Related guides
VPN protocols compared: WireGuard, OpenVPN, AnyConnect, Hysteria2
Updated
A protocol is the agreement between client and server on how to encrypt and carry your traffic. No single protocol wins everywhere; each suits a kind of network. On restricted networks such as campuses and offices, choose AnyConnect, which runs over TLS. On lossy links, choose Hysteria2, which is built on QUIC. For log-in-once, always-on use with devices that reach each other, choose something based on WireGuard. For routers, NAS boxes and servers, choose OpenVPN. For a browser only, choose an HTTPS proxy. Encryption strength is sufficient in all of them and is not what sets them apart. Each is described below, followed by which of this site’s six connection methods uses which.
What a protocol means for you: four things
- Whether it works on a restricted network. Many campus, office and hotel networks limit UDP and pass only TCP with TLS, the same traffic as opening a website. UDP-based protocols slow down or drop there; TLS-based ones carry on.
- How fast it is when packets are lost. Mobile data, old-building broadband and cross-border links lose packets often, and the way a protocol copes decides real speed on such links.
- How much battery it uses. The lighter the protocol and the fewer keep-alive packets it sends, the less power it draws; repeated reconnecting costs the most.
- Which devices can run it. Some protocols have a client built into nearly every system, router and NAS; others exist only as phone and desktop apps.
- One more point matters as much as the protocol itself: whether there is an alternative once it is detected. A service with a single protocol has nowhere to go when that protocol is disrupted.
OpenVPN: the veteran that nearly every device supports
- What it is: an open-source VPN protocol more than twenty years old; one .ovpn file carries everything needed to connect.
- Strengths: the widest support, with clients built into most router firmware, NAS systems and Linux servers; it runs over UDP or TCP.
- Weaknesses: heavier than newer protocols and harder on a phone battery; its handshake has a fixed signature that restrictive networks can recognise.
- Suits: routers, NAS boxes and servers that must connect at boot and run unattended. See How to use OpenVPN and when to choose it.
What WireGuard is: light, fast, survives network changes
- What it is: a newer open-source VPN protocol with a small codebase, included in the Linux kernel, with clients for every mainstream system.
- Strengths: quick to connect, low encryption overhead, easy on the battery; the connection picks itself up when you move from Wi‑Fi to mobile data.
- Weaknesses: UDP only, so it fails or crawls where UDP is limited; its packet format is fixed and easy to recognise.
- Built on it: Tailscale adds account login and device-to-device reachability on top of WireGuard, producing a log-in-once, always-on mesh — see What the Private Network (Tailscale) Is.
- WireGuard vs OpenVPN: on a clean network WireGuard is faster and lighter; OpenVPN leads on device support and on being able to run over TCP.
Cisco AnyConnect: over TLS, steadiest on restricted networks
- What it is: Cisco’s enterprise VPN protocol; the client is now called Cisco Secure Client. Open-source implementations exist: OpenConnect for the client and ocserv for the server.
- Strengths: traffic runs over standard TLS and looks from outside like a visit to an HTTPS site, so it keeps working on campus and office networks that limit UDP; you enter only an address, a username and a password, with nothing to import; companies worldwide rely on it for remote work, so clients are available on every platform.
- Weaknesses: once connected, the whole device takes the route, and keeping local sites direct needs separate split routing; on lossy links it is slower than a protocol designed for loss.
- Suits: campus and office networks, iPhones, older devices. More in Does AnyConnect work in China?
The Hysteria2 protocol: built on QUIC for lossy links
- What it is: an open-source proxy protocol built on QUIC, the UDP-based transport that HTTP/3 uses.
- Strengths: it handles packet loss deliberately and is the fastest of this group on mobile data, old-building broadband and cross-border links; its traffic resembles ordinary HTTP/3.
- Weaknesses: it uses UDP, so it slows or drops where UDP is limited; it needs a client that supports it, such as Hiddify and the sing-box family.
- Suits: your own phone and computer, a preference for speed, a lossy network. Import steps are in the Hiddify subscription guide.
v2ray and the TLS-proxy family
v2ray is a proxy tool, not one protocol. The protocols it and similar tools support — VMess, VLESS, Trojan and others — share an idea with the plain HTTPS proxy: wrap proxy traffic in TLS so it looks like a visit to an HTTPS site. Most nodes in an “airport” subscription are of this kind; see VPN vs proxy subscriptions vs accelerators.
- Strengths: TCP with TLS gets through restricted networks; a single program can be proxied without touching the rest of the device.
- Weaknesses: these are proxies, not tunnels, so client rules decide what is proxied, and a wrong rule shows up as some sites failing to load; clients differ in the formats they accept.
- The simplest member is an HTTPS proxy in the browser: one extension, no client to install and no connection state — see What a Web Proxy Is and When to Use One.
Which protocol each of this site’s six methods uses
One LeoTun account has six connection methods running on different protocols. Disruption to one is independent of the others, so when one struggles you switch to another on the same account.
- Cisco: Cisco AnyConnect, over TLS. First choice where UDP is limited. See the Cisco section.
- OpenVPN: prefers UDP and falls back to TCP automatically when UDP is limited. See the OpenVPN section.
- Private network: Tailscale, based on WireGuard. Log in once and stay online; devices on one account reach each other. See the private-network section.
- Hiddify: the Hiddify client with the hysteria2 protocol. Fastest on lossy links. See the Hiddify section.
- Web proxy: an encrypted HTTPS proxy that covers the browser only. See the web-proxy section.
- Router: the firmware makes the choice and updates itself; you log in and use it, with no protocol to pick. See the router section.
- For choosing by device, network and purpose, see Which connection method fits which scenario; for the order to switch in when something fails, see the troubleshooting checklist.
FAQ
What protocol does a VPN use?
It depends on the provider. Common ones are OpenVPN, WireGuard, Cisco AnyConnect and IKEv2, along with Hysteria2 and various TLS proxies. The client’s settings or the provider’s documentation normally say which.
WireGuard vs OpenVPN: which is better?
Where UDP is not limited, WireGuard is faster, lighter on battery and survives network changes. OpenVPN’s advantages are a built-in client on nearly every router and NAS, and the ability to run over TCP. Use the first for everyday phone and laptop use and the second for routers, NAS boxes and servers.
Which VPN protocol is the most secure?
All of these use public, long-tested cryptography and are secure enough when configured correctly. The practical differences lie in how the provider operates and where the client comes from, not in the protocol name.
Can I use a v2ray-style client with this site?
The Hiddify method provides a one-line hysteria2 share link that imports into clients supporting hysteria2, such as NekoBox, Shadowrocket, Stash and Clash Meta. A share link carries the node only, so routing rules are set in the client. Without a particular reason, scanning the QR code in Hiddify is less work.
Why do some methods fail on campus or office networks?
Such networks often limit UDP. Hiddify, the private network and OpenVPN all use UDP and will slow or drop; switch to Cisco, which runs over TLS, or to the web proxy for the browser.
Do I need to study protocols before choosing?
No. Three rules cover it: Cisco on restricted networks, Hiddify on lossy links, the router for devices that cannot run a client. The same account lets you switch at any time.
Related pages
- Which connection method fits which scenario →
- What a VPN is and how to connect →
- How to use OpenVPN and when to choose it →
- Does AnyConnect work in China? →
- What the Private Network (Tailscale) Is →
- Tencent Video or iQIYI Blocked Abroad? Fix It in 5 Steps →
- How to Choose a China VPN →
- Choosing a VPN Router →
- How to Import a Hiddify Subscription →
- China VPN for Students Abroad →
- What a Web Proxy Is and When to Use One →
- Free or Paid China VPN? →
- Flashing the Router Firmware: From Stock to Ours, Step by Step →
- What the Router Firmware Does →
- How to Reach Us and Never Lose Contact →
- Where We Beat Other VPNs →
- How to Recognise a Risky VPN App →
- Which Region Is Fastest from Inside China →
- For the TV and the Grandparents at Home →
- Watching Home Cameras and a NAS in China from Abroad →
- What to Do When iOS Cannot Install an App →
- Cannot Connect, Slow, or Dropping: What to Check →
- Setting Up for Business Trips and Travel →
- On a Company Laptop: No Admin Rights, Corporate VPN Already On →
- Many Devices, One Setup, No Redo on a New Phone →
- Routing a Synology or QNAP NAS →
- Routing a Linux Server and Command-Line Tools →
- “Damaged” on a Mac, and how to verify the installer →
- Using RustDesk for remote help →
- What macOS's Network Extension Approval Is →
- How split routing works on a VPN router →
- Not enough device slots? Temporary vs long-term fixes →
- Dropbox and other apps want an HTTP / SOCKS proxy — what to do →
- How to Get Good Answers from the AI Support →
- How to manually uninstall the Cisco client on a Mac →
- Cisco error “remote user is disabled” →
- Refund Policy and Feedback →
- VPN vs “airport” proxy subscriptions vs accelerators →
- Is a VPN Safe to Use? Who Can See What →
- VPN Slow? How to Run a Speed Test and Find the Cause →
- DNS Leak vs DNS Poisoning: How to Check and Fix →
- VPN on iPhone: which method to use and how to set it up →
- VPN on Android: which client to use and how to set it up →
- VPN on a computer: which method for Windows and Mac →
- Using ChatGPT in China: Why It Fails and What Matters →
- No Verification Code for an Overseas App? Telegram, Instagram and TikTok in China →
- What Is OpenWrt? Soft Routers, Bypass Gateways and VPN Routers for China →
- How to Use a VPN in China: Set Up Before You Land →
- VPN Not Working in China? Why, and What to Try →
- Best VPN for China: How to Judge One Yourself →
- Do VPNs Work in China? What NordVPN, ExpressVPN and Others Say Themselves →
- eSIM vs VPN in China: Which One Do You Need? →
- Travel VPN Router for China: Setup and Who Needs One →
- WhatsApp in China: Does It Work and How to Set It Up →
- Google in China: Gmail, Maps and Google Play Explained →
- YouTube in China: How to Watch, and Why Netflix Refuses →