◈ netchecks.org

17 checks · no account · self-hosted

Test your network in one click

17 free network diagnostic tools in one dashboard.

FAQ

0 trackers · 14 languages · dark & light mode · self-hosted

← All articles

Network history

The Rise of the VPN: From Dial-Up Tunnels to WireGuard and Zero Trust

A VPN's core idea has not changed since the mid-1990s: wrap traffic in an encrypted tunnel so it can cross a network you do not trust - typically the public Internet - while behaving as if it were still on the private network at the other end. What has changed dramatically, generation after generation, is how that tunnel is built, how strong its encryption is, how fast it runs, and eventually, whether the whole concept of a single trusted 'inside' the tunnel still makes sense at all.

That evolution tracks almost exactly against the Internet's own growth from a curiosity to critical infrastructure: each new protocol generation exists because the previous one's weaknesses became too expensive, too slow, or too insecure to keep tolerating at the new scale.

  1. 1996

    PPTP is developed

    Microsoft and a consortium of vendors create the Point-to-Point Tunneling Protocol, the first widely deployed consumer/enterprise VPN protocol, built into Windows 95's OSR2 update.

  2. 1999

    L2TP is standardized

    Layer 2 Tunneling Protocol (RFC 2661) combines the best ideas of PPTP and Cisco's L2F, but has no built-in encryption of its own - it is almost always paired with IPsec.

  3. 1998-2005

    IPsec matures

    The IPsec suite (RFC 2401 and successors) becomes the enterprise standard for site-to-site VPNs, providing strong, standardized encryption and authentication at the network layer.

  4. 2001

    OpenVPN is released

    James Yonan releases OpenVPN, an open-source SSL/TLS-based VPN that runs over standard UDP or TCP - easy to firewall-traverse and free from any single vendor's control.

  5. 2002-2003

    SSL VPNs go mainstream

    SSL/TLS-based 'clientless' VPNs (accessible from a browser) emerge as a lighter alternative to IPsec for remote-access use cases, avoiding IPsec's notorious firewall/NAT traversal headaches.

  6. 2005

    IKEv2 is published

    RFC 4306 (later RFC 7296) modernizes IPsec's key exchange, adding fast reconnection after a dropped connection - the feature that made IPsec genuinely usable on mobile devices switching between WiFi and cellular.

  7. 2012

    WireGuard development begins

    Jason A. Donenfeld starts designing WireGuard around a radical goal: a fraction of the code size of IPsec or OpenVPN, using a small, fixed set of modern cryptographic primitives instead of dozens of negotiable, sometimes-outdated options.

  8. 2018

    Linus Torvalds merges WireGuard into Linux

    WireGuard enters the Linux kernel mainline, a strong technical endorsement, and rapidly becomes the reference implementation for a new generation of fast, minimal VPN protocols.

  9. 2020

    Zero Trust goes mainstream

    NIST publishes SP 800-207, formalizing the Zero Trust Architecture model: verify every request individually regardless of network location, rather than trusting anything already 'inside' a VPN tunnel.

  10. 2020-2024

    SASE and ZTNA displace classic remote-access VPN

    Secure Access Service Edge and Zero Trust Network Access platforms increasingly replace always-on, full-network VPN access with per-application, continuously verified access - the direct architectural response to VPN's long-standing 'once you're in, you're trusted everywhere' weakness.

Why VPNs exist at all

Before broadband and cloud services, reaching a corporate file server or mainframe from outside the office meant a direct dial-up modem connection into a bank of remote-access servers - reliable but expensive to scale and entirely dependent on phone infrastructure. As the public Internet became cheap and ubiquitous in the mid-1990s, the obvious next step was to reuse it as the transport, but that only works if the traffic crossing it is protected from the untrusted networks in between - which is exactly the problem PPTP was built to solve in 1996.

Every VPN protocol since has been solving some combination of the same three problems: how to build the tunnel, how to prove both ends are who they claim to be, and how to encrypt what flows through it - with each generation making different tradeoffs between security strength, connection speed, and how well it survives firewalls, NAT, and unreliable networks.

A VPN wraps a client's traffic in an encrypted tunnel across an untrusted network (typically the public Internet) to a gateway, which then forwards it onto the private network as if the client were directly attached.

The first generation: PPTP, L2TP, and IPsec

PPTP was fast and simple to set up - genuinely groundbreaking for 1996 - but its encryption (Microsoft's MS-CHAP-based scheme) was progressively broken by researchers over the following decade and is now considered insecure for anything sensitive. L2TP, standardized in 1999, fixed PPTP's tunneling design but deliberately left out encryption entirely, on the assumption it would always be paired with a separate encryption layer.

That layer was IPsec, and the combination of L2TP for tunneling plus IPsec for encryption became the de facto enterprise standard through the 2000s. IPsec's strength was operating at the network layer, meaning it could secure any IP traffic transparently without any application even being aware of it - but that same low-level design made it notoriously difficult to get through firewalls and NAT devices, a persistent operational headache for anyone deploying it at scale.

SSL VPNs and OpenVPN: solving the firewall problem

The mid-2000s answer to IPsec's traversal problems was to build VPNs on top of SSL/TLS instead - the same protocol securing HTTPS traffic, which every firewall on Earth already had to let through on port 443. 'Clientless' SSL VPNs, accessible straight from a browser, made remote access dramatically simpler to deploy for basic use cases, while OpenVPN (released in 2001, but reaching wide enterprise adoption through this period) offered the same SSL/TLS-based approach as a full, flexible, open-source tunnel that could run over either UDP or TCP.

OpenVPN's open-source nature mattered as much as its technical design: unlike IPsec's dozens of vendor implementations with inconsistent interoperability, or PPTP's Microsoft-controlled evolution, anyone could audit, extend, or embed OpenVPN, and it became the default choice for consumer VPN services and self-hosted deployments alike for the better part of two decades.

WireGuard and the move toward radical simplicity

By the 2010s, IPsec and OpenVPN both carried real technical debt: large codebases (tens of thousands of lines), dozens of negotiable cryptographic algorithms (several since deprecated as insecure), and correspondingly large attack surfaces. WireGuard's answer, starting in 2012, was almost the opposite design philosophy: roughly 4,000 lines of code, a single fixed, modern cryptographic suite with no negotiation, and a connectionless design built around the same principles as SSH's key-based authentication rather than certificate hierarchies.

The result measurably outperforms both predecessors on speed and battery life on mobile devices, while its small codebase is genuinely auditable in a way IPsec's implementations never realistically were - which is exactly why Linus Torvalds merged it directly into the Linux kernel in 2018, an endorsement almost no other VPN protocol has received.

The next shift: from VPN to Zero Trust

Every protocol generation up to this point solved how to build a better tunnel. The most recent shift questions the tunnel model itself: a classic VPN grants broad access to an entire private network once a user authenticates, which means a single compromised laptop or stolen credential can move laterally across everything that network reaches - a weakness behind a long list of major breaches.

NIST's 2020 Zero Trust Architecture framework (SP 800-207) reframes the problem: instead of one strong perimeter check followed by implicit trust, verify every single request independently, regardless of whether it originates 'inside' or 'outside' any tunnel. Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) platforms implement that model in practice, granting access per application rather than to the whole network - not a replacement for the encryption VPNs pioneered, but a fundamentally different answer to the access-control question a VPN alone was never actually designed to solve.

The takeaway

Encryption strength was never really the bottleneck in this history - AES has been considered sound for decades. What actually changed, generation after generation, was operational reality: making tunnels traverse real-world firewalls and NAT (SSL VPN, OpenVPN), making reconnection survivable on flaky mobile networks (IKEv2), making the whole implementation small enough to actually audit (WireGuard), and finally questioning whether 'inside the tunnel' should ever again mean 'implicitly trusted' (Zero Trust). Each generation is a direct answer to the previous one's most painful real-world limitation, not a purely academic improvement.

← All articles

My IP Check

Your public IP address and network location, detected automatically.

Loads automatically when you open NetChecks — no input needed. Use the Refresh button to re-check after switching networks or reconnecting your VPN.

Your browser

All-in-One Scan

Runs every relevant check against one IP or hostname in a single pass: DNS, whois, ping, traceroute, a well-known-ports scan (1-1024), HTTP headers and the SSL certificate.

Enter a domain or IP address and run it to check DNS, whois, ping, traceroute, common ports, HTTP headers, and the SSL certificate all at once.

Most checks run in parallel - typically finishes in about 30 seconds, longer if the target is slow or unreachable.

The port scan step only runs once the consent checkbox above is checked - every other check runs regardless.

Ping

Send ICMP echo requests to a host to check reachability and latency.

Enter a hostname or IP address and press Ping to send ICMP echo requests and measure round-trip latency.

You Host ICMP Echo Request (type 8) ICMP Echo Reply (type 0) measures: RTT · TTL · packet loss

      

Learn more about Ping

What it is

Ping sends ICMP Echo Request packets to a host and measures how long it takes for ICMP Echo Reply packets to come back. It is the most basic network connectivity test there is: it answers exactly one question, "is this machine reachable, and how quickly?" The ICMP protocol (RFC 792) was designed back in 1981 specifically to carry control and diagnostic messages over IP networks, outside of any application traffic - Ping is its best-known and most universally available implementation, present on virtually every operating system and network device since their earliest versions.

How it works

Every ICMP packet carries a TTL (Time To Live) field decremented by one at each router it crosses; if it hits zero before reaching the target, the packet is dropped and an error is sent back to the sender. The round-trip time (RTT) measured in milliseconds reflects the cumulative network latency over the entire round trip, not just the last leg near the target - a point that is often misunderstood, since slow ping results can have their root cause anywhere along the path, not necessarily near the server being tested. A ping typically sends several packets in a row rather than just one, which lets you tell a one-off latency spike apart from a recurring problem and calculate a packet loss rate over the sample.

Reading the results

A stable, low RTT - a few milliseconds on a local network, 10 to 50 ms for a destination within the same country, and noticeably more for an intercontinental link - indicates a healthy connection. Even a small amount of packet loss (above 1-2%) is particularly damaging for latency-sensitive uses like VoIP or interactive remote sessions, where every dropped packet shows up as a glitch or audible cutout. Highly variable latency from one packet to the next (jitter) is often more of a problem for these same use cases than latency that is high but perfectly stable. "Request timed out" means no reply arrived within the allotted time - the host could genuinely be down, a firewall could be silently blocking ICMP, or a route could be broken somewhere along the path; "Destination unreachable" is different and more informative: an intermediate router explicitly sent back a message saying it could not forward the packet, which helps narrow down where the problem actually sits.

Common mistakes

The most common misreading is concluding a host is "down" the moment a ping fails, when in fact a great many servers and devices - especially behind a properly hardened firewall, or hosted with major cloud providers - deliberately block inbound ICMP as a matter of policy while being fully operational and reachable on their actual services (HTTP, a database, and so on). A missing ping reply is therefore only meaningful evidence of downtime when combined with other signals, such as the application itself also failing to respond. Conversely, a successful ping is no guarantee whatsoever that the application service hosted on that machine is working correctly - these are two entirely independent layers of the network stack.

When to use it

The first thing to check before escalating a ticket: does the machine respond at all, before digging any further? Confirming connectivity after a firewall rule or routing table change, to make sure the change did not break access. Establishing a baseline latency measurement before a VoIP rollout or a carrier link failover, so there is an objective point of comparison if call quality complaints come in later. A lightweight, low-overhead periodic health check for an MSP monitoring several client sites in parallel, always as a complement to - never a replacement for - deeper application-level monitoring.

Traceroute

Trace the network path (hop by hop) to a destination host.

Enter a hostname or IP address and run it to see every network hop between this server and the destination, with latency per hop.

You TTL=1 TTL=2 TTL=3 Host each hop replies "ICMP Time Exceeded" until TTL reaches the host

      

DNS Lookup (Nslookup)

Query DNS records: A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, CAA.

Enter a domain, choose a record type (A, AAAA, MX, TXT, NS, CNAME, SOA, PTR, SRV, or CAA), then look it up.

You Root .com Auth NS ① query root ② referral → TLD ③ referral → auth NS ④ answer

      

Whois

Look up registration information for a domain or IP address.

Enter a domain or IP address to look up its registration details — registrar, owner organization, and important dates.

You Registry RDAP / :43 query: domain / IP reply: registrar, dates, name servers

      

Blacklist Check

Check whether an IP address or domain is listed on public spam/abuse blocklists (DNSBL).

Enter an IPv4 address or domain and run it to check 7 public DNSBL/RBL blocklists at once - each shows as listed, not listed, or check failed.

You zen.spamhaus.org spamcop.net sorbs.net +4 more reverse-IP DNS query to each DNSBL zone, in parallel

      

TCP Port Scan

Check whether TCP ports are open on a host or IP: common ports, a custom list, or the full 1-65535 range.

Enter a host or IP, pick common ports, a custom list, or the full range, then scan to see which TCP ports respond.

You 22 open 443 open 3389 closed 8080 closed SYN → SYN-ACK = open · SYN → RST = closed

        
      

HTTP Header Inspector

Fetch the HTTP response status and headers for a URL.

Enter a URL to fetch its HTTP response status code and every response header the server sends back.

You Server GET / HTTP/1.1 200 OK + headers Content-Type · Strict-Transport-Security · X-Frame-Options …

      

SSL / TLS Certificate Checker

Inspect a host's TLS certificate: issuer, validity dates, and days remaining.

Enter a hostname to inspect its TLS certificate — issuer, validity dates, and days remaining before it expires.

You Host ClientHello → ← ServerHello + Certificate + Finished Root CA Intermediate Leaf (site) certificate chain of trust · validity dates checked

      

Geo-IP Lookup

Look up the geographic location and network info for an IP address. Leave empty to look up your own public IP.

Enter any IP address, or leave it empty to look up your own, to see its approximate location and network/ISP info.

IP address Geo / RIR database City · Country ASN · Org

Subnet / CIDR Calculator

Computed entirely in your browser — no data sent to the server.

Enter an IP address and CIDR prefix (e.g. 192.168.1.0/24) to instantly compute the network range, broadcast address, and usable host count.

network bits (prefix) host bits /24 example — split moves with your prefix

      

Speed Test

Basic download/upload throughput test against this server (accuracy depends on the server's own uplink).

Press Start to measure download and upload throughput against this server. Accuracy depends on this server's own connection.

You Server ↓ download ↑ upload throughput (Mbps)

      

Country Code Dictionary

ISO 3166-1 alpha-2 country codes — searched entirely in your browser.

Search or browse the list of ISO 3166-1 alpha-2 country codes, looked up entirely in your browser.

CountryISO Code

Phone Dialing Code Dictionary

International calling codes by country — searched entirely in your browser.

Search or browse international calling codes by country, looked up entirely in your browser.

CountryDial Code

World Clock

Pick a time zone to see the current time — drag the globe to spin it.

Pick a time zone from the list, or drag the globe, to see the current time there.

Your time
--:--:--
—

—

Selected time
--:--:--
—
— UTC±00:00
Difference vs. you —

—

Drag to rotate the globe.

French Mobile Network Status

Mobile antenna sites down or under maintenance in France, by operator (Orange, Free, SFR, Bouygues Telecom), from ARCEP's public data. Snapshot updated once a day by ARCEP - not a minute-by-minute feed.

Browse mobile antenna and fibre outage data by French operator — no input needed, updated automatically from ARCEP's public data.

Source: ARCEP, "Sites indisponibles" dataset, published under Licence Ouverte / Etalab 2.0 - commercial reuse explicitly allowed, unlike the IODA/CAIDA data this tab used before. The Normal/Watch/Alert badge is an in-house estimate (today's outage count vs. the median of prior days), not an official ARCEP classification. Source links below.

Most affected departments

Number of sites currently down or under maintenance, by department. Click an operator above to filter.

Data: Arcep — Sites indisponibles · Official network status map


Fixed Network (Fibre)

Fibre (FTTH) network quality by operator: reported-outage rate and connection-failure rate, from ARCEP's public data. Monthly indicators, 6-month rolling average - not a live feed like the mobile section.

Source: ARCEP, "Qualité des réseaux en fibre optique" dataset, published under Licence Ouverte / Etalab 2.0 - commercial reuse explicitly allowed. Source links below.

By operator (parent group)

Averages over the last 6 available months, per infrastructure-operator parent group.

Data: Arcep — Qualité des réseaux en fibre optique