Top10VPN is editorially independent. Buying a VPN through our links supports our work.
The 4 Main Types of VPN
Follow us:
JP Jones
JP Jones is our CTO. He has over 25 years of software engineering and networking experience, and oversees all technical aspects of our VPN testing process. Read full bio
The four main VPN types are: Personal (encrypts traffic to mask IP and bypass restrictions), Remote Access (connects to private networks remotely), Mobile (maintains connections when switching networks), and Site-to-Site (combines separate networks).
Understanding the different types of VPN (Virtual Private Network) can be confusing, even if you’ve used one before.
Inconsistent terminology doesn’t help, and it’s easy to mix up VPN types with protocols (like WireGuard or OpenVPN) and configurations (such as Double VPN).
To cut through the confusion, we drew on our decades of experience implementing corporate VPNs around the world, plus thousands of tests of personal VPN services, to create this definitive guide to the different types of VPN.
At its core, every VPN creates an encrypted tunnel over the internet to keep your data private.
There are four distinct types of VPN, and the difference between them comes down to how they use that tunnel.
VPN technology is constantly evolving, most recently with post-quantum encryption and new censorship-resistant protocols, but these four core types haven’t changed.
If you’re not sure which type is right for you, use the flowchart below to help you decide.
Use the flowchart to find out what type of VPN you need.
Why Trust Us?
We’re fully independent and have been reviewing VPNs since 2016. Our advice is based on our own testing results and is unaffected by financial incentives. Learn who we are and how we test VPNs.
🔄 July 2026 Updates
Added post-quantum protocol coverage and the new obfuscation protocols (NordWhisper, Proton Stealth, Mullvad QUIC). Also expanded our remote access section to cover the industry shift from traditional VPNs to ZTNA and SASE.
Different Types of VPNs
The table below summarizes how the four main VPN types compare to each other:
Connecting to private networks from another location
Remote private network access with an unstable internet connection
Connecting multiple networks to each other
Below we’ll explain each of these VPN types in more detail, covering how they work and what they are useful for.
1. Personal VPNs
What Is a Personal VPN?
A personal VPN service connects you to a remote VPN server, which can be anywhere in the world.
This VPN server then acts like a middleman between your device and the online services you want to access.
Here we connected to a VPN server in Germany using a personal VPN service.
The personal VPN – sometimes also called a ‘consumer’ or ‘commercial’ VPN – encrypts your connection, hides your identity online, and lets you spoof your geographic location.
A personal VPN service differs from a remote access VPN in that it doesn’t give you access to a private network.
Instead, a personal VPN works by giving you access to the public internet, but over an encrypted connection.
Personal VPNs are what we mostly talk about on this website in our VPN reviews, recommendations, and guides.
The most common type of personal VPNs are the subscription services offered by providers such as ExpressVPN, NordVPN and Private Internet Access, or free services like Windscribe and Proton VPN.
There are several reasons to use a personal VPN. Some of the most popular ones include:
Unblocking geo-restricted content: A personal VPN allows you to stream movies and TV shows from different regions. For instance, connecting to a US-based VPN server allows you to access American Netflix’s extensive content library from anywhere in the world.
Bypassing censorship: A personal VPN helps you overcome internet restrictions in countries with strict online censorship. Connecting to a VPN server in another country not only allows you to access blocked content but also protects your browsing activity from government surveillance.
Enhancing internet privacy and performance: Personal VPNs prevent your internet service provider (ISP), governments, hackers, and anyone else from monitoring your online activity. This not only safeguards your privacy but can also prevent ISPs from throttling your connection speeds during high-bandwidth activities like streaming or gaming.
Personal VPNs can be used to bypass geo-blocked content from anywhere.
How Personal VPNs Work
Diagram explaining how VPN services encrypt and reroute web traffic.
Personal VPNs work the same way whether they’re free or paid: you simply install the provider’s app on your device.
Your provider manages the server network, which typically spans many locations worldwide, either physically, virtually, or both.
Self-managed, or “roll your own”, personal VPNs come in many forms and, like remote access VPNs, require you to spin up your own server.
Unless you rent a Virtual Private Server (VPS) in another country, though, this type won’t let you spoof your location the way a commercial VPN service can.
That said, some DIY setups give you both a remote access and a personal VPN at once.
Here’s how a personal VPN from a service provider works:
Install software from your VPN service provider onto your device.
Personal VPN apps are available on all sorts of devices, including smartphones, streaming devices and gaming consoles.
The setup process usually just requires a one-time sign-in or an activation code.
Connect to a server in your VPN provider’s network.
Personal VPNs are very straightforward. You just tap connect, and authentication happens automatically between the client and server.
The tunnel is established in the same way as with a remote access VPN.
Personal VPNs tend to have large server networks to choose from. If you just want to protect your privacy, connect to a local server for the fastest speeds.
To unblock streaming content, choose a server in the country where that content is available.
Browse the internet as normal.
While connected, all your internet traffic routes via the remote server you selected.
Your connection is encrypted, your IP address is replaced with the VPN server’s, and you can access geo-blocked content from other countries.
EXPERT TIP: It’s important to choose the right VPN protocol. We recommend WireGuard for most situations, as it’s fast, secure, and open-source.
Leading apps now also secure the handshake with post-quantum encryption, see the VPN protocols section for who’s shipped it.
Examples of Personal VPNs
We’ve tested hundreds of free and paid personal VPNs since 2016. Currently, our three highest-rated VPNs are ExpressVPN, NordVPN and Surfshark.
NOTE: Personal VPNs are typically sold on a subscription basis, with discounts available when you pay upfront for a year or more. There’s also a small number of free (safe to use) VPNs.
2. Remote Access VPNs
What Is a Remote Access VPN?
A remote access VPN, sometimes called client-based VPNs or client-to-server VPNs, lets you use the internet to securely connect to a private network, such as your home network or your company’s office network, from another location.
At one end of the scale, big tech companies like Fortinet, Palo Alto and Cisco all offer sophisticated and expensive software solutions aimed at larger businesses.
At the other, it’s also perfectly possible to set up your own VPN server for free if you have the appropriate hardware to hand.
We found Tailscale the easiest way to create a remote access VPN.
Screenshot of the browser-based Tailscale admin console after we connected several of our devices.
In fact, we liked Tailscale so much that one of our reviewers now runs it on a Raspberry Pi at his mother’s house, allowing him to fix issues with her network remotely. What used to be difficult technical support calls are now quick, simple fixes.
Once installed on your device, a remote access VPN client creates an encrypted tunnel between you and the private network you want to access.
When to Use a Remote Access VPN
Remote access VPNs can be used in different ways, for example:
Traveling for work: You can use a remote access VPN to connect securely to your company network on your hotel WiFi. Not only are you able to access all your usual files and software, but the VPN also protects your data from security threats on public networks.
Working from home: This type of VPN can provide secure access to sensitive company systems that have been locked down by IP address. Your computer simply functions as if it were on the corporate network, with all the data encrypted as it travels across the public internet.
Access to personal files: A remote access VPN will allow you to directly access files on any device connected to your home network, such as photos saved to your desktop PC or music and movie files on a home media server, from wherever you are.
Securely access networked devices: As well as files, this type of VPN will allow you to securely control and monitor IoT devices on your network, such as surveillance cameras or smart home systems, which can otherwise be vulnerable to attack, while you are away.
EXPERT TIP: While remote access VPNs are very useful, cloud storage might be a more straightforward alternative if all you want to do is to access files remotely. Cloud storage (such as Dropbox or Drive) uses an encrypted browser connection to protect your data, and is much easier to set up than a VPN.
How Remote Access VPNs Work
Here’s exactly how a remote access VPN works:
Authentication: when you try to establish a VPN connection, the server first checks that you are who you say you are. Authentication methods include:
Username and password
Digital certificates for automatic authentication
Multi-factor authentication (MFA), using some combination of Time-based One-Time Passwords (TOTP), hardware security keys (FIDO2/U2F), and biometric data like fingerprints or facial recognition
Single Sign-On (SSO)
Tunnel establishment: once you’re authenticated, your VPN client and the server negotiate and set up an encrypted tunnel. The exact steps depend on the VPN protocol you’re using, but they typically include:
Sharing encryption keys
Agreeing on encryption standards
Setting up the virtual network interface
IP assignment: the private network assigns you a virtual IP address.
Remote access: you can now reach permitted resources on the private network through the VPN server, just as if you were sitting in the same building.
To use a remote access VPN, you typically install client software on your device, or configure your operating system to connect to the VPN. There also needs to be a VPN server at the network end of the connection.
WireGuard tunnel management interface on macOS.
You can connect as many devices and users as you need to.
The client software and VPN server handle the connection between them.
There are many versions of a remote access VPN, but fundamentally you have two choices: pay for a service, or manage it yourself.
If you go the DIY route, it really comes down to how you set up the VPN server that acts as the gateway to your private network. Popular options include:
An always-on PC, server, or Raspberry Pi-style device running WireGuard or OpenVPN
A flashed router with WireGuard or OpenVPN installed
Tailscale on a PC, mobile device, or Raspberry Pi
Alternatively, if you’d rather pay for a managed service, the main types of remote access VPN include:
Client-to-site VPN
Cloud VPN
SSL VPN Portal
SSL VPN Tunnel
NordVPN’s Meshnet feature
The Shift Away From Traditional Remote Access VPNs
If you’re setting up remote access for a business, there’s something you should know before you commit: the traditional corporate VPN is rapidly falling out of favor, and it’s a security problem that’s driving the change.
VPNs that were once the default way to connect remote workers are increasingly one of the most attacked parts of corporate networks.
The 2025 Verizon Data Breach Investigations Report backs this up: edge devices and VPNs were behind 22% of the breaches that started with a software vulnerability, up from just 3% the year before. That’s a nearly eightfold jump.
Worse still, only 54% of those flaws were fully patched, and the median fix took 32 days.
And the problem isn’t going away. Zscaler’s ThreatLabz 2025 VPN Risk Report found that VPN vulnerabilities grew by over 80% between 2020 and 2025, with roughly 60% rated high or critical.
It’s no surprise, then, that businesses are moving on. Gartner has forecast that at least 70% of new remote-access deployments will be served mainly by Zero Trust Network Access (ZTNA) rather than VPNs, up from under 10% in 2021.
In Zscaler’s own survey, 65% of organizations planned to replace their VPN within the year, and 81% were moving toward a zero trust architecture.
So what makes these alternatives different? Rather than dropping you onto an entire network, ZTNA, Software-Defined Perimeter (SDP), and Secure Access Service Edge (SASE) only let you reach the specific applications you’re cleared to use. That shrinks the attack surface and stops an intruder moving freely across your network if your credentials are stolen.
Let’s be clear, though: this shift is a business concern. If you just want to secure your own connection or reach your home network while you’re away, a traditional remote access VPN is still a perfectly good choice.
Examples of Remote Access VPNs
Examples of remote access VPNs for business include:
NordLayer, from the same company behind our highly-rated personal VPN service, NordVPN.
Other popular remote access VPN products include FortiClient, Palo Alto GlobalProtect, Ivanti Connect Secure, SonicWall SSL VPN, and Juniper Secure Connect.
NOTE: This type of VPN is typically licensed according to how many people need to use it at the same time.
To show you what a self-managed remote access VPN looks like in practice, here’s the one we’ve set up for our own team to support hybrid working.
We run a WireGuard VPN server on a Linux box in our office. WireGuard was the logical choice for us: it’s built into Linux, and it’s simpler and faster than OpenVPN.
The client software on our team’s laptops is free and open-source too. We use the official WireGuard client for both Windows and Mac.
This lets us give the team secure access to our back-end systems and other shared resources whenever they work remotely.
Our setup is free, highly secure, and completely in the hands of our own sysadmins, with none of the risk that comes with relying on a third party.
3. Mobile VPNs
What Is a Mobile VPN?
A mobile VPN, also known as an “always-on VPN”, is a better option than a remote access VPN when you’re unlikely to have a stable connection, on the same network, for a whole session.
The key difference is that a mobile VPN connection persists even if you switch WiFi or cellular network, lose signal, or turn your device off for a while.
Mobile VPN service offered by Bittium.
Mobile VPNs tend to be offered by the same big tech companies that provide standard remote access VPN services.
NOTE: A mobile VPN can be used with any device and any connection: it doesn’t have to be a phone on a cellular network.
Confusingly, the ExpressVPN or PIA app on your smartphone is not a mobile VPN. It’s the mobile client for your personal VPN.
When to Use a Mobile VPN
You should use a mobile VPN if you are constantly on the move and it’s critical that you maintain an uninterrupted connection to a remote private network.
This type of VPN also provides the convenience of a connection that adapts to network changes. For example:
First responders like firefighters and police officers rely on mobile VPNs to maintain access to critical resources such as vehicle databases, location tracking systems, and emergency dispatch applications as they move throughout their service area.
Remote professionals in regions with unreliable internet can use a mobile VPN to maintain a secure office connection throughout the workday. This type of VPN avoids the inconvenience of constant re-authentication or the challenge of whitelisting revolving IP addresses.
How Mobile VPNs Work
In day-to-day use, connecting to and using a mobile VPN feels much the same as using a remote access VPN.
The main differences are under the hood: a mobile VPN uses specialized protocols to hold your connection open as you move between networks, whether you’re switching cellular towers or dropping from WiFi to mobile data.
That’s why mobile VPNs typically use UDP-based protocols like IKEv2, the same reason those protocols are usually the default in the mobile apps of personal VPN services.
UDP-based protocols cope with network changes far better than TCP-based ones, because they can re-establish a connection quickly without a full VPN handshake.
It’s no coincidence that the newest protocol developments tend to reach providers’ mobile apps first.
The same network-switch resilience that makes UDP- and QUIC-based protocols ideal on the move is exactly why features like QUIC obfuscation and post-quantum encryption usually debut on mobile.
Since the basics work just like a remote access VPN, here’s the part that’s unique to mobile VPNs: what happens when you switch networks.
Your device switches networks (e.g., from WiFi to cellular), changing its IP address in the process.
Your VPN client detects the change.
It sends a reconnection request using the unique ID assigned to the session.
The VPN gateway validates that session and seamlessly resumes the connection.
Even if you switch your device off to save battery, the VPN is still connected when you turn it back on.
Behind the scenes, mobile VPNs work hard to make this seamless, tolerating brief drop-outs, reconnecting with minimal overhead, and compressing data on slow networks, all while trying not to drain your battery.
Many also offer user-facing extras like split tunneling, automatic connection rules based on the network you’re on, and integration with Mobile Device Management (MDM) for business fleets.
Radio IP software: enables mobile VPNs across all wireless network technologies.
4. Site-to-Site VPNs
What Is a Site-to-Site VPN?
Site-to-site VPNs connect entire networks in different locations, for example linking the corporate networks of a company’s multiple offices.
Unlike remote access VPNs, which connect individual users to a network, site-to-site VPNs bridge two or more separate local area networks (LANs) over the internet.
This lets offices share resources and communicate as if they were part of the same network, while encryption keeps everything secure.
You can also extend a site-to-site VPN to trusted business partners, giving external companies secure access to parts of your network.
NOTE: Site-to-site VPNs are also called router-to-router VPNs or network-based VPNs, because they connect entire networks rather than individual users.
When to Use a Site-to-Site VPN
A site-to-site VPN is ideal when you need to connect multiple networks securely, for instance:
Intranet-based VPN: connects different branches of the same company into a unified private wide area network (WAN). Employees from each location can access shared resources across all branches seamlessly.
Extranet-based VPN: allows companies to securely share specific resources with external business partners by connecting their respective networks. It’s useful for suppliers, contractors, and collaborative ventures.
EXPERT TIP: You can combine a site-to-site VPN with a remote access VPN, enabling secure network connections between offices and allowing individual employees to connect remotely.
How Site-to-Site VPNs Work
There are three main ways to implement a site-to-site VPN:
IPsec tunnels create encrypted pathways between networks, set up through the routers at each connected site. This method is also known as a router-to-router VPN, and it comes in two variants:
A route-based IPsec tunnel acts as a virtual wire between networks, letting all traffic pass through.
A policy-based IPsec tunnel uses specific rules to control the flow of traffic between IP networks.
Pros
Cons
Widely supported by most firewalls and routers
Point-to-point nature limits scalability
Strong security through encryption
Can become complex to manage in large networks
Relatively simple to implement for small-scale deployments
Relies on internet connectivity, which may affect performance
Dynamic Multipoint VPN (DMVPN)
DMVPN tackles the scalability problem of traditional IPsec tunnels. This Cisco-proprietary technology suits large organizations with many sites, which would otherwise need thousands of individual router-to-router IPsec connections. Instead, DMVPN uses a hub-and-spoke architecture, where:
Branch sites (spokes) connect to a central location (hub).
Dynamic IP addressing is supported.
Direct spoke-to-spoke connections are possible with extra configuration.
May require specialized expertise to implement and manage
Reduces configuration complexity in hub-and-spoke topologies
Still subject to internet performance limitations
MPLS-based Layer 3 VPN (L3VPN)
The IPsec and DMVPN approaches both sit on top of the internet, so they can’t guarantee consistent performance.
L3VPNs instead operate at the network layer of the OSI model and use Multiprotocol Label Switching (MPLS) to guarantee quality of service across different transport media. These are typically sold by service providers as managed WAN solutions.
NOTE: L3VPNs are also sometimes known as Virtual Private Routed Networks (VPRNs).
Pros
Cons
Guaranteed performance and QoS
Significantly higher cost compared to internet-based VPNs
Traffic prioritization capabilities
Limited flexibility in terms of service changes
Provider-managed infrastructure
Dependency on service provider coverage
Protocol and transport medium agnostic
As with remote access, the multi-site world is shifting too. Many businesses now fold site-to-site connectivity into a broader SD-WAN or SASE setup, which bundles network links and cloud-delivered security into a single managed service, rather than maintaining site-to-site tunnels on their own.
Examples of Site-to-Site VPNs
Examples of site-to-site VPN products include:
OpenVPN Access Server: allows for secure site-to-site connectivity using the OpenVPN protocol.
Cisco’s Meraki Auto VPN: one of a number of site-to-site VPNs by Cisco, Meraki promises single-click VPN tunnel creation to link compatible devices.
AWS Site-to-Site VPN: enables secure, scalable connectivity between on-premises data centers and Amazon Virtual Private Cloud (VPC).
Fortinet SD-WAN: provides secure site-to-site connectivity with advanced traffic optimization and security features.
VPN Types Are Not the Same as VPN Protocols
Let’s clear up a common source of confusion: a VPN’s type and its protocol are two different things.
The VPN protocol is simply the set of rules your software follows to build a secure connection to the server and move your data through it. It doesn’t determine what type of VPN you’re using.
In fact, the same protocol often shows up across several types. WireGuard, for example, is used by personal, remote access, and site-to-site VPNs alike, while IKEv2 is a favorite of both mobile VPNs and the mobile apps of personal VPN services.
So when you see a VPN described as “a WireGuard VPN” or “an OpenVPN VPN”, that’s telling you the protocol, not the type.
The table below compares the main protocols on speed, security, data usage, and whether they’re ready for the coming shift to post-quantum encryption.
Protocol
Speed
Security
Data Usage
Post-Quantum
WireGuard
Very Fast
Very High
Very Low
Yes (hybrid)
OpenVPN
Moderate
Very High
High
Emerging
IKEv2/IPsec
Very Fast
High
Moderate
Emerging
SoftEther
Very Fast
High
Low
No
L2TP/IPsec
Moderate
Moderate
High
No
SSTP
Slow
Moderate
High
No
PPTP
Slow
Low
Moderate
No
NOTE: The Post-Quantum column reflects what’s actually available in consumer VPNs today, not what’s theoretically possible. We explain what post-quantum encryption is, and why it matters, at the end of this section.
We’ve explained each protocol below, along with its main strengths and weaknesses.
WireGuard
WireGuard is a modern VPN protocol built around simplicity and performance. It uses state-of-the-art cryptography and runs on only about 4,000 lines of code, which makes it far easier to audit and less prone to vulnerabilities than older protocols.
It’s also built into the Linux kernel, which is part of why it’s so fast and efficient.
WireGuard is ideal when you need a high-speed connection, such as for streaming or gaming, and it’s particularly effective on mobile because it switches between networks seamlessly. Its main advantages are faster connection times, better battery life on mobile, and stronger all-round performance.
The trade-off is that WireGuard’s simplicity makes it less configurable than some other protocols, which may put off advanced users. Any concerns over IP logging are unfounded, in our view, since WireGuard can be configured not to record that data. Increasingly, providers also pair it with post-quantum encryption to protect against future quantum attacks (more on that below).
It’s the protocol we typically recommend using wherever possible.
OpenVPN
OpenVPN is an open-source protocol that was the industry standard for personal VPN services for well over a decade. For many years it was our own recommended choice too, until we switched to WireGuard.
It offers a highly secure, versatile connection, using the OpenSSL library and TLS protocols for encryption and authentication. It’s extremely flexible and hard to block, as it can run on any port and use either UDP or TCP.
OpenVPN is an excellent choice if security and privacy matter more to you than raw speed. It’s especially good at bypassing firewalls and runs on almost any platform.
The drawbacks are that it’s slower than newer protocols like WireGuard, it needs third-party software to run, and it can be complex to set up manually.
That shift is now playing out across the industry: Mullvad, for example, dropped OpenVPN support entirely in January 2026 in favor of WireGuard and newer obfuscation protocols. OpenVPN remains widely used and highly secure, but it’s no longer the default choice it once was.
IKEv2
IKEv2 (Internet Key Exchange version 2), when combined with IPsec, makes for a highly secure and fast VPN protocol.
Developed jointly by Microsoft and Cisco, IKEv2 handles the Security Association (SA) negotiation, while IPsec encrypts the actual data traffic.
It’s known for quickly re-establishing a connection when you switch networks or briefly lose signal, which is exactly why it’s a go-to for mobile VPNs and the mobile apps of personal VPNs. Its main strengths are excellent stability, fast speeds, and native support on many platforms.
The biggest downside is that many IKEv2 implementations are closed-source, so they can’t be independently audited for flaws or backdoors the way WireGuard and OpenVPN can.
It’s also supported on fewer platforms than OpenVPN and, in theory at least, easier to block, since it uses fixed ports.
SoftEther
SoftEther (Software Ethernet) is multi-protocol VPN software designed as an alternative to OpenVPN.
It can tunnel through most firewalls using HTTPS, which makes it highly versatile in restrictive networks. It began as an academic project at the University of Tsukuba in Japan and has since grown into a powerful, flexible solution.
SoftEther is a good option if you need to bypass strict firewalls while keeping performance high. Its strengths include multi-protocol support, speeds that usually beat OpenVPN, and strong encryption.
On the downside, it isn’t as widely supported by commercial providers as other protocols, it can be complex to set up, and it takes some technical know-how to implement well.
L2TP/IPsec
L2TP (Layer 2 Tunneling Protocol) is typically paired with IPsec for encryption, since it provides none on its own. Together they create a very secure connection that encapsulates your data twice.
L2TP/IPsec is the successor to PPTP and is far more secure, while keeping wide compatibility.
It’s best when security is the priority and native support matters, as it’s built into many operating systems. Its main advantages are broad support, good security when configured correctly, and easy setup on most platforms.
The drawbacks are slower speeds from that double encapsulation, difficulty getting through firewalls due to fixed ports, and potential vulnerabilities if Network Address Translation (NAT) is set up incorrectly.
SSTP
SSTP (Secure Socket Tunneling Protocol) is Microsoft’s proprietary protocol, using SSL/TLS encryption.
Like OpenVPN, it can run over TCP port 443, which makes it hard to block and able to bypass most firewalls.
SSTP can be handy where other protocols are blocked, but we don’t recommend it except as a last resort, as it’s closed-source.
It’s also poorly supported outside Windows and slower than the alternatives.
PPTP
PPTP (Point-to-Point Tunneling Protocol) is one of the oldest VPN protocols still in use.
Developed by Microsoft for dial-up networks, it was once the standard for corporate VPN access but has largely been phased out.
We don’t recommend ever using this obsolete protocol, given its age and well-documented security flaws.
Proprietary and Obfuscation Protocols
The seven protocols above are the established options, but they’re not the whole story any more.
As governments and networks have gotten better at spotting and blocking VPN traffic, providers have built a new generation of protocols designed to slip past those filters.
These fall into two camps: obfuscation layers that disguise an existing protocol, and brand-new proprietary protocols.
NordWhisper, which NordVPN launched in January 2025, is a good example of the latter.
It uses web-tunnel technology to make your VPN traffic look like ordinary web browsing, so deep packet inspection has a much harder time detecting and blocking it.
NordVPN has since made it the default on its obfuscated servers, replacing OpenVPN, and is moving it toward a fully TLS-based design with QUIC support.
Mullvad took a different route, becoming the first major VPN to add QUIC obfuscation to WireGuard, while Proton VPN built its own Stealth protocol and ExpressVPN and Surfshark created modified versions of OpenVPN for the same purpose.
It’s worth busting one common myth here: not every proprietary protocol is just WireGuard with a new name.
Lightway, ExpressVPN’s protocol, was built from scratch on the wolfSSL library, rewritten in Rust in 2025 for better memory safety, and supports both TCP and UDP, which vanilla WireGuard does not.
If you regularly connect from somewhere that blocks VPNs, such as a school, an office, or a heavily censored country, these are the protocols to look for.
Are VPN Protocols Ready for Quantum Computers?
There’s one more shift happening: post-quantum encryption.
The concern is simple. Powerful quantum computers, once they arrive, could break the encryption that protects VPN traffic today.
Some attackers already know this, which is why they’re stealing encrypted data now to decrypt later, an approach known as a “Store Now, Decrypt Later” attack.
To counter it, the US National Institute of Standards and Technology (NIST) has standardized a set of quantum-resistant algorithms, the most important being ML-KEM (formerly known as Kyber) for key exchange.
VPNs are adopting these in a hybrid form, pairing the classical Curve25519 key exchange with ML-KEM, so your tunnel stays secure even if one of the two is later broken.
Rollout is well underway. NordVPN is the first major provider to make post-quantum key exchange the default across its apps, built into its NordLynx protocol.
ExpressVPN added it to Lightway in late 2025, initially on a subset of servers; Surfshark rolled it out for WireGuard in January 2026; and Mullvad supports it on WireGuard too.
Our advice: post-quantum protection is fast becoming a standard feature, and there’s no real downside to having it. If your provider offers it, turn it on. If it doesn’t, that’s an increasingly good reason to ask why.