Skip to content

freeswan.ca is independent. Some links earn us a commission; your price stays the same. How we review

freeswan.ca

What is a VPN protocol? WireGuard, OpenVPN, IKEv2 and the rest

A VPN protocol is the set of rules that decides how your device and the VPN server authenticate each other, agree on keys and wrap your traffic. For most people today the practical choice is WireGuard, OpenVPN or IKEv2/IPsec.

Updated

Blue Ethernet patch cable

The short answer

A VPN protocol is the rulebook a VPN client and server follow to set up a tunnel. It covers three jobs: proving each side is who it claims to be, agreeing on encryption keys, and packaging your traffic so it can cross the internet and be unwrapped at the other end. The app on your phone is only the interface. The protocol underneath decides which ports are used, how the connection survives a network change and how much there is to configure.

Three protocols cover nearly every modern use: WireGuard, OpenVPN and IKEv2/IPsec. A fourth family, TLS (SSL) VPNs, is common in workplaces. PPTP and L2TP are older and best left alone.

WireGuard

WireGuard is the newest of the three. Its own site says it "securely encapsulates IP packets over UDP" and lists its cryptography as the "Noise protocol framework, Curve25519, ChaCha20, Poly1305, BLAKE2, SipHash24, HKDF". There is no cipher menu to pick from. Each device has a key pair, and each peer is identified by its public key, much like SSH keys.

Points worth knowing:

  • It runs only over UDP. The project's known-limitations page states that "WireGuard explicitly does not support tunneling over TCP."
  • It does not try to disguise itself: "WireGuard does not focus on obfuscation." On networks that block unusual UDP traffic, it may not connect.
  • It is designed to be small. The site describes it as "meant to be easily implemented in very few lines of code, and easily auditable."
  • Its Linux kernel component is GPLv2, and it has been part of the mainline Linux kernel since version 5.6, released on March 29, 2020.

Some commercial VPN providers build their own protocol on top of WireGuard: NordVPN, for example, describes its NordLynx protocol as based on WireGuard. Those variants are specific to each provider and only work with that provider's app.

OpenVPN

OpenVPN is an open source VPN daemon used in both commercial apps and self-hosted servers. Its community how-to calls it "a full-featured SSL VPN" that uses "the industry standard SSL/TLS protocol." In practice, that means it uses TLS for the handshake and certificates, then carries your traffic in its own format.

  • It can run over a single UDP or TCP port. The official sample server configuration uses port 1194 and proto udp, with TCP as a commented-out alternative.
  • Running over TCP can help on restrictive networks. Tunnelling TCP inside TCP tends to slow down when packets are lost, which is why UDP is the usual first choice.
  • It is open source under GPL version 2, according to its COPYING file on GitHub.
  • It needs its own client app on most devices.

We compare it head to head with WireGuard in WireGuard vs OpenVPN.

IKEv2/IPsec

IPsec is the IETF standard for securing traffic at the IP layer, and IKEv2 (RFC 7296) is the protocol that authenticates the two ends and sets up the keys. The data itself travels in ESP. Our page on what an IPsec VPN is explains the pieces in detail.

  • It uses UDP 500 and UDP 4500, plus ESP (IP protocol 50) when no NAT is in the way.
  • The Canadian Centre for Cyber Security notes that "an IPsec VPN client is built into many operating systems", so you may not need to install anything.
  • The MOBIKE extension (RFC 4555) lets a mobile client keep its tunnel "while moving from one address to another", for example from home Wi-Fi to cellular data.
  • The same Cyber Centre guidance warns that "some third-party networks restrict or block IPsec traffic."

For organizations, the Cyber Centre recommends "that IPsec be used for VPN access as a primary consideration", mainly because it is an open standard that different vendors implement compatibly.

TLS (SSL) VPNs

"SSL VPN" is a loose label for VPNs that run over TLS, the protocol behind HTTPS. The current version, TLS 1.3, is RFC 8446 (August 2018). Many workplace remote-access products work this way, often on TCP port 443 so they look like ordinary web traffic to a firewall. Some are "clientless" and run in a web browser.

The catch, according to the Cyber Centre, is that "TLS VPNs often use custom, non-standard features to tunnel traffic via TLS", and those from different vendors "will rarely interoperate." TLS itself is standard, but each vendor's tunnel built on it is not. OpenVPN is the best-known open source member of this family. For the business angle, see IPsec vs SSL VPN.

Older protocols: PPTP and L2TP

PPTP is described in RFC 2637, an Informational RFC from July 1999. It uses a TCP control connection and an extended version of GRE to carry PPP traffic. It predates every modern design on this page, and we would not choose it for anything new.

L2TP (RFC 2661, August 1999) is a tunnelling protocol without its own encryption. RFC 3193 (November 2001) describes how L2TP uses IPsec "to provide for tunnel authentication, privacy protection, integrity checking and replay protection." That is the "L2TP/IPsec" option you still see in some settings menus. IKEv2/IPsec does the same job more directly.

The protocols side by side

ProtocolTransportUsual portBuilt into many systemsMain standard or source
WireGuardUDP onlySet by you (examples on wireguard.com use 51820)Linux kernel since 5.6wireguard.com
OpenVPNUDP or TCP1194 in the official sample configNo, needs an appopenvpn.net, OpenVPN GitHub
IKEv2/IPsecUDP for IKE, ESP or ESP-in-UDP for dataUDP 500 and 4500Yes, per the Cyber CentreRFC 7296, RFC 4303
TLS VPN (vendor)Usually TCPOften TCP 443Sometimes runs in a browserRFC 8446 for TLS; tunnel is vendor-specific
L2TP/IPsecUDPIPsec ports plus L2TPOften, on older systemsRFC 2661, RFC 3193
PPTPTCP control plus GREn/aLegacy onlyRFC 2637

Sources: the documents listed under Sources below, checked October 6, 2026.

Which protocol to pick on each device

On a phone

Phones change networks constantly. WireGuard handles that by design: its site says it is "capable of roaming between IP addresses." IKEv2 handles it through MOBIKE. Either is a sensible default. If you are on hotel or airport Wi-Fi that blocks UDP, switching to OpenVPN over TCP is the usual fallback. Our public Wi-Fi guide covers the rest of what to check on shared networks.

On a laptop

For a commercial VPN app, WireGuard (or the provider's WireGuard-based variant) is a reasonable first choice, with OpenVPN as a fallback on difficult networks. For work, use whatever your employer's gateway runs. That is often IKEv2/IPsec through the built-in client, or a vendor's TLS VPN client.

On a router

A router VPN protects every device behind it, including smart TVs and consoles that cannot run an app. Check which protocols the router firmware supports before you buy. WireGuard is attractive here because its configuration is short. If the router only offers OpenVPN or IPsec, both work too. See our VPN router guide.

What the protocol does not change

The protocol protects the path between you and the VPN server. After that, the server forwards your traffic. The Office of the Privacy Commissioner of Canada noted in 2017 that a VPN provider is in a "privileged position to monitor, log, or tamper with any or all communications that are sent through the VPN." Choosing WireGuard over OpenVPN does not change that. Choosing a provider carefully does.

If you simply want a consumer VPN that offers WireGuard and works well from Canada, our best VPN for Canada page compares providers on published data.

Common questions

Which VPN protocol is the most secure?

WireGuard, OpenVPN and IKEv2/IPsec can all be configured securely with modern ciphers. Weak spots usually come from old settings (such as DES or 3DES in IPsec, which RFC 8221 rules out or discourages) or from outdated protocols like PPTP, not from the three main protocols themselves.

Does the VPN protocol change what my VPN provider can see?

No. Every protocol encrypts traffic between you and the VPN server, and the server then forwards it. The Office of the Privacy Commissioner of Canada has pointed out that a VPN provider sits in a privileged position to monitor or log what passes through it, whichever protocol you use.

Why does my VPN app offer TCP and UDP?

That option usually belongs to OpenVPN, which can run over a single TCP or UDP port. UDP is the default in OpenVPN's sample server configuration; TCP can help on networks that only let web-style traffic through. WireGuard runs only over UDP.

Is L2TP/IPsec still worth using?

Only if a device offers nothing newer. L2TP (RFC 2661, 1999) has no encryption of its own and relies on IPsec for it (RFC 3193). IKEv2/IPsec does the same job with fewer layers.

Sources