[{"data":1,"prerenderedAt":274},["ShallowReactive",2],{"{\"cv\":1785043903981,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}\u002Fblog\u002Ftcp-setup-time-is-the-vpn-metric-nobodys-measuring":3},{"data":4,"headers":252},{"story":5,"cv":249,"rels":250,"links":251},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":241,"full_slug":242,"sort_by_date":23,"position":243,"tag_list":244,"is_startpage":210,"parent_id":245,"meta_data":23,"group_id":246,"first_published_at":8,"release_id":23,"lang":247,"path":23,"alternates":248,"default_full_slug":23,"translated_slugs":23},"TCP Setup Time is the VPN Metric Nobody's Measuring","2026-06-15T23:18:21.831Z","2026-07-25T18:53:15.717Z","2026-07-25T18:53:15.733Z",187907693916850,"c7245ec6-2dc5-4e77-aa7e-1fd3b4f3d38d",{"Tags":13,"_uid":14,"body":15,"title":6,"content":16,"component":204,"seoOgImage":205,"keyTakeaways":211,"previewImage":236,"previewTitle":6,"relatedContent":238,"seoDescription":239,"previewDescription":240},"","69a52ed9-008b-4441-a3c4-57b32d15254b",[],{"type":17,"content":18},"doc",[19,28,41,46,51,60,74,76,81,86,91,98,103,108,115,123,128,133,140,145,155,162,167,199],{"type":20,"attrs":21,"content":24},"heading",{"level":22,"textAlign":23},3,null,[25],{"text":26,"type":27},"And it’s the one that breaks modern infrastructure.","text",{"type":29,"attrs":30,"content":31},"paragraph",{"textAlign":23},[32,34,39],{"text":33,"type":27},"If you've ever benchmarked a VPN, you've probably done it the same way everyone else does: spin up ",{"text":35,"type":27,"marks":36},"iperf3",[37],{"type":38},"code",{"text":40,"type":27},", push as much TCP as the pipe will carry, and write down a Mbps number. It's a clean test. It's also the wrong number to chase for most of what runs on modern infrastructure.",{"type":29,"attrs":42,"content":43},{"textAlign":23},[44],{"text":45,"type":27},"APIs, dashboards, monitoring, control planes, CI agents, and database health checks. These aren't bandwidth-bound workloads. They open lots of short-lived connections, do a small amount of work, and tear down. For that pattern, throughput tells you almost nothing. Setup time tells you everything.",{"type":29,"attrs":47,"content":48},{"textAlign":23},[49],{"text":50,"type":27},"Xiid® benchmarked Terniion’s SealedTunnel technology against WireGuard, Tailscale, OpenVPN, IPsec, and a direct public path from an intentionally constrained edge client (Ubuntu on an older Xeon, behind WiFi, on a consumer\u002Fsatellite-class uplink) into six AWS and GCP endpoints. The throughput results were competitive. The setup time results weren't even close.",{"type":20,"attrs":52,"content":54},{"level":53,"textAlign":23},5,[55],{"text":56,"type":27,"marks":57},"Seven to twenty-two milliseconds. Across every path.",[58],{"type":59},"bold",{"type":29,"attrs":61,"content":62},{"textAlign":23},[63,69],{"type":64,"attrs":65},"image",{"id":66,"alt":13,"src":67,"title":13,"source":13,"copyright":13,"meta_data":68},187908076818099,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F509x314\u002F98d56565db\u002Ftcp-setup-time.png",{},{"text":70,"type":27,"marks":71},"TCP setup time, median milliseconds across three runs. Lower is faster.",[72],{"type":73},"italic",{"type":29,"attrs":75},{"textAlign":23},{"type":29,"attrs":77,"content":78},{"textAlign":23},[79],{"text":80,"type":27},"Across every path tested, SealedTunnel's setup time stayed inside a 7-to-22 ms band. Everything else lived between 47 and 258 ms, with the long-haul AWS Singapore path pushing every traditional transport past a quarter-second.",{"type":29,"attrs":82,"content":83},{"textAlign":23},[84],{"text":85,"type":27},"The mechanism is straightforward. The application connects to a local STLink binding while the encrypted tunnel path is already established. So a new connection from your code to the local binding completes at near-loopback speed, regardless of how far the remote endpoint actually sits.",{"type":29,"attrs":87,"content":88},{"textAlign":23},[89],{"text":90,"type":27},"This is not raw network RTT, and we don't claim it is. The practical effect is what matters: application-level connection setup completes in single-digit milliseconds even across an intercontinental path.",{"type":20,"attrs":92,"content":93},{"level":22,"textAlign":23},[94],{"text":95,"type":27,"marks":96},"Setup time compounds fast.",[97],{"type":59},{"type":29,"attrs":99,"content":100},{"textAlign":23},[101],{"text":102,"type":27},"A request budget of 250 ms per TCP setup sounds tolerable until you put it in context. A modestly chatty service: think of a dashboard refreshing widgets, a health-check sweep, or an integration that polls a REST endpoint; can open a thousand connections in a minute. At 250 ms each, that's over four minutes of pure connection setup before a single byte of payload moves. Push the same workload through SealedTunnel and the same thousand connections cost about twenty seconds.",{"type":29,"attrs":104,"content":105},{"textAlign":23},[106],{"text":107,"type":27},"That's the difference between a dashboard that feels live and one that feels broken. It's the reason a teammate three time zones away thinks the system is down when it's just shaking hands.",{"type":20,"attrs":109,"content":110},{"level":22,"textAlign":23},[111],{"text":112,"type":27,"marks":113},"On the path where edge links break, throughput nearly doubled.",[114],{"type":59},{"type":29,"attrs":116,"content":117},{"textAlign":23},[118],{"type":64,"attrs":119},{"id":120,"alt":13,"src":121,"title":13,"source":13,"copyright":13,"meta_data":122},187908283969211,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F616x131\u002F42926555bf\u002Fthroughput.png",{},{"type":29,"attrs":124,"content":125},{"textAlign":23},[126],{"text":127,"type":27},"For completeness: SealedTunnel stayed inside the same practical throughput envelope as every other tested transport on US paths. On the long-haul AWS Singapore path, it pulled meaningfully ahead — 5.79 Mbps median TCP, versus 1.99-3.08 Mbps for the rest.",{"type":29,"attrs":129,"content":130},{"textAlign":23},[131],{"text":132,"type":27},"Intercontinental paths are where constrained edge links suffer most. In this run, SealedTunnel's path through the connector service delivered a better effective TCP route than even the direct public link.",{"type":20,"attrs":134,"content":135},{"level":22,"textAlign":23},[136],{"text":137,"type":27,"marks":138},"Speed is the bonus. Architecture is the product.",[139],{"type":59},{"type":29,"attrs":141,"content":142},{"textAlign":23},[143],{"text":144,"type":27},"And connection time is the visible win. SealedTunnel requires no open inbound ports on the protected endpoint. The tunnel is outbound-only. The endpoint is non-addressable from the public internet so there are no IPs to expose, no listeners to scan, no NAT traversal contortions. Access is process-to-process, not subnet-to-subnet, so a compromised endpoint cannot pivot across the network. There is nothing on the other end to pivot into except the specific service you mapped.",{"type":29,"attrs":146,"content":147},{"textAlign":23},[148,153],{"type":64,"attrs":149},{"id":150,"alt":13,"src":151,"title":13,"source":13,"copyright":13,"meta_data":152},187908457623230,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1020x184\u002F6f92ff05cc\u002Fscreenshot-2026-06-03-082213.png",{},{"text":154,"type":27},"For organizations securing remote sites, field systems, regulated workloads, or critical infrastructure, that's the result that matters. The speed result is a nice surprise on top of it.",{"type":20,"attrs":156,"content":157},{"level":22,"textAlign":23},[158],{"text":159,"type":27,"marks":160},"Pick SealedTunnel when these are true.",[161],{"type":59},{"type":29,"attrs":163,"content":164},{"textAlign":23},[165],{"text":166,"type":27},"Reach for it when any of these describe your situation:",{"type":168,"content":169},"bullet_list",[170,178,185,192],{"type":171,"content":172},"list_item",[173],{"type":29,"attrs":174,"content":175},{"textAlign":23},[176],{"text":177,"type":27},"You can't open inbound ports, whether for regulated, field, or critical-infrastructure access.",{"type":171,"content":179},[180],{"type":29,"attrs":181,"content":182},{"textAlign":23},[183],{"text":184,"type":27},"Your workload is connection-chatty: APIs, dashboards, monitoring, short-lived service calls.",{"type":171,"content":186},[187],{"type":29,"attrs":188,"content":189},{"textAlign":23},[190],{"text":191,"type":27},"You're operating over messy edge links: NAT-heavy, satellite, and branch sites with consumer uplinks.",{"type":171,"content":193},[194],{"type":29,"attrs":195,"content":196},{"textAlign":23},[197],{"text":198,"type":27},"You need to limit lateral movement to specific services, not whole subnets.",{"type":29,"attrs":200,"content":201},{"textAlign":23},[202],{"text":203,"type":27},"Want the full methodology, raw data, and limitations in the Xiid edge-to-cloud benchmark paper? Read it, then run it yourself. A setup-time gap this wide either holds up or it doesn't.","BlogPost",{"id":206,"alt":13,"name":13,"focus":13,"title":13,"source":13,"filename":207,"copyright":13,"fieldtype":208,"meta_data":209,"is_external_url":210},187908650626754,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F4000x2667\u002Fa4c9a34027\u002Fcloud-storage-background-remixed-from-public-domain-by-nasa.jpg","asset",{},false,{"type":17,"content":212},[213],{"type":168,"content":214},[215,222,229],{"type":171,"content":216},[217],{"type":29,"attrs":218,"content":219},{"textAlign":23},[220],{"text":221,"type":27},"Throughput benchmarks are the wrong metric for modern infrastructure: APIs, dashboards, CI agents, and monitoring tools open many short-lived connections, where setup time — not bandwidth — determines whether a system feels live or broken.",{"type":171,"content":223},[224],{"type":29,"attrs":225,"content":226},{"textAlign":23},[227],{"text":228,"type":27},"In Xiid's benchmarks across AWS and GCP endpoints, SealedTunnel's TCP setup time stayed in a 7–22 ms band; every other transport (WireGuard, Tailscale, OpenVPN, IPsec) ranged from 47 to 258 ms, a difference that compounds to minutes of connection overhead on chatty workloads.",{"type":171,"content":230},[231],{"type":29,"attrs":232,"content":233},{"textAlign":23},[234],{"text":235,"type":27},"The speed advantage is a byproduct of architecture: SealedTunnel requires no open inbound ports, makes endpoints non-addressable from the public internet, and limits connectivity to process-to-process rather than subnet-to-subnet, eliminating lateral movement risk in addition to reducing latency.",{"id":206,"alt":13,"name":13,"focus":13,"title":13,"source":13,"filename":207,"copyright":13,"fieldtype":208,"meta_data":237,"is_external_url":210},{},[],"TCP setup in 7-22 ms. Every other tested VPN: 47-258 ms. Why setup time, not throughput, is the metric that breaks modern infrastructure.","VPN setup time benchmark: SealedTunnel™ vs WireGuard, IPsec","tcp-setup-time-is-the-vpn-metric-nobodys-measuring","blog\u002Ftcp-setup-time-is-the-vpn-metric-nobodys-measuring",10,[],193139877037850,"cc858941-5ce0-4d46-b9a0-9f30b85cc8aa","default",[],1785043618,[],[],{"cache-control":253,"connection":254,"content-encoding":255,"content-type":256,"date":257,"etag":258,"referrer-policy":259,"sb-be-version":260,"server":261,"transfer-encoding":262,"vary":263,"via":264,"x-amz-cf-id":265,"x-amz-cf-pop":266,"x-cache":267,"x-content-type-options":268,"x-frame-options":269,"x-permitted-cross-domain-policies":270,"x-request-id":271,"x-runtime":272,"x-xss-protection":273},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","gzip","application\u002Fjson; charset=utf-8","Sun, 26 Jul 2026 05:32:12 GMT","W\u002F\"ef4d4c527437035188c7c7749ef7ba41\"","strict-origin-when-cross-origin","5.924.0","nginx\u002F1.29.1","chunked","Origin,Accept-Encoding","1.1 f21e3e9a304f8d928ae6a7ae28c35ce8.cloudfront.net (CloudFront)","BP3Vi8sNG1UIYBCv29XKgMCNjhfkGBoUmdZLl4QaK1tnUdH22JutzA==","CMH68-P4","Miss from cloudfront","nosniff","SAMEORIGIN","none","931bfcfb-5811-4c99-ab3b-cf6b8332ec7f","0.020885","0",1785043931857]