Skip to content
Guide

Best VPN protocol in 2026: WireGuard vs OpenVPN vs IKEv2

The protocol is the set of rules your VPN uses to build its encrypted tunnel. It decides how fast the connection is, how well it copes with switching networks and whether it gets through strict firewalls. Three open protocols matter today: WireGuard, OpenVPN and IKEv2. Here is how they compare, and which one to use when.

6 min read

At a glance

CriterionWireGuardOpenVPNIKEv2/IPsec
SpeedFastest in most testsSlower, especially over TCPFast
Time to connectNear instantA few secondsQuick
Moving between Wi-Fi and mobile dataSeamlessUsually reconnectsSeamless with MOBIKE
Battery use on phonesLowHigherLow
Code sizeAbout 4,000 linesTens of thousands of lines plus a TLS libraryLarge, varies by vendor
Strict firewallsUDP only, easy to blockCan run over TCP on a web portFixed UDP ports 500 and 4500, easy to block
Built into systemsLinux kernel; free apps elsewhereFree apps everywhereWindows, macOS, iOS and Android 11 or later
In BoltVeilYes, recommendedYes: UDP, and TCP firewall mode (port 8080)Not offered

WireGuard: the default choice

WireGuard was created by Jason A. Donenfeld and has shipped with the Linux kernel since 2020. Its core idea is radical simplicity: one fixed set of modern cryptography (Curve25519 for key exchange, ChaCha20-Poly1305 for encryption, BLAKE2s for hashing) and nothing to negotiate. Fewer choices mean fewer ways to misconfigure it, and a code base small enough for experts to review.

Users notice three things. It connects almost instantly, it keeps running when your phone moves from Wi-Fi to mobile data, and it is light on the battery. The trade-offs are just as clear:

  • UDP only. WireGuard sends everything over UDP. Networks that block UDP, or allow only web ports, stop it.
  • It needs state on the server. The server keeps your public key, your address inside the tunnel and, while you are connected, the address you connect from. Providers handle the privacy side of this in different ways; our no-logs policy explains what our network keeps and what it does not.
  • It does not try to hide. WireGuard makes no attempt to look like other traffic, so it is easy to recognise on networks that look for VPNs.

Several large providers build their own layers on top of WireGuard to manage keys and addresses, such as NordVPN's NordLynx. Underneath, the tunnel is still WireGuard.

OpenVPN: the flexible veteran

OpenVPN was first released in 2001 and is still the most widely supported VPN protocol. It runs on top of a TLS library such as OpenSSL, which makes it very configurable: it can use UDP or TCP, any port, and a range of ciphers.

That flexibility has costs. It is slower than WireGuard, takes longer to connect, uses more battery and is much larger, which makes it harder to review. Current configurations with AES-GCM or ChaCha20-Poly1305 are secure; old configurations with outdated ciphers are the main risk.

Its big advantage is that it can run over TCP on web ports such as 443 or 8080, so networks that let web traffic through often let it through too. BoltVeil calls this setting firewall mode and uses TCP port 8080. It is slower than UDP, because running TCP inside TCP multiplies delays when packets are lost, so use it only when you need it.

IKEv2/IPsec: great on phones, easy to block

IKEv2 is an IETF standard (RFC 7296) for setting up IPsec tunnels, developed with major contributions from Microsoft and Cisco. It is built into Windows, macOS and iOS, and into Android since version 11, which is why many company VPNs use it.

Its strength is mobility. With the MOBIKE extension a connection survives network changes without reconnecting, and it is efficient on battery. Its weaknesses are fixed UDP ports, 500 and 4500, which a firewall can block with a single rule, and implementations whose quality varies between vendors.

BoltVeil does not offer IKEv2. On the platforms where IKEv2 shines, WireGuard now does the same job at least as well.

What about proprietary protocols?

Large providers also ship their own protocols and obfuscation modes, such as ExpressVPN's Lightway or modes designed for networks with heavy censorship. Some are open source and independently audited, and some are excellent. Judge them by what is published: source code, audits and documentation. A protocol that nobody outside the company can inspect asks you to take its security on trust.

Post-quantum security in 2026

Quantum computers able to break today's key exchange do not exist yet, but traffic recorded now could in theory be decrypted later. That is why some providers have started adding post-quantum key exchange, usually by combining a classic exchange with a newer algorithm such as ML-KEM, which NIST standardised in 2024.

WireGuard has an optional pre-shared key that mixes a symmetric secret into its key exchange, which is how several post-quantum add-ons are built. For most people the practical risk today is low; it matters most for data that has to stay secret for many years.

What really decides your VPN speed

The protocol matters, but it is rarely the only bottleneck. Roughly in order of impact:

  1. Distance to the server. Every extra border and ocean adds delay. Pick the closest location unless you need a particular country.
  2. Server load. A busy server is slower. Our servers page lists every location, and the dashboard suggests the least busy server in each country.
  3. Your own connection. A VPN cannot be faster than the line it runs on, and crowded Wi-Fi is often the real limit.
  4. Your device. Old phones and budget routers run out of processing power, which is where WireGuard's efficiency shows most.
  5. TCP or UDP. Firewall mode over TCP is noticeably slower on unreliable connections, so switch back to WireGuard when you can.

To compare fairly, run a speed test with the VPN off and then with WireGuard on a nearby server, at the same time of day. Some slowdown is normal. A very large drop usually points to distance, server load or the Wi-Fi rather than the protocol.

Which protocol to use, device by device

SituationUseWhy
Phone on Wi-Fi and mobile dataWireGuardInstant reconnects, low battery use
Laptop at home or in a cafeWireGuardFastest and simplest
Router, or a TV or console behind oneWireGuardLight on router processors
Hotel, train or guest Wi-Fi that stops WireGuardOpenVPN over TCP (firewall mode)Uses a web port, where VPNs are allowed
Older device or app without WireGuardOpenVPN over UDPSupported almost everywhere
Company-managed deviceYour company's VPNFollow your employer's policy

Setup steps for every platform are in our WireGuard guide. Every BoltVeil plan includes both protocols; see pricing, the download page and the current server locations.

Frequently asked questions

Is WireGuard more secure than OpenVPN?

Both are secure when configured well. WireGuard's advantage is simplicity: one modern set of algorithms and a small code base, so there is less to get wrong. OpenVPN's security depends more on its configuration.

Why is OpenVPN over TCP slower?

When a packet is lost, TCP sends it again. With the VPN itself running over TCP, both the tunnel and the traffic inside it may resend, which multiplies delays on poor connections. UDP avoids this, so use TCP only when UDP is blocked.

Can my internet provider see which protocol I use?

Usually, yes. The content is encrypted, but ports and traffic patterns can reveal WireGuard, OpenVPN or IKEv2. A VPN hides what you do, not the fact that you use a VPN.

Which protocol uses the least battery?

WireGuard and IKEv2 are both efficient on phones. OpenVPN generally uses more, and OpenVPN over TCP the most.

Are PPTP and L2TP still fine to use?

No. PPTP has well-known security flaws and should not be used at all. L2TP/IPsec is dated and easy to block. Use WireGuard, or OpenVPN when you need TCP.

Your IP, hidden in minutes.

Create your account, pick a country and connect. Pay less, or earn it free.