Privex VPN
EN
Get Privex
PROTOCOLS

Pick the right tool for your network

Six battle-tested options. Switch with one tap from any client.

ProtocolSpeedStealth
WireGuardβš‘βš‘βš‘βš‘βš‘β˜…β˜…
IKEv2 / IPsecβš‘βš‘βš‘βš‘βš‘β˜…β˜…
OpenVPN UDPβš‘βš‘βš‘β˜…β˜…
OpenVPN TCPβš‘β˜…β˜…β˜…
Reality (VLESS)βš‘βš‘βš‘βš‘β˜…β˜…β˜…β˜…β˜…
VLESS+WS+TLS (CF)βš‘βš‘βš‘β˜…β˜…β˜…β˜…β˜…
WIREGUARD

WireGuard β€” modern, fast, default

Speed: ⚑⚑⚑⚑⚑
Stealth: β˜…β˜…

A modern protocol designed by Jason A. Donenfeld in 2015. ~4000 lines of audited C, kernel-mode on Linux, line-rate throughput on most hardware. ChaCha20 + Poly1305 + Curve25519 β€” a single fixed crypto suite, no negotiation.

Use this unless your network specifically blocks UDP 51820 or runs aggressive deep-packet inspection. It's the default in every Privex client.

IKEv2 / IPsec

IKEv2 β€” built for mobile

Speed: ⚑⚑⚑⚑⚑
Stealth: β˜…β˜…

Native IPsec stack on iOS, macOS, and Windows β€” no client install needed. Excellent at re-establishing the tunnel when your phone roams between Wi-Fi and cellular without interrupting in-flight TCP connections.

Use this on iPhones and laptops that frequently change networks. Same key exchange security as WireGuard, slightly more overhead.

OpenVPN UDP

OpenVPN UDP β€” the proven workhorse

Speed: ⚑⚑⚑
Stealth: β˜…β˜…

25 years old, audited dozens of times, supported on every operating system that's ever existed. AES-256-GCM by default in our setup. UDP transport keeps latency low.

Pick this when your client doesn't support WireGuard or you need to interop with legacy VPN gateways. Solid fallback.

OpenVPN TCP

OpenVPN TCP β€” the captive portal escape hatch

Speed: ⚑
Stealth: β˜…β˜…β˜…

Same OpenVPN, but tunneled over TCP/443 β€” looks like ordinary HTTPS to firewalls. Slower (TCP-over-TCP is famously suboptimal) but it gets through hotel Wi-Fi, coffee shops, and university captive portals that block UDP entirely.

Use this only when you have to. Reality and VLESS+WS+TLS are better stealth options on networks where the firewall is actively hostile.

REALITY (VLESS)

Reality β€” TLS that actually is TLS

Speed: ⚑⚑⚑⚑
Stealth: β˜…β˜…β˜…β˜…β˜…

Reality piggy-backs on a real TLS handshake to a real third-party site (microsoft.com by default). To a censor's DPI box, the entire connection looks like ordinary HTTPS to Microsoft β€” same JA3, same TLS extensions, same certificate chain.

Use this in restrictive networks (school, office, country-level filters) where standard VPN protocols are blocked. The fastest stealth option we offer.

VLESS+WS+TLS (CF)

VLESS+WS+TLS β€” fronted by Cloudflare

Speed: ⚑⚑⚑
Stealth: β˜…β˜…β˜…β˜…β˜…

Traffic is wrapped in WebSocket-over-TLS and routed through Cloudflare's edge. To any observer it's just HTTPS to a Cloudflare IP β€” exactly like the millions of legitimate sites behind Cloudflare. Hard to block without breaking half the internet.

The strongest unblock option, but Cloudflare proxying adds a hop so it's slightly slower than Reality. Use when even Reality is being blocked.

All six in every Privex client

One subscription, switch as your network changes.