The short answer
A VPN protocol is the rulebook a VPN client and server follow to set up a tunnel. It covers three jobs: proving each side is who it claims to be, agreeing on encryption keys, and packaging your traffic so it can cross the internet and be unwrapped at the other end. The app on your phone is only the interface. The protocol underneath decides which ports are used, how the connection survives a network change and how much there is to configure.
Three protocols cover nearly every modern use: WireGuard, OpenVPN and IKEv2/IPsec. A fourth family, TLS (SSL) VPNs, is common in workplaces. PPTP and L2TP are older and best left alone.
WireGuard
WireGuard is the newest of the three. Its own site says it "securely encapsulates IP packets over UDP" and lists its cryptography as the "Noise protocol framework, Curve25519, ChaCha20, Poly1305, BLAKE2, SipHash24, HKDF". There is no cipher menu to pick from. Each device has a key pair, and each peer is identified by its public key, much like SSH keys.
Points worth knowing:
- It runs only over UDP. The project's known-limitations page states that "WireGuard explicitly does not support tunneling over TCP."
- It does not try to disguise itself: "WireGuard does not focus on obfuscation." On networks that block unusual UDP traffic, it may not connect.
- It is designed to be small. The site describes it as "meant to be easily implemented in very few lines of code, and easily auditable."
- Its Linux kernel component is GPLv2, and it has been part of the mainline Linux kernel since version 5.6, released on March 29, 2020.
Some commercial VPN providers build their own protocol on top of WireGuard: NordVPN, for example, describes its NordLynx protocol as based on WireGuard. Those variants are specific to each provider and only work with that provider's app.
OpenVPN
OpenVPN is an open source VPN daemon used in both commercial apps and self-hosted servers. Its community how-to calls it "a full-featured SSL VPN" that uses "the industry standard SSL/TLS protocol." In practice, that means it uses TLS for the handshake and certificates, then carries your traffic in its own format.
- It can run over a single UDP or TCP port. The official sample server configuration uses
port 1194andproto udp, with TCP as a commented-out alternative. - Running over TCP can help on restrictive networks. Tunnelling TCP inside TCP tends to slow down when packets are lost, which is why UDP is the usual first choice.
- It is open source under GPL version 2, according to its COPYING file on GitHub.
- It needs its own client app on most devices.
We compare it head to head with WireGuard in WireGuard vs OpenVPN.
IKEv2/IPsec
IPsec is the IETF standard for securing traffic at the IP layer, and IKEv2 (RFC 7296) is the protocol that authenticates the two ends and sets up the keys. The data itself travels in ESP. Our page on what an IPsec VPN is explains the pieces in detail.
- It uses UDP 500 and UDP 4500, plus ESP (IP protocol 50) when no NAT is in the way.
- The Canadian Centre for Cyber Security notes that "an IPsec VPN client is built into many operating systems", so you may not need to install anything.
- The MOBIKE extension (RFC 4555) lets a mobile client keep its tunnel "while moving from one address to another", for example from home Wi-Fi to cellular data.
- The same Cyber Centre guidance warns that "some third-party networks restrict or block IPsec traffic."
For organizations, the Cyber Centre recommends "that IPsec be used for VPN access as a primary consideration", mainly because it is an open standard that different vendors implement compatibly.
TLS (SSL) VPNs
"SSL VPN" is a loose label for VPNs that run over TLS, the protocol behind HTTPS. The current version, TLS 1.3, is RFC 8446 (August 2018). Many workplace remote-access products work this way, often on TCP port 443 so they look like ordinary web traffic to a firewall. Some are "clientless" and run in a web browser.
The catch, according to the Cyber Centre, is that "TLS VPNs often use custom, non-standard features to tunnel traffic via TLS", and those from different vendors "will rarely interoperate." TLS itself is standard, but each vendor's tunnel built on it is not. OpenVPN is the best-known open source member of this family. For the business angle, see IPsec vs SSL VPN.
Older protocols: PPTP and L2TP
PPTP is described in RFC 2637, an Informational RFC from July 1999. It uses a TCP control connection and an extended version of GRE to carry PPP traffic. It predates every modern design on this page, and we would not choose it for anything new.
L2TP (RFC 2661, August 1999) is a tunnelling protocol without its own encryption. RFC 3193 (November 2001) describes how L2TP uses IPsec "to provide for tunnel authentication, privacy protection, integrity checking and replay protection." That is the "L2TP/IPsec" option you still see in some settings menus. IKEv2/IPsec does the same job more directly.
The protocols side by side
| Protocol | Transport | Usual port | Built into many systems | Main standard or source |
|---|---|---|---|---|
| WireGuard | UDP only | Set by you (examples on wireguard.com use 51820) | Linux kernel since 5.6 | wireguard.com |
| OpenVPN | UDP or TCP | 1194 in the official sample config | No, needs an app | openvpn.net, OpenVPN GitHub |
| IKEv2/IPsec | UDP for IKE, ESP or ESP-in-UDP for data | UDP 500 and 4500 | Yes, per the Cyber Centre | RFC 7296, RFC 4303 |
| TLS VPN (vendor) | Usually TCP | Often TCP 443 | Sometimes runs in a browser | RFC 8446 for TLS; tunnel is vendor-specific |
| L2TP/IPsec | UDP | IPsec ports plus L2TP | Often, on older systems | RFC 2661, RFC 3193 |
| PPTP | TCP control plus GRE | n/a | Legacy only | RFC 2637 |
Sources: the documents listed under Sources below, checked October 6, 2026.
Which protocol to pick on each device
On a phone
Phones change networks constantly. WireGuard handles that by design: its site says it is "capable of roaming between IP addresses." IKEv2 handles it through MOBIKE. Either is a sensible default. If you are on hotel or airport Wi-Fi that blocks UDP, switching to OpenVPN over TCP is the usual fallback. Our public Wi-Fi guide covers the rest of what to check on shared networks.
On a laptop
For a commercial VPN app, WireGuard (or the provider's WireGuard-based variant) is a reasonable first choice, with OpenVPN as a fallback on difficult networks. For work, use whatever your employer's gateway runs. That is often IKEv2/IPsec through the built-in client, or a vendor's TLS VPN client.
On a router
A router VPN protects every device behind it, including smart TVs and consoles that cannot run an app. Check which protocols the router firmware supports before you buy. WireGuard is attractive here because its configuration is short. If the router only offers OpenVPN or IPsec, both work too. See our VPN router guide.
What the protocol does not change
The protocol protects the path between you and the VPN server. After that, the server forwards your traffic. The Office of the Privacy Commissioner of Canada noted in 2017 that a VPN provider is in a "privileged position to monitor, log, or tamper with any or all communications that are sent through the VPN." Choosing WireGuard over OpenVPN does not change that. Choosing a provider carefully does.
If you simply want a consumer VPN that offers WireGuard and works well from Canada, our best VPN for Canada page compares providers on published data.
Common questions
Which VPN protocol is the most secure?
WireGuard, OpenVPN and IKEv2/IPsec can all be configured securely with modern ciphers. Weak spots usually come from old settings (such as DES or 3DES in IPsec, which RFC 8221 rules out or discourages) or from outdated protocols like PPTP, not from the three main protocols themselves.
Does the VPN protocol change what my VPN provider can see?
No. Every protocol encrypts traffic between you and the VPN server, and the server then forwards it. The Office of the Privacy Commissioner of Canada has pointed out that a VPN provider sits in a privileged position to monitor or log what passes through it, whichever protocol you use.
Why does my VPN app offer TCP and UDP?
That option usually belongs to OpenVPN, which can run over a single TCP or UDP port. UDP is the default in OpenVPN's sample server configuration; TCP can help on networks that only let web-style traffic through. WireGuard runs only over UDP.
Is L2TP/IPsec still worth using?
Only if a device offers nothing newer. L2TP (RFC 2661, 1999) has no encryption of its own and relies on IPsec for it (RFC 3193). IKEv2/IPsec does the same job with fewer layers.
Sources
- WireGuard home page, accessed October 6, 2026
- WireGuard: Protocol and Cryptography, accessed October 6, 2026
- WireGuard: Known Limitations, accessed October 6, 2026
- OpenVPN community how-to, accessed October 6, 2026
- OpenVPN sample server.conf (GitHub), accessed October 6, 2026
- OpenVPN COPYING (licence), accessed October 6, 2026
- RFC 7296: IKEv2, accessed October 6, 2026
- RFC 4555: MOBIKE, accessed October 6, 2026
- RFC 8221: ESP and AH algorithm requirements, accessed October 6, 2026
- RFC 8446: TLS 1.3, accessed October 6, 2026
- RFC 2637: PPTP, accessed October 6, 2026
- RFC 2661: L2TP, accessed October 6, 2026
- RFC 3193: Securing L2TP using IPsec, accessed October 6, 2026
- Canadian Centre for Cyber Security, Virtual private networks (ITSAP.80.101), accessed October 6, 2026
- Office of the Privacy Commissioner of Canada, The actual privacy benefits of virtual private networks, accessed October 6, 2026
