, P2MP/server client, server client, server client, server
UDP as transport yes yes yes
TCP as transport yes (not for server) yes no
Ciphers AES-GCM AES-GCM AES-GCM
ChaCha20-Poly1305 (Win11 only) ChaCha20-Poly1305 ChaCha20-Poly1305
AEAD Epoch Keys no no no desirable
Internal routes handling --iroute yes standard system routes yes (do not use identical route/iroute masks)
Outside fragmentation (inside MTU 1500) yes handled by kernel yes (to be tested)
OpenVPN fragmentation (--fragment) no no no not planned
MSS mangling --mssfix yes no (can be done via nft) no (can be done via pf) desirable
Compression no no no not planned
OCC packets in data channel ? no ? required for mtu-test (other use cases?)
RPF check (server only) n/a yes ?
Topology other than subnet --topology net30|p2p no no no not planned
--float on TLS server yes yes no 2.7_alpha3 needed to receive kernel notifications
--float on TLS client no no no
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9