WireGuard vs OpenVPN
One is about 4,000 lines of code. The other is well past 600,000. That single difference explains almost every other difference between them — including the one problem WireGuard creates for a no-logs VPN.
See our protocol stackThe short version
| WireGuard | OpenVPN | |
|---|---|---|
| Codebase | ~4,000 lines | ~600,000 lines |
| Released | 2016 | 2001 |
| Typical speed | Faster | Slower |
| Connection time | Under a second | Several seconds |
| Roaming between networks | Seamless | Reconnects |
| Battery use on mobile | Lower | Higher |
| Runs over TCP port 443 | No | Yes |
| Resists DPI blocking | Weaker | Stronger |
| Cryptographic agility | Fixed suite | Configurable |
Small code is a security argument
OpenVPN has been in production since 2001 and it shows. It supports a wide range of ciphers, both TCP and UDP, certificate schemes, plugins and configuration options accumulated over two decades. Every one of those is a feature somebody needs, and every one is also surface area that has to be reviewed.
WireGuard took the opposite decision. It ships one cipher suite — ChaCha20, Poly1305, Curve25519, BLAKE2s — with no negotiation. You cannot configure it badly because there is almost nothing to configure. At roughly 4,000 lines, a competent reviewer can read the entire implementation in an afternoon, which is not a realistic claim for OpenVPN.
Fewer options is also a cost. If a weakness is ever found in WireGuard’s fixed suite, there is no negotiating your way around it — the protocol has to be revised and everyone has to update. OpenVPN would simply be reconfigured to a different cipher.
The part most comparisons skip: WireGuard was designed for point-to-point links, not for commercial VPNs, and it keeps a static mapping of your public key to an assigned internal IP address on the server for as long as the session and a timeout window last. Left untouched, that is a record of who was connected and when — exactly the thing a no-logs provider says it does not keep. Serious providers solve it with in-memory-only allocation, frequent key rotation and double-NAT so that the mapping is never written to disk and never uniquely identifies a subscriber. Any provider offering WireGuard should be able to explain how they handle it.
Which one should you use?
Pick WireGuard for speed
Streaming, large downloads, video calls and anything on a phone. It connects almost instantly, survives moving from Wi-Fi to mobile data without dropping, and uses noticeably less battery — which is the single biggest reason mobile VPN apps default to it.
Pick OpenVPN to get through
On a network that blocks VPNs, OpenVPN over TCP port 443 is far harder to distinguish from ordinary HTTPS traffic. WireGuard is UDP-only with a distinctive handshake, which makes it comparatively easy for inspection equipment to spot and drop.
Pick OpenVPN for control
Enterprise deployments that need specific ciphers, certificate infrastructure, or compatibility with hardware and operating systems too old to have WireGuard support. Its age is the reason it runs on nearly everything.
Or let the app decide
In practice most people should not be choosing manually. A good client uses WireGuard by default and falls back automatically when the network refuses it. LunoGuard is our WireGuard-based tunnel, with obfuscation available when a network is hostile — see our technology page.
How much faster is WireGuard, really?
On a fast connection with a nearby server, both protocols will usually saturate whatever your line can do, and you will not be able to tell them apart. The gap opens up in the conditions where VPNs are actually inconvenient: distant servers, congested mobile networks, and modest hardware such as a router or an older phone.
WireGuard’s advantage comes from running in kernel space with a much shorter code path per packet, which means less CPU per megabyte. On a phone that shows up as battery life; on a router it shows up as throughput the device could not otherwise reach.
Reconnection is the difference people notice most. WireGuard is stateless in a way that lets a session survive a change of network entirely — walk out of the house, move from Wi-Fi to 5G, and the tunnel continues. OpenVPN renegotiates, which takes seconds and drops whatever was in flight.
Common questions
Is WireGuard more secure than OpenVPN?
Is WireGuard bad for privacy?
Which protocol is better for streaming?
Why do some networks block WireGuard but not OpenVPN?
Should I use IKEv2 instead?
Related reading
We run WireGuard, carefully
LunoGuard is built on WireGuard, with in-memory key allocation and obfuscation for networks that would rather you didn’t. The implementation is public.