Guideschevron_rightServers

Servers · 7 min read · Updated

WireGuard vs OpenVPN vs Tailscale

WireGuard is a VPN protocol: small, fast, built into the Linux kernel, and configured with one key pair per device. OpenVPN is an older TLS-based VPN that is slower but more flexible, with certificates, user logins and a TCP mode that gets through strict networks. Tailscale is not a separate protocol but a managed service that builds a WireGuard mesh between your devices for you. For your own server and a few devices, use WireGuard; for many users with logins or locked-down networks, OpenVPN; to connect lots of devices without managing keys yourself, Tailscale.

Side by Side

WireGuard, OpenVPN and Tailscale compared
AspectWireGuardOpenVPNTailscale
What it isA VPN protocol and kernel moduleA VPN program built on TLSA managed mesh network built on WireGuard
TransportUDP onlyUDP or TCP (can use port 443)WireGuard over UDP, relayed over HTTPS if UDP is blocked
SpeedFast, low CPUSlower in user space; better with kernel offload (2.6+)WireGuard speed when direct; slower when relayed
IdentityOne public key per deviceCertificates, or username and password pluginsYour existing login (Google, Microsoft, GitHub and others)
SetupA short config file per deviceA certificate authority and longer configsInstall the app and sign in
Who runs the control sideYouYouTailscale (or a self-hosted control server such as Headscale)
Best forYour own server and a handful of devicesMany users, strict networks, existing OpenVPN clientsConnecting many devices and servers with no key handling

WireGuard

WireGuard has been part of the mainline Linux kernel since version 5.6. Each device has a key pair, and each side lists the other's public key and the addresses it may use. There are no certificates, no user accounts and no negotiation of ciphers: it uses one fixed modern set (Curve25519, ChaCha20-Poly1305, BLAKE2s). That makes the code small and the configuration short.

The trade-offs follow from the same simplicity. It only speaks UDP, so a network that blocks UDP blocks it. It does not hand out addresses or push settings to clients; you write them into each config. And adding a device means adding its key on the server. Our guide to setting up WireGuard on a VPS goes through the whole setup in about fifteen minutes.

OpenVPN

OpenVPN builds its tunnel on TLS. Clients authenticate with certificates issued by your own certificate authority, optionally with a username and password on top, and the server can push routes and DNS settings to them. It runs over UDP by default and can switch to TCP, including on port 443, which helps on hotel, school and corporate networks that only let web traffic out.

It is slower than WireGuard in a default install because packets pass through a user-space program. OpenVPN 2.6 added data channel offload (a kernel module that moves encryption into the kernel), which brings it much closer where it is available. Choose it when you need per-user logins, when clients already have OpenVPN, or when UDP is not an option.

Tailscale

Tailscale uses WireGuard for every tunnel but takes over the parts WireGuard leaves to you. A coordination service distributes keys and addresses, works out a direct path between two devices even when both are behind NAT, and relays traffic through its own servers when no direct path exists. You sign in with an existing account, and access rules decide which devices may reach which.

The cost of that convenience is a dependency: the coordination service is run by Tailscale. If you want the same model under your own control, Headscale is an open-source, self-hosted implementation of the control server that works with the Tailscale clients.

Which to Choose

  • A private tunnel to your own server: WireGuard. One server, a few laptops and phones, nothing else to run.
  • Many people with their own logins, or networks that block UDP: OpenVPN, ideally on TCP 443 for the restrictive networks.
  • Many devices in many places, little time: Tailscale, or Headscale if you want to run the control server yourself.

Whichever you pick on a server, open its port in the server's firewall (51820/udp is WireGuard's usual one) and check that the server is a KVM VPS rather than a container, which may not allow the kernel module or TUN device. To join several of your own servers in one location without any VPN at all, private networking is simpler.

Tailscale, OpenVPN and WireGuard are trademarks of their respective owners. Virteche is not affiliated with or endorsed by them. Details about their products come from their public documentation as of the date at the top of this guide.

Common Questions

  • Is WireGuard faster than OpenVPN?

    Usually, yes. WireGuard runs inside the Linux kernel, uses a small set of modern ciphers and has no TLS handshake on the data path, so it typically moves more data with less CPU. OpenVPN 2.6 narrows the gap with its kernel data channel offload, but a default OpenVPN install still runs in user space.

  • Is Tailscale just WireGuard?

    The tunnels are WireGuard. What Tailscale adds is the control plane: it hands out keys and addresses, finds a direct path between devices through NAT, relays traffic when no direct path exists, and applies access rules. That coordination service is run by Tailscale unless you self-host an alternative such as Headscale.

  • Which one gets through restrictive networks best?

    OpenVPN, because it can run over TCP on port 443 and look much like ordinary HTTPS traffic. WireGuard only uses UDP. Tailscale falls back to relaying over HTTPS when UDP is blocked, which works but is slower.

  • Can I run WireGuard or OpenVPN on a VPS?

    Yes, on any KVM VPS, since both need kernel features or a TUN device that container-based VPSes often restrict. Open the VPN's port (UDP for WireGuard) in your server's firewall as well as in any firewall on the server itself.

KVM VPSes in Ashburn and Dallas run WireGuard and OpenVPN with full root access, with a host firewall you manage from the dashboard.

See VPS plans

Keep Reading

All guides
WireGuard vs OpenVPN vs Tailscale | Virteche Cloud