Short answer
For linking offices, data centres and cloud networks, use IPsec. It is the open standard for gateway-to-gateway tunnels, and devices from different vendors can usually talk to each other. For remote staff, both work. IPsec with IKEv2 can use the client built into many operating systems. A TLS (SSL) VPN is easier to get through restrictive networks and can run in a browser, but you are tied to one vendor's client and gateway. The Canadian Centre for Cyber Security recommends that organizations consider IPsec first for VPN access.
What each one is
IPsec
IPsec protects traffic at the IP layer. IKEv2 (RFC 7296) authenticates the two ends and sets up keys; ESP (RFC 4303) encrypts the packets. Because it works below applications, every program on the device uses the tunnel without knowing it is there. Our page What is an IPsec VPN? covers ESP, security associations and the two modes in detail.
SSL / TLS VPN
A TLS VPN uses Transport Layer Security, the same protocol that protects HTTPS websites. RFC 8446 describes TLS 1.3 as a way for client/server applications to communicate "in a way that is designed to prevent eavesdropping, tampering, and message forgery." The name "SSL VPN" survives from TLS's predecessor.
TLS VPNs come in two broad styles:
- Clientless (browser-based). The user logs in to a web portal and reaches internal web apps or remote desktops through it.
- Full tunnel with a client. A small app creates a virtual network interface and sends traffic over TLS, much like IPsec does over ESP. TLS also has a datagram counterpart for UDP traffic, DTLS; its current version is RFC 9147 (April 2022).
OpenVPN belongs to this second group. Its how-to calls it "a full-featured SSL VPN" that uses "the industry standard SSL/TLS protocol."
What Canada's Cyber Centre says
The Canadian Centre for Cyber Security's VPN guidance for organizations (ITSAP.80.101, February 2025) addresses this choice head on. It says "the protocols most widely used for VPNs are Internet Protocol Security (IPsec) and Transport Layer Security (TLS)", and recommends:
"It is recommended that IPsec be used for VPN access as a primary consideration." (Canadian Centre for Cyber Security, ITSAP.80.101)
The reasons it gives:
- "IPsec is an open standard, meaning that anyone can build a client or server which will work with other IPsec implementations."
- "TLS VPNs often use custom, non-standard features to tunnel traffic via TLS." In the Centre's words, "While TLS is a standardized protocol, how it is used to create a VPN is not."
- "TLS VPNs that use a third-party client and server will rarely interoperate", so client and gateway usually have to come from the same vendor.
- A clientless TLS VPN "exposes a public web interface and may have a greater risk of split tunnelling", and the Centre tells organizations to patch that web interface regularly.
It is also fair about IPsec's weak spot: "some third-party networks restrict or block IPsec traffic, so your mobile devices may be unable to create the VPN connection."
Side by side
| IPsec (IKEv2) | SSL / TLS VPN | |
|---|---|---|
| Layer | IP layer (network) | Runs over TLS, above TCP or UDP |
| Standard | Open IETF standard end to end | TLS is standard; the VPN tunnel on top is vendor-specific |
| Ports (Cyber Centre advice) | UDP 500 and 4500, plus ESP | TCP 443 or other necessary ports |
| Client | Built into many operating systems | Vendor app, or a web browser for clientless access |
| Interoperability | Different vendors generally work together | Rarely, per the Cyber Centre |
| Restrictive networks | Some networks block it; TCP fallback exists (RFC 9329) | Usually passes, since it looks like HTTPS on 443 |
| Best fit | Site-to-site, managed remote access | Remote access, browser-only access to web apps |
Sources: Cyber Centre ITSAP.80.101 and the RFCs listed below, checked October 6, 2026.
Site-to-site VPN vs remote access VPN
Much of the IPsec-versus-SSL debate goes away once you separate the two jobs. The Cyber Centre's guidance lists the types of VPN, including:
- Gateway-to-gateway: "Used to connect 2 networks by creating a VPN over a public network". This is what most people call site-to-site, for example a Calgary branch connected to a Toronto head office.
- Host-to-gateway (remote access): "Used to provide remote access to an enterprise network, such as from a remote worker's laptop".
Site to site: IPsec almost by default
Two routers or firewalls, each guarding a network, build a permanent tunnel between them. RFC 4301 requires tunnel mode whenever either end of a security association is a security gateway, and the Cyber Centre notes that "tunnel mode is commonly used for business VPNs." Because IPsec is an open standard, your office firewall can usually connect to a cloud provider's VPN gateway or to a partner's equipment from another vendor. TLS VPN products are mostly designed for people connecting in, so check carefully before using one for a network-to-network link.
Remote access: either can work
Here the choice depends on your users and your network.
- Lean toward IPsec/IKEv2 if you manage the devices, want to use the built-in client, need certificate-based machine authentication, or must interoperate with gateways from more than one vendor.
- Lean toward a TLS VPN if staff often work from hotel, airport or client networks that block UDP, if contractors need access from devices you do not manage, or if browser-only access to a few internal web apps is enough.
Whichever you pick, the Cyber Centre's operational advice applies to both: restrict the VPN device to the needed ports, turn on multi-factor authentication with phishing-resistant factors, prefer a forced (full) tunnel, and "avoid split tunnelling as much as possible."
Security considerations
Neither approach is secure or insecure on its own. Two practical points stand out.
The exposed surface. A clientless TLS VPN puts a login web page on the internet, and that web application must be patched like any other. An IPsec gateway exposes IKE on UDP 500 and 4500. The Cyber Centre lists credential harvesting, remote code execution on the VPN device and session hijacking as examples of attacks on VPNs, and stresses using "the latest patches and versions."
Configuration. IPsec offers many algorithm choices; TLS VPNs add vendor-specific options on top of TLS. The Cyber Centre "strongly" recommends configuring either according to its network protocol guidance, ITSP.40.062.
Questions to put to a vendor
Most organizations buy a VPN as part of a firewall or a remote access product. Whichever protocol it uses, these questions come from the Cyber Centre's list of risks and practices:
- Are the cryptographic modules validated? The Cyber Centre warns that accepting modules without Cryptographic Module Validation Program (CMVP) certification increases risk. The CMVP is run jointly by the U.S. National Institute of Standards and Technology and the Canadian Centre for Cyber Security.
- Which IPsec or TLS settings does it allow? Ask whether you can restrict it to the configurations in ITSP.40.062.
- Does it support phishing-resistant multi-factor authentication? The Centre names application authenticators, biometrics and hard tokens as examples.
- Can you force all traffic through the tunnel? A forced tunnel is, in the Centre's words, "a safer method than split tunnelling."
- How quickly are vulnerabilities patched? For a TLS VPN, that includes the web portal.
- Will it interoperate with what you have? With IPsec, ask which IKEv2 features are supported. With a TLS VPN, assume you will need the same vendor's client.
Where WireGuard fits
WireGuard is neither IPsec nor a TLS VPN. It is its own protocol over UDP with fixed cryptography and a very short configuration. It shares IPsec's weakness on networks that block UDP. We compare it with IPsec in IPsec vs WireGuard, and the full field in our guide to VPN protocols.
For individuals
If you are choosing a VPN for yourself rather than for a company, the IPsec-versus-SSL question rarely comes up. If your app has a protocol setting, the usual choices are WireGuard or a variant of it, OpenVPN and IKEv2, and any of them is reasonable. For staying safe on shared networks, see our public Wi-Fi guide, and for general background, what a VPN is.
Common questions
Is SSL VPN the same as TLS VPN?
Yes, in everyday use. SSL was the predecessor of TLS, and products still use the older name. Current deployments run on TLS; the latest version, TLS 1.3, is RFC 8446 (August 2018).
Which ports do I need to open for each?
The Canadian Centre for Cyber Security advises allowing only UDP 500 and 4500 plus ESP for IPsec VPNs, and only TCP 443 or other necessary ports for TLS VPNs.
Can an IPsec client connect to an SSL VPN gateway?
No. They are different protocols. An IPsec client needs an IPsec gateway, and a TLS VPN client usually needs a gateway from the same vendor; the Cyber Centre notes that TLS VPNs using a third-party client and server will rarely interoperate.
Is OpenVPN an SSL VPN?
Yes. OpenVPN's own how-to describes it as a full-featured SSL VPN that uses the SSL/TLS protocol. Like other TLS VPNs, its tunnel format is its own, so you need OpenVPN at both ends.
What is the difference between a site-to-site VPN and a remote access VPN?
A site-to-site (gateway-to-gateway) VPN connects two whole networks, such as two offices. A remote access (host-to-gateway) VPN connects one device, such as an employee's laptop, to a company network. The Cyber Centre lists both types in its VPN guidance.
Sources
- Canadian Centre for Cyber Security, Virtual private networks (ITSAP.80.101), accessed October 6, 2026
- RFC 4301: Security Architecture for the Internet Protocol, accessed October 6, 2026
- RFC 7296: IKEv2, accessed October 6, 2026
- RFC 4303: ESP, accessed October 6, 2026
- RFC 9329: TCP Encapsulation of IKE and IPsec Packets, accessed October 6, 2026
- RFC 8446: TLS 1.3, accessed October 6, 2026
- RFC 9147: DTLS 1.3, accessed October 6, 2026
- OpenVPN community how-to, accessed October 6, 2026
