VPN protocol guide + paid test evidence

VPN Protocols Compared: WireGuard, OpenVPN, IKEv2 & More

A VPN protocol helps determine how your encrypted tunnel is built and how traffic moves through it. We compare the protocols you will actually encounter, then add the part most glossaries cannot: what happened when we switched protocols during nine paid VPN reviews.

9Paid VPN reviews
65Protocol speed records
7/7Provider pairs: WG-family > OpenVPN download
5/5Provider pairs: OpenVPN UDP > TCP download
Aug. 2026Official sources rechecked

Hands-on protocol tests were recorded during our May–July 2026 paid review cycle; volatile protocol and platform facts were rechecked on August 6, 2026. Speed findings compare modes inside the same provider and test session, not raw Mbps across different VPNs. Reviews Ally may earn a commission when you use some links elsewhere on our site. Read our advertising disclosure.

What you’ll find here

Definitions, decision help, and protocol data from paid VPN tests

This page covers the main types of VPN protocols without turning into a glossary dump. You can pick a sensible starting protocol, see how WireGuard, OpenVPN, and IKEv2 differ, inspect our own paid protocol results, and check where a protocol was actually available in the VPN apps we reviewed.

Choose by use case

Start with everyday use, streaming, gaming, mobile, restrictive networks, routers, or troubleshooting.

Compare the protocol families

Separate actual protocols from UDP/TCP transports, obfuscation layers, and Automatic/Smart app logic.

Inspect our paid test patterns

See the 7/7 WireGuard-family and 5/5 OpenVPN UDP/TCP patterns plus the underlying repeat depth.

Download the 65-row CSV

Use the sanitized VPN-on protocol records without private baselines, raw timestamps, or account/tester details.

Start here

Which VPN protocol should you use?

For most people, the boring answer is the useful one: leave a trustworthy VPN on its recommended Automatic or Smart setting, or try WireGuard (or a well-documented WireGuard-based option) when you want a fast general-purpose default. OpenVPN UDP is a strong fallback when you want OpenVPN without TCP overhead. OpenVPN TCP and provider-specific stealth modes become more interesting when a network blocks ordinary VPN traffic.

There is no protocol that wins every network, device, and provider. In our paid tests, WireGuard-family options were the fastest download choice in all seven providers where we had a usable same-session WireGuard-family versus OpenVPN pairing. That is meaningful first-party evidence, but it is a pattern from our test cycle, not a law of networking.

Use case Good first choice Why Try next if needed
Everyday use Automatic/Smart or WireGuard Lets the app choose, or starts with a modern low-overhead protocol. OpenVPN UDP
Streaming & large downloads WireGuard / provider WireGuard option It produced the strongest download result in all seven usable WireGuard-family pairings from our test cycle. OpenVPN UDP, then Automatic
Gaming WireGuard Low protocol overhead is attractive for latency-sensitive traffic, but server distance and routing still matter enormously. IKEv2/IPsec or OpenVPN UDP
Phones / changing networks WireGuard or IKEv2/IPsec Both are common mobile choices; IKEv2 can use MOBIKE to handle address/network changes when implemented. Provider Automatic/Smart
Restrictive Wi-Fi or filtering Provider stealth mode or OpenVPN TCP Compatibility can matter more than peak throughput. TCP 443 is commonly allowed where UDP or obvious VPN traffic is restricted. Provider-specific obfuscation
Router / manual configuration OpenVPN or WireGuard Both can work well, but support depends on the VPN and router firmware. OpenVPN remains widely documented. Use the provider’s supported manual method
Troubleshooting a connection Switch protocol before blaming the whole VPN A server, transport, driver, or filtered network can fail while another protocol works normally. Automatic/Smart, then a different server

These are starting points, not security or performance guarantees. Provider implementation, server route, device, network filtering, and app version can change the result.

The terminology matters

What a VPN protocol actually controls

A VPN protocol is the set of rules and cryptographic/networking behavior used to establish and operate the tunnel between your device and a VPN endpoint. The protocol influences connection setup, packet handling, supported transports, cryptography, roaming behavior, and how easily a VPN can fit through different network conditions.

VPN apps make this harder to read than it should be because the same menu can contain actual protocols, transports, obfuscation modes, and an Automatic selector. Those labels are not interchangeable. Split tunneling is a routing policy that decides which traffic uses the tunnel; it is not another VPN protocol.

Protocol

WireGuard, OpenVPN, and IKEv2/IPsec are protocol families you can meaningfully compare at a technical level.

Transport

UDP and TCP describe how traffic is transported in contexts such as OpenVPN. Native WireGuard sends its packets over UDP.

Obfuscation

Obfuscation tries to make VPN traffic harder to identify or block. It can sit above or alongside a protocol rather than being the protocol itself.

Automatic / Smart

This is app logic that chooses a connection mode for you. Unless the provider exposes the result, we do not guess which protocol it selected.

One trap worth avoiding: “WireGuard TCP”

The WireGuard protocol specification says its packets are sent over UDP, and WireGuard’s own limitations page says native WireGuard does not tunnel over TCP. A VPN can still offer a product setting called “WireGuard TCP” by adding its own transport or obfuscation layer. Proton VPN does exactly that. We treat the provider-labeled mode as a provider implementation, not as evidence that native WireGuard suddenly gained TCP support.

Decision matrix

VPN protocols compared

Protocol / family Transport / behavior Practical strengths Trade-offs Our default read
WireGuard Native packets over UDP Modern, compact design; low overhead; strong performance potential. No native TCP mode or built-in focus on obfuscation. Provider implementation still matters. Excellent general-purpose starting point when the provider supports it well.
OpenVPN UDP OpenVPN over UDP Mature, flexible, widely supported, usually the faster OpenVPN transport. UDP can be restricted on some networks; our results varied substantially by provider. Best OpenVPN starting point for normal networks.
OpenVPN TCP OpenVPN over TCP; often supports TCP 443 Useful compatibility option on networks that restrict UDP. TCP-over-TCP effects can hurt throughput; all five direct pairings in our test cycle favored UDP for download. A compatibility fallback, not our first speed choice.
IKEv2/IPsec IKEv2 negotiates and maintains IPsec security associations Fast connection behavior and strong mobility potential; MOBIKE can support address changes. Consumer-VPN app availability now varies sharply by platform/provider. Still useful, especially where a provider/OS supports it cleanly.
Provider-specific protocols Varies by provider Can target speed, censorship resistance, fast reconnection, or provider-specific architecture. You cannot infer behavior from a marketing name. Documentation and implementation matter. Evaluate one implementation at a time.
PPTP Legacy tunneling protocol Historically broad compatibility. Outdated security. Microsoft no longer accepts PPTP by default on new Windows Server 2025 RRAS installs. Avoid as a modern privacy/security default.
L2TP/IPsec L2TP tunneling commonly paired with IPsec Legacy OS compatibility in some environments. Older design and shrinking consumer-VPN relevance; also disabled by default for new Windows Server 2025 RRAS installs. Use only when a compatibility requirement gives you a reason.

First-party evidence

What our paid VPN protocol speed tests showed

Our consolidated speed dataset contains 268 records. The protocol-comparison subset contains 65 VPN-on records across all nine VPNs in our current ranked comparison. We changed protocol or connection mode while keeping the provider and comparison route fixed, then used the Speedtest by Ookla Windows app to record ping, download, upload, and secondary fields when the tool captured them.

Protocol is only one variable in a speed result. To compare a no-VPN baseline with a VPN-on result on your own connection, use our VPN speed test and speed-loss calculator; the guide separates throughput retention, latency, route choice, protocol choice, and repeatability instead of collapsing them into one “fast” label.

Two patterns were unusually consistent. Among the seven providers where we had a usable WireGuard or WireGuard-derived result and a comparable OpenVPN result, the WireGuard-family option posted the higher download result in all seven sessions. Among the five providers with direct OpenVPN UDP and TCP results, UDP posted the higher download result in all five sessions. The consistency is interesting; the sample size is still seven and five providers, not the entire VPN market.

Provider WireGuard-family result Comparable OpenVPN result Repeat depth Readout
NordVPN NordLynx: 285.23 Mbps OpenVPN UDP: 47.96 Mbps 1 run per mode WireGuard-based result higher
PureVPN WireGuard: 219.64 Mbps OpenVPN UDP: 66.41 Mbps 1 run per mode WireGuard higher
Private Internet Access WireGuard: 171.55 Mbps avg. OpenVPN UDP: 116.15 Mbps avg. 2 runs per mode WireGuard higher
Proton VPN WireGuard UDP: 267.82 Mbps avg. OpenVPN UDP: 200.28 Mbps avg. 2 runs per mode WireGuard UDP higher
Surfshark WireGuard: 491.38 Mbps avg. OpenVPN UDP: 291.00 Mbps avg. 2 runs per mode WireGuard higher
VPN.ac WireGuard: 653.06 Mbps avg. OpenVPN UDP: 198.44 Mbps avg. 2 runs per mode WireGuard higher; external WireGuard client
CyberGhost VPN WireGuard: 625.18 Mbps avg. OpenVPN: 235.41 Mbps avg. 2 runs per mode WireGuard higher

These are same-provider Miami comparisons from each documented session, not a seven-VPN speed ranking. Absolute Mbps should not be compared across providers because baseline speed, routing, test date, and implementation differ. VPN.ac WireGuard used the official WireGuard Windows client with VPN.ac profiles.

A concrete example: Surfshark in Miami

Surfshark gives us a particularly clean illustration because OpenVPN TCP, OpenVPN UDP, and WireGuard were each tested twice on the same Miami comparison route. Average ping barely moved, but download throughput changed dramatically: 30.81 Mbps on OpenVPN TCP, 291.00 Mbps on OpenVPN UDP, and 491.38 Mbps on WireGuard.

Mode Runs Avg. ping Avg. download Avg. upload
OpenVPN TCP 2 121 ms 30.81 Mbps 17.75 Mbps
OpenVPN UDP 2 121.5 ms 291.00 Mbps 61.44 Mbps
WireGuard 2 121 ms 491.38 Mbps 68.35 Mbps
Speedtest by Ookla result from Surfshark OpenVPN TCP protocol run in Miami
Representative OpenVPN TCP run: 29.06 Mbps download, 22.55 Mbps upload, 121 ms ping. The table above uses the average of both TCP runs.
Speedtest by Ookla result from Surfshark OpenVPN UDP protocol run in Miami
Representative OpenVPN UDP run: 294.96 Mbps download, 55.24 Mbps upload, 121 ms ping. The table uses the two-run average.
Speedtest by Ookla result from Surfshark WireGuard protocol run in Miami
Representative WireGuard run: 454.76 Mbps download, 67.23 Mbps upload, 121 ms ping. The two-run WireGuard average was 491.38 Mbps.

Download the 65-row protocol CSV

The public file contains VPN-on protocol records only and strips baseline location, raw timestamps, account/payment information, internal filenames, and other unnecessary private test details.

See our full VPN testing methodology

Read how paid workflows, evidence levels, speed records, leak checks, streaming tests, support, refunds, and limitations fit together.

The high-volume comparison, kept honest

WireGuard vs. OpenVPN: the short version

WireGuard and OpenVPN are both serious VPN technologies, but they make different design choices. WireGuard is deliberately compact and uses a fixed modern cryptographic design with UDP transport. OpenVPN is older, highly configurable, and can operate over UDP or TCP. That flexibility makes OpenVPN valuable when compatibility matters, even when a WireGuard implementation is faster on an ordinary network.

Question WireGuard OpenVPN
Native transport UDP only UDP or TCP
Performance in our paired tests WireGuard-family result led download in all 7 usable provider pairings. Slower in those seven specific pairings; magnitude varied widely by provider.
Restrictive networks No native focus on obfuscation; a provider may add a separate layer. TCP compatibility and flexible ports give providers more fallback options.
Manual configuration Excellent when both provider and device/router support it. Very mature ecosystem with broad router and manual-configuration support.
Our default Try first for normal high-speed use. Keep as a flexible fallback, especially UDP first and TCP when compatibility calls for it.

Search demand for “WireGuard vs OpenVPN” is large enough that we plan to give this comparison its own dedicated evidence page. This broad protocol guide deliberately stops at the decision-level answer instead of stretching one section into a second article.

Same protocol, different transport

OpenVPN UDP vs. TCP: use UDP for speed, TCP for compatibility

OpenVPN’s own documentation says UDP is used for optimal performance while TCP is supported for compatibility with restrictive networks. That lines up with our test direction. In all five providers where we recorded a direct OpenVPN UDP-versus-TCP comparison, UDP had the higher download result.

Provider OpenVPN UDP OpenVPN TCP Runs
PureVPN 66.41 Mbps 26.23 Mbps 1 each
Private Internet Access 116.15 Mbps avg. 16.38 Mbps avg. 2 each
Proton VPN 200.28 Mbps avg. 139.12 Mbps avg. 2 each
Surfshark 291.00 Mbps avg. 30.81 Mbps avg. 2 each
VPN.ac 198.44 Mbps avg. 15.19 Mbps avg. 2 each

PureVPN is a single-run early-cycle pairing; the other four provider rows use two runs per transport. These results do not mean TCP is “bad.” TCP can be the connection that works when UDP is filtered, and a working slower tunnel beats a fast protocol the network refuses to pass.

The three families buyers see most often

WireGuard, OpenVPN, and IKEv2/IPsec explained

WireGuard

WireGuard is a modern VPN tunnel protocol designed around a small, focused implementation and a fixed suite of modern cryptographic primitives. The official project states that WireGuard encapsulates IP packets over UDP and deliberately leaves areas such as key distribution and pushed configuration to other layers. For consumer VPNs, that means the provider still owns a large part of the experience around account identity, key handling, server selection, NAT behavior, and app features.

The practical reason WireGuard is popular is performance. In our current paid protocol dataset, a WireGuard or WireGuard-derived option produced the highest download result inside the tested protocol set for eight of nine providers. Turbo VPN is the exception because WireGuard was not exposed in the Windows app we tested. PrivateVPN also gave us a useful warning against oversimplifying the story: WireGuard worked strongly, while its OpenVPN options did not connect in that session, so there was no valid WireGuard-versus-OpenVPN speed pair to calculate.

WireGuard is not designed to look like ordinary web traffic. Its own limitations page says obfuscation should happen at a layer above WireGuard. If your school, hotel, office, ISP, or country filters VPN traffic, the provider’s stealth implementation may matter more than WireGuard’s raw speed potential.

OpenVPN

OpenVPN is the veteran in this comparison. It is open-source, configurable, and supported across a wide range of clients, servers, routers, ports, and deployment styles. Most consumer users only need to understand one choice: UDP versus TCP. OpenVPN’s own documentation recommends UDP for performance and keeps TCP for networks where compatibility is the bigger concern.

Our data also shows why “OpenVPN is slow” is too crude. The results ranged from perfectly usable OpenVPN UDP sessions to severe TCP throughput drops, and VPN.ac’s obfuscated/proxied OpenVPN variants behaved differently again. The implementation, route, transport, port, proxy/obfuscation layer, server, and test environment can matter almost as much as the protocol family name.

IKEv2/IPsec

IKEv2 is the key-management and negotiation protocol used to establish and maintain IPsec Security Associations. The base standard is RFC 7296. Its mobility extension, MOBIKE (RFC 4555), allows an IKEv2/IPsec VPN to update addresses as connectivity changes, which is one reason IKEv2 became associated with mobile use.

Consumer availability is now the bigger caveat. In our Windows reviews, IKEv2 appeared in PureVPN, VPN.ac, and CyberGhost, but not every app exposed it. Proton VPN’s current protocol page, rechecked August 6, lists IKEv2 in its macOS app only, while PIA’s current desktop documentation lists WireGuard and OpenVPN and its current iOS documentation includes IKEv2. The lesson is simple: “this VPN supports IKEv2” is not the same statement as “IKEv2 is available in the app on your device.”

Names that need context

NordLynx, NordWhisper, Stealth, Lightway, Dausos, and other provider modes

Provider-specific protocols can be genuinely useful, but their names are not a technical specification. We only map them to a protocol family when the provider documents that relationship or our evidence supports it. If documentation is thin, we leave the internals unknown rather than reverse-engineering a marketing label from vibes.

Name Provider What we can support Evidence boundary
NordLynx NordVPN NordVPN’s WireGuard-based option; current docs recommend it and say it is the default in most apps. Hands-on speed result: 285.23 Mbps download in our single-run May Miami comparison.
NordWhisper NordVPN Provider-specific protocol aimed at restrictive local networks. Observed in our paid Windows app; not part of NordVPN’s three-row protocol speed comparison.
Stealth Proton VPN Provider protocol designed to disguise VPN traffic for censored/restrictive networks. Two paid Windows speed runs in June; current platform availability rechecked separately in August.
WireGuard TCP Proton VPN A provider-labeled WireGuard-based TCP mode. Not native WireGuard TCP. Native WireGuard is UDP-only; Proton adds its own transport architecture.
Lightway ExpressVPN ExpressVPN’s provider protocol; current official troubleshooting documentation continues to list it alongside newer protocol choices including WireGuard. Official-source context only. ExpressVPN is not part of this page’s 65-row paid protocol benchmark.
Dausos Surfshark Surfshark’s newer proprietary protocol. Not visible in our June Windows test. Surfshark’s current article says Dausos is available only in the macOS App Store app as of our Aug. 6 recheck.
Lepus / LinkSentinel Turbo VPN Protocol labels we observed in the paid Windows app. Public technical documentation was not sufficient for us to assign an internal protocol family, so we do not invent one.
NordVPN Windows connection and security settings showing Automatic, NordLynx, NordWhisper, OpenVPN TCP, and OpenVPN UDP
NordVPN’s Windows settings during our May 2026 paid review. One menu contains Automatic selection, a WireGuard-based protocol, a restrictive-network protocol, and OpenVPN transports, which is exactly why protocol labels need context.

Old does not automatically mean useful

PPTP, L2TP/IPsec, SSTP, and SoftEther

Legacy protocols still appear in search results and some VPN apps, but they should not all be treated as peer alternatives to WireGuard or OpenVPN. Microsoft’s current VPN protocol guidance says new Windows Server 2025 RRAS installations no longer accept PPTP and L2TP by default; SSTP and IKEv2 remain accepted. Microsoft also recommends against PPTP and L2TP there because of their security limitations.

Protocol / project Where it fits ReviewsAlly position
PPTP Legacy compatibility. Do not choose it as a modern privacy/security default. We tested it only because PrivateVPN exposed it.
L2TP/IPsec Older OS/device compatibility, usually pairing L2TP with IPsec. Not our default. PrivateVPN exposed it, but both Miami runs showed more than 50% packet loss in our session.
SSTP Windows-oriented VPN protocol that remains supported in current Windows Server RRAS. Relevant in some Windows/enterprise setups, but not part of our nine-provider protocol speed benchmark.
SoftEther Open-source multi-protocol VPN software with its own SSL-VPN protocol plus interoperability for other protocols. Useful technology to know about, but not a protocol option we benchmarked across the nine consumer VPN apps here.
VPN.ac Windows app protocol list showing OpenVPN variants, IKEv2 IPsec, L2TP IPsec, and PPTP marked insecure
VPN.ac’s Windows app during our July 2026 review. It explicitly marked PPTP “insecure.” WireGuard was supported separately through the official WireGuard client rather than this native protocol menu.

Hands-on first, current docs second

Which protocols our reviewed VPNs exposed

The left side of this table is historical first-party evidence: what we actually saw in the paid Windows app during that provider’s review. The current-source note is a separate August 2026 documentation check. Keeping those two clocks separate matters because apps change faster than protocol definitions.

VPN Review Windows protocols / modes observed hands-on Official-source note rechecked Aug. 6, 2026
NordVPN May 2026 Automatic, NordLynx, NordWhisper, OpenVPN TCP, OpenVPN UDP. NordVPN still documents NordLynx as its recommended/default option in most apps and NordWhisper for restrictive networks.
PureVPN May 2026 Automatic, WireGuard, IKEv2, UDP, TCP, plus a restrictive-network mode. PureVPN’s current support guide documents WireGuard selection in its Windows app and other platforms; exact menus vary by platform.
Private Internet Access May 2026 Automatic behavior, WireGuard, OpenVPN UDP/TCP; IKEv2 was not visible in the Windows app. Current desktop documentation lists WireGuard and OpenVPN. Current iOS docs additionally list IPsec/IKEv2.
Proton VPN June 2026 Smart/Automatic, WireGuard UDP, WireGuard TCP, OpenVPN UDP/TCP, Stealth. Current Windows docs list Smart, Stealth, WireGuard UDP/TCP and the Proton Protocols beta architecture. OpenVPN is currently listed in the Linux GUI only; IKEv2 in macOS only.
CyberGhost VPN June 2026 Automatic, WireGuard, OpenVPN UDP/TCP, IKEv2. Current CyberGhost documentation lists WireGuard, OpenVPN, and IKEv2, with platform-specific availability.
Surfshark June 2026 Automatic, WireGuard, OpenVPN UDP/TCP; IKEv2 and Dausos were not visible in our Windows app. Surfshark documents WireGuard, OpenVPN, IKEv2, and Dausos across its ecosystem; Dausos is currently macOS App Store only.
PrivateVPN July 2026 Automatic, WireGuard, OpenVPN UDP/TCP/TAP variants, L2TP/IPsec, PPTP. OpenVPN variants did not connect in our protocol session. PrivateVPN’s current protocol page continues to discuss OpenVPN, WireGuard, IKEv2, L2TP/IPsec, and PPTP. Availability inside a specific app can differ.
VPN.ac July 2026 OpenVPN variants, IKEv2/IPsec, L2TP/IPsec, PPTP; WireGuard used separately through the official WireGuard Windows app. VPN.ac still documents WireGuard through the official WireGuard app on Windows and supports OpenVPN/IKEv2/L2TP in its service.
Turbo VPN July 2026 Automatic, OpenVPN, V2Ray, Lepus, LinkSentinel. V2Ray did not connect in our test. Public technical detail is limited, so we keep the proprietary labels as observations and do not infer their internals.

“Observed hands-on” is not a promise of current availability. Check your exact OS and app version before choosing a VPN specifically for one protocol.

How the 65 records were produced

How we tested VPN protocol performance

Protocol testing was one block inside a much larger paid review workflow. We purchased each service, installed and used the consumer apps, documented the protocol choices actually exposed, and ran protocol comparisons with the Speedtest by Ookla Windows app. A protocol speed block could take hours once reconnections, repeat runs, screenshots, notes, and troubleshooting were included.

We kept each protocol comparison inside one provider and one documented server route, usually Miami. That is the right level for claims such as “WireGuard was faster than OpenVPN in this Surfshark session.” It is not valid to look at VPN.ac’s 653 Mbps WireGuard average and CyberGhost’s 625 Mbps average and declare VPN.ac universally faster, because the baselines, dates, app/client path, routing, server load, and other conditions were not one laboratory-controlled cross-provider session.

Later reviews generally used two runs per protocol/mode. NordVPN and PureVPN were part of the earlier stage of the cycle and have single-run protocol comparisons. We keep those measurements because they are genuine recorded tests and useful directional evidence, while labeling their smaller repeat depth anywhere it affects interpretation. We do not silently manufacture a second run to make a table look symmetrical.

We also preserve implementation boundaries. VPN.ac’s WireGuard result came from the official WireGuard Windows client loaded with VPN.ac profiles because WireGuard was not integrated into the VPN.ac Windows app. Automatic/Smart is never treated as a known protocol unless the app or provider identifies what it selected. Failed connections, such as PrivateVPN’s OpenVPN modes and Turbo VPN’s V2Ray attempt, are recorded as connection observations rather than converted into fictional 0 Mbps speed tests.

For the full testing system, including Evidence Levels, baseline handling, speed-ranking formulas, leaks, streaming, app controls, support, cancellations, and refunds, read How We Test VPNs.

What the evidence can and cannot say

Limitations of this protocol comparison

We are proud of this dataset, and we also know exactly where its edges are. This was our first full paid VPN test cycle. As we finished the early reviews, the methodology became more structured, so there are small differences in repeat depth and secondary fields between providers. The underlying measurements remain intact and correspond to real VPN sessions; the improvement was in how consistently we repeated and documented later sessions, not in retroactively changing earlier results.

Limit What we did What it means for you
Different repeat depth NordVPN and PureVPN protocol comparisons use one run per tested mode; later providers generally use two. Treat early-cycle results as directional and later repeated averages as stronger estimates of that session.
One primary desktop environment Speed/protocol comparison centered on a Windows consumer environment. macOS, Linux, Android, iOS, routers, and different drivers can expose different protocol choices and performance.
Provider-specific sessions We controlled protocol changes within each provider rather than running all nine VPNs as one simultaneous lab batch. Use the data for within-provider protocol choices, not an absolute cross-provider Mbps leaderboard.
Reconnection not standardized We observed connection behavior, but did not time reconnection with one stopwatch method across all nine providers. This page does not rank protocols by reconnect time.
Availability changes Hands-on app menus are dated to the review; volatile facts were rechecked from official sources in August. Your current app may legitimately differ from a June or July screenshot.
Resource ceiling We used real paid consumer workflows rather than a multi-location hardware lab with dozens of devices and ISPs. More devices, networks, countries, time windows, and repeat runs would improve external validity. We do not pretend otherwise.

None of those limits makes a 491 Mbps WireGuard result turn into a 31 Mbps OpenVPN TCP result, or vice versa. They tell us how far the conclusion can travel. Our strongest conclusion is therefore a bounded one: in this paid test cycle, WireGuard-family options consistently led comparable OpenVPN download results, and OpenVPN UDP consistently led TCP in the five direct pairings we recorded.

Primary sources + our own evidence

Sources used for this VPN protocol guide

Technical claims use protocol projects, standards bodies, Microsoft documentation, and current provider documentation. Competitor articles were useful during SERP research for understanding page format, but they are not the factual authority behind the protocol claims published here.

ReviewsAlly hands-on evidence

Our source set includes nine Level 4 paid Evidence Logs, final dictated research files, screenshots, and the consolidated 268-record speed dataset. The public protocol subset contains 65 VPN-on rows and deliberately excludes no-VPN baselines and private test-environment details. Speed measurements were recorded with the Speedtest by Ookla Windows app.

Hands-on review cycle: May–July 2026. Technical/provider source recheck: August 6, 2026.

Common questions

VPN protocol FAQ

What is the best VPN protocol?

There is no universal winner. For normal high-speed use, we usually start with Automatic/Smart or WireGuard. OpenVPN UDP is a strong flexible fallback, while OpenVPN TCP or a provider stealth mode can be more useful on restrictive networks. Your provider, device, route, and network can change the best choice.

Is WireGuard better than OpenVPN?

WireGuard has a modern compact design and was faster for download in all seven usable WireGuard-family versus OpenVPN pairings from our paid test cycle. OpenVPN remains more transport-flexible and can use TCP, which is valuable on restrictive networks. “Better” therefore depends on whether you need maximum normal-network performance, compatibility, manual setup, or a filtering workaround.

Should I use OpenVPN UDP or TCP?

Try UDP first on a normal network if performance matters. OpenVPN itself recommends UDP for optimal performance and TCP for compatibility with restrictive networks. UDP had the higher download result in all five direct UDP/TCP provider comparisons we recorded, but TCP can still be the right fallback when UDP is blocked.

Does WireGuard support TCP?

Native WireGuard does not. The WireGuard project says its packets are sent over UDP and explicitly says it does not provide a TCP tunneling mode. A VPN provider can wrap or transport WireGuard traffic through another layer and label that product mode “WireGuard TCP,” as Proton VPN does. That is a provider implementation, not native WireGuard over TCP.

Is PPTP still safe to use?

We do not recommend PPTP as a modern privacy/security default. Even when a VPN still exposes it for compatibility, its legacy security is the reason to choose a modern alternative when one is available. Microsoft no longer accepts PPTP by default on new Windows Server 2025 RRAS installations.