Independent · not affiliated with SpaceX or StarlinkReport: logger not startedFacts checked

Work · VPN

Starlink and VPNs: what works, what drops, what to ask IT

Starlink doesn’t block VPNs. Its Residential plans share one IPv4 address among many customers (CGNAT), and a few older VPN types can’t get through that. Most modern ones can.

Quick answer

Most work VPNs work on Starlink, because they connect out from your laptop. Starlink says WireGuard, OpenVPN and SSTP generally work behind its CGNAT, while PPTP and L2TP generally don’t (checked Oct 5, 2026); if your VPN drops, short outages and VPN timers are the usual cause, not a block.

Facts checked Research-based, not measured by us

Outbound client VPN
Generally works
Needs
NAT traversal (UDP or TCP)
PPTP, plain L2TP
Generally fails
Starlink support for VPNs
None: ask your IT team

Which VPN types work behind Starlink’s CGNAT

Residential and Roam plans use CGNAT (checked Oct 5, 2026). A VPN gets through it if its traffic is ordinary TCP or UDP. Starlink says NAT traversal support is required, and SSL-based VPNs typically traverse CGNAT best. Starlink’s support page is specific: CGNAT drops VPNs relying on IP protocols 47 (GRE), 50 (ESP), 51 (AH) and 115 (L2TP). (checked Oct 5, 2026).

VPN typeBehind CGNATWhy
WireGuardGenerally worksPlain UDP. On Starlink’s “works well” list.
OpenVPN (UDP or TCP)Generally worksOrdinary UDP or TCP. On Starlink’s list.
SSTPGenerally worksRuns over HTTPS (TCP). On Starlink’s list.
SSL VPN clients (many corporate “secure access” apps)Usually worksStarlink says SSL-based VPNs typically traverse CGNAT best. Ask IT which mode your client uses.
IPsec / IKEv2 with NAT-TUsually worksNAT-T wraps IPsec in UDP. Fails if the gateway has NAT-T turned off.
L2TP over IPsecGenerally failsOn Starlink’s “does not work well” list; relies on protocols CGNAT drops.
PPTPGenerally failsNeeds GRE, which CGNAT drops. PPTP is also outdated; most IT teams have retired it.
Site-to-site GRE or IPsec without NAT-TFailsRaw GRE/ESP is dropped. This is the case where a public IP plan may help, and Starlink still doesn’t guarantee it.

Starlink says switching to a public IP may help an incompatible VPN, but that it can’t guarantee compatibility even then (checked Oct 5, 2026). For a normal laptop VPN, the fix is a supported VPN mode, not a plan change. That’s IT’s call.

VPN drops every hour: is it obstructions?

Look at when it drops. The pattern tells you the cause.

PatternLikely causeWhat to do
Drops at the same minute every hour, or after the same length of timeA VPN timer: re-keying, a session limit or an idle timeout on the company side.Send IT the exact times. Obstructions don’t keep to a clock.
Drops at random times, more on some daysShort outages: obstructions, satellite handovers, weather.Match the drop times to outages on the Starlink app’s Statistics page.
Drops when the house is busy (streams, downloads, games)Upload saturation, or the CGNAT session limit.Cap uploads on your router; cut background connections.
Drops after a Starlink update or rebootYour public address changed, so the tunnel must rebuild.Normal. Make sure the client reconnects on its own.

Short outages. Satellites hand over about every 15 s (APNIC measurement, not ours), and an obstruction can turn a handover into a gap of a second or more. A call rides through that. A VPN survives it only if the gap is shorter than its keepalive timeout. The Starlink app’s Statistics page shows outages and alerts while you’re on the Starlink router, so you can line them up with your VPN log. For the dish’s view of the sky, use the Starlink app’s obstruction check.

Address changes. Starlink leases addresses for 5 min but tries to keep the same IP while you stay connected, and it doesn’t offer static IPs (checked Oct 5, 2026). If your company allow-lists home IP addresses, a Starlink line will break that rule now and then. Tell IT.

The session limit. CGNAT plans are limited to 1,200 sessions at once, and Starlink says hitting it can disrupt VPNs, freeze video meetings and drop VoIP calls (checked Oct 5, 2026). One laptop won’t hit it. A house full of devices, torrents or a small office might.

VPN verdict from the owner’s logger

Logger not started yet

  • VPN sessionsWork VPN, remote desktopNot measured yetWhy this rating

    Our measurement: none yet.

    Published figures: Starlink says SSTP, OpenVPN and WireGuard generally work behind its CGNAT, while PPTP and L2TP generally don’t. Which VPN types work.

    VPN sessions usually survive a few seconds of loss but not a minute. OK = an outage longer than 60 s on at most 1 workday in 10; Degraded = up to 1 every 2 workdays; Would drop = more. Read the guide.

When the logger runs, this card grades one Residential connection at the owner’s home. It will never be a regional average. How we measure.

Some pages load, others hang: the MTU check

Starlink provides a standard 1,500 bytes MTU (checked Oct 5, 2026), so the line itself isn’t unusual. A VPN wraps each packet in extra headers, though. If the tunnel doesn’t shrink its packets to fit, small things (chat, email) work while big transfers, some websites or file shares stall. This isn’t Starlink-specific, but people often notice it after switching providers. IT can lower the tunnel MTU or clamp the TCP MSS on the VPN.

IT For your IT person: VPN behind Starlink
  • IPv4: CGNAT on Residential/Roam; outbound TCP/UDP fine. CGNAT drops VPNs relying on IP protocols 47 (GRE), 50 (ESP), 51 (AH) and 115 (L2TP). NAT-T (UDP encapsulation) required for IPsec.
  • Concurrent session limit: 1,200 sessions per line on CGNAT plans; oldest dropped.
  • MTU 1,500 bytes at the WAN. Size the tunnel MTU / MSS clamp for your encapsulation overhead.
  • Native IPv6 on all plans. Check the client for IPv6 leaks or v6-only path failures.
  • Public IPv4 changes occasionally (no static IPs). Don’t rely on source-IP allow-lists; prefer certificate or identity-based access.
  • Expect short outages around satellite handovers. Keepalive/dead-peer timeouts of a few seconds will flap; tolerate a few missed keepalives and enable auto-reconnect.

What to ask IT before you rely on Starlink

Copy these into an email. Starlink can’t troubleshoot VPNs (checked Oct 5, 2026), so your IT team is the only one who can answer them.

  • Which VPN client and protocol do we use (WireGuard, OpenVPN, SSL, IKEv2/IPsec, L2TP)? Does it support NAT traversal over UDP or TCP?
  • My home line uses carrier-grade NAT (CGNAT) and has no static IP. Does our VPN or any security rule require a fixed home IP or an allow-listed address?
  • Does our VPN work over IPv6, or should I turn IPv6 off at home?
  • What are the keepalive and reconnect settings? Will a gap of a few seconds end my session?
  • Do call apps (Teams, Zoom) go through the VPN or around it (split tunnel)? Calls usually do better around it.
  • Am I allowed to use my own router with the work laptop, or a cellular backup line when the main line drops?
  • Is a personal Residential internet plan fine for work, or does the company want its own account? (See employer-paid setups.)
  • Who do I call when the VPN drops, and what logs do you want from me?

When this is the wrong choice

  • Changing plans to “fix” a laptop VPN. Most client VPNs don’t need a public IP. Find out the VPN type first.
  • Blaming obstructions for drops at fixed times. Check the clock pattern before moving the dish.
  • Using Starlink alone for a site-to-site tunnel built on GRE or IPsec without NAT-T. It’s dropped by CGNAT. Change the tunnel type, or use a wired business line.
  • Relying on IP allow-listing. Starlink addresses change; there’s no static IP.

Questions people ask

Does Starlink block VPNs?

No. Starlink says VPNs over TCP or UDP work, as long as the VPN supports NAT traversal (checked Oct 5, 2026). What fails are older types that rely on raw GRE or ESP packets, such as PPTP and plain L2TP/IPsec.

Do I need a public IP for my work VPN?

Usually not. A normal work VPN connects out from your laptop, and that works behind CGNAT. A public IP matters for site-to-site tunnels or for something that has to connect in to your home. Even then, Starlink says it can’t guarantee VPN compatibility.

Why does my VPN drop when the call doesn’t?

A call app rides out a short gap and keeps going. Some VPN clients treat the same gap as a lost tunnel, tear it down and log in again, which takes longer. A client that reconnects on its own, or a setting that tolerates a few missed keepalives, hides most short outages.

Will Starlink support help with my VPN?

No. Starlink says VPN connection issues fall outside its network support, and the Starlink app may not work properly while a VPN is on (checked Oct 5, 2026). Your IT team owns the VPN; send them the checklist on this page.

Does IPv6 help or hurt a work VPN?

It depends on the VPN. Starlink gives every plan native IPv6, and some VPN clients handle it well. Others leak traffic outside the tunnel over IPv6 or refuse to connect. If your VPN acts oddly, ask IT whether it supports IPv6 or whether you should turn IPv6 off on your own router.

Sources

  1. Does Starlink work with VPNs? (Starlink support), checked Oct 5, 2026
  2. Will enterprise site-to-site VPN or SDWAN appliances work on Starlink? (Starlink support), checked Oct 5, 2026
  3. What are CGNAT session limits and how do they affect my connection? (Starlink support), checked Oct 5, 2026
  4. IP Address (Starlink support), checked Oct 5, 2026
  5. DHCP Configuration (Starlink support), checked Oct 5, 2026
  6. What is the MTU size support for Starlink? (Starlink support), checked Oct 5, 2026
  7. What IP address does Starlink provide? (Starlink support), checked Oct 5, 2026
  8. How can I monitor my Starlink's performance? (Starlink support), checked Oct 5, 2026
  9. Geoff Huston (APNIC), ISP Column: A Transport Protocol's View of Starlink (May 2024) (secondary), checked Oct 5, 2026