What is a VPN, and why does it sometimes hurt calls?
A VPN is an encrypted "tunnel" that sends a computer's traffic through another server, such as the office network. It is useful for working from home and for security, but for calls it lengthens the route, adds overhead and sometimes disrupts the connection to the PBX server. With a cloud PBX, you usually do not need a VPN to make calls from home.
What is a VPN
A VPN (Virtual Private Network) creates an encrypted connection between your computer and a certain server, and passes your traffic through it. From the outside, you only see an encrypted "pipe"; what travels inside is hidden.
Think of a courier who takes all your letters in a locked bag, drives them to the office's post branch, and from there they are sent to their destinations. The letters are protected along the way — but every letter now takes a longer route.
There are two main uses: a corporate VPN — so an employee at home can reach the office's servers and folders as if sitting there; and a commercial VPN — a service that routes your browsing through a server in another country, in the name of privacy.
It is important to understand: a VPN does not make the connection faster, and does not improve line quality. It adds a layer of protection and changes the route the data takes. Sometimes that is exactly what you need — and sometimes, for calls, it is an unnecessary cost.
Why calls and a VPN don't always get along
- A longer route — instead of going from home straight to the PBX server, every voice packet first goes to the VPN server and only from there to its destination. If the VPN server is in a distant country, the ping can jump by tens or even hundreds of milliseconds.
- Overhead — every packet is wrapped in another layer of encryption and headers. For voice packets, which are very small, this is a relatively large addition.
- A bottleneck — all of the employee's traffic, including updates and downloads, goes through the same tunnel. A busy VPN server delays the voice too.
- Connections that close — some VPN services and firewalls along the way close quiet connections too fast. The phone loses its registration, and incoming calls do not arrive.
- A tunnel inside a tunnel — many PBXs already encrypt the call themselves. An extra VPN adds work without adding much protection.
Cloud PBX: why you usually don't need a VPN for calls
With an old PBX that sits in a cabinet in the office, an employee at home had to "get into" the office network to talk — so a VPN was the only way. With a cloud PBX, it is the opposite: the server is not in the office at all, but on the internet. The phone in the office and the softphone at home connect to the same server in the cloud, each from its own network.
So an employee at home only needs a reasonable internet connection. If he has a corporate VPN for the office's files and programs, it is better that calls do not go through it, but directly to the PBX server.
| PBX in the office | Cloud PBX | |
|---|---|---|
| Where the server is | In a cabinet in the office | On servers on the internet |
| Extension from home | Usually through a VPN to the office | Directly to the server, no VPN |
| If the office internet goes down | The employee at home is cut off too | The employee at home keeps working |
| The voice's path | Home → Office → World | Home → Cloud → World |
Split Tunneling — only what's needed inside the tunnel
Most corporate VPN systems let you set what goes through the tunnel and what does not. The setting is called Split Tunneling. For example: everything meant for the office servers goes through the VPN, and everything else — including calls — goes straight out to the internet.
This is usually the best way to combine a VPN and telephony: the employee gets secure access to files, and his calls don't travel a long route. The setting is made by the organization's network administrator, according to its security policy.
Some organizations prefer, for security reasons, that all traffic go through the tunnel. That is a legitimate decision, and in that case it is worth making sure the VPN server is close and stable, with enough bandwidth for the calls of all employees.
Commercial VPN on a cell phone — the problem you don't see
Commercial VPN apps are installed on many cell phones today, sometimes without the phone's owner even remembering. They send all traffic — including the softphone — through a server that is sometimes chosen in a distant country.
The signs: calls on the softphone are delayed (people talk over each other), the voice cuts out, or the softphone connects and disconnects on and off. When the VPN is turned off, everything goes back to normal.
Another problem: some VPN services change the phone's outgoing address with each connection. If the organization restricts access by IP address, such a change can block the employee from connecting.
If you must have a VPN on a cell phone, choose a nearby server, and check whether the app lets you exclude the softphone from the tunnel.
VPN and filtering
In a community that works with filtered internet, it is important to know that installing a commercial VPN can take browsing outside the filter, so many filtering providers block it or ask that it not be used. This is not only a technical matter — it is a matter of household and organizational policy.
Telephony does not need such a VPN. A PBX that is adapted to filtering works through the regular filtered connection, and this is the simple, stable situation. A corporate VPN for access to the office servers is a different subject, which the network administrator and the filtering provider decide on together.
How to check whether the VPN is the problem
- Turn the VPN off for a moment and make a test call. If the call sounds better — you found it.
- Ping a known server with the VPN and without it, and compare. A difference of tens of milliseconds is a clear sign.
- tracert with the VPN shows only the VPN server — without it you see the real route.
- Check the split settings — if there is Split Tunneling, make sure the softphone does not go into the tunnel.
- Ask the network administrator — if the VPN is corporate, he knows what goes through it and why.
A field example: the agent who sounded "like he was in space"
At an insurance services business (fictitious name: "Magen Insurance"), an agent named Yosef started working two days a week from home, with a softphone on his laptop. Customers complained about a strange delay in the call, "like a broadcast from space".
The laptop had an old corporate VPN installed, set to send all traffic through a parent company's server abroad. The ping from there reached 280 ms. The network administrator set up split tunneling, so calls go out directly, and the ping dropped to 30. Customers stopped noticing anything different.
Working from home without a VPN — what you do need
For an employee to talk from home as a regular extension of the office, in most cases this is enough:
- A stable internet connection — preferably wired, with an upload speed of at least a few megabits.
- An extension — a softphone on a computer or cell phone, or a desk phone connected to the home router.
- A headset — so that people at home are not heard in the background, and the voice is clear.
- A correctly configured router — SIP ALG off, and a long enough hold time for UDP connections.
Someone who also needs access to the office's files and programs will use a VPN for those — and it is better for calls to go out separately. More details in the article on remote work.
How a VPN works, a bit deeper
When the VPN is on, the computer gets an additional address — an "internal" address on the VPN server's network — and from then on it behaves as if it sits on that network. Every packet it sends is packed inside another packet, encrypted, and sent to the VPN server. There it is opened and sent on its way, as if it had been sent from there.
From the PBX server's point of view, the call does not come from the employee's home but from the VPN server's address. So any restriction or setting by address sees the VPN server and not the employee.
In addition, inside the tunnel there is sometimes a limit on packet size (MTU). Packets that are too big are split in two or dropped. In the call itself the packets are small, but the phone's registration and dialing messages are larger — and sometimes it is precisely they that get stuck, with the result that the phone "doesn't register" only when the VPN is on.
VPN between branches
Organizations with several branches sometimes connect the branch networks with a permanent VPN between the routers (Site-to-Site), so that everyone works on the same servers. With a cloud PBX there is no need for this for the phones: each branch connects to the cloud server separately, and the extensions of all branches talk to each other through the PBX as if they sat in the same building.
If the VPN between the branches already exists for other things, it is worth making sure the phones of each branch go straight out to the internet, and not through the main branch. Otherwise, a line failure at the main branch could shut down the phones in all branches.
What to ask your network administrator
- That calls (or the softphone app) go out outside the tunnel, if the policy allows.
- If not — that the VPN server be close, stable, with free bandwidth for calls.
- That the connection hold time in the firewall not be too short, so the phone does not lose its registration.
- To check that there is no packet size (MTU) problem in the tunnel.
- A test call after every change to the VPN settings — incoming and outgoing.
How it works with us at Kesher
Kesher's PBX is cloud-only. An employee at home connects directly to the servers, like the phone in the office, so there is no need for a VPN to talk as an extension from home.
Our extension types suit working from anywhere: an IP phone, a softphone on a computer or cell phone, and a SIM extension — a SIM card that behaves as an extension, with no app and no internet, which also suits a kosher phone.
The system is fully adapted to NetFree and other filters, and works through the regular filtered connection. Customers who want to restrict access to the control panel can use IP-address access restrictions.
Our recommendations for the router, at home too: SIP ALG off and a UDP timeout of 180 seconds. When there is a problem, a person at our company answers and helps check — not an automated answer and not a queue for an agent.
FAQ
Do I need a VPN to talk from home as an office extension?
With a cloud PBX — usually not. The extension connects directly to a server on the internet, just like in the office.
Since I installed a VPN, calls are delayed. Why?
Every voice packet now goes through the VPN server, and sometimes it is far away. Try turning it off or excluding the softphone from the tunnel.
What is Split Tunneling?
A setting that decides that only part of the traffic goes through the VPN. That way the office files go through the tunnel, and calls go out directly.
Doesn't a VPN add security to calls?
It encrypts the route up to the VPN server. But many PBXs encrypt the call themselves, and beyond that the VPN mostly just lengthens the route.
I have a VPN on my cell phone and I don't know why. Does it interfere?
It can. If calls on the softphone sound bad, check which app is running a VPN and whether it is needed.
Can a VPN affect filtering?
A commercial VPN can take browsing outside the filter, so many filtering providers block it. Calls don't need it.
Which is better for working from home — a softphone or a desk phone?
Both work. Someone who talks a lot will benefit from a desk phone wired to the home router; someone who moves from place to place will prefer a softphone.
If the company VPN is mandatory, what can be done?
Ask the network administrator to exclude calls from the tunnel, or make sure the VPN server is close and has enough bandwidth for calls.
The phone registers only when the VPN is off. What is the reason?
Usually one of two things: the VPN blocks or filters the traffic to the PBX server, or the packet size in the tunnel (MTU) is too small and the large registration messages get stuck. The network administrator can check both.
Does a VPN also affect incoming calls?
Yes. If the connection in the tunnel is closed when it is quiet, the phone loses its registration and incoming calls do not reach it until it reconnects. That is why it is important that the connection hold time be long enough.