
WireGuard — Fast, minimal open-source VPN protocol built into the Linux kernel
What it is
WireGuard is an open-source VPN protocol and reference implementation focused on speed and simplicity, using modern cryptography such as Curve25519 and ChaCha20. It ships in the Linux kernel and is widely used for site-to-site links, remote access and as the engine behind commercial VPN products. Configuration is minimal but manual: there is no built-in user management or automatic NAT traversal, so multi-peer setups take hands-on maintenance.
Editor's review
Long-form introduction by the BetterPicker editors · checked against the official site · Oct 8, 2026
WireGuard is the VPN protocol that reset expectations: a modern design measured in thousands of lines of code instead of hundreds of thousands, and fast enough to live inside the Linux kernel. It exchanges public keys like SSH, encrypts UDP packets with modern cryptography, and roams between networks without dropping a session. First released for Linux and merged into the kernel mainline in 2020, it now runs on Windows, macOS, iOS, Android, and the BSDs. It is a building block rather than a finished product: expect to configure peers yourself, or to use one of the platforms built on top of it.
What it does well
Speed comes from living in the kernel. The Linux implementation runs in-kernel, which is why throughputs beat most userspace VPNs and phones barely notice the tunnel. The design pairs fast cryptographic primitives with a tiny codebase, so overhead stays small and connections establish almost instantly, even on modest routers.
The codebase is auditable by a person. The protocol was designed to need a fraction of the code of IPsec or OpenVPN, and the accompanying academic paper documents the reasoning behind every decision. A security reviewer can genuinely read the entire implementation, which changes the trust conversation from marketing to math.
Configuration is nearly SSH-simple. You exchange public keys and list allowed addresses, and the rest, including roaming across Wi-Fi and mobile networks, is handled without state machines to babysit. A working tunnel between two machines is a handful of lines, which is why the quick-start guide fits on a single page.
Who it's for
Self-hosters, homelab builders, small businesses linking offices, and embedded device makers are the core audience, along with the platform builders, Tailscale being the visible example, who stack services on the protocol. It fits people comfortable with config files and key management. It fits poorly for teams wanting user directories, dashboards, or push-button onboarding without adding a management layer.
Where it falls short
It hands you primitives, not a product. There is no built-in user directory, no key rotation ceremony, no usage dashboards, and assigning static tunnel addresses is manual bookkeeping. Teams that need those pieces reach for management layers or for platforms built on WireGuard, which is a common and sensible path.
No obfuscation story. Traffic is recognizable as WireGuard UDP, which matters on networks that filter VPNs, and the project deliberately declines to disguise its traffic. Where deep packet inspection is hostile, connections fail outright, and no amount of configuration will change that outcome.
Peer management does not scale by hand. Every peer's key must be listed wherever it should be reachable, so a mesh of dozens of devices becomes a spreadsheet exercise that punishes typos. Scripting helps, but the honest answer at team scale is a coordination layer on top.
Specs at a glance
Facts from the official site · not editorial opinion
| License | GPLv2 (kernel code and tools) |
|---|---|
| Price | Free, open source |
| Platforms | Linux (in-kernel), Windows, macOS, iOS, Android, BSD |
| Open source | Yes, developed openly with an academic paper |
| In Linux mainline | Since kernel 5.6 (2020) |
| Model | Peer-to-peer UDP tunnels with Cryptokey Routing |
| Design | Small auditable codebase; SSH-style key exchange |
Frequently asked questions
▸What is WireGuard?
WireGuard is a modern VPN protocol and toolset that creates encrypted point-to-point tunnels over UDP. It uses public key exchange similar to SSH, runs inside the Linux kernel for speed, and is available across all major desktop and mobile platforms.
▸Is WireGuard free?
Yes. The kernel code and tools are open source under GPLv2, the protocol specification and academic paper are public, and the official site documents installation for every supported platform. Commercial products built on it charge for their layers, not for the protocol.
▸WireGuard or OpenVPN?
WireGuard is faster, far smaller, and simpler to configure; OpenVPN is older, extremely mature, more configurable, and easier to disguise on restrictive networks. New deployments usually pick WireGuard, while some compliance regimes still specify OpenVPN deployments.
▸Does WireGuard hide traffic from an ISP?
It encrypts the content of your traffic and hides destinations from local snooping. Your ISP can still see encrypted packets flowing to your peer's address and can identify the protocol, since WireGuard does not attempt obfuscation. Privacy from the peer operator is a separate question.
Reviews on YouTube
4 review videos aggregated · praise and criticism included alike · click through to the original video
Channels that covered it
Channels are aggregated as sources only — we don’t rate creators
Related tools
Where to go next
External links open in a new tab; external content is independent of this site.
Link down? Every object page is re-checked monthly.




