WireGuard, OpenVPN and the rest
Which protocol to pick, in one paragraph, plus why if you want it — including how many devices each one covers.
Published 2026-09-26 · updated 2026-09-28
Short answer: use WireGuard. If something blocks it, use OpenVPN. That is genuinely the whole decision for almost everybody.
If you want to know why, read on.
WireGuard
The modern one, and what we use by default. Its defining feature is size: roughly 4,000 lines of code against OpenVPN's several hundred thousand. That matters because code that does not exist cannot have a flaw in it, and because a small codebase can actually be reviewed by humans.
In practice it is faster, it uses less battery, and it reconnects almost instantly when you change network — which is why it feels so much better on a phone.
Its one design quirk: it was not built to hide the fact that it is a VPN. On a network that is actively blocking VPN traffic, it is easier to spot.
OpenVPN
The old workhorse, around since 2001, audited to death, and supported by everything. Slower and heavier, particularly on mobile, because it is doing more work in more places.
Its advantage is disguise. Run over TCP on port 443 it looks much like ordinary HTTPS traffic, which is why it still gets through restrictive networks that WireGuard does not. If you are on a corporate or hotel network that blocks VPNs, this is the one to try.
IKEv2/IPsec
Fast, stable, and excellent at surviving a switch from Wi-Fi to mobile data without dropping. Built into iOS and Windows, so it needs no app. A perfectly good choice on an iPhone. Less flexible than the other two, and more often blocked.
VLESS
The specialist. Where the other three are trying to carry your traffic securely, VLESS is trying to carry it *unnoticed* — it travels inside what looks like an ordinary HTTPS connection to an unremarkable website, so there is no VPN-shaped handshake to spot.
You want this in exactly one situation: a country that filters internet traffic and blocks VPNs, such as China, Iran or Russia. It is slower than WireGuard and needs a different app, so it is the wrong choice anywhere else. See will my VPN work in China?
How many devices each one covers
This one surprises people, and it is worth knowing before you set up four devices and wonder why they keep dropping.
A VPN account normally has one WireGuard key and one tunnel address. A WireGuard connection serves one of those at a time, so on WireGuard it is one device at a time — connect the laptop and the phone drops off.
The other protocols do not work that way. On OpenVPN or VLESS, one account carries several devices at once — with Veystrix, up to ten.
So the practical arrangement for most households is: WireGuard on the one device where you care about speed, OpenVPN on everything else. Same account, same subscription, no extra cost.
The ones to avoid
PPTP. Broken since the 1990s. Its encryption can be cracked in hours. If an app still offers it, that tells you something about the app.
L2TP/IPsec. Not broken, but slower than IKEv2 with no compensating advantage. No reason to pick it today.
So
Default to WireGuard. Keep OpenVPN as the fallback for networks that fight you. On an iPhone, IKEv2 is a fine built-in option. Ignore PPTP entirely.
And if your provider only offers PPTP or L2TP, the protocol is not really your problem.
See plans Free, and it needs no account.