VPN Protocols

VPN Protocols Compared: WireGuard, OpenVPN, IKEv2, L2TP, SSTP, PPTP

October 3, 2026

Six protocols sit in this comparison, but they aren’t six options. Three are live choices, two are fallbacks you reach for when a network fights back, and one has been cryptographically broken since 2012 and should have been removed from every app years ago.

Sorting them that way first saves a lot of time, because most comparison tables treat all six as equals scored on the same axes and that’s where they go wrong.

Why “security” is the wrong column

Nearly every protocol table you’ll find rates security as High, Strong or Moderate. For the four modern protocols, that column is meaningless. WireGuard, OpenVPN, IKEv2/IPsec and SSTP all use ciphers with no practical break. None of them is going to be the weak point in your setup your provider’s logging policy, your password, and your DNS configuration all will be, long before the protocol is.

What genuinely separates them is operational: how fast they move data, which ports they use and whether those survive the network you’re on, how they behave when you walk out of Wi-Fi range, and how much code a reviewer has to read to check the implementation.

Speed and CPU cost

WireGuard wins this on architecture. Its codebase is roughly 4,000 lines against OpenVPN’s 70,000-plus, and on Linux it runs in the kernel rather than user space, which removes a layer of context switching from every packet. Less code doing less work, in a hotter part of the system.

IKEv2/IPsec is close behind and is often the lighter option on phones, because iOS and Android implement it natively rather than through a third-party client.

OpenVPN has historically been the slow one, and that reputation is now partly out of date. OpenVPN 2.6 introduced Data Channel Offload, which moves bulk encryption into the kernel and narrows the gap considerably. Most consumer providers haven’t shipped it yet, so the old ranking still holds in practice just don’t assume it’s permanent.

For a deeper comparison of their performance, architecture, and security differences, read our guide to WireGuard vs OpenVPN: Speed and Security Compared.

Ports, and which networks will block you

This is the section that decides things in the real world, and most comparisons give it a line.

ProtocolTransport and portBlocked by restrictive networks?
WireGuardUDP 51820Easily UDP on an unusual port is an obvious target
OpenVPN (UDP)UDP 1194Often
OpenVPN (TCP)TCP 443Rarely looks like HTTPS
IKEv2/IPsecUDP 500 and 4500Often, especially on hotel and campus Wi-Fi
SSTPTCP 443Rarely rides inside TLS
L2TP/IPsecUDP 1701, 500, 4500Frequently
PPTPTCP 1723 plus GREFrequently, and it breaks behind some NAT

Two things fall out of this. First, WireGuard is UDP-only by design and has no TCP fallback, which makes it the easiest protocol to block outright the price of its simplicity. Second, anything travelling over TCP 443 is hard to filter without also breaking normal web browsing, which is why OpenVPN-TCP and SSTP remain useful long after they stopped being fast.

PPTP’s entry is worth a note of its own. GRE isn’t a TCP or UDP port at all, it’s a separate IP protocol, and plenty of consumer routers handle it badly. That’s a large share of PPTP’s reliability complaints, quite apart from the security problem.

Roaming and battery

If you use a VPN mostly on a phone, this axis matters more than speed.

IKEv2 has MOBIKE built in, a mechanism that lets a session survive a change of IP address. Walk out of a coffee shop onto cellular and the tunnel follows you without renegotiating. That’s why Apple and Microsoft built it into their operating systems, and why it stayed the default on iOS for years.

WireGuard handles roaming well too, though differently it’s connectionless, so it simply starts sending from the new address. Its handshake is cheap enough that reconnection is barely noticeable. It’s also generally the gentlest on battery, being the least work per packet.

OpenVPN is the weakest here. Change networks and you’ll usually watch it drop and rebuild the tunnel.

The three you’d actually choose

WireGuard. Default choice for most people on most devices. Fastest, leanest, easiest to audit, best on battery. Weaknesses: UDP-only, so it’s the first thing a restrictive network blocks, and it has a privacy wrinkle covered below.

OpenVPN. The reliability pick. Eighteen years of scrutiny, runs on everything including ancient routers, and configurable onto TCP 443 when a network is hostile. Slower, heavier, and awkward on mobile handover. Keep it as your fallback even if you never use it as your default.

IKEv2/IPsec. The mobile pick. Native on iOS, Android, Windows and macOS, so no third-party client needed, and the best roaming behaviour of the three. Its standing is slipping: Proton VPN began phasing IKEv2 out in April 2026 in favour of WireGuard, and other providers are following. If it’s your default, know that it may not be an option indefinitely.

The two fallbacks

SSTP. Microsoft’s protocol, tunnelling over TLS on port 443. Excellent at getting through firewalls, natively supported on Windows, poorly supported everywhere else. It’s closed-source and Microsoft-controlled, which is why it never gained traction outside Windows environments. Use it if a network blocks everything and your provider offers it.

L2TP/IPsec. L2TP builds the tunnel, IPsec does the encryption L2TP alone has none. It works, and it’s built into most operating systems, but it double-encapsulates traffic, which adds overhead that neither WireGuard nor IKEv2 carries. Its fixed ports make it easy to block. There’s no scenario in 2026 where it’s the best available answer; it survives because old client software already speaks it.

The one to never use

PPTP. Fast, because it barely encrypts anything. Its authentication, MS-CHAPv2, was comprehensively broken in 2012 the attack reduced the effective key strength to a single DES key, recoverable by rented hardware in under a day. That isn’t a theoretical weakness or a caveat; it means captured PPTP traffic can be decrypted.

If your VPN app still lists PPTP, treat it as a signal about the provider rather than a feature. Nothing legitimate needs it.

The WireGuard wrinkle nobody mentions

Here’s the part left out of almost every comparison. WireGuard assigns each connected peer a fixed internal IP address and, in its plain form, keeps that association for as long as the peer exists. Combined with the fact that it holds session state on the server, that makes a naive WireGuard deployment less privacy-friendly than OpenVPN, which hands out addresses dynamically and forgets you on disconnect.

Commercial providers solve this by layering something on top double NAT, dynamic address assignment, or in-memory session handling which is what branded names like NordLynx actually describe. The protocol is excellent. A provider running it straight out of the box, without that layer, is doing something you should ask about.

What to pick

  • Everyday use, any modern device: WireGuard.
  • Phone, heavy roaming, no third-party app wanted: IKEv2, while your provider still offers it.
  • Hotel, campus, airport or office Wi-Fi that blocks you: OpenVPN over TCP 443, or SSTP on Windows.
  • Old router or a device your provider’s app doesn’t support: OpenVPN.
  • L2TP/IPsec or PPTP: only when nothing else is available, and never for PPTP if the traffic matters.