Bridge Mode

Multi-Hop Circumvention

Bridge Mode

When direct international VPN connections are blocked, Bridge Mode routes you through a domestic entry server to a foreign exit server, keeping you online during the harshest censorship and internet shutdowns.

0
Entry to Exit
0
Bridge Protocols
0
Bridge Selection
0
Encrypted Tunnel

What Is Bridge Mode?

In the most extreme censorship scenarios, a government does not merely throttle VPN traffic, it blocks all connections to foreign IP addresses outright. A normal VPN cannot help here, because the very first packet to an overseas server never leaves the country.

Bridge Mode solves this with a two-hop architecture. Instead of connecting directly to a server abroad, your device connects to a domestic entry server (the bridge) that is still reachable from inside your country. The bridge then relays your already-encrypted tunnel onward to a foreign exit server of your choice. To the censor, you are only ever talking to a local address; the foreign hop happens server-to-server, out of reach of domestic blocking.

When You Need It

Use Bridge Mode if OrbVPN connects but you have no internet, or if connections to foreign servers time out entirely while local sites still load. These are signatures of IP-level blocking of overseas destinations, exactly what Bridge Mode is designed to defeat.


How Bridge Mode Works

Bridge Mode reverses the usual order of operations. The bridge session is registered before the VPN tunnel is built, so the entry server knows in advance which exit server to forward your traffic to.

1

Register the Bridge Session

OrbVPN first contacts the entry (bridge) server to open a session, telling it your chosen protocol and which foreign exit server you want to reach.

2

Receive Exit Server Details

The bridge responds with the connection details for the exit server, the credentials and parameters your tunnel needs to terminate abroad.

3

Connect to the Domestic Bridge

Your device establishes the VPN tunnel to the domestic entry server, a destination that is still reachable from inside the country.

4

Bridge Forwards to the Exit

The entry server forwards your encrypted traffic on to the foreign exit server, which sends it out to the open internet. Your browsing IP is the exit server's.

The Traffic Path

Your Device

Sees only a domestic IP address as its VPN endpoint. From the network's point of view, you are connecting to a local service, not a foreign one.

Entry (Bridge) Server

A domestic server that remains reachable under blocking. It registers your session and relays your encrypted tunnel onward to the exit you selected.

Exit Server

The foreign server where your tunnel terminates. Your public IP and apparent location come from here, giving you full, unrestricted internet access.

Open Internet

Traffic leaves the exit server to the destination site. The two-hop path stays end-to-end encrypted; no hop can read your data.

Always Encrypted

Bridge Mode never weakens your encryption. Your tunnel stays end-to-end encrypted across both hops. The bridge server forwards opaque, encrypted traffic, it cannot decrypt or inspect what you send.


Supported Protocols

Bridge Mode works across OrbVPN's core protocols. The bridge registers your session with the chosen protocol, then routes accordingly.

WireGuard

The bridge tunnels WireGuard traffic through to the exit server. Fast and modern, ideal when raw speed matters and WireGuard ports survive locally.

VLESS

The bridge uses VLESS routing to forward your traffic to the exit server's outbound. Pairs with Reality and mimicry profiles for maximum DPI resistance.

OrbConnect

OrbVPN's HTTPS-tunnel protocol. The bridge detects the session and forwards packets to the exit server over a resilient, TLS-based path.

Combine With Mimicry and CDN

Because Bridge Mode runs over your normal protocol, it stacks with everything else OrbMesh offers. Run VLESS with a mimicry profile, or layer CDN-fronting on top, so even the first hop to the domestic bridge looks like innocuous everyday traffic.


Enabling Bridge Mode

1

Open Bridge Settings

In OrbVPN, navigate to Settings and open Bridge Mode. This screen controls multi-hop routing for extreme censorship conditions.

2

Toggle Bridge Mode On

Enable the Bridge Mode switch. OrbVPN will now route connections through a domestic entry server before reaching your chosen exit.

3

Choose Automatic or Manual

Leave Auto-Select enabled to let OrbVPN pick the best available bridge for your region, or manually select a specific bridge server from the list.

4

Select Your Exit Server

Pick the foreign exit server whose location and IP you want for your browsing, for example, a server in Western Europe or the United States.

5

Connect

Connect as usual. OrbVPN registers the bridge session, connects to the domestic entry, and the bridge forwards your traffic to the exit. Verify your public IP matches the exit server's location.

Let OrbVPN Choose

Auto-Select is recommended for most users. It picks an online, low-latency bridge that is under capacity, and updates its choice as network conditions change. Manual selection is best when you have tested which specific bridge works most reliably on your connection.


Automatic vs Manual Bridge Selection

Automatic Selection

OrbVPN evaluates all available bridges by status, load, latency, and priority, then connects through the best one. It adapts automatically if a bridge goes offline or fills up.

Manual Selection

Choose a specific bridge server yourself. Useful when you have identified one bridge that consistently performs best on your particular ISP or mobile network.


Bridge Mode and Smart Connect

You do not always have to think about Bridge Mode yourself. When protocol selection is set to Auto (Smart Connect) in a heavily restricted region, OrbVPN already factors multi-hop routing into its decision, racing protocols, transports, and mimicry profiles, then verifying that real traffic flows and your public IP actually changes before declaring success.

Region Awareness

In Iran, Russia, China, and other restricted regions, Smart Connect prioritizes the chains most likely to survive, including bridge routing, CDN-fronting, and Reality.

Shutdown Detection

Smart Connect detects UDP black-holes and total-blackout conditions, then steers toward transports and bridge paths that remain reachable.


Troubleshooting

Connected but No Internet

This is the classic case for Bridge Mode. If you connect directly but get no traffic, enable Bridge Mode so a domestic entry relays you to a foreign exit.

Bridge Won't Connect

Switch from manual to Auto-Select so OrbVPN picks a healthy bridge. If a specific bridge is full or offline, the automatic selector routes around it.

Still Detected by DPI

Pair Bridge Mode with VLESS and a mimicry profile, or add CDN-fronting, so the first hop to the domestic bridge also looks like ordinary allowed traffic.

Not Sure What to Pick

Set protocol to Auto (Smart Connect) and let OrbVPN choose the protocol, transport, mimicry, and bridge path for you, verified against live traffic.

Online Through Any Blackout

Bridge Mode chains a domestic entry server to a foreign exit, defeating IP-level blocking that stops ordinary VPNs cold. Stay connected when it matters most.

Get OrbVPN