Most VPN apps let you pick a protocol, offer no explanation, and default to something reasonable. The choice does matter, but only along a few axes: speed, behaviour on mobile networks, and whether it keeps working where VPNs are blocked.
Here is what actually distinguishes them.
OpenVPN — the old reliable
OpenVPN has been the default for most of the industry's history. It is mature, extensively audited, and runs essentially everywhere.
Its weakness is age. The codebase is large — on the order of hundreds of thousands of lines — which makes it harder to audit exhaustively and slower in operation. It runs in user space rather than inside the operating system kernel, adding overhead to every packet. On fast connections it is often the bottleneck, and on phones it uses noticeably more battery.
It has one significant practical advantage: it can run over TCP on port 443, the same port as HTTPS. That does not make it invisible to inspection, but it gets through simple port-based filtering on restrictive corporate and hotel networks.
Use it when: compatibility matters more than speed, or when you need the TCP-443 fallback and nothing better is available.
WireGuard — the fast one
WireGuard is a much newer design built on a deliberately narrow foundation: roughly four thousand lines of code, a single modern cipher suite with no negotiation, and operation inside the kernel.
The results are substantial. It is typically several times faster than OpenVPN, uses less battery, and connects almost instantly. Because it is small, it can be meaningfully reviewed in full — a real security property, not just an aesthetic one.
Its most useful practical trait is roaming. WireGuard identifies a connection by its cryptographic keys rather than by the network address, so moving from Wi-Fi to mobile data does not break the tunnel. It simply continues. Anyone who has watched an older VPN drop every time they leave the house will notice this immediately.
There are two trade-offs worth knowing. WireGuard assigns each client a static internal address, and by default keeps the most recent endpoint address in memory — so providers must add a layer to avoid holding data they claim not to keep. Reputable ones do; it is a fair question to ask.
More importantly for some users: WireGuard is easy to identify. Its handshake is distinctive and its packets have a consistent shape. On a network that blocks VPNs, this is the first thing to go.
Use it when: you want speed and reliability, and the network is not actively hostile. For most people, most of the time, this is the right default.
IKEv2/IPsec — the mobile specialist
IKEv2 is built into iOS, Android, Windows and macOS natively, so it needs no third-party client. It is fast, and it handles network changes well, reconnecting quickly when a phone switches networks.
It uses fixed, well-known UDP ports, which makes it trivial to block. It is also less flexible than the alternatives.
Use it when: you want native OS integration without installing anything, on a network that is not filtering.
Stealth and obfuscated protocols — the ones that get through
This is a category rather than a single protocol, covering transports designed around one goal: give a filtering system nothing to act on.
The techniques were covered in more detail in how censorship detects a VPN, but in summary they combine some of:
- Imitating ordinary HTTPS precisely, including the cipher list and extension ordering a real browser would send, so that fingerprint comparison fails to distinguish them.
- Removing structure from the wire by randomising initial bytes and padding packet lengths, defeating the size-and-timing signatures that identify tunnels.
- Refusing to respond to unauthenticated probes, so a censor that connects to the server to test it gets what a boring web server would return, and learns nothing.
- Rotating entry points, so scraped address lists go stale.
The cost is real: obfuscation adds overhead, so a stealth protocol is slower than raw WireGuard. That is the trade. You are buying reachability with throughput.
Use it when: you are on a national firewall, a corporate network that blocks VPNs, or any connection where the standard protocols connect for a while and then stop working. On restrictive networks this is not a preference — it is the difference between a working connection and none.
What to actually do
Default to WireGuard. Best speed, best battery, best roaming behaviour. If your provider offers it, this should be your normal setting.
Switch to a stealth protocol when the connection starts failing. If the VPN connects and then drops, or refuses to connect on one specific network while working elsewhere, you are being filtered. That is what stealth transports are for.
Keep OpenVPN over TCP 443 as a fallback for awkward networks where nothing else is permitted.
Do not agonise over cipher choice. All the mainstream protocols use strong, modern cryptography. Nobody is breaking AES-256 or ChaCha20. The realistic threats are leaks, logging and endpoint compromise — not the encryption itself.
The protocol determines how fast the tunnel is and whether it survives a hostile network. It does not determine whether the operator on the other end keeps records of what you did. That part is a policy question, and no protocol answers it for you.