This material explains lawful network security and configuration scenarios. Follow the rules that apply in your location.
WireGuard vs OpenVPN: the short answer
On phones and laptops, WireGuard (or a protocol built on it) is usually the better default. It connects faster, adds less overhead to each packet, copes well when you switch between Wi-Fi and mobile data and tends to be easier on the battery. OpenVPN still makes sense when you need what WireGuard leaves out on purpose: TCP transport, logins tied to an existing certificate or user database, settings pushed from the server and two decades of enterprise tooling.
Neither protocol is insecure when it is up to date and configured properly. The real difference is philosophy: WireGuard removes choices so there is less to get wrong, while OpenVPN offers choices so it can fit almost any setup.
| Aspect | WireGuard | OpenVPN |
|---|---|---|
| Transport | UDP only | UDP (default) or TCP |
| Typical port | No official default; 51820 in most examples | 1194 (IANA-registered); sometimes run on TCP 443 |
| Cryptography | Fixed: Curve25519, ChaCha20-Poly1305, BLAKE2s | Negotiated; AES-GCM or ChaCha20-Poly1305 on current versions |
| Code size | Under 4,000 lines (Linux implementation) | Far larger, plus an external TLS library |
| Where it runs | Kernel on Linux, Windows and BSD; userspace elsewhere | Userspace; optional kernel data channel offload since 2.6 |
| Authentication | Public keys, plus an optional pre-shared key | Certificates, username and password, plugins |
| Network changes | Carries on from the new address | Often reconnects with a new TLS handshake |
| Traffic when idle | None, unless a keepalive is set | Pings in typical configs; rekeying every hour |
Architecture and code size
OpenVPN is a userspace program built around two channels. The control channel is a TLS session that authenticates both sides and agrees on keys; the data channel carries your encrypted packets. On top of TLS, OpenVPN adds hundreds of its own options, from pushed routes and DNS servers to scripts, plugins and proxy support. That flexibility lets it fit almost any network, at the cost of a large codebase and many ways to misconfigure it.
WireGuard went the other way. Its whitepaper describes a Linux implementation of fewer than 4,000 lines of code, small enough for one reviewer to read in full. It is built on the Noise protocol framework and uses cryptokey routing: each peer is identified by a public key, and that key is bound to the IP addresses the peer may use inside the tunnel. What Is WireGuard? shows how this looks in a real config file.
What WireGuard leaves out on purpose
- Dynamic addressing. Tunnel addresses are fixed in each peer's config; the server pushes no routes or DNS settings.
- User accounts. Peers authenticate by key pair only; logins, expiry dates and device limits belong to the app or service around the protocol.
- TCP mode. WireGuard speaks UDP and nothing else.
- Cipher negotiation. If the cryptography ever needs replacing, the plan is a new protocol version, not a menu of options.
WireGuard vs OpenVPN speed and latency
In OpenVPN vs WireGuard speed tests, WireGuard usually comes out ahead, for structural reasons:
- Where packets are processed. On Linux and Windows, WireGuard runs in the kernel. Classic OpenVPN copies every packet between the kernel and a single-threaded userspace process, so encryption runs on one CPU core.
- Cipher fit for the hardware. ChaCha20-Poly1305 is fast in plain software, which helps on routers, older CPUs and other chips without AES acceleration. On processors with AES instructions, OpenVPN's AES-GCM is fast too.
- Handshake cost. WireGuard sets up a session in one round trip. OpenVPN's TLS handshake needs several, plus certificate checks, so connecting and reconnecting take longer, especially to a distant server.
- Per-packet overhead. WireGuard's own framing plus the outer IP and UDP headers adds 60 bytes on IPv4 and 80 on IPv6, which is why 1420 is the usual default MTU for a WireGuard interface.
OpenVPN 2.6 introduced data channel offload (DCO), which moves data channel encryption into a kernel module on Linux, Windows and FreeBSD. With DCO on both ends, WireGuard vs OpenVPN performance on the same hardware can be much closer than older comparisons suggest.
The protocol is only one factor in VPN speed. Distance to the server, server load, Wi-Fi quality and routing often matter more, so when testing, change only the protocol. More in Does a VPN Slow Down Your Internet?
Security and cryptography
With current versions and sensible settings, both protocols give you strong encryption, mutual authentication and perfect forward secrecy: session keys are temporary, so a long-term key stolen later cannot decrypt traffic recorded earlier. The real WireGuard vs OpenVPN security difference is how much has to be set up correctly.
WireGuard: fixed, modern primitives
WireGuard uses Curve25519 for key exchange, ChaCha20-Poly1305 for authenticated encryption, BLAKE2s for hashing and HKDF for key derivation, and replaces session keys every couple of minutes. An optional pre-shared key adds a layer of protection against future quantum attacks. The handshake has been formally analysed by academic researchers, and the small codebase makes independent review practical. A WireGuard endpoint also stays silent towards senders that cannot prove they know its public key, so a port scan gets no reply.
OpenVPN: mature and configuration-sensitive
OpenVPN relies on a TLS library, usually OpenSSL, for its control channel. Current releases default to AEAD ciphers such as AES-256-GCM and support ChaCha20-Poly1305, and the tls-crypt option encrypts and authenticates control packets with an extra pre-shared key, so unauthenticated packets are dropped early. It has a long track record and several independent audits behind it. Its weak points are configuration and dependencies: old config files may still name legacy CBC ciphers, and both OpenVPN and its TLS library need regular patching.
A privacy trade-off worth knowing
WireGuard has no log-in or log-out step: each peer keeps a fixed tunnel address, and the server keeps each peer's latest public IP in memory while the interface is up. OpenVPN, by contrast, can assign addresses per session. It is a design trade-off, not a vulnerability.
Battery life and mobile roaming
On a phone, VPN battery drain comes mostly from how often the radio wakes up and how much processing each packet needs. WireGuard's design helps on both counts.
- Idle behaviour. WireGuard sends nothing while you send nothing; many mobile configs add a light keepalive every 25 seconds or so to keep NAT mappings on routers and carrier networks open. OpenVPN configs typically exchange periodic pings and renegotiate keys hourly by default.
- Work per packet. ChaCha20 runs efficiently in software, including on mobile chips, and a lean code path means less CPU time per packet.
- Switching networks. When your phone moves from Wi-Fi to mobile data, its public IP changes. WireGuard accepts the next authenticated packet from the new address and carries on. OpenVPN often has to detect the dead connection and complete a full TLS handshake, costing time and extra traffic.
So a WireGuard-based connection tends to feel always-on. If one still drops every time you change networks, check the device first, for example battery-saving settings that stop the VPN app in the background.
Ports, UDP vs TCP and network compatibility
WireGuard uses UDP only, which is good for performance: UDP does not retransmit lost packets itself, so the TCP connections inside the tunnel handle recovery once, end to end. OpenVPN supports both, and UDP is its default for the same reason.
Why TCP mode is slower
OpenVPN over TCP wraps your apps' TCP traffic inside another TCP connection. When a packet is lost, both layers retry on their own timers, and on lossy links the retransmissions pile up, an effect often called TCP meltdown. On a clean wired connection you may not notice; on weak mobile coverage you usually will.
When the port matters
Some guest networks in hotels and conference venues allow only web ports (TCP 80 and 443) and drop other traffic, including UDP. WireGuard has no TCP mode, so on such a network it may not connect at all. OpenVPN can run on TCP 443, and VLESS + Reality works over TCP and TLS by design.
If the network belongs to your employer or school, its acceptable-use rules apply. Check them, or ask the network administrator, before connecting a personal VPN.
What about IKEv2/IPsec?
IKEv2 with IPsec is the third protocol you will often see in VPN settings. It is built into Windows, macOS, iOS and, since version 11, Android, so it can work without a separate app. Where both sides support its MOBIKE extension (RFC 4555), a session survives a change of network address, as with WireGuard.
In a WireGuard vs IKEv2 comparison, IKEv2 wins on built-in operating system support and integration with enterprise identity systems. WireGuard wins on simplicity: IPsec is a large family of standards with many negotiable algorithms and differences between vendors. Standard IKEv2 setups use UDP ports 500 and 4500, so they share WireGuard's limitation on networks that allow only web ports. For the ports each protocol needs, see VPN Protocols and Ports.
Where AmneziaWG and VLESS + Reality fit
Two newer options build on the ideas above:
- AmneziaWG is based on WireGuard and keeps its UDP transport, its cryptography and its lightweight design, while adding extra masking of service packets such as the handshake. Its keys need a compatible client, such as the Amnezia VPN app, rather than the standard WireGuard app.
- VLESS + Reality runs over TCP with TLS, and the connection looks like ordinary HTTPS traffic. It is usually deployed on port 443, so it can often connect where only web ports are open, with the usual TCP behaviour on lossy links.
Flex-VPN offers profiles built on these two: AmneziaWG for a quick, simple start and VLESS + Reality as an alternative for networks where a different connection approach works better. AmneziaWG vs VLESS + Reality compares the two in detail.
How to compare them on your own devices
- Install a compatible app from the download page: Amnezia VPN for AmneziaWG keys, Happ or v2RayTun for a VLESS + Reality subscription.
- Import your Flex-VPN key or subscription link and pick one server location for every test.
- Run a speed test without the VPN and note latency and download speed.
- Connect with the AmneziaWG profile and repeat the test two or three times.
- Switch to the VLESS + Reality profile and run the same tests.
- Try everyday tasks too, such as a video call, and turn Wi-Fi off and on to see how each profile recovers.
Keep whichever profile is more stable on your usual networks, or keep both imported. The Amnezia VPN setup guide shows how to import an AmneziaWG key.
Frequently asked questions
Is WireGuard faster than OpenVPN?
In most cases, yes, especially on routers and older processors, thanks to its lean design, a one-round-trip handshake, low per-packet overhead and in-kernel processing on Linux and Windows. The exact gap depends on hardware, server and network, and OpenVPN 2.6 with data channel offload narrows it.
Is WireGuard more secure than OpenVPN?
Both are secure when kept up to date and configured properly. WireGuard's advantage is a small codebase and fixed modern cryptography, which leave less room for mistakes; OpenVPN offers more options to fit existing infrastructure.
Can WireGuard run over TCP?
Not natively: WireGuard uses UDP only. On a network that allows only web ports, you need a TCP-based option such as OpenVPN in TCP mode or VLESS + Reality.
Which uses less battery, WireGuard or OpenVPN?
WireGuard generally does. It sends no traffic while idle apart from an optional keepalive, and it handles a switch between Wi-Fi and mobile data without a full reconnect.
Is AmneziaWG the same as WireGuard?
No. AmneziaWG is based on WireGuard and also works over UDP, but it adds extra masking of service packets, so its keys need a compatible client such as Amnezia VPN rather than the standard WireGuard app.
Is WireGuard better than IKEv2?
Not in every case. IKEv2 is built into most operating systems and handles network changes well, while WireGuard is simpler, quicker to connect and behaves more consistently across platforms.