On this page
At a glance
| Criterion | WireGuard | OpenVPN | IKEv2/IPsec |
|---|---|---|---|
| Speed | Fastest in most tests | Slower, especially over TCP | Fast |
| Time to connect | Near instant | A few seconds | Quick |
| Moving between Wi-Fi and mobile data | Seamless | Usually reconnects | Seamless with MOBIKE |
| Battery use on phones | Low | Higher | Low |
| Code size | About 4,000 lines | Tens of thousands of lines plus a TLS library | Large, varies by vendor |
| Strict firewalls | UDP only, easy to block | Can run over TCP on a web port | Fixed UDP ports 500 and 4500, easy to block |
| Built into systems | Linux kernel; free apps elsewhere | Free apps everywhere | Windows, macOS, iOS and Android 11 or later |
| In BoltVeil | Yes, recommended | Yes: UDP, and TCP firewall mode (port 8080) | Not offered |
WireGuard: the default choice
WireGuard was created by Jason A. Donenfeld and has shipped with the Linux kernel since 2020. Its core idea is radical simplicity: one fixed set of modern cryptography (Curve25519 for key exchange, ChaCha20-Poly1305 for encryption, BLAKE2s for hashing) and nothing to negotiate. Fewer choices mean fewer ways to misconfigure it, and a code base small enough for experts to review.
Users notice three things. It connects almost instantly, it keeps running when your phone moves from Wi-Fi to mobile data, and it is light on the battery. The trade-offs are just as clear:
- UDP only. WireGuard sends everything over UDP. Networks that block UDP, or allow only web ports, stop it.
- It needs state on the server. The server keeps your public key, your address inside the tunnel and, while you are connected, the address you connect from. Providers handle the privacy side of this in different ways; our no-logs policy explains what our network keeps and what it does not.
- It does not try to hide. WireGuard makes no attempt to look like other traffic, so it is easy to recognise on networks that look for VPNs.
Several large providers build their own layers on top of WireGuard to manage keys and addresses, such as NordVPN's NordLynx. Underneath, the tunnel is still WireGuard.
OpenVPN: the flexible veteran
OpenVPN was first released in 2001 and is still the most widely supported VPN protocol. It runs on top of a TLS library such as OpenSSL, which makes it very configurable: it can use UDP or TCP, any port, and a range of ciphers.
That flexibility has costs. It is slower than WireGuard, takes longer to connect, uses more battery and is much larger, which makes it harder to review. Current configurations with AES-GCM or ChaCha20-Poly1305 are secure; old configurations with outdated ciphers are the main risk.
Its big advantage is that it can run over TCP on web ports such as 443 or 8080, so networks that let web traffic through often let it through too. BoltVeil calls this setting firewall mode and uses TCP port 8080. It is slower than UDP, because running TCP inside TCP multiplies delays when packets are lost, so use it only when you need it.
IKEv2/IPsec: great on phones, easy to block
IKEv2 is an IETF standard (RFC 7296) for setting up IPsec tunnels, developed with major contributions from Microsoft and Cisco. It is built into Windows, macOS and iOS, and into Android since version 11, which is why many company VPNs use it.
Its strength is mobility. With the MOBIKE extension a connection survives network changes without reconnecting, and it is efficient on battery. Its weaknesses are fixed UDP ports, 500 and 4500, which a firewall can block with a single rule, and implementations whose quality varies between vendors.
BoltVeil does not offer IKEv2. On the platforms where IKEv2 shines, WireGuard now does the same job at least as well.
What about proprietary protocols?
Large providers also ship their own protocols and obfuscation modes, such as ExpressVPN's Lightway or modes designed for networks with heavy censorship. Some are open source and independently audited, and some are excellent. Judge them by what is published: source code, audits and documentation. A protocol that nobody outside the company can inspect asks you to take its security on trust.
Post-quantum security in 2026
Quantum computers able to break today's key exchange do not exist yet, but traffic recorded now could in theory be decrypted later. That is why some providers have started adding post-quantum key exchange, usually by combining a classic exchange with a newer algorithm such as ML-KEM, which NIST standardised in 2024.
WireGuard has an optional pre-shared key that mixes a symmetric secret into its key exchange, which is how several post-quantum add-ons are built. For most people the practical risk today is low; it matters most for data that has to stay secret for many years.
What really decides your VPN speed
The protocol matters, but it is rarely the only bottleneck. Roughly in order of impact:
- Distance to the server. Every extra border and ocean adds delay. Pick the closest location unless you need a particular country.
- Server load. A busy server is slower. Our servers page lists every location, and the dashboard suggests the least busy server in each country.
- Your own connection. A VPN cannot be faster than the line it runs on, and crowded Wi-Fi is often the real limit.
- Your device. Old phones and budget routers run out of processing power, which is where WireGuard's efficiency shows most.
- TCP or UDP. Firewall mode over TCP is noticeably slower on unreliable connections, so switch back to WireGuard when you can.
To compare fairly, run a speed test with the VPN off and then with WireGuard on a nearby server, at the same time of day. Some slowdown is normal. A very large drop usually points to distance, server load or the Wi-Fi rather than the protocol.
Which protocol to use, device by device
| Situation | Use | Why |
|---|---|---|
| Phone on Wi-Fi and mobile data | WireGuard | Instant reconnects, low battery use |
| Laptop at home or in a cafe | WireGuard | Fastest and simplest |
| Router, or a TV or console behind one | WireGuard | Light on router processors |
| Hotel, train or guest Wi-Fi that stops WireGuard | OpenVPN over TCP (firewall mode) | Uses a web port, where VPNs are allowed |
| Older device or app without WireGuard | OpenVPN over UDP | Supported almost everywhere |
| Company-managed device | Your company's VPN | Follow your employer's policy |
Setup steps for every platform are in our WireGuard guide. Every BoltVeil plan includes both protocols; see pricing, the download page and the current server locations.