Skip to content

freeswan.ca is independent. Some links earn us a commission; your price stays the same. How we review

freeswan.ca

WireGuard vs OpenVPN: differences, and where Tailscale fits

Use WireGuard when UDP gets through and you want a short configuration with fixed modern cryptography. Use OpenVPN when you need TCP, a TLS certificate setup you already run, or a fallback for networks that block WireGuard.

Updated

Laptop screen showing programming code

Short answer

Pick WireGuard for a new setup where UDP traffic is allowed: phones, laptops, a home server or a router. The configuration is short, the cryptography is fixed and there is little to tune. Pick OpenVPN when you need to run over TCP, when you already have a certificate authority and TLS-based setup you want to keep, or as a fallback on networks that block WireGuard. Plenty of people run both.

What is WireGuard?

WireGuard is a VPN protocol and its reference implementation. Its site describes it simply: "WireGuard securely encapsulates IP packets over UDP." You add a WireGuard network interface, give it a private key, list your peers by their public keys, and send packets through it.

The design rests on a few choices:

  • Fixed cryptography. The project lists "Noise protocol framework, Curve25519, ChaCha20, Poly1305, BLAKE2, SipHash24, HKDF." There is no negotiation.
  • Cryptokey Routing. Each peer's public key is tied to the tunnel IP addresses it may use, so the same table handles both authentication and routing.
  • Small code base. It is "meant to be easily implemented in very few lines of code, and easily auditable."
  • Quiet by default. According to the quick start, "it is not a chatty protocol" and sends nothing when there is nothing to send.

WireGuard entered the mainline Linux kernel with version 5.6, released March 29, 2020. Its kernel components are GPLv2. The installation page lists packages for Windows, macOS, Android, iOS, OpenWRT and many Linux distributions.

What is OpenVPN?

OpenVPN describes itself on GitHub as "an open source VPN daemon." Its community how-to calls it "a full-featured SSL VPN" built on "the industry standard SSL/TLS protocol", with client authentication by certificates, smart cards and/or username and password. It is distributed under GPL version 2.

OpenVPN runs in user space and lets "multiple clients connect to a single OpenVPN server process over a single TCP or UDP port." Its configuration language is large, which is both its strength and its burden: you can adjust routing, authentication and encryption in detail, and you have to understand those settings to do it safely.

Side by side

WireGuardOpenVPN
HandshakeNoise_IK with static public keysTLS, typically with X.509 certificates
Cipher choiceFixed setConfigurable
TransportUDP onlyUDP or TCP
PortChosen by you; wireguard.com examples use 518201194 in the official sample server config
Where it runs on LinuxIn the kernel since 5.6User-space daemon
Authentication optionsPublic keys onlyCertificates, smart cards, username and password
Obfuscation"Does not focus on obfuscation"TCP mode can help on restrictive networks
LicenceKernel components GPLv2GPL version 2

Sources: wireguard.com, openvpn.net and the OpenVPN GitHub repository, checked October 6, 2026.

Configuration compared

A WireGuard client fits in a few lines. This illustrative example follows the format shown on wireguard.com, with placeholders:

# Example only
[Interface]
PrivateKey = <client-private-key>

[Peer]
PublicKey = <server-public-key>
Endpoint = <server-address>:51820
AllowedIPs = 0.0.0.0/0

Setting AllowedIPs to 0.0.0.0/0 sends all IPv4 traffic through the tunnel, which is how the client example on wireguard.com is written.

OpenVPN's sample server configuration starts with lines like these, taken from the file in its GitHub repository:

# From OpenVPN's sample server.conf
port 1194
proto udp
dev tun

The rest of that file points to the certificate authority, the server certificate and its key, sets the client address pool and offers optional routes to push to clients. A working OpenVPN server needs a small public key infrastructure; WireGuard needs one key pair per device.

Keys, identity and access control

The two protocols think about identity differently, and that shapes day-to-day administration.

In WireGuard, a peer is its public key. There are no user names, certificate chains or expiry dates. To revoke a device, you delete its [Peer] section. Keys inside the tunnel still rotate: the protocol page explains that the initial handshake "occurs every few minutes, in order to provide rotating keys for perfect forward secrecy." WireGuard also does not answer packets from unknown peers. In the project's words, the server "does not even respond at all to an unauthorized client; it is silent and invisible."

OpenVPN builds on the usual TLS model. Its how-to lists client authentication "based on certificates, smart cards, and/or username/password credentials", and access control policies applied per user or group. That is more to run, with a certificate authority, revocation lists and expiry dates to track. It also fits naturally into organizations that already manage certificates or want password and directory-based logins on top. If you are weighing WireGuard against the other standards-based option, see IPsec vs WireGuard.

Networks that block VPNs

This is where OpenVPN keeps a real advantage. WireGuard's limitations page says it "explicitly does not support tunneling over TCP", on the grounds that TCP inside TCP performs badly, and leaves any conversion to separate tools. If a hotel, campus or workplace network lets only web traffic out, an OpenVPN server on TCP may still connect when WireGuard cannot. Our VPN for travel guide covers that situation from the traveller's side.

On ordinary home and mobile networks, both connect without trouble. WireGuard also handles moving between networks well: its site says it is "capable of roaming between IP addresses."

Security notes

Both are open source and both can be configured securely. The difference lies in where mistakes can happen. With OpenVPN, the large option set means a weak or outdated setting can slip in. With WireGuard, the cipher set is fixed, so the main risks are key handling and allowed-IP mistakes. WireGuard's own documentation lists its trade-offs openly, including that it "is not, by default, post-quantum secure", with an optional pre-shared key as a mitigation.

Whichever you use with a commercial service, the provider still sees your traffic leave its servers. The protocol does not change that. Our VPN protocols guide covers that and the other options, including IKEv2.

Tailscale vs WireGuard

This comparison comes up often because Tailscale is built on WireGuard. Tailscale's documentation says it "enables encrypted point-to-point connections using the open source WireGuard protocol." The difference is everything around the tunnel.

Plain WireGuardTailscale
Data tunnelWireGuardWireGuard (the userspace Go version, wireguard-go)
Who distributes public keysYou, by hand or with your own toolingA coordination server that acts as "a shared drop box for public keys"
TopologyWhatever you configure, often hub and spokePeer-to-peer mesh (a "tailnet"); can also route all traffic through an exit node
Networks that block direct UDPYou must open a port or relay yourselfFalls back to its DERP relay servers
Account neededNoYes

Sources: Tailscale Docs, "What is Tailscale?", and Tailscale's "How Tailscale works", checked October 6, 2026.

Use plain WireGuard if you want no third-party service in the loop and are comfortable managing keys and a reachable endpoint. Use Tailscale if you have many devices behind NAT and want them to find each other without port forwarding, and you accept that a coordination service (in Tailscale's case, login.tailscale.com) holds your devices' public keys and metadata. Tailscale states that its node software is open source.

Which to choose

  • Phone or laptop with a commercial VPN: WireGuard (or the provider's WireGuard-based protocol), with OpenVPN TCP as a fallback.
  • Your own server for a few devices: WireGuard.
  • Many devices behind different NATs: Tailscale or a similar WireGuard-based mesh tool.
  • Existing certificate-based setup, or networks that only allow TCP: OpenVPN.
  • Whole household on one tunnel: a router with WireGuard support; see the VPN router guide.

If you just want a ready-made consumer VPN with WireGuard support and no server to run, our best VPN for Canada page compares providers using their published information.

Common questions

What is WireGuard in simple terms?

WireGuard is an open source VPN protocol and implementation that sends encrypted IP packets over UDP. Each device has a key pair, and you tell each device which public keys it may talk to and which IP addresses belong to each key.

Is Tailscale just WireGuard?

Tailscale uses WireGuard to carry the traffic, and adds a coordination server that distributes public keys, NAT traversal, and relay servers called DERP for networks that block direct connections. Plain WireGuard leaves key distribution and addressing to you.

Can OpenVPN and WireGuard run on the same server?

Yes. They are separate programs listening on separate ports. OpenVPN's sample configuration uses port 1194, and WireGuard uses whichever UDP port you set, so the two do not conflict as long as the ports differ.

Why does OpenVPN have a TCP option and WireGuard does not?

OpenVPN can accept clients on a single TCP or UDP port. WireGuard's documentation says it explicitly does not support tunnelling over TCP because TCP inside TCP performs badly, and leaves any TCP conversion to separate obfuscation tools.

Sources