By Eric L.
09/08/2026 · 7 MIN READ

WireGuard is usually faster than OpenVPN, is designed to use less battery, has a far smaller codebase, and is the right default on most connections.

OpenVPN is slower and heavier, but it has twenty years of deployment behind it, runs over TCP as well as UDP, and can be tuned in ways WireGuard deliberately doesn't allow. The short answer for 2026: use WireGuard when it works, fall back to OpenVPN in TCP mode when a network blocks UDP, and consider VLESS when a network actively filters VPN traffic.

WireGuard vs OpenVPN: design

OpenVPN, released in 2001, is built on OpenSSL and supports a long list of ciphers, key exchanges, compression options and transport modes. Every one of those options is a decision an administrator can get wrong, and the codebase is large, in the range of several hundred thousand lines including its dependencies.

WireGuard, merged into the Linux kernel in 2020, takes the opposite approach: one fixed set of modern primitives (ChaCha20-Poly1305 for encryption, Curve25519 for key exchange, BLAKE2s for hashing), no negotiation, no options. The protocol itself is around four thousand lines of code. If a primitive is ever broken, the protocol version changes; there's nothing to misconfigure.

WHEN THE BARS STOP MATTERINGFIG. 01
                    WireGuard OpenVPN
speed               ####      ##
battery             ####      ##
simplicity          ####      #
if UDP is blocked   no        yes
audited             yes       yes
Three rows favor WireGuard on an open network. The fourth decides whether you get one.
TWO DESIGN PHILOSOPHIESFIG. 02
OpenVPN    many options, many ciphers
           configurable to a fault
WireGuard  one scheme, fixed ciphers
           almost nothing to choose
   └─ fewer choices, fewer ways
      to get it wrong

WireGuard vs OpenVPN speed

In the three tests below, WireGuard ranged from on par with OpenVPN to 8 times faster; the gap depends on the hardware and on how OpenVPN is set up. Against OpenVPN over UDP, its default mode, WireGuard was 2.4 to 4 times faster in two of the tests and tied with full-size packets in the third:

  • About 4 times, in WireGuard's own benchmark (Linux 4.6, so about 2016): two laptops on gigabit Ethernet, WireGuard at 1,011 Mbps, OpenVPN at 258 Mbps in UDP mode, using the older AES-plus-HMAC setup and maxing out its CPU. It's the vendor's number, and the project's page calls these benchmarks old.
  • About 2.4 times over UDP and 8 times over TCP, in an independent RTINGS test (updated March 2026): Windows laptops in Montreal, Mullvad servers in London, runs spread over 12 hours. WireGuard averaged 353.6 Mbps download, OpenVPN 149.1 Mbps over UDP and 44.1 Mbps over TCP. OpenVPN over UDP also lost 15% of its packets, and 10 of its 19 runs failed.
  • A tie with full-size packets, in a 2020 University of Amsterdam lab study: two Xeon servers on a 1 Gbps link, UDP traffic, OpenVPN with AES-GCM at 922 Mbps, WireGuard at 917. The authors attribute the tie to CPUs that encrypt AES in hardware and to AES-GCM ciphers, which earlier studies hadn't tested. With small 64-byte packets the same study had WireGuard more than twice as fast, 109 Mbps to 48.
DOWNLOAD MBPS, MONTREAL TO LONDONFIG. 03
no VPN       897  ####################
WireGuard    354  ########
OpenVPN UDP  149  ###
OpenVPN TCP   44  #
In RTINGS' test the shortest bar is the fallback: OpenVPN over TCP is what still gets through when a network blocks UDP.
  • Widest gap: small routers and TCP mode. Router maker GL.iNet lists its Mango travel router, with a 580 MHz chip, at up to 45 Mbps on WireGuard and 11 Mbps on OpenVPN, measured on a local network. OpenVPN in TCP mode is the bottom bar above: an eighth of WireGuard's speed.
  • Closing gap: OpenVPN DCO. Data Channel Offload moves OpenVPN's data path into the kernel, where WireGuard already runs on Linux. GL.iNet lists its Flint 2 router at 900 Mbps on WireGuard and 880 Mbps on OpenVPN with DCO, again on a local network. The 2016 and 2020 tests ran without it.
  • Latency and setup time. WireGuard's handshake is one round trip: in the Amsterdam study its tunnel came up in 6.9 ms on average, OpenVPN's with certificates in about 1.15 seconds. Once connected, ping was practically equal in both independent tests, but during a heavy download RTINGS measured more lag on WireGuard and names bufferbloat (overfull queues in network gear that hold packets back) or routing as likely causes.
  • Battery. WireGuard's quickstart guide says it stays as quiet as possible when idle, with keepalives off by default (it suggests one every 25 seconds for a device behind NAT that must receive while idle); OpenVPN's sample server config pings every 10 seconds. We found no published battery test of the two, so this is design reasoning, not a measurement.
SAME TWO PROTOCOLS, A DIFFERENT GAPWireGuardOpenVPNLab servers, AES-GCMfull-size packets, 2020917 Mbps922 MbpstieRouter, OpenVPN DCOFlint 2, local network900 Mbps880 Mbpsgap closingReal internet link, UDPMontreal to London354 Mbps149 Mbps2.4xSmall router chipMango, 580 MHz45 Mbps11 Mbpswidest gapOpenVPN over TCPsame link, TCP mode354 Mbps44 Mbpswidest gap: 8xBars compare the two protocols within one row; each row is a different test.
The protocols stay the same; the hardware and the OpenVPN mode decide how wide the gap is.

So WireGuard is the sensible default: on par with OpenVPN using AES-GCM on fast lab servers, clearly ahead over a real internet link, and far ahead on a small router or against OpenVPN over TCP. Why speed drops at all is covered in does a VPN slow down your internet.

LINES OF CODEFIG. 04
OpenVPN     ||||||||||
WireGuard   |
   └─ this is the actual argument,
      not a marketing number: less
      code is less attack surface

Is WireGuard or OpenVPN more secure?

Both are secure when they're set up correctly. The difference is how easy "correctly" turns out to be.

WireGuard's fixed cryptography means every deployment uses the same modern set; there's no legacy cipher to accidentally enable. Its small size has been formally analyzed. One design trade-off: WireGuard servers keep the client's public key and last-seen IP address in memory while the session is active, which some providers work around by assigning addresses dynamically and wiping them on disconnect.

WHAT IS FIXED, WHAT YOU HAVE TO CHECKWIREGUARD: ONE FIXED SETOPENVPN: WHATEVER THE CONFIG SAYSChaCha20-Poly1305encryptionCurve25519key exchangeBLAKE2shashingsame in every deployment, nothing to pickTLS 1.2 or newercheck itAES-GCM or ChaCha20check itA strong key exchangecheck itCompression offit enabled old attackscheck ita config from an old guide may miss one
WireGuard leaves nothing to choose; with OpenVPN, each of these lines is up to the config.

OpenVPN's security rides on the configuration (the settings file your app loads): TLS 1.2 or newer, AES-GCM or ChaCha20, a strong key exchange, and no compression (compression is what enabled a family of old attacks). A well-configured OpenVPN is solid. A default you copied out of a five-year-old guide may not be.

WHERE OPENVPN WINSFIG. 05
                   OpenVPN   WireGuard
raw speed          ||        ||||
network handover   ||        ||||
blends into HTTPS  |||       |
corporate support  ||||      ||
Two rows favor OpenVPN, and neither is about outrunning WireGuard: blending into ordinary traffic, and the fine-grained control IT teams rely on.

Where OpenVPN still wins

  • TCP mode on port 443. Some networks block UDP or throttle unknown UDP traffic. WireGuard is UDP-only; OpenVPN can run over TCP on the HTTPS port and often gets through where WireGuard can't.
  • Fine-grained control: per-client certificates, custom routing pushes, scripts on connect. Corporate deployments rely on this.
  • Old hardware and firmware (the software inside your router) that shipped with OpenVPN and never got WireGuard.
WHERE IKEv2 SITSFIG. 06
built into iOS, macOS, Windows
survives network changes well
recognizable on the network
   └─ the default when a company
      hands you a profile

What about IKEv2/IPsec?

The protocol built into iOS, macOS and Windows without any app. Fast, and excellent at switching between Wi-Fi and mobile data without dropping. Its weakness is the same as WireGuard's: recognizable traffic and standard ports, so it's easily blocked, and its configuration surface is larger than WireGuard's. A good choice on phones when the network is friendly.

WHAT NEITHER OF THEM DOESFIG. 07
neither hides that it is a tunnel
neither imitates ordinary HTTPS
   └─ on a network that classifies
      protocols, both are visible

VLESS: the option neither of them offers

WireGuard, OpenVPN and IKEv2 all produce traffic that a network can recognize as a VPN. On networks that filter or throttle VPNs, hotels, campuses, corporate networks, some countries, they either fail or crawl. VLESS with Reality, from the Xray project, is designed for exactly that case: the tunnel is indistinguishable from an ordinary HTTPS connection to a well-known website, at a speed close to WireGuard's. It isn't a replacement for WireGuard on a normal network, but it's the tool for a hostile one.

A SIMPLE RULEFIG. 08
want speed and simplicity
  └─ WireGuard
need to look like ordinary HTTPS
  └─ neither: you want VLESS
locked to corporate kit
  └─ whatever it supports

Most of the time you don't get to choose: you use whatever your provider handed you. But if you do get a say, here's the short version.

Prompt for an AI
Help me choose between WireGuard and OpenVPN.

Why I want a tunnel: (privacy on untrusted
networks / reaching a work network / getting
around filtering).
What I already have: (a config file, a profile,
a corporate client, nothing).
Devices: (which).
What matters more: (speed / compatibility /
working on networks that interfere).

Say which fits me and why, given what I already
have.
If the choice was already made for me by what I
was given, say so plainly.

WireGuard or OpenVPN: which to use

  1. Start with WireGuard. On most home, office and mobile networks it's the fastest and lightest option.
  2. If the connection fails or is throttled, try VLESS. If your app selects protocols automatically, this happens on its own.
  3. If you must use OpenVPN, use UDP if it passes, TCP on port 443 if not, and check that the configuration uses TLS 1.2+ with AES-GCM or ChaCha20 and no compression.
  4. On iPhone without an app, IKEv2 is the built-in fallback.

Whichever one you end up on, check the tunnel with What Is My IP and run the IPv6 leak test. Picking the right protocol does nothing for a config that leaks.

404 VPN offers VLESS with Reality in its Android and macOS apps and, since September 2026, WireGuard as a config file or QR code from the dashboard for Istanbul and Marseille. You choose the protocol yourself; both keep DNS inside the tunnel, and the Android app has a kill switch. How the connection is built is described on the how it works page; get started here.