[{"data":1,"prerenderedAt":319},["ShallowReactive",2],{"{\"cv\":1787329964117,\"version\":\"published\"}widgets\u002Fnavigation-bar":3,"{\"cv\":1787329964117,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}\u002Fblog\u002Fvpn-setup-time-benchmark-sealedtunnel":66},{"data":4,"headers":45},{"story":5,"cv":42,"rels":43,"links":44},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":32,"full_slug":33,"sort_by_date":22,"position":34,"tag_list":35,"is_startpage":15,"parent_id":36,"meta_data":22,"group_id":37,"first_published_at":38,"release_id":22,"lang":39,"path":40,"alternates":41,"default_full_slug":22,"translated_slugs":22},"Navigation Bar","2026-08-05T05:55:49.585Z","2026-08-07T15:41:09.255Z","2026-08-07T15:41:09.269Z",205700094329908,"be34732b-2155-45e7-8ee2-86e1157a8cb4",{"_uid":13,"component":14,"showMarketingBanner":15,"marketingBannerContent":16},"e7a8d72d-8af8-452e-87b2-de4098162fb9","NavigationBar",false,{"type":17,"content":18},"doc",[19],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26,"marks":27},"See us at Black Hat booth #7505","text",[28],{"type":29,"attrs":30},"textStyle",{"color":31},"#000000","navigation-bar","widgets\u002Fnavigation-bar",0,[],205696803161001,"e116d2fb-7cac-4697-9dcb-91d9283aecc3","2026-08-05T06:19:33.200Z","default","\u002F",[],1787329558,[],[],{"cache-control":46,"connection":47,"content-length":48,"content-type":49,"date":50,"etag":51,"referrer-policy":52,"sb-be-version":53,"server":54,"vary":55,"via":56,"x-amz-cf-id":57,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":63,"x-runtime":64,"x-xss-protection":65},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","986","application\u002Fjson; charset=utf-8","Fri, 21 Aug 2026 16:33:13 GMT","W\u002F\"91adc74ad473171fb603c9d22fce84f3\"","strict-origin-when-cross-origin","5.946.1","nginx\u002F1.29.1","Origin","1.1 b3f79c7629585fd4818d306efdc55e44.cloudfront.net (CloudFront)","A1Ug_yiW629XWKDV5PmiEfNjL8S71-w356woEwcDg4s0Mjclpu9qiw==","CMH68-P4","Miss from cloudfront","nosniff","SAMEORIGIN","none","fecc0317-cc4e-447d-b2bb-75437b56c7b2","0.027731","0",{"data":67,"headers":309},{"story":68,"cv":42,"rels":307,"links":308},{"name":69,"created_at":70,"published_at":71,"updated_at":72,"id":73,"uuid":74,"content":75,"slug":299,"full_slug":300,"sort_by_date":301,"position":34,"tag_list":302,"is_startpage":15,"parent_id":303,"meta_data":22,"group_id":304,"first_published_at":305,"release_id":22,"lang":39,"path":22,"alternates":306,"default_full_slug":22,"translated_slugs":22},"TCP Setup Time is the VPN Metric Nobody's Measuring","2026-06-15T23:18:21.831Z","2026-07-27T21:01:55.503Z","2026-07-27T21:01:55.521Z",187907693916850,"c7245ec6-2dc5-4e77-aa7e-1fd3b4f3d38d",{"Tags":76,"_uid":77,"body":78,"title":69,"content":79,"component":263,"seoOgImage":264,"keyTakeaways":269,"previewImage":294,"previewTitle":69,"relatedContent":296,"seoDescription":297,"previewDescription":298},"","69a52ed9-008b-4441-a3c4-57b32d15254b",[],{"type":17,"content":80},[81,88,100,105,110,119,133,135,140,145,150,157,162,167,174,182,187,192,199,204,214,221,226,258],{"type":82,"attrs":83,"content":85},"heading",{"level":84,"textAlign":22},3,[86],{"text":87,"type":26},"And it’s the one that breaks modern infrastructure.",{"type":20,"attrs":89,"content":90},{"textAlign":22},[91,93,98],{"text":92,"type":26},"If you've ever benchmarked a VPN, you've probably done it the same way everyone else does: spin up ",{"text":94,"type":26,"marks":95},"iperf3",[96],{"type":97},"code",{"text":99,"type":26},", push as much TCP as the pipe will carry, and write down a Mbps number. It's a clean test. It's also the wrong number to chase for most of what runs on modern infrastructure.",{"type":20,"attrs":101,"content":102},{"textAlign":22},[103],{"text":104,"type":26},"APIs, dashboards, monitoring, control planes, CI agents, and database health checks. These aren't bandwidth-bound workloads. They open lots of short-lived connections, do a small amount of work, and tear down. For that pattern, throughput tells you almost nothing. Setup time tells you everything.",{"type":20,"attrs":106,"content":107},{"textAlign":22},[108],{"text":109,"type":26},"Xiid® benchmarked Terniion’s SealedTunnel technology against WireGuard, Tailscale, OpenVPN, IPsec, and a direct public path from an intentionally constrained edge client (Ubuntu on an older Xeon, behind WiFi, on a consumer\u002Fsatellite-class uplink) into six AWS and GCP endpoints. The throughput results were competitive. The setup time results weren't even close.",{"type":82,"attrs":111,"content":113},{"level":112,"textAlign":22},5,[114],{"text":115,"type":26,"marks":116},"Seven to twenty-two milliseconds. Across every path.",[117],{"type":118},"bold",{"type":20,"attrs":120,"content":121},{"textAlign":22},[122,128],{"type":123,"attrs":124},"image",{"id":125,"alt":76,"src":126,"title":76,"source":76,"copyright":76,"meta_data":127},187908076818099,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F509x314\u002F98d56565db\u002Ftcp-setup-time.png",{},{"text":129,"type":26,"marks":130},"TCP setup time, median milliseconds across three runs. Lower is faster.",[131],{"type":132},"italic",{"type":20,"attrs":134},{"textAlign":22},{"type":20,"attrs":136,"content":137},{"textAlign":22},[138],{"text":139,"type":26},"Across every path tested, SealedTunnel's setup time stayed inside a 7-to-22 ms band. Everything else lived between 47 and 258 ms, with the long-haul AWS Singapore path pushing every traditional transport past a quarter-second.",{"type":20,"attrs":141,"content":142},{"textAlign":22},[143],{"text":144,"type":26},"The mechanism is straightforward. The application connects to a local STLink binding while the encrypted tunnel path is already established. So a new connection from your code to the local binding completes at near-loopback speed, regardless of how far the remote endpoint actually sits.",{"type":20,"attrs":146,"content":147},{"textAlign":22},[148],{"text":149,"type":26},"This is not raw network RTT, and we don't claim it is. The practical effect is what matters: application-level connection setup completes in single-digit milliseconds even across an intercontinental path.",{"type":82,"attrs":151,"content":152},{"level":84,"textAlign":22},[153],{"text":154,"type":26,"marks":155},"Setup time compounds fast.",[156],{"type":118},{"type":20,"attrs":158,"content":159},{"textAlign":22},[160],{"text":161,"type":26},"A request budget of 250 ms per TCP setup sounds tolerable until you put it in context. A modestly chatty service: think of a dashboard refreshing widgets, a health-check sweep, or an integration that polls a REST endpoint; can open a thousand connections in a minute. At 250 ms each, that's over four minutes of pure connection setup before a single byte of payload moves. Push the same workload through SealedTunnel and the same thousand connections cost about twenty seconds.",{"type":20,"attrs":163,"content":164},{"textAlign":22},[165],{"text":166,"type":26},"That's the difference between a dashboard that feels live and one that feels broken. It's the reason a teammate three time zones away thinks the system is down when it's just shaking hands.",{"type":82,"attrs":168,"content":169},{"level":84,"textAlign":22},[170],{"text":171,"type":26,"marks":172},"On the path where edge links break, throughput nearly doubled.",[173],{"type":118},{"type":20,"attrs":175,"content":176},{"textAlign":22},[177],{"type":123,"attrs":178},{"id":179,"alt":76,"src":180,"title":76,"source":76,"copyright":76,"meta_data":181},187908283969211,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F616x131\u002F42926555bf\u002Fthroughput.png",{},{"type":20,"attrs":183,"content":184},{"textAlign":22},[185],{"text":186,"type":26},"For completeness: SealedTunnel stayed inside the same practical throughput envelope as every other tested transport on US paths. On the long-haul AWS Singapore path, it pulled meaningfully ahead — 5.79 Mbps median TCP, versus 1.99-3.08 Mbps for the rest.",{"type":20,"attrs":188,"content":189},{"textAlign":22},[190],{"text":191,"type":26},"Intercontinental paths are where constrained edge links suffer most. In this run, SealedTunnel's path through the connector service delivered a better effective TCP route than even the direct public link.",{"type":82,"attrs":193,"content":194},{"level":84,"textAlign":22},[195],{"text":196,"type":26,"marks":197},"Speed is the bonus. Architecture is the product.",[198],{"type":118},{"type":20,"attrs":200,"content":201},{"textAlign":22},[202],{"text":203,"type":26},"And connection time is the visible win. SealedTunnel requires no open inbound ports on the protected endpoint. The tunnel is outbound-only. The endpoint is non-addressable from the public internet so there are no IPs to expose, no listeners to scan, no NAT traversal contortions. Access is process-to-process, not subnet-to-subnet, so a compromised endpoint cannot pivot across the network. There is nothing on the other end to pivot into except the specific service you mapped.",{"type":20,"attrs":205,"content":206},{"textAlign":22},[207,212],{"type":123,"attrs":208},{"id":209,"alt":76,"src":210,"title":76,"source":76,"copyright":76,"meta_data":211},187908457623230,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1020x184\u002F6f92ff05cc\u002Fscreenshot-2026-06-03-082213.png",{},{"text":213,"type":26},"For organizations securing remote sites, field systems, regulated workloads, or critical infrastructure, that's the result that matters. The speed result is a nice surprise on top of it.",{"type":82,"attrs":215,"content":216},{"level":84,"textAlign":22},[217],{"text":218,"type":26,"marks":219},"Pick SealedTunnel when these are true.",[220],{"type":118},{"type":20,"attrs":222,"content":223},{"textAlign":22},[224],{"text":225,"type":26},"Reach for it when any of these describe your situation:",{"type":227,"content":228},"bullet_list",[229,237,244,251],{"type":230,"content":231},"list_item",[232],{"type":20,"attrs":233,"content":234},{"textAlign":22},[235],{"text":236,"type":26},"You can't open inbound ports, whether for regulated, field, or critical-infrastructure access.",{"type":230,"content":238},[239],{"type":20,"attrs":240,"content":241},{"textAlign":22},[242],{"text":243,"type":26},"Your workload is connection-chatty: APIs, dashboards, monitoring, short-lived service calls.",{"type":230,"content":245},[246],{"type":20,"attrs":247,"content":248},{"textAlign":22},[249],{"text":250,"type":26},"You're operating over messy edge links: NAT-heavy, satellite, and branch sites with consumer uplinks.",{"type":230,"content":252},[253],{"type":20,"attrs":254,"content":255},{"textAlign":22},[256],{"text":257,"type":26},"You need to limit lateral movement to specific services, not whole subnets.",{"type":20,"attrs":259,"content":260},{"textAlign":22},[261],{"text":262,"type":26},"Want the full methodology, raw data, and limitations in the Xiid edge-to-cloud benchmark paper? Read it, then run it yourself. A setup-time gap this wide either holds up or it doesn't.","BlogPost",{"id":265,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":266,"copyright":76,"fieldtype":267,"meta_data":268,"is_external_url":15},201601587046755,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F5472x3648\u002F3767323510\u002Fdeveloper-writes-ai-code-laptop.jpg","asset",{},{"type":17,"content":270},[271],{"type":227,"content":272},[273,280,287],{"type":230,"content":274},[275],{"type":20,"attrs":276,"content":277},{"textAlign":22},[278],{"text":279,"type":26},"Throughput benchmarks are the wrong metric for modern infrastructure: APIs, dashboards, CI agents, and monitoring tools open many short-lived connections, where setup time — not bandwidth — determines whether a system feels live or broken.",{"type":230,"content":281},[282],{"type":20,"attrs":283,"content":284},{"textAlign":22},[285],{"text":286,"type":26},"In Xiid's benchmarks across AWS and GCP endpoints, SealedTunnel's TCP setup time stayed in a 7–22 ms band; every other transport (WireGuard, Tailscale, OpenVPN, IPsec) ranged from 47 to 258 ms, a difference that compounds to minutes of connection overhead on chatty workloads.",{"type":230,"content":288},[289],{"type":20,"attrs":290,"content":291},{"textAlign":22},[292],{"text":293,"type":26},"The speed advantage is a byproduct of architecture: SealedTunnel requires no open inbound ports, makes endpoints non-addressable from the public internet, and limits connectivity to process-to-process rather than subnet-to-subnet, eliminating lateral movement risk in addition to reducing latency.",{"id":265,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":266,"copyright":76,"fieldtype":267,"meta_data":295,"is_external_url":15},{},[],"TCP setup in 7-22 ms. Every other tested VPN: 47-258 ms. Why setup time, not throughput, is the metric that breaks modern infrastructure.","VPN setup time benchmark: SealedTunnel™ vs WireGuard, IPsec","vpn-setup-time-benchmark-sealedtunnel","blog\u002Fvpn-setup-time-benchmark-sealedtunnel","2026-06-03",[],193139877037850,"cc858941-5ce0-4d46-b9a0-9f30b85cc8aa","2026-06-03T18:53:00.000Z",[],[],[],{"cache-control":46,"connection":47,"content-encoding":310,"content-type":49,"date":311,"etag":312,"referrer-policy":52,"sb-be-version":53,"server":54,"transfer-encoding":313,"vary":314,"via":315,"x-amz-cf-id":316,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":317,"x-runtime":318,"x-xss-protection":65},"gzip","Fri, 21 Aug 2026 16:33:15 GMT","W\u002F\"9c00368ba464187907fd29f90db4ed02\"","chunked","Origin,Accept-Encoding","1.1 18cb903dd2c9ff38a33d79715104de0a.cloudfront.net (CloudFront)","LhlZESCNp8VqZ7NB5F2yJ9_ipVfu2cm5dmSo3VoelbjdZOyBp7QdSA==","c61d4e3a-d6f4-4daf-9e99-645254bc131d","0.022474",1787329994993]