DEV Community

Cover image for We Put Colitu's VPN Verification to the Test. Here's What Changed.
Colitu VPN
Colitu VPN

Posted on Originally published at lab.colitu.com

We Put Colitu's VPN Verification to the Test. Here's What Changed.

We Put Colitu's VPN Verification to the Test. Here's What Changed.

Good engineering gets stronger when people challenge it.

On October 10, 2026, a DEV Community member, @launchgatecheck, suggested an interesting test for Colitu's VPN connection verification system.

The question was simple but important:

What happens if a VPN handshake succeeds, but the tunnel itself cannot carry traffic? Could the application mistakenly report a working connection?

Rather than speculate, we reproduced the scenario, examined the results, made improvements, and published our findings through Colitu Lab.

The test

We built a controlled environment where a VPN server accepts the handshake but silently drops traffic inside the tunnel, while verification endpoints remain accessible through the normal internet connection.

We also examined automatic fallback between servers, DNS routing, and network changes.

The testing identified three areas requiring improvements.

What we improved

1. Tunnel-bound verification

We identified a case where certain follow-up verification requests could be affected by split-tunneling rules, potentially reporting a successful connection through the wrong route.

We corrected this behavior. Connection checks now use a dedicated, tunnel-bound verification path that cannot be redirected by ordinary routing rules.

2. Network transition recovery

We improved how the Windows application responds when the same Wi-Fi adapter connects to a different network.

Colitu now detects address and gateway changes, invalidates previous verification, and begins reconnecting within seconds.

3. DNS consistency

Our tests also revealed an opportunity to improve DNS handling on one Windows transport path.

We standardized tunnel adapter handling so DNS resolution follows the VPN tunnel across the tested Windows transports.

Released and documented

These improvements are available in Colitu Windows 2.8.4 and Linux 1.4.3, including fixes introduced in earlier releases.

Our published research includes the test methodology, results, technical changes, and testing limitations. Windows was tested on real devices; Linux verification used automated tests and the same fixture logic. Mobile platforms were outside the scope of this investigation.

Thanks to the community

Special thanks to @launchgatecheck for proposing the test scenarios that prompted this investigation.

This is exactly why we believe open technical discussion matters.

At Colitu, constructive criticism is an opportunity to validate assumptions, improve our engineering, and make our results publicly available.

Read the full technical research:

Colitu Lab — Does the connection check really go through the tunnel?

Colitu — Connection Liberty Tunnel

Built for networks that fight back.

Website | Research Lab

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments. Some comments have been hidden by the post's author - find out more