Why the protocol matters more than the marketing
Every VPN connection needs a protocol — a set of rules for how your device and the VPN server authenticate each other, agree on encryption keys, and wrap your traffic. Most VPN apps let you pick between two or three protocols in settings, usually WireGuard, OpenVPN, and IKEv2/IPsec. Providers often brand their own variant of one of these (NordLynx is NordVPN’s implementation of WireGuard, Lightway is ExpressVPN’s own protocol built on wolfSSL). The underlying tradeoffs, though, are the same regardless of provider: speed, auditability, firewall traversal, and mobile roaming behaviour.
WireGuard: small codebase, modern cryptography
WireGuard is a comparatively new protocol, first released by Jason A. Donenfeld and merged into the mainline Linux kernel in version 5.6 (2020). Its defining technical feature is size: the reference implementation is a few thousand lines of code, compared to tens of thousands for OpenVPN’s codebase built on OpenSSL. A smaller codebase is easier to audit line-by-line, which is part of why WireGuard has been formally reviewed by academic cryptographers relatively quickly after release.
WireGuard uses a fixed, modern cryptographic suite rather than negotiating between options: the Noise protocol framework for the handshake, Curve25519 for key exchange, ChaCha20 for symmetric encryption, Poly1305 for authentication, and BLAKE2 for hashing. It runs over UDP only — there is no TCP fallback built into the protocol itself, which is the main practical limitation: on networks that block or heavily throttle UDP (some corporate firewalls, some restrictive national networks), WireGuard traffic can be blocked outright unless a provider layers obfuscation on top of it.
OpenVPN: older, slower, but more configurable
OpenVPN has been around since 2001 and remains widely deployed because of its flexibility. It’s built on the OpenSSL library, which means it inherits a large, well-studied but also large attack surface, and it supports a wide range of ciphers rather than a fixed set. The practically important feature is that OpenVPN can run over TCP port 443 — the same port used for ordinary HTTPS web traffic — which makes it harder for a firewall to distinguish OpenVPN traffic from normal encrypted browsing. That’s why OpenVPN (or a provider’s obfuscated variant of it) is still the fallback of choice on networks that actively block VPN traffic.
The tradeoff is speed: OpenVPN’s handshake and per-packet overhead are heavier than WireGuard’s, and independent throughput testing consistently shows it slower, particularly on high-latency or long-distance connections.
IKEv2/IPsec: built for switching networks
IKEv2 (Internet Key Exchange version 2) is defined in IETF RFC 7296 and is typically paired with IPsec for the actual data encryption — the combination is usually written IKEv2/IPsec. Its standout technical feature is MOBIKE (Mobility and Multihoming Protocol), an extension that lets a VPN connection survive a network change — for example, moving from Wi-Fi to mobile data — without dropping and re-establishing the tunnel. That makes it a natural fit for phones, and it has had native OS-level support in iOS since iOS 8, which historically made it battery-efficient there.
IKEv2 doesn’t have OpenVPN’s TCP-443 disguise trick, so it can be blocked by firewalls that specifically target IPsec (UDP 500/4500), and its codebase and negotiation process are more complex than WireGuard’s, though nowhere near OpenVPN’s total surface area.
So which one should you actually pick?
- Default to WireGuard (or a provider’s WireGuard-based protocol) for everyday use. It’s faster and its small codebase means fewer places for bugs to hide.
- Switch to OpenVPN (TCP mode) if you’re on a network that blocks or throttles VPN traffic, since it can travel disguised as normal HTTPS.
- IKEv2/IPsec is a reasonable mobile default if your app offers it and you move between Wi-Fi and cellular a lot, though most modern apps now handle that reconnection reasonably well over WireGuard too.
- None of the three protocols is a marketing gimmick — a provider claiming its own protocol is simply ‘faster and more secure’ with no technical detail is a claim to treat skeptically until they publish what it’s actually built on.
FAQ
Is WireGuard less secure because it’s newer?
Not based on current evidence. Its small size has allowed faster, more thorough academic and independent review than OpenVPN’s much larger codebase has received cumulatively, even though OpenVPN has existed for longer.
Why do some providers rename WireGuard?
Providers like NordVPN (NordLynx) and Surfshark (this varies by provider) wrap WireGuard with their own IP address-handling layer, since stock WireGuard assigns a static internal IP per device that could otherwise be reused across sessions. The underlying cryptography is still WireGuard’s.
Can I just leave my VPN on ‘Automatic’ protocol?
Yes for most people — automatic mode typically tries WireGuard first and falls back to OpenVPN if the network blocks it. Manually choosing OpenVPN TCP is mainly useful if you already know your network is restrictive.
Compare VPN providers side by side