Choosing a Virtual Private Network (VPN) is only half the decision. The tunnelling protocol running underneath it — the ruleset that actually encrypts your traffic and moves it between your device and a remote server — shapes your speed, battery life, and how reliably you stay connected on New Zealand networks. Two open-source protocols dominate that layer today: WireGuard and OpenVPN. This guide explains how each one works, where they genuinely differ in 2026, and how to pick the right default for streaming in Christchurch, working remotely from Auckland, or hopping onto café Wi-Fi in Wellington. If you are new to the topic, our plain-English explainer on what a VPN is and how it works is a useful starting point.
Key Points
- WireGuard is a lean (~4,000-line) protocol with a fixed modern cipher suite — fast, easy to audit, and excellent on mobile.
- OpenVPN (since 2001) is highly configurable and unmatched at slipping past VPN-blocking firewalls via TCP on port 443.
- OpenVPN 2.6 with DCO now runs in the kernel and reaches near-parity with WireGuard on speed — “legacy = slow” is outdated.
- WireGuard is kernel-level on Linux but runs in userspace on Windows, macOS, and mobile.
- WireGuard’s static-IP quirk is solved by good providers using double NAT and RAM-only servers.
- Simple rule: WireGuard as your everyday default; OpenVPN as the fallback for restricted networks.
What a VPN protocol is and why it matters
A VPN protocol is the set of rules that establishes an encrypted “tunnel” between your device and a VPN server. It defines which cryptographic ciphers scramble your data, how data packets are formatted and authenticated, and how the two ends perform the “handshake” that proves they are talking to the right party. For everyday users, the protocol you run is one of the biggest factors in your connection speed, your latency (the delay, measured in milliseconds, before data starts moving), and how quickly a battery drains on a phone or laptop.
Older protocols such as PPTP are now considered insecure and are widely deprecated. The modern choice is effectively between two audited, open-source frameworks: OpenVPN, which has protected connections since 2001, and WireGuard, which reached its stable 1.0 release in 2020 and was merged into the Linux kernel that same year. Both are free software, so independent researchers can inspect the code — an important point for everyday cyber security.
Two design philosophies
The two protocols were built with different priorities. WireGuard was designed to be small, fast, and opinionated: a minimal codebase with one fixed set of modern ciphers and no options to misconfigure. OpenVPN was designed to be flexible and configurable: it can negotiate from a wide range of ciphers and run over more than one transport method, which makes it adaptable but heavier. Neither approach is “wrong” — they simply optimise for different things, and recent updates have narrowed the gap that once separated them.
WireGuard explained
WireGuard was created by security researcher Jason Donenfeld and is deliberately compact — roughly 4,000 lines of code. That small surface area is a genuine security advantage: a smaller codebase gives bugs fewer places to hide and can be reviewed far more quickly than a sprawling one. WireGuard’s handshake is also formally verified, meaning its cryptographic design has been checked with mathematical proof tools rather than only tested by hand.
On Linux, WireGuard runs inside the kernel — the core layer of the operating system that talks directly to your hardware. Running there avoids the constant “context switching” of copying data between the kernel and ordinary applications, which is a large part of why WireGuard feels so quick to connect. On Windows, macOS, iOS, and Android, WireGuard typically runs as a userspace application (using implementations such as wireguard-go or wireguard-nt), so the kernel-level advantage is strongest on Linux and Linux-based VPN servers rather than universal across every device.
WireGuard’s fixed cryptographic suite
Instead of letting administrators pick from dozens of options, WireGuard hard-codes one modern set of cryptographic building blocks. That removes the risk of a weak or mismatched configuration, at the cost of flexibility:
- ChaCha20 for encryption — a fast cipher that often outperforms AES on phones and other chips that lack dedicated AES hardware acceleration.
- Poly1305 for authentication — confirms that packets have not been altered in transit.
- Curve25519 for key exchange — modern elliptic-curve cryptography used to agree on session keys efficiently.
- BLAKE2s for hashing — handles key derivation quickly while resisting collision attacks.
Because the suite is fixed, upgrading a cipher in future means updating the protocol itself rather than flipping a setting — a trade-off WireGuard accepts in exchange for simplicity and predictability. Privacy-focused providers such as Mullvad and Proton VPN lean heavily on WireGuard for exactly these reasons.
OpenVPN explained
OpenVPN, first released in 2001 by James Yonan, is the long-standing industry workhorse. It is built on the widely used OpenSSL library, which is why it can negotiate from a large catalogue of ciphers, hashing functions, and certificate types. Its own core is in the region of 70,000 lines of code; counted together with OpenSSL and other dependencies, the wider stack runs past 600,000 lines. That size reflects two decades of features, compatibility, and enterprise controls rather than bloat for its own sake.
The pay-off is adaptability. Network administrators get granular control over routing, authentication, and encryption, which makes OpenVPN a mainstay in corporate networks, on older equipment, and in setups with strict compliance requirements. The traditional cost was performance: classic OpenVPN processed traffic in userspace, adding overhead compared with WireGuard’s kernel path — but that limitation has changed significantly, as the next section explains.
Transport flexibility: UDP, TCP and port 443
One of OpenVPN’s most useful traits is that it can run over two different transport methods and adapt to the network it finds:
- UDP mode is the default for everyday use — it sends packets without waiting for delivery confirmations, which keeps speeds high.
- TCP mode verifies every packet and re-sends anything lost, trading some speed for reliability on unstable lines.
- Port 443 is the same port standard HTTPS websites use. Running OpenVPN over TCP on port 443 makes its traffic blend in with ordinary encrypted web browsing.
- That blending is what makes OpenVPN effective at slipping past restrictive firewalls and deep packet inspection, where a more distinctive protocol might be blocked.
OpenVPN DCO: the update that closes the speed gap
The single biggest change since WireGuard’s rise is OpenVPN Data Channel Offload (DCO). Enabled by default in OpenVPN 2.6 and later, DCO moves the heavy data-channel encryption out of userspace and into a kernel module — the same architectural trick that made WireGuard fast. The results are dramatic: independent 2026 benchmarks and hardware vendors now report OpenVPN with DCO reaching broadly the same top speeds as WireGuard on comparable equipment, with far lower CPU use than classic OpenVPN.
DCO requires OpenVPN 2.6 or newer with modern AEAD ciphers, and the Linux kernel module (ovpn) was merged into the mainline kernel from version 6.16, with support also available on Windows and FreeBSD. The practical takeaway: describing OpenVPN as inherently “slow” or “legacy” is now out of date. What matters is whether your VPN app and server are running a recent, DCO-enabled build.
Speed and latency on New Zealand connections
New Zealand’s fibre network, delivered largely over Chorus infrastructure alongside mobile 5G from Spark, One NZ, and 2degrees, gives both protocols a fast, stable base to work with. On a healthy fibre line, the protocol is rarely the bottleneck for typical browsing or streaming; the difference shows up most on high-bandwidth tasks, on long international routes to overseas servers, and on lower-powered devices.
Published testing paints a consistent picture rather than a single number. WireGuard connects almost instantly (a one-round-trip handshake) and preserves a very high share of raw throughput with minimal CPU load. Classic OpenVPN is slower to connect and carries more overhead. OpenVPN with DCO, however, closes most of that gap — a June 2026 benchmark from DATAZONE, for example, measured both protocols at multi-gigabit speeds, with DCO using modestly more CPU than WireGuard under identical load. The figures below are indicative ranges drawn from published sources, not a guarantee for any specific line:
| Behaviour | WireGuard | OpenVPN (classic, userspace) | OpenVPN 2.6 with DCO |
|---|---|---|---|
| Connection handshake | Near-instant (about 1 round trip) | Several seconds | Fast (kernel data path) |
| Throughput on fast fibre | Very high, close to line speed | Noticeably reduced under load | Broadly comparable to WireGuard |
| CPU / battery overhead | Low | Higher | Low, slightly above WireGuard in some tests |
| Best-case use | Everyday speed, mobile, gaming | Compatibility, obfuscation | Speed plus OpenVPN’s flexibility |
If you want to see how much headroom your own line has, our guide to real fibre speeds in NZ explains what Fibre 100, 300, and Hyperfibre actually deliver.
Mobile use: battery life and network roaming
For people who move between Wi-Fi and mobile data throughout the day, how a protocol handles roaming matters as much as raw speed. WireGuard’s design is “stateless” and quiet: when you stop sending data, the tunnel effectively goes silent and consumes little power. Because a WireGuard connection is not tied to a fixed source IP address, it also handles handoffs — say, walking out of home Wi-Fi range onto a 5G tower — smoothly, usually without tearing the tunnel down.
Classic OpenVPN handles those transitions with more friction. It relies on an explicit session, so switching networks can force the client to rebuild the tunnel from scratch. In practice that can mean:
- A few seconds of reconnection lag or buffering when you change networks.
- More background processing to keep the session alive, which can add to battery drain on older phones.
- A brief risk of data leaking onto the open network during reconnection if the app lacks a responsive kill switch.
WireGuard is generally the more comfortable choice on a phone. Many current routers and VPN apps support it directly; if you plan to run a VPN on your home network hardware, see our guide to choosing an internet router in NZ.
Privacy considerations
WireGuard’s speed comes with one design quirk worth understanding. In its plain form, WireGuard keeps a table linking each connected user to an internal IP address, and it holds that state until the connection ends or the server restarts. In theory, a server seized while running an unmodified configuration could reveal which internal session mapped to which user. OpenVPN, by contrast, can allocate and discard addresses dynamically out of the box.
Reputable commercial VPNs have engineered around this without giving up WireGuard’s speed:
- Double NAT. Providers such as NordVPN (in its NordLynx implementation) add a network address translation layer that separates your identity from the internal IP the server sees, so no single static table ties you to a session. You can read more in our NordVPN guide.
- RAM-only servers. Running the whole server fleet from volatile memory means all session data is wiped on any reboot or power loss, leaving nothing on a disk to seize.
- No-logs policies. The protocol is only part of the picture; a provider’s audited logging policy and jurisdiction matter at least as much.
The practical point: WireGuard’s theoretical privacy trade-off is a concern with a raw, self-hosted setup, not with a well-run commercial provider that has addressed it.
Bypassing firewalls and censorship
This is where OpenVPN still holds a clear edge. Because it can run over TCP on port 443 and be wrapped in obfuscation tools, its traffic can be made to look like ordinary HTTPS, letting it pass through strict corporate, campus, or national firewalls that block VPNs. WireGuard runs only over UDP and has a distinctive handshake signature, which makes it easier for advanced filtering systems to identify and drop.
The gap is narrowing here too: some providers now layer obfuscation on top of WireGuard, or offer a stealth mode built on it. But if you regularly connect from a network that actively blocks VPNs, keeping an obfuscated OpenVPN option available remains the more dependable fallback. The best VPN apps let you switch protocols in a couple of taps, so you are not locked into one choice.
Choosing a protocol for New Zealand networks
For most people on New Zealand fibre or 5G, WireGuard (or a provider’s WireGuard-based protocol) is the sensible default. Its low overhead squeezes the most out of a fast home line and is well suited to streaming 4K media, low-latency gaming, and quick device-to-device backups. It is also the friendliest option for phones and tablets thanks to its battery efficiency and smooth roaming.
Reach for OpenVPN when the situation calls for it: connecting through a network that blocks VPN traffic, working with older equipment or corporate systems that expect it, or needing a specific cipher or authentication setup. With DCO enabled, modern OpenVPN no longer forces you to trade away much speed for that flexibility. Whichever you use, a good VPN protects the same everyday tasks — online banking with ANZ, ASB, BNZ, Westpac NZ, or Kiwibank; government logins such as RealMe and IRD; and investing on platforms like Sharesies — by keeping the connection encrypted on shared or public networks. iPhone users can follow our dedicated VPN setup guide for iPhone to get started.
Who each protocol suits
- Choose WireGuard if you want the fastest everyday connection, the best mobile battery life, and low-latency gaming, and you use a reputable provider that has addressed its privacy quirk.
- Choose OpenVPN if you need to bypass a VPN-blocking firewall, run on legacy or enterprise gear, or require specific cipher and authentication controls — ideally on a DCO-enabled 2.6+ build for speed.
- Not sure? Start on WireGuard and keep OpenVPN as a fallback. Most quality apps make switching a two-tap job.
Protocol Comparison
| Criterion | WireGuard | OpenVPN |
|---|---|---|
| First released | 2020 (stable 1.0) | 2001 |
| Codebase size | ~4,000 lines | ~70,000 lines (600,000+ with dependencies) |
| Ciphers | Fixed modern suite (ChaCha20, Poly1305, Curve25519, BLAKE2s) | Configurable via OpenSSL (AES and many others) |
| Transport | UDP only | UDP and TCP (incl. port 443) |
| Kernel data path | Yes on Linux; userspace elsewhere | Yes with DCO (OpenVPN 2.6+); otherwise userspace |
| Connection speed | Near-instant handshake | Slower classic; fast with DCO |
| Mobile battery & roaming | Excellent (stateless) | Weaker; rebuilds sessions on network change |
| Firewall bypass / obfuscation | Limited (UDP, distinctive signature) | Strong (TCP 443, obfuscation add-ons) |
| Out-of-the-box privacy | Needs provider workarounds (double NAT) | Dynamic address allocation natively |
| Config error risk | Very low (fixed suite) | Higher (many options) |
Sources
- WireGuard — Official project site and protocol documentation
- WireGuard — Cross-platform (userspace) implementations
- OpenVPN — OpenVPN vs. WireGuard comparison
- OpenVPN — Data Channel Offload (DCO) documentation
- Palo Alto Networks — WireGuard vs. OpenVPN differences
- NordVPN — How the WireGuard protocol and NordLynx work
- DATAZONE — WireGuard vs. OpenVPN 2026 benchmark
Frequently asked questions (FAQ)
Is WireGuard genuinely faster than OpenVPN on NZ fibre?
WireGuard connects almost instantly and preserves a very high share of your line speed, so it usually feels faster than classic OpenVPN. However, OpenVPN 2.6 with Data Channel Offload (DCO) now reaches broadly comparable speeds on similar hardware, so the gap is much smaller than it used to be if both sides run recent software.
Does WireGuard drain my phone battery?
No — it is one of the most battery-friendly options. Its stateless design goes quiet when you stop sending data and does not need constant keep-alive traffic, so it typically uses less power than classic OpenVPN and handles switching between Wi-Fi and mobile data smoothly.
Why do some school or corporate firewalls block WireGuard?
WireGuard runs only over UDP and has a recognisable handshake, which makes it easier for advanced firewalls to detect and drop. OpenVPN can run over TCP on port 443 and be obfuscated to look like normal web traffic, so it is the more reliable choice on networks that actively block VPNs.
Does WireGuard have a privacy weakness?
In its raw form, WireGuard keeps a table linking users to internal IP addresses until the connection ends or the server restarts. Reputable providers remove this concern using techniques such as double NAT (for example NordVPN’s NordLynx) and RAM-only servers, so it is mainly an issue for self-hosted setups rather than well-run commercial VPNs.
Which protocol should I pick for gaming?
WireGuard is usually the best choice for gaming because of its low latency and light CPU load, which helps keep ping stable. If your network blocks it, a DCO-enabled OpenVPN connection is a strong alternative that no longer sacrifices much speed.




