A connect button, a downloaded file, and a service account can all be called “the VPN.” Separating those roles makes a setup failure easier to describe and sends each question to the right place.
By Mohammad Hesameddin Montazerilisar. This article is adapted from the author’s original Lisar Connect article, first published July 8, 2026 and updated September 11, 2026. The author writes technical guidance for Lisar Connect. AI assisted the editing and presentation of this human-authored source.
Illustration of a client connection-status dashboard, not a screenshot of the current Lisar UI or a measured test.
The client runs the connection
The VPN client is the program on your device that establishes and maintains the connection: the software with the connect control, status indicator, and prompts. In an OpenVPN Connect setup, it reads the imported OpenVPN profile and runs the connection on the device.
Client, profile, and service describe different roles. The client runs the connection, the profile supplies its connection settings, and the service manages the account, profiles, and plan. Follow the current setup guide for your device and profile when choosing the software and settings to use.
This distinction matters before troubleshooting begins. A client can be installed without the intended profile being present. A profile can be imported without a connection being established. Check the stage that has actually completed instead of treating the app's presence as proof that every part is ready.
The profile supplies the connection instructions
The client needs to be told what connection to run, and that is the profile's job. In the documented OpenVPN Connect flow, the profile arrives as a .ovpn file carrying the setup information for that particular connection. Obtain it from the approved source for your own assignment and follow the guide for the intended device.
The file-import sequence brings the parts together: obtain the current .ovpn file, open OpenVPN Connect, choose Upload File, import and save the profile, and connect. The exact screens depend on the client version and device; the current supported guide takes precedence over remembered button wording.
Because the file carries profile-specific setup information, treat it as sensitive material. Do not paste its contents into a support ticket or public discussion. Do not pass it through casual chats or shared folders. When a new device needs setup, use the approved download and assignment process rather than borrowing another person's file.
The service manages accounts, profiles, and plans
Behind the client and file sits the service layer. It manages the account, profiles, and plan. Its current management interface is where profile-specific questions belong: which assignment is current, what the plan includes, and what status the service records for a profile.
Connection-state questions start at the client and device in front of you. Questions about the client software belong with its maker's documentation. Profile and plan questions belong with the service's management interface and official support. A status shown in one layer does not automatically answer a question about another.
Ask each part the right question
The service layer manages the assignment, the profile carries the instructions, and the client runs them. In the documented OpenVPN Connect flow, these roles meet in that order: management interface to file to client. Other supported setup paths use the settings and software specified in their own guides.
Consider three common questions:
- “The button says disconnected.” Start with the current client and device state. Record the wording and the stage where setup stopped.
- “Is my profile still active, and what does my plan include?” Check the current service-side information, rather than inferring it from an old downloaded file.
- “Which file should this new tablet use?” Confirm the intended assignment and obtain its current profile through the supported process for that device.
This keeps a support request precise. Instead of “my VPN is missing,” describe which client is installed, whether the intended profile has been imported, what the client currently reports, and which service-side status you checked. Keep the profile contents and other secrets out of that record.
Keep expectations within each layer
The client reports connection state; it does not decide what an unrelated website or application does with the traffic. The profile supplies connection settings; it does not grant permission to use unrelated accounts or services. The service manages its own plans and profiles; it does not override the rules of networks or devices you do not control.
On a managed device, follow the organization's setup process. Use the supported client and assigned profile, then verify the connection separately. The model is useful because it gives each question an appropriate starting point without promising that one status indicator proves everything.
Frequently asked questions
Is OpenVPN Connect itself the VPN service?
No. OpenVPN's documentation distinguishes its client application from the compatible server or service that supplies the connection profile.
Does importing a profile mean I am connected?
Importing makes the profile available to the client. Check the client's current connection state after the connection step; do not infer it from an import confirmation.
Where should a profile or plan question go?
Use the service's current management interface and official support. For client-software questions, use the client's own documentation. Do not share profile contents to explain which layer you are checking.
References
- OpenVPN Connect: Import a Profile — the file-import flow and the distinction between client and service.
- OpenVPN Connect: How to Get Your Connection Profile — obtaining the profile from the responsible provider, administrator, or supported server setup.
Top comments (0)