VPN protocol guide + paid test evidence
VPN Protocols Compared: WireGuard, OpenVPN, IKEv2 & More
A VPN protocol helps determine how your encrypted tunnel is built and how traffic moves through it. We compare the protocols you will actually encounter, then add the part most glossaries cannot: what happened when we switched protocols during nine paid VPN reviews.
Hands-on protocol tests were recorded during our May–July 2026 paid review cycle; volatile protocol and platform facts were rechecked on August 6, 2026. Speed findings compare modes inside the same provider and test session, not raw Mbps across different VPNs. Reviews Ally may earn a commission when you use some links elsewhere on our site. Read our advertising disclosure.
What you’ll find here
Definitions, decision help, and protocol data from paid VPN tests
This page covers the main types of VPN protocols without turning into a glossary dump. You can pick a sensible starting protocol, see how WireGuard, OpenVPN, and IKEv2 differ, inspect our own paid protocol results, and check where a protocol was actually available in the VPN apps we reviewed.
Choose by use case
Start with everyday use, streaming, gaming, mobile, restrictive networks, routers, or troubleshooting.
Compare the protocol families
Separate actual protocols from UDP/TCP transports, obfuscation layers, and Automatic/Smart app logic.
Inspect our paid test patterns
See the 7/7 WireGuard-family and 5/5 OpenVPN UDP/TCP patterns plus the underlying repeat depth.
Download the 65-row CSV
Use the sanitized VPN-on protocol records without private baselines, raw timestamps, or account/tester details.
Start here
Which VPN protocol should you use?
For most people, the boring answer is the useful one: leave a trustworthy VPN on its recommended Automatic or Smart setting, or try WireGuard (or a well-documented WireGuard-based option) when you want a fast general-purpose default. OpenVPN UDP is a strong fallback when you want OpenVPN without TCP overhead. OpenVPN TCP and provider-specific stealth modes become more interesting when a network blocks ordinary VPN traffic.
There is no protocol that wins every network, device, and provider. In our paid tests, WireGuard-family options were the fastest download choice in all seven providers where we had a usable same-session WireGuard-family versus OpenVPN pairing. That is meaningful first-party evidence, but it is a pattern from our test cycle, not a law of networking.
| Use case | Good first choice | Why | Try next if needed |
|---|---|---|---|
| Everyday use | Automatic/Smart or WireGuard | Lets the app choose, or starts with a modern low-overhead protocol. | OpenVPN UDP |
| Streaming & large downloads | WireGuard / provider WireGuard option | It produced the strongest download result in all seven usable WireGuard-family pairings from our test cycle. | OpenVPN UDP, then Automatic |
| Gaming | WireGuard | Low protocol overhead is attractive for latency-sensitive traffic, but server distance and routing still matter enormously. | IKEv2/IPsec or OpenVPN UDP |
| Phones / changing networks | WireGuard or IKEv2/IPsec | Both are common mobile choices; IKEv2 can use MOBIKE to handle address/network changes when implemented. | Provider Automatic/Smart |
| Restrictive Wi-Fi or filtering | Provider stealth mode or OpenVPN TCP | Compatibility can matter more than peak throughput. TCP 443 is commonly allowed where UDP or obvious VPN traffic is restricted. | Provider-specific obfuscation |
| Router / manual configuration | OpenVPN or WireGuard | Both can work well, but support depends on the VPN and router firmware. OpenVPN remains widely documented. | Use the provider’s supported manual method |
| Troubleshooting a connection | Switch protocol before blaming the whole VPN | A server, transport, driver, or filtered network can fail while another protocol works normally. | Automatic/Smart, then a different server |
These are starting points, not security or performance guarantees. Provider implementation, server route, device, network filtering, and app version can change the result.
The terminology matters
What a VPN protocol actually controls
A VPN protocol is the set of rules and cryptographic/networking behavior used to establish and operate the tunnel between your device and a VPN endpoint. The protocol influences connection setup, packet handling, supported transports, cryptography, roaming behavior, and how easily a VPN can fit through different network conditions.
VPN apps make this harder to read than it should be because the same menu can contain actual protocols, transports, obfuscation modes, and an Automatic selector. Those labels are not interchangeable. Split tunneling is a routing policy that decides which traffic uses the tunnel; it is not another VPN protocol.
Protocol
WireGuard, OpenVPN, and IKEv2/IPsec are protocol families you can meaningfully compare at a technical level.
Transport
UDP and TCP describe how traffic is transported in contexts such as OpenVPN. Native WireGuard sends its packets over UDP.
Obfuscation
Obfuscation tries to make VPN traffic harder to identify or block. It can sit above or alongside a protocol rather than being the protocol itself.
Automatic / Smart
This is app logic that chooses a connection mode for you. Unless the provider exposes the result, we do not guess which protocol it selected.
One trap worth avoiding: “WireGuard TCP”
The WireGuard protocol specification says its packets are sent over UDP, and WireGuard’s own limitations page says native WireGuard does not tunnel over TCP. A VPN can still offer a product setting called “WireGuard TCP” by adding its own transport or obfuscation layer. Proton VPN does exactly that. We treat the provider-labeled mode as a provider implementation, not as evidence that native WireGuard suddenly gained TCP support.
Decision matrix
VPN protocols compared
| Protocol / family | Transport / behavior | Practical strengths | Trade-offs | Our default read |
|---|---|---|---|---|
| WireGuard | Native packets over UDP | Modern, compact design; low overhead; strong performance potential. | No native TCP mode or built-in focus on obfuscation. Provider implementation still matters. | Excellent general-purpose starting point when the provider supports it well. |
| OpenVPN UDP | OpenVPN over UDP | Mature, flexible, widely supported, usually the faster OpenVPN transport. | UDP can be restricted on some networks; our results varied substantially by provider. | Best OpenVPN starting point for normal networks. |
| OpenVPN TCP | OpenVPN over TCP; often supports TCP 443 | Useful compatibility option on networks that restrict UDP. | TCP-over-TCP effects can hurt throughput; all five direct pairings in our test cycle favored UDP for download. | A compatibility fallback, not our first speed choice. |
| IKEv2/IPsec | IKEv2 negotiates and maintains IPsec security associations | Fast connection behavior and strong mobility potential; MOBIKE can support address changes. | Consumer-VPN app availability now varies sharply by platform/provider. | Still useful, especially where a provider/OS supports it cleanly. |
| Provider-specific protocols | Varies by provider | Can target speed, censorship resistance, fast reconnection, or provider-specific architecture. | You cannot infer behavior from a marketing name. Documentation and implementation matter. | Evaluate one implementation at a time. |
| PPTP | Legacy tunneling protocol | Historically broad compatibility. | Outdated security. Microsoft no longer accepts PPTP by default on new Windows Server 2025 RRAS installs. | Avoid as a modern privacy/security default. |
| L2TP/IPsec | L2TP tunneling commonly paired with IPsec | Legacy OS compatibility in some environments. | Older design and shrinking consumer-VPN relevance; also disabled by default for new Windows Server 2025 RRAS installs. | Use only when a compatibility requirement gives you a reason. |
First-party evidence
What our paid VPN protocol speed tests showed
Our consolidated speed dataset contains 268 records. The protocol-comparison subset contains 65 VPN-on records across all nine VPNs in our current ranked comparison. We changed protocol or connection mode while keeping the provider and comparison route fixed, then used the Speedtest by Ookla Windows app to record ping, download, upload, and secondary fields when the tool captured them.
Protocol is only one variable in a speed result. To compare a no-VPN baseline with a VPN-on result on your own connection, use our VPN speed test and speed-loss calculator; the guide separates throughput retention, latency, route choice, protocol choice, and repeatability instead of collapsing them into one “fast” label.
Two patterns were unusually consistent. Among the seven providers where we had a usable WireGuard or WireGuard-derived result and a comparable OpenVPN result, the WireGuard-family option posted the higher download result in all seven sessions. Among the five providers with direct OpenVPN UDP and TCP results, UDP posted the higher download result in all five sessions. The consistency is interesting; the sample size is still seven and five providers, not the entire VPN market.
| Provider | WireGuard-family result | Comparable OpenVPN result | Repeat depth | Readout |
|---|---|---|---|---|
| NordVPN | NordLynx: 285.23 Mbps | OpenVPN UDP: 47.96 Mbps | 1 run per mode | WireGuard-based result higher |
| PureVPN | WireGuard: 219.64 Mbps | OpenVPN UDP: 66.41 Mbps | 1 run per mode | WireGuard higher |
| Private Internet Access | WireGuard: 171.55 Mbps avg. | OpenVPN UDP: 116.15 Mbps avg. | 2 runs per mode | WireGuard higher |
| Proton VPN | WireGuard UDP: 267.82 Mbps avg. | OpenVPN UDP: 200.28 Mbps avg. | 2 runs per mode | WireGuard UDP higher |
| Surfshark | WireGuard: 491.38 Mbps avg. | OpenVPN UDP: 291.00 Mbps avg. | 2 runs per mode | WireGuard higher |
| VPN.ac | WireGuard: 653.06 Mbps avg. | OpenVPN UDP: 198.44 Mbps avg. | 2 runs per mode | WireGuard higher; external WireGuard client |
| CyberGhost VPN | WireGuard: 625.18 Mbps avg. | OpenVPN: 235.41 Mbps avg. | 2 runs per mode | WireGuard higher |
These are same-provider Miami comparisons from each documented session, not a seven-VPN speed ranking. Absolute Mbps should not be compared across providers because baseline speed, routing, test date, and implementation differ. VPN.ac WireGuard used the official WireGuard Windows client with VPN.ac profiles.
A concrete example: Surfshark in Miami
Surfshark gives us a particularly clean illustration because OpenVPN TCP, OpenVPN UDP, and WireGuard were each tested twice on the same Miami comparison route. Average ping barely moved, but download throughput changed dramatically: 30.81 Mbps on OpenVPN TCP, 291.00 Mbps on OpenVPN UDP, and 491.38 Mbps on WireGuard.
| Mode | Runs | Avg. ping | Avg. download | Avg. upload |
|---|---|---|---|---|
| OpenVPN TCP | 2 | 121 ms | 30.81 Mbps | 17.75 Mbps |
| OpenVPN UDP | 2 | 121.5 ms | 291.00 Mbps | 61.44 Mbps |
| WireGuard | 2 | 121 ms | 491.38 Mbps | 68.35 Mbps |
Download the 65-row protocol CSV
The public file contains VPN-on protocol records only and strips baseline location, raw timestamps, account/payment information, internal filenames, and other unnecessary private test details.
See our full VPN testing methodology
Read how paid workflows, evidence levels, speed records, leak checks, streaming tests, support, refunds, and limitations fit together.
The high-volume comparison, kept honest
WireGuard vs. OpenVPN: the short version
WireGuard and OpenVPN are both serious VPN technologies, but they make different design choices. WireGuard is deliberately compact and uses a fixed modern cryptographic design with UDP transport. OpenVPN is older, highly configurable, and can operate over UDP or TCP. That flexibility makes OpenVPN valuable when compatibility matters, even when a WireGuard implementation is faster on an ordinary network.
| Question | WireGuard | OpenVPN |
|---|---|---|
| Native transport | UDP only | UDP or TCP |
| Performance in our paired tests | WireGuard-family result led download in all 7 usable provider pairings. | Slower in those seven specific pairings; magnitude varied widely by provider. |
| Restrictive networks | No native focus on obfuscation; a provider may add a separate layer. | TCP compatibility and flexible ports give providers more fallback options. |
| Manual configuration | Excellent when both provider and device/router support it. | Very mature ecosystem with broad router and manual-configuration support. |
| Our default | Try first for normal high-speed use. | Keep as a flexible fallback, especially UDP first and TCP when compatibility calls for it. |
Search demand for “WireGuard vs OpenVPN” is large enough that we plan to give this comparison its own dedicated evidence page. This broad protocol guide deliberately stops at the decision-level answer instead of stretching one section into a second article.
Same protocol, different transport
OpenVPN UDP vs. TCP: use UDP for speed, TCP for compatibility
OpenVPN’s own documentation says UDP is used for optimal performance while TCP is supported for compatibility with restrictive networks. That lines up with our test direction. In all five providers where we recorded a direct OpenVPN UDP-versus-TCP comparison, UDP had the higher download result.
| Provider | OpenVPN UDP | OpenVPN TCP | Runs |
|---|---|---|---|
| PureVPN | 66.41 Mbps | 26.23 Mbps | 1 each |
| Private Internet Access | 116.15 Mbps avg. | 16.38 Mbps avg. | 2 each |
| Proton VPN | 200.28 Mbps avg. | 139.12 Mbps avg. | 2 each |
| Surfshark | 291.00 Mbps avg. | 30.81 Mbps avg. | 2 each |
| VPN.ac | 198.44 Mbps avg. | 15.19 Mbps avg. | 2 each |
PureVPN is a single-run early-cycle pairing; the other four provider rows use two runs per transport. These results do not mean TCP is “bad.” TCP can be the connection that works when UDP is filtered, and a working slower tunnel beats a fast protocol the network refuses to pass.
The three families buyers see most often
WireGuard, OpenVPN, and IKEv2/IPsec explained
WireGuard
WireGuard is a modern VPN tunnel protocol designed around a small, focused implementation and a fixed suite of modern cryptographic primitives. The official project states that WireGuard encapsulates IP packets over UDP and deliberately leaves areas such as key distribution and pushed configuration to other layers. For consumer VPNs, that means the provider still owns a large part of the experience around account identity, key handling, server selection, NAT behavior, and app features.
The practical reason WireGuard is popular is performance. In our current paid protocol dataset, a WireGuard or WireGuard-derived option produced the highest download result inside the tested protocol set for eight of nine providers. Turbo VPN is the exception because WireGuard was not exposed in the Windows app we tested. PrivateVPN also gave us a useful warning against oversimplifying the story: WireGuard worked strongly, while its OpenVPN options did not connect in that session, so there was no valid WireGuard-versus-OpenVPN speed pair to calculate.
WireGuard is not designed to look like ordinary web traffic. Its own limitations page says obfuscation should happen at a layer above WireGuard. If your school, hotel, office, ISP, or country filters VPN traffic, the provider’s stealth implementation may matter more than WireGuard’s raw speed potential.
OpenVPN
OpenVPN is the veteran in this comparison. It is open-source, configurable, and supported across a wide range of clients, servers, routers, ports, and deployment styles. Most consumer users only need to understand one choice: UDP versus TCP. OpenVPN’s own documentation recommends UDP for performance and keeps TCP for networks where compatibility is the bigger concern.
Our data also shows why “OpenVPN is slow” is too crude. The results ranged from perfectly usable OpenVPN UDP sessions to severe TCP throughput drops, and VPN.ac’s obfuscated/proxied OpenVPN variants behaved differently again. The implementation, route, transport, port, proxy/obfuscation layer, server, and test environment can matter almost as much as the protocol family name.
IKEv2/IPsec
IKEv2 is the key-management and negotiation protocol used to establish and maintain IPsec Security Associations. The base standard is RFC 7296. Its mobility extension, MOBIKE (RFC 4555), allows an IKEv2/IPsec VPN to update addresses as connectivity changes, which is one reason IKEv2 became associated with mobile use.
Consumer availability is now the bigger caveat. In our Windows reviews, IKEv2 appeared in PureVPN, VPN.ac, and CyberGhost, but not every app exposed it. Proton VPN’s current protocol page, rechecked August 6, lists IKEv2 in its macOS app only, while PIA’s current desktop documentation lists WireGuard and OpenVPN and its current iOS documentation includes IKEv2. The lesson is simple: “this VPN supports IKEv2” is not the same statement as “IKEv2 is available in the app on your device.”
Names that need context
NordLynx, NordWhisper, Stealth, Lightway, Dausos, and other provider modes
Provider-specific protocols can be genuinely useful, but their names are not a technical specification. We only map them to a protocol family when the provider documents that relationship or our evidence supports it. If documentation is thin, we leave the internals unknown rather than reverse-engineering a marketing label from vibes.
| Name | Provider | What we can support | Evidence boundary |
|---|---|---|---|
| NordLynx | NordVPN | NordVPN’s WireGuard-based option; current docs recommend it and say it is the default in most apps. | Hands-on speed result: 285.23 Mbps download in our single-run May Miami comparison. |
| NordWhisper | NordVPN | Provider-specific protocol aimed at restrictive local networks. | Observed in our paid Windows app; not part of NordVPN’s three-row protocol speed comparison. |
| Stealth | Proton VPN | Provider protocol designed to disguise VPN traffic for censored/restrictive networks. | Two paid Windows speed runs in June; current platform availability rechecked separately in August. |
| WireGuard TCP | Proton VPN | A provider-labeled WireGuard-based TCP mode. | Not native WireGuard TCP. Native WireGuard is UDP-only; Proton adds its own transport architecture. |
| Lightway | ExpressVPN | ExpressVPN’s provider protocol; current official troubleshooting documentation continues to list it alongside newer protocol choices including WireGuard. | Official-source context only. ExpressVPN is not part of this page’s 65-row paid protocol benchmark. |
| Dausos | Surfshark | Surfshark’s newer proprietary protocol. | Not visible in our June Windows test. Surfshark’s current article says Dausos is available only in the macOS App Store app as of our Aug. 6 recheck. |
| Lepus / LinkSentinel | Turbo VPN | Protocol labels we observed in the paid Windows app. | Public technical documentation was not sufficient for us to assign an internal protocol family, so we do not invent one. |
Old does not automatically mean useful
PPTP, L2TP/IPsec, SSTP, and SoftEther
Legacy protocols still appear in search results and some VPN apps, but they should not all be treated as peer alternatives to WireGuard or OpenVPN. Microsoft’s current VPN protocol guidance says new Windows Server 2025 RRAS installations no longer accept PPTP and L2TP by default; SSTP and IKEv2 remain accepted. Microsoft also recommends against PPTP and L2TP there because of their security limitations.
| Protocol / project | Where it fits | ReviewsAlly position |
|---|---|---|
| PPTP | Legacy compatibility. | Do not choose it as a modern privacy/security default. We tested it only because PrivateVPN exposed it. |
| L2TP/IPsec | Older OS/device compatibility, usually pairing L2TP with IPsec. | Not our default. PrivateVPN exposed it, but both Miami runs showed more than 50% packet loss in our session. |
| SSTP | Windows-oriented VPN protocol that remains supported in current Windows Server RRAS. | Relevant in some Windows/enterprise setups, but not part of our nine-provider protocol speed benchmark. |
| SoftEther | Open-source multi-protocol VPN software with its own SSL-VPN protocol plus interoperability for other protocols. | Useful technology to know about, but not a protocol option we benchmarked across the nine consumer VPN apps here. |
Hands-on first, current docs second
Which protocols our reviewed VPNs exposed
The left side of this table is historical first-party evidence: what we actually saw in the paid Windows app during that provider’s review. The current-source note is a separate August 2026 documentation check. Keeping those two clocks separate matters because apps change faster than protocol definitions.
| VPN | Review | Windows protocols / modes observed hands-on | Official-source note rechecked Aug. 6, 2026 |
|---|---|---|---|
| NordVPN | May 2026 | Automatic, NordLynx, NordWhisper, OpenVPN TCP, OpenVPN UDP. | NordVPN still documents NordLynx as its recommended/default option in most apps and NordWhisper for restrictive networks. |
| PureVPN | May 2026 | Automatic, WireGuard, IKEv2, UDP, TCP, plus a restrictive-network mode. | PureVPN’s current support guide documents WireGuard selection in its Windows app and other platforms; exact menus vary by platform. |
| Private Internet Access | May 2026 | Automatic behavior, WireGuard, OpenVPN UDP/TCP; IKEv2 was not visible in the Windows app. | Current desktop documentation lists WireGuard and OpenVPN. Current iOS docs additionally list IPsec/IKEv2. |
| Proton VPN | June 2026 | Smart/Automatic, WireGuard UDP, WireGuard TCP, OpenVPN UDP/TCP, Stealth. | Current Windows docs list Smart, Stealth, WireGuard UDP/TCP and the Proton Protocols beta architecture. OpenVPN is currently listed in the Linux GUI only; IKEv2 in macOS only. |
| CyberGhost VPN | June 2026 | Automatic, WireGuard, OpenVPN UDP/TCP, IKEv2. | Current CyberGhost documentation lists WireGuard, OpenVPN, and IKEv2, with platform-specific availability. |
| Surfshark | June 2026 | Automatic, WireGuard, OpenVPN UDP/TCP; IKEv2 and Dausos were not visible in our Windows app. | Surfshark documents WireGuard, OpenVPN, IKEv2, and Dausos across its ecosystem; Dausos is currently macOS App Store only. |
| PrivateVPN | July 2026 | Automatic, WireGuard, OpenVPN UDP/TCP/TAP variants, L2TP/IPsec, PPTP. OpenVPN variants did not connect in our protocol session. | PrivateVPN’s current protocol page continues to discuss OpenVPN, WireGuard, IKEv2, L2TP/IPsec, and PPTP. Availability inside a specific app can differ. |
| VPN.ac | July 2026 | OpenVPN variants, IKEv2/IPsec, L2TP/IPsec, PPTP; WireGuard used separately through the official WireGuard Windows app. | VPN.ac still documents WireGuard through the official WireGuard app on Windows and supports OpenVPN/IKEv2/L2TP in its service. |
| Turbo VPN | July 2026 | Automatic, OpenVPN, V2Ray, Lepus, LinkSentinel. V2Ray did not connect in our test. | Public technical detail is limited, so we keep the proprietary labels as observations and do not infer their internals. |
“Observed hands-on” is not a promise of current availability. Check your exact OS and app version before choosing a VPN specifically for one protocol.
How the 65 records were produced
How we tested VPN protocol performance
Protocol testing was one block inside a much larger paid review workflow. We purchased each service, installed and used the consumer apps, documented the protocol choices actually exposed, and ran protocol comparisons with the Speedtest by Ookla Windows app. A protocol speed block could take hours once reconnections, repeat runs, screenshots, notes, and troubleshooting were included.
We kept each protocol comparison inside one provider and one documented server route, usually Miami. That is the right level for claims such as “WireGuard was faster than OpenVPN in this Surfshark session.” It is not valid to look at VPN.ac’s 653 Mbps WireGuard average and CyberGhost’s 625 Mbps average and declare VPN.ac universally faster, because the baselines, dates, app/client path, routing, server load, and other conditions were not one laboratory-controlled cross-provider session.
Later reviews generally used two runs per protocol/mode. NordVPN and PureVPN were part of the earlier stage of the cycle and have single-run protocol comparisons. We keep those measurements because they are genuine recorded tests and useful directional evidence, while labeling their smaller repeat depth anywhere it affects interpretation. We do not silently manufacture a second run to make a table look symmetrical.
We also preserve implementation boundaries. VPN.ac’s WireGuard result came from the official WireGuard Windows client loaded with VPN.ac profiles because WireGuard was not integrated into the VPN.ac Windows app. Automatic/Smart is never treated as a known protocol unless the app or provider identifies what it selected. Failed connections, such as PrivateVPN’s OpenVPN modes and Turbo VPN’s V2Ray attempt, are recorded as connection observations rather than converted into fictional 0 Mbps speed tests.
For the full testing system, including Evidence Levels, baseline handling, speed-ranking formulas, leaks, streaming, app controls, support, cancellations, and refunds, read How We Test VPNs.
What the evidence can and cannot say
Limitations of this protocol comparison
We are proud of this dataset, and we also know exactly where its edges are. This was our first full paid VPN test cycle. As we finished the early reviews, the methodology became more structured, so there are small differences in repeat depth and secondary fields between providers. The underlying measurements remain intact and correspond to real VPN sessions; the improvement was in how consistently we repeated and documented later sessions, not in retroactively changing earlier results.
| Limit | What we did | What it means for you |
|---|---|---|
| Different repeat depth | NordVPN and PureVPN protocol comparisons use one run per tested mode; later providers generally use two. | Treat early-cycle results as directional and later repeated averages as stronger estimates of that session. |
| One primary desktop environment | Speed/protocol comparison centered on a Windows consumer environment. | macOS, Linux, Android, iOS, routers, and different drivers can expose different protocol choices and performance. |
| Provider-specific sessions | We controlled protocol changes within each provider rather than running all nine VPNs as one simultaneous lab batch. | Use the data for within-provider protocol choices, not an absolute cross-provider Mbps leaderboard. |
| Reconnection not standardized | We observed connection behavior, but did not time reconnection with one stopwatch method across all nine providers. | This page does not rank protocols by reconnect time. |
| Availability changes | Hands-on app menus are dated to the review; volatile facts were rechecked from official sources in August. | Your current app may legitimately differ from a June or July screenshot. |
| Resource ceiling | We used real paid consumer workflows rather than a multi-location hardware lab with dozens of devices and ISPs. | More devices, networks, countries, time windows, and repeat runs would improve external validity. We do not pretend otherwise. |
None of those limits makes a 491 Mbps WireGuard result turn into a 31 Mbps OpenVPN TCP result, or vice versa. They tell us how far the conclusion can travel. Our strongest conclusion is therefore a bounded one: in this paid test cycle, WireGuard-family options consistently led comparable OpenVPN download results, and OpenVPN UDP consistently led TCP in the five direct pairings we recorded.
Primary sources + our own evidence
Sources used for this VPN protocol guide
Technical claims use protocol projects, standards bodies, Microsoft documentation, and current provider documentation. Competitor articles were useful during SERP research for understanding page format, but they are not the factual authority behind the protocol claims published here.
Protocol & standards sources
Current provider protocol sources
- NordVPN protocol guide
- NordWhisper documentation
- Proton VPN protocol availability
- Proton VPN Stealth protocol
- Surfshark protocol guide
- Surfshark Dausos availability
- PIA desktop protocol settings
- PIA iOS protocol settings
- CyberGhost protocol support
- PureVPN WireGuard guide
- PrivateVPN protocol guide
- VPN.ac WireGuard on Windows
- ExpressVPN Lightway
- ExpressVPN current protocol troubleshooting
ReviewsAlly hands-on evidence
Our source set includes nine Level 4 paid Evidence Logs, final dictated research files, screenshots, and the consolidated 268-record speed dataset. The public protocol subset contains 65 VPN-on rows and deliberately excludes no-VPN baselines and private test-environment details. Speed measurements were recorded with the Speedtest by Ookla Windows app.
Related ReviewsAlly pages
Hands-on review cycle: May–July 2026. Technical/provider source recheck: August 6, 2026.
Common questions
VPN protocol FAQ
What is the best VPN protocol?
There is no universal winner. For normal high-speed use, we usually start with Automatic/Smart or WireGuard. OpenVPN UDP is a strong flexible fallback, while OpenVPN TCP or a provider stealth mode can be more useful on restrictive networks. Your provider, device, route, and network can change the best choice.
Is WireGuard better than OpenVPN?
WireGuard has a modern compact design and was faster for download in all seven usable WireGuard-family versus OpenVPN pairings from our paid test cycle. OpenVPN remains more transport-flexible and can use TCP, which is valuable on restrictive networks. “Better” therefore depends on whether you need maximum normal-network performance, compatibility, manual setup, or a filtering workaround.
Should I use OpenVPN UDP or TCP?
Try UDP first on a normal network if performance matters. OpenVPN itself recommends UDP for optimal performance and TCP for compatibility with restrictive networks. UDP had the higher download result in all five direct UDP/TCP provider comparisons we recorded, but TCP can still be the right fallback when UDP is blocked.
Does WireGuard support TCP?
Native WireGuard does not. The WireGuard project says its packets are sent over UDP and explicitly says it does not provide a TCP tunneling mode. A VPN provider can wrap or transport WireGuard traffic through another layer and label that product mode “WireGuard TCP,” as Proton VPN does. That is a provider implementation, not native WireGuard over TCP.
Is PPTP still safe to use?
We do not recommend PPTP as a modern privacy/security default. Even when a VPN still exposes it for compatibility, its legacy security is the reason to choose a modern alternative when one is available. Microsoft no longer accepts PPTP by default on new Windows Server 2025 RRAS installations.