Short answer
Pick WireGuard for a new setup where UDP traffic is allowed: phones, laptops, a home server or a router. The configuration is short, the cryptography is fixed and there is little to tune. Pick OpenVPN when you need to run over TCP, when you already have a certificate authority and TLS-based setup you want to keep, or as a fallback on networks that block WireGuard. Plenty of people run both.
What is WireGuard?
WireGuard is a VPN protocol and its reference implementation. Its site describes it simply: "WireGuard securely encapsulates IP packets over UDP." You add a WireGuard network interface, give it a private key, list your peers by their public keys, and send packets through it.
The design rests on a few choices:
- Fixed cryptography. The project lists "Noise protocol framework, Curve25519, ChaCha20, Poly1305, BLAKE2, SipHash24, HKDF." There is no negotiation.
- Cryptokey Routing. Each peer's public key is tied to the tunnel IP addresses it may use, so the same table handles both authentication and routing.
- Small code base. It is "meant to be easily implemented in very few lines of code, and easily auditable."
- Quiet by default. According to the quick start, "it is not a chatty protocol" and sends nothing when there is nothing to send.
WireGuard entered the mainline Linux kernel with version 5.6, released March 29, 2020. Its kernel components are GPLv2. The installation page lists packages for Windows, macOS, Android, iOS, OpenWRT and many Linux distributions.
What is OpenVPN?
OpenVPN describes itself on GitHub as "an open source VPN daemon." Its community how-to calls it "a full-featured SSL VPN" built on "the industry standard SSL/TLS protocol", with client authentication by certificates, smart cards and/or username and password. It is distributed under GPL version 2.
OpenVPN runs in user space and lets "multiple clients connect to a single OpenVPN server process over a single TCP or UDP port." Its configuration language is large, which is both its strength and its burden: you can adjust routing, authentication and encryption in detail, and you have to understand those settings to do it safely.
Side by side
| WireGuard | OpenVPN | |
|---|---|---|
| Handshake | Noise_IK with static public keys | TLS, typically with X.509 certificates |
| Cipher choice | Fixed set | Configurable |
| Transport | UDP only | UDP or TCP |
| Port | Chosen by you; wireguard.com examples use 51820 | 1194 in the official sample server config |
| Where it runs on Linux | In the kernel since 5.6 | User-space daemon |
| Authentication options | Public keys only | Certificates, smart cards, username and password |
| Obfuscation | "Does not focus on obfuscation" | TCP mode can help on restrictive networks |
| Licence | Kernel components GPLv2 | GPL version 2 |
Sources: wireguard.com, openvpn.net and the OpenVPN GitHub repository, checked October 6, 2026.
Configuration compared
A WireGuard client fits in a few lines. This illustrative example follows the format shown on wireguard.com, with placeholders:
# Example only
[Interface]
PrivateKey = <client-private-key>
[Peer]
PublicKey = <server-public-key>
Endpoint = <server-address>:51820
AllowedIPs = 0.0.0.0/0
Setting AllowedIPs to 0.0.0.0/0 sends all IPv4 traffic through the tunnel, which is how the client example on wireguard.com is written.
OpenVPN's sample server configuration starts with lines like these, taken from the file in its GitHub repository:
# From OpenVPN's sample server.conf
port 1194
proto udp
dev tun
The rest of that file points to the certificate authority, the server certificate and its key, sets the client address pool and offers optional routes to push to clients. A working OpenVPN server needs a small public key infrastructure; WireGuard needs one key pair per device.
Keys, identity and access control
The two protocols think about identity differently, and that shapes day-to-day administration.
In WireGuard, a peer is its public key. There are no user names, certificate chains or expiry dates. To revoke a device, you delete its [Peer] section. Keys inside the tunnel still rotate: the protocol page explains that the initial handshake "occurs every few minutes, in order to provide rotating keys for perfect forward secrecy." WireGuard also does not answer packets from unknown peers. In the project's words, the server "does not even respond at all to an unauthorized client; it is silent and invisible."
OpenVPN builds on the usual TLS model. Its how-to lists client authentication "based on certificates, smart cards, and/or username/password credentials", and access control policies applied per user or group. That is more to run, with a certificate authority, revocation lists and expiry dates to track. It also fits naturally into organizations that already manage certificates or want password and directory-based logins on top. If you are weighing WireGuard against the other standards-based option, see IPsec vs WireGuard.
Networks that block VPNs
This is where OpenVPN keeps a real advantage. WireGuard's limitations page says it "explicitly does not support tunneling over TCP", on the grounds that TCP inside TCP performs badly, and leaves any conversion to separate tools. If a hotel, campus or workplace network lets only web traffic out, an OpenVPN server on TCP may still connect when WireGuard cannot. Our VPN for travel guide covers that situation from the traveller's side.
On ordinary home and mobile networks, both connect without trouble. WireGuard also handles moving between networks well: its site says it is "capable of roaming between IP addresses."
Security notes
Both are open source and both can be configured securely. The difference lies in where mistakes can happen. With OpenVPN, the large option set means a weak or outdated setting can slip in. With WireGuard, the cipher set is fixed, so the main risks are key handling and allowed-IP mistakes. WireGuard's own documentation lists its trade-offs openly, including that it "is not, by default, post-quantum secure", with an optional pre-shared key as a mitigation.
Whichever you use with a commercial service, the provider still sees your traffic leave its servers. The protocol does not change that. Our VPN protocols guide covers that and the other options, including IKEv2.
Tailscale vs WireGuard
This comparison comes up often because Tailscale is built on WireGuard. Tailscale's documentation says it "enables encrypted point-to-point connections using the open source WireGuard protocol." The difference is everything around the tunnel.
| Plain WireGuard | Tailscale | |
|---|---|---|
| Data tunnel | WireGuard | WireGuard (the userspace Go version, wireguard-go) |
| Who distributes public keys | You, by hand or with your own tooling | A coordination server that acts as "a shared drop box for public keys" |
| Topology | Whatever you configure, often hub and spoke | Peer-to-peer mesh (a "tailnet"); can also route all traffic through an exit node |
| Networks that block direct UDP | You must open a port or relay yourself | Falls back to its DERP relay servers |
| Account needed | No | Yes |
Sources: Tailscale Docs, "What is Tailscale?", and Tailscale's "How Tailscale works", checked October 6, 2026.
Use plain WireGuard if you want no third-party service in the loop and are comfortable managing keys and a reachable endpoint. Use Tailscale if you have many devices behind NAT and want them to find each other without port forwarding, and you accept that a coordination service (in Tailscale's case, login.tailscale.com) holds your devices' public keys and metadata. Tailscale states that its node software is open source.
Which to choose
- Phone or laptop with a commercial VPN: WireGuard (or the provider's WireGuard-based protocol), with OpenVPN TCP as a fallback.
- Your own server for a few devices: WireGuard.
- Many devices behind different NATs: Tailscale or a similar WireGuard-based mesh tool.
- Existing certificate-based setup, or networks that only allow TCP: OpenVPN.
- Whole household on one tunnel: a router with WireGuard support; see the VPN router guide.
If you just want a ready-made consumer VPN with WireGuard support and no server to run, our best VPN for Canada page compares providers using their published information.
Common questions
What is WireGuard in simple terms?
WireGuard is an open source VPN protocol and implementation that sends encrypted IP packets over UDP. Each device has a key pair, and you tell each device which public keys it may talk to and which IP addresses belong to each key.
Is Tailscale just WireGuard?
Tailscale uses WireGuard to carry the traffic, and adds a coordination server that distributes public keys, NAT traversal, and relay servers called DERP for networks that block direct connections. Plain WireGuard leaves key distribution and addressing to you.
Can OpenVPN and WireGuard run on the same server?
Yes. They are separate programs listening on separate ports. OpenVPN's sample configuration uses port 1194, and WireGuard uses whichever UDP port you set, so the two do not conflict as long as the ports differ.
Why does OpenVPN have a TCP option and WireGuard does not?
OpenVPN can accept clients on a single TCP or UDP port. WireGuard's documentation says it explicitly does not support tunnelling over TCP because TCP inside TCP performs badly, and leaves any TCP conversion to separate obfuscation tools.
Sources
- WireGuard home page, accessed October 6, 2026
- WireGuard: Quick Start, accessed October 6, 2026
- WireGuard: Protocol and Cryptography, accessed October 6, 2026
- WireGuard: Known Limitations, accessed October 6, 2026
- WireGuard: Installation, accessed October 6, 2026
- KernelNewbies: Linux 5.6, accessed October 6, 2026
- OpenVPN community how-to, accessed October 6, 2026
- OpenVPN community page, accessed October 6, 2026
- OpenVPN sample server.conf (GitHub), accessed October 6, 2026
- OpenVPN COPYING (licence), accessed October 6, 2026
- OpenVPN repository on GitHub, accessed October 6, 2026
- Tailscale Docs: What is Tailscale?, accessed October 6, 2026
- Tailscale: How Tailscale works, accessed October 6, 2026
