Skip to content
ProtocolsPublished ·

How to choose a VPN protocol

WireGuard, OpenVPN, Xray's obfuscated transports — each one trades speed against resilience differently. Here's when each makes sense.

"Which protocol is best" doesn't have one answer: different protocols make different trade-offs, and the right pick depends on the network, not just the protocol itself.

WireGuard: speed and simplicity

WireGuard is a modern protocol with a compact codebase — a few thousand lines, against hundreds of thousands for older alternatives — which makes it easier to audit and shrinks the surface for bugs. It uses Curve25519 and ChaCha20-Poly1305: a fixed, modern set of algorithms, with no cipher-suite negotiation to get wrong.

Upsides: high throughput, fast reconnects when switching networks, low battery drain on mobile. The downside: WireGuard packets have a recognizable signature, and networks with advanced filtering can detect and block it.

OpenVPN: flexibility at the cost of weight

An older, heavier protocol, but a flexible one: it runs over UDP or TCP and supports a wide range of configurable cipher suites. TCP mode on port 443 is sometimes used specifically to make traffic harder to distinguish from ordinary HTTPS.

The cost is that same flexibility: more code, more surface for configuration mistakes, and typically lower throughput than WireGuard under comparable conditions.

Xray's obfuscated transports: resilience on difficult networks

VLESS+Reality, Trojan+TLS, and Hysteria2 share one goal: make VPN traffic indistinguishable from ordinary HTTPS browsing to anything inspecting the network. Reality, for instance, reproduces the genuine TLS handshake of a real, legitimate site.

Trojan+TLS wraps traffic in standard TLS so that, from the outside, it looks like a request to an ordinary web server. Hysteria2 runs over UDP and is built to hold up on networks with significant packet loss.

The price of that resilience is extra obfuscation overhead, so on networks without strict filtering, the gap over a plain WireGuard connection isn't always worth paying for.

Why picking one protocol forever isn't quite the right approach

Different networks behave differently: home Wi-Fi usually doesn't filter unusual traffic at all, while a network running corporate or carrier-grade DPI might block unencrypted protocols, or protocols with a recognizable signature.

That's why MearVPN understands both formats — WireGuard, and VLESS over Xray with REALITY and XTLS Vision — and leaves the choice to you and your server: which one works better on a given network shows in the traffic counters on the Shield screen.

Related questions

If Xray is more resilient, why not use it all the time?

Obfuscation is overhead: an extra layer of packet wrapping costs speed compared to a more direct WireGuard connection on a network that isn't filtering unusual traffic anyway. Reaching for the heavier tool when it isn't needed isn't free.

Can the protocol be switched manually?

Yes: the configuration sets the protocol. Keep both a VLESS link and a WireGuard configuration for your server in the app, and pick the one you need with a single tap in the list.

Are AmneziaWG and WireGuard the same thing?

AmneziaWG is a WireGuard variant with added packet obfuscation: the same cryptographic core, but a less recognizable network signature. It's a separate point on the trade-off curve between WireGuard's speed and the resilience of fully obfuscated protocols.