← Blog Blog

VPN Protocols Explained: WireGuard vs OpenVPN vs AmneziaWG

September 4, 2026

Every time a VPN connects, two computers spend a few milliseconds agreeing on a shared secret using math that would take a classical computer billions of years to brute-force. The rulebook that governs how they do that — what cipher they use, how they verify each other, how they recover from a dropped Wi-Fi signal — is the protocol. Pick a weak one and you get a slow, fragile connection. Pick the right one and you barely notice the VPN is running at all.

What a Protocol Actually Controls

A VPN app is the interface; the protocol is the engine underneath it. It decides three things: how your device and the server prove who they are (the handshake), what cipher scrambles your traffic afterward, and how the connection behaves when conditions change — you switch from Wi-Fi to mobile data, the network hiccups, or a firewall inspects the traffic shape. Two apps can look identical on screen and behave completely differently depending on which protocol runs behind the button.

OpenVPN: The Established Standard

OpenVPN has been the default choice for close to two decades. It builds its tunnel using TLS — the same handshake family that secures HTTPS websites — which makes it flexible and compatible with almost any network setup. That flexibility comes from a large, configurable codebase, and configurability has a cost: more code paths to process, more overhead per packet, and a noticeably heavier footprint on battery and CPU than newer designs.

WireGuard: Built for Speed and a Small Attack Surface

WireGuard took the opposite approach: instead of supporting dozens of ciphers and options, it hard-codes one modern set — Curve25519 for key exchange, ChaCha20-Poly1305 as its authenticated encryption scheme under RFC 7539, and BLAKE2 for hashing — with no negotiation step at all. That decision keeps the entire implementation to roughly 4,000 lines of code, small enough that independent researchers have been able to formally analyze the full handshake (the peer-reviewed Dowling–Paterson cryptographic analysis is the most cited example). Fewer lines means fewer places for a bug to hide.

The speed difference shows up in real testing, not just theory. An independent 2026 throughput benchmark on a 1 Gbps link measured WireGuard at 940 Mbps against 480 Mbps for OpenVPN — roughly double, consistent with the wider pattern of WireGuard running about 3x faster than OpenVPN across most connection types.

Quick takeaway: protocol choice affects battery life as much as speed. A leaner handshake means your phone’s radio spends less time processing crypto and more time idle.

AmneziaWG and VLESS-Reality: Built for a Stable Connection Everywhere

Raw speed isn’t the only variable. Some networks apply traffic-shaping rules that specifically recognize the packet patterns of standard WireGuard and slow or drop them — which is a real, growing problem: the deep packet inspection market was valued at roughly $33.9 billion in 2025 and is projected to reach $85.5 billion by 2030, a sign of how much investment is going into traffic classification worldwide. AmneziaWG answers that by obfuscating WireGuard’s packet headers so the traffic doesn’t present the same fingerprint, while keeping WireGuard’s underlying speed and cryptography untouched.

VLESS-Reality, running on the Xray engine with XTLS-Vision, takes a different route: it shapes your connection to look like ordinary HTTPS traffic to a real website, which keeps the connection stable on networks that are more aggressive about shaping unfamiliar traffic patterns. This isn’t about defeating anything — it’s about connection quality staying consistent regardless of the network you’re on.

A typical connection under the hood looks like this:

  1. You sign in to the app (Google, email, or Telegram).
  2. The app fetches your configuration automatically — no codes, no manual setup.
  3. Your device and the RunVPN server complete the protocol handshake.
  4. Traffic moves through the encrypted tunnel, re-keying periodically for forward secrecy.
Your device encrypted Encrypted tunnel WireGuard / AmneziaWG RunVPN server standard Web
How your traffic moves through a VPN protocol before reaching the open internet.

What a Strong Protocol Should Give You

  • Forward secrecy — a compromised key today shouldn’t unlock yesterday’s traffic.
  • A small, auditable codebase — fewer lines, fewer places for a bug to hide.
  • Resistance to traffic fingerprinting — a stable connection even on networks that shape unfamiliar patterns.
  • Fast reconnection — no dropped calls or stalled downloads when you switch from Wi-Fi to mobile data.
  • Zero manual setup — no config files, no QR codes, no copy-pasted keys.

Protocol Comparison at a Glance

ProtocolSpeedCodebaseBest for
OpenVPNModerate — TLS handshake overheadLarge, mature, highly configurableMaximum network compatibility
WireGuardFast — up to ~2-3x OpenVPN in throughput tests~4,000 lines, formally analyzedEveryday speed and battery life
AmneziaWGSame speed as WireGuardSame lean core, obfuscated headersStable connections on shaping-heavy networks
VLESS-Reality (XTLS-Vision)FastXray engineLooking like ordinary HTTPS traffic

Which Protocol Does RunVPN Use

RunVPN runs AmneziaWG by default and falls back to VLESS-Reality automatically when a network needs it — you never pick a protocol or paste a config. Sign in, tap connect, and the app handles the rest, with a no-logs policy underneath. Read more about how that policy works on the trust page.

FAQ

Do I need to choose a protocol myself in RunVPN? No. The app selects AmneziaWG or VLESS-Reality automatically based on network conditions. There’s no settings menu to configure.

Is WireGuard actually secure enough for everyday use? Yes. Its cryptography has been through peer-reviewed formal analysis, and its small codebase means fewer places for vulnerabilities to hide compared to older, larger protocols.

What’s the difference between AmneziaWG and regular WireGuard? AmneziaWG keeps WireGuard’s speed and encryption but obfuscates the packet headers, so the traffic doesn’t present the same recognizable pattern on networks that shape unfamiliar connections.

Why does RunVPN use more than one protocol? Because no single protocol performs best on every network. Running AmneziaWG with a VLESS-Reality fallback keeps your connection fast where possible and stable everywhere else.

Ready to try it yourself? Download RunVPN and connect in under a minute.