WireGuard is usually faster than OpenVPN, is designed to use less battery, has a far smaller codebase, and is the right default on most connections.
OpenVPN is slower and heavier, but it has twenty years of deployment behind it, runs over TCP as well as UDP, and can be tuned in ways WireGuard deliberately doesn't allow. The short answer for 2026: use WireGuard when it works, fall back to OpenVPN in TCP mode when a network blocks UDP, and consider VLESS when a network actively filters VPN traffic.
WireGuard vs OpenVPN: design
OpenVPN, released in 2001, is built on OpenSSL and supports a long list of ciphers, key exchanges, compression options and transport modes. Every one of those options is a decision an administrator can get wrong, and the codebase is large, in the range of several hundred thousand lines including its dependencies.
WireGuard, merged into the Linux kernel in 2020, takes the opposite approach: one fixed set of modern primitives (ChaCha20-Poly1305 for encryption, Curve25519 for key exchange, BLAKE2s for hashing), no negotiation, no options. The protocol itself is around four thousand lines of code. If a primitive is ever broken, the protocol version changes; there's nothing to misconfigure.
WireGuard OpenVPN
speed #### ##
battery #### ##
simplicity #### #
if UDP is blocked no yes
audited yes yesOpenVPN many options, many ciphers
configurable to a fault
WireGuard one scheme, fixed ciphers
almost nothing to choose
└─ fewer choices, fewer ways
to get it wrongWireGuard vs OpenVPN speed
In the three tests below, WireGuard ranged from on par with OpenVPN to 8 times faster; the gap depends on the hardware and on how OpenVPN is set up. Against OpenVPN over UDP, its default mode, WireGuard was 2.4 to 4 times faster in two of the tests and tied with full-size packets in the third:
- About 4 times, in WireGuard's own benchmark (Linux 4.6, so about 2016): two laptops on gigabit Ethernet, WireGuard at 1,011 Mbps, OpenVPN at 258 Mbps in UDP mode, using the older AES-plus-HMAC setup and maxing out its CPU. It's the vendor's number, and the project's page calls these benchmarks old.
- About 2.4 times over UDP and 8 times over TCP, in an independent RTINGS test (updated March 2026): Windows laptops in Montreal, Mullvad servers in London, runs spread over 12 hours. WireGuard averaged 353.6 Mbps download, OpenVPN 149.1 Mbps over UDP and 44.1 Mbps over TCP. OpenVPN over UDP also lost 15% of its packets, and 10 of its 19 runs failed.
- A tie with full-size packets, in a 2020 University of Amsterdam lab study: two Xeon servers on a 1 Gbps link, UDP traffic, OpenVPN with AES-GCM at 922 Mbps, WireGuard at 917. The authors attribute the tie to CPUs that encrypt AES in hardware and to AES-GCM ciphers, which earlier studies hadn't tested. With small 64-byte packets the same study had WireGuard more than twice as fast, 109 Mbps to 48.
no VPN 897 #################### WireGuard 354 ######## OpenVPN UDP 149 ### OpenVPN TCP 44 #
- Widest gap: small routers and TCP mode. Router maker GL.iNet lists its Mango travel router, with a 580 MHz chip, at up to 45 Mbps on WireGuard and 11 Mbps on OpenVPN, measured on a local network. OpenVPN in TCP mode is the bottom bar above: an eighth of WireGuard's speed.
- Closing gap: OpenVPN DCO. Data Channel Offload moves OpenVPN's data path into the kernel, where WireGuard already runs on Linux. GL.iNet lists its Flint 2 router at 900 Mbps on WireGuard and 880 Mbps on OpenVPN with DCO, again on a local network. The 2016 and 2020 tests ran without it.
- Latency and setup time. WireGuard's handshake is one round trip: in the Amsterdam study its tunnel came up in 6.9 ms on average, OpenVPN's with certificates in about 1.15 seconds. Once connected, ping was practically equal in both independent tests, but during a heavy download RTINGS measured more lag on WireGuard and names bufferbloat (overfull queues in network gear that hold packets back) or routing as likely causes.
- Battery. WireGuard's quickstart guide says it stays as quiet as possible when idle, with keepalives off by default (it suggests one every 25 seconds for a device behind NAT that must receive while idle); OpenVPN's sample server config pings every 10 seconds. We found no published battery test of the two, so this is design reasoning, not a measurement.
So WireGuard is the sensible default: on par with OpenVPN using AES-GCM on fast lab servers, clearly ahead over a real internet link, and far ahead on a small router or against OpenVPN over TCP. Why speed drops at all is covered in does a VPN slow down your internet.
OpenVPN |||||||||| WireGuard | └─ this is the actual argument, not a marketing number: less code is less attack surface
Is WireGuard or OpenVPN more secure?
Both are secure when they're set up correctly. The difference is how easy "correctly" turns out to be.
WireGuard's fixed cryptography means every deployment uses the same modern set; there's no legacy cipher to accidentally enable. Its small size has been formally analyzed. One design trade-off: WireGuard servers keep the client's public key and last-seen IP address in memory while the session is active, which some providers work around by assigning addresses dynamically and wiping them on disconnect.
OpenVPN's security rides on the configuration (the settings file your app loads): TLS 1.2 or newer, AES-GCM or ChaCha20, a strong key exchange, and no compression (compression is what enabled a family of old attacks). A well-configured OpenVPN is solid. A default you copied out of a five-year-old guide may not be.
OpenVPN WireGuard raw speed || |||| network handover || |||| blends into HTTPS ||| | corporate support |||| ||
Where OpenVPN still wins
- TCP mode on port 443. Some networks block UDP or throttle unknown UDP traffic. WireGuard is UDP-only; OpenVPN can run over TCP on the HTTPS port and often gets through where WireGuard can't.
- Fine-grained control: per-client certificates, custom routing pushes, scripts on connect. Corporate deployments rely on this.
- Old hardware and firmware (the software inside your router) that shipped with OpenVPN and never got WireGuard.
built into iOS, macOS, Windows survives network changes well recognizable on the network └─ the default when a company hands you a profile
What about IKEv2/IPsec?
The protocol built into iOS, macOS and Windows without any app. Fast, and excellent at switching between Wi-Fi and mobile data without dropping. Its weakness is the same as WireGuard's: recognizable traffic and standard ports, so it's easily blocked, and its configuration surface is larger than WireGuard's. A good choice on phones when the network is friendly.
neither hides that it is a tunnel neither imitates ordinary HTTPS └─ on a network that classifies protocols, both are visible
VLESS: the option neither of them offers
WireGuard, OpenVPN and IKEv2 all produce traffic that a network can recognize as a VPN. On networks that filter or throttle VPNs, hotels, campuses, corporate networks, some countries, they either fail or crawl. VLESS with Reality, from the Xray project, is designed for exactly that case: the tunnel is indistinguishable from an ordinary HTTPS connection to a well-known website, at a speed close to WireGuard's. It isn't a replacement for WireGuard on a normal network, but it's the tool for a hostile one.
want speed and simplicity └─ WireGuard need to look like ordinary HTTPS └─ neither: you want VLESS locked to corporate kit └─ whatever it supports
Most of the time you don't get to choose: you use whatever your provider handed you. But if you do get a say, here's the short version.
Help me choose between WireGuard and OpenVPN.
Why I want a tunnel: (privacy on untrusted
networks / reaching a work network / getting
around filtering).
What I already have: (a config file, a profile,
a corporate client, nothing).
Devices: (which).
What matters more: (speed / compatibility /
working on networks that interfere).
Say which fits me and why, given what I already
have.
If the choice was already made for me by what I
was given, say so plainly.
WireGuard or OpenVPN: which to use
- Start with WireGuard. On most home, office and mobile networks it's the fastest and lightest option.
- If the connection fails or is throttled, try VLESS. If your app selects protocols automatically, this happens on its own.
- If you must use OpenVPN, use UDP if it passes, TCP on port 443 if not, and check that the configuration uses TLS 1.2+ with AES-GCM or ChaCha20 and no compression.
- On iPhone without an app, IKEv2 is the built-in fallback.
Whichever one you end up on, check the tunnel with What Is My IP and run the IPv6 leak test. Picking the right protocol does nothing for a config that leaks.
404 VPN offers VLESS with Reality in its Android and macOS apps and, since September 2026, WireGuard as a config file or QR code from the dashboard for Istanbul and Marseille. You choose the protocol yourself; both keep DNS inside the tunnel, and the Android app has a kill switch. How the connection is built is described on the how it works page; get started here.