Home / Blog / WireGuard vs OpenVPN vs Stealth Protocols: Which One Should You Actually Use?
Korp Labs · Field Notes

WireGuard vs OpenVPN vs Stealth Protocols: Which One Should You Actually Use?

 ·  4 min read  ·  By Korp VPN

Most VPN apps let you pick a protocol, offer no explanation, and default to something reasonable. The choice does matter, but only along a few axes: speed, behaviour on mobile networks, and whether it keeps working where VPNs are blocked.

Here is what actually distinguishes them.

OpenVPN — the old reliable

OpenVPN has been the default for most of the industry's history. It is mature, extensively audited, and runs essentially everywhere.

Its weakness is age. The codebase is large — on the order of hundreds of thousands of lines — which makes it harder to audit exhaustively and slower in operation. It runs in user space rather than inside the operating system kernel, adding overhead to every packet. On fast connections it is often the bottleneck, and on phones it uses noticeably more battery.

It has one significant practical advantage: it can run over TCP on port 443, the same port as HTTPS. That does not make it invisible to inspection, but it gets through simple port-based filtering on restrictive corporate and hotel networks.

Use it when: compatibility matters more than speed, or when you need the TCP-443 fallback and nothing better is available.

WireGuard — the fast one

WireGuard is a much newer design built on a deliberately narrow foundation: roughly four thousand lines of code, a single modern cipher suite with no negotiation, and operation inside the kernel.

The results are substantial. It is typically several times faster than OpenVPN, uses less battery, and connects almost instantly. Because it is small, it can be meaningfully reviewed in full — a real security property, not just an aesthetic one.

Its most useful practical trait is roaming. WireGuard identifies a connection by its cryptographic keys rather than by the network address, so moving from Wi-Fi to mobile data does not break the tunnel. It simply continues. Anyone who has watched an older VPN drop every time they leave the house will notice this immediately.

There are two trade-offs worth knowing. WireGuard assigns each client a static internal address, and by default keeps the most recent endpoint address in memory — so providers must add a layer to avoid holding data they claim not to keep. Reputable ones do; it is a fair question to ask.

More importantly for some users: WireGuard is easy to identify. Its handshake is distinctive and its packets have a consistent shape. On a network that blocks VPNs, this is the first thing to go.

Use it when: you want speed and reliability, and the network is not actively hostile. For most people, most of the time, this is the right default.

IKEv2/IPsec — the mobile specialist

IKEv2 is built into iOS, Android, Windows and macOS natively, so it needs no third-party client. It is fast, and it handles network changes well, reconnecting quickly when a phone switches networks.

It uses fixed, well-known UDP ports, which makes it trivial to block. It is also less flexible than the alternatives.

Use it when: you want native OS integration without installing anything, on a network that is not filtering.

Stealth and obfuscated protocols — the ones that get through

This is a category rather than a single protocol, covering transports designed around one goal: give a filtering system nothing to act on.

The techniques were covered in more detail in how censorship detects a VPN, but in summary they combine some of:

The cost is real: obfuscation adds overhead, so a stealth protocol is slower than raw WireGuard. That is the trade. You are buying reachability with throughput.

Use it when: you are on a national firewall, a corporate network that blocks VPNs, or any connection where the standard protocols connect for a while and then stop working. On restrictive networks this is not a preference — it is the difference between a working connection and none.

What to actually do

Default to WireGuard. Best speed, best battery, best roaming behaviour. If your provider offers it, this should be your normal setting.

Switch to a stealth protocol when the connection starts failing. If the VPN connects and then drops, or refuses to connect on one specific network while working elsewhere, you are being filtered. That is what stealth transports are for.

Keep OpenVPN over TCP 443 as a fallback for awkward networks where nothing else is permitted.

Do not agonise over cipher choice. All the mainstream protocols use strong, modern cryptography. Nobody is breaking AES-256 or ChaCha20. The realistic threats are leaks, logging and endpoint compromise — not the encryption itself.

The protocol determines how fast the tunnel is and whether it survives a hostile network. It does not determine whether the operator on the other end keeps records of what you did. That part is a policy question, and no protocol answers it for you.

vpn guidewireguardopenvpnstealth protocol

Read this on a network nobody is watching

Korp VPN encrypts every packet leaving your device with AES-256 and a stealth protocol that looks like ordinary HTTPS traffic. Unlimited bandwidth, 20+ countries, a strict no-logs policy, and a 5-day free trial — from $1.60 per month.

← Previous
Colonial Pipeline: One Old Password Shut Down Fuel for the US East Coast
Next →
Could Smarter AI Threaten Humanity? The Debate Behind the Headlines

More from Korp Labs

What "No-Logs VPN" Really Means and How to Check the Claim

Almost every VPN says it keeps no logs. The phrase can mean very different things. Here is what a meaningful no-logs policy covers, and the questions that expose a weak one.

VPN vs Proxy vs Tor: What Each One Actually Protects

They all change your IP address, but they protect very different things. A plain-language comparison of VPNs, proxies and Tor, and how to pick the right one for what you are doing.

How to Test Your VPN for Leaks: DNS, IPv6 and WebRTC

A VPN can be connected and still leak your real IP address or DNS lookups. Here is how to run the three tests that matter in under five minutes, and how to fix what you find.