
The comparison pages want a zoo. IKEv2, SSTP, Lightway, NordLynx, a proprietary UDP thing with a trademark. Klox ships four protocols: WireGuard, OpenVPN, OpenConnect, and Shadowsocks. That is the product. Four protocols in the picker. Not a protocol hobby.
I want WireGuard first on a normal network. Home broadband. A phone hotspot. A cafe that is not performing security theater. If the handshake completes, leave it. OpenVPN is the first fallback when UDP is rude. OpenConnect and Shadowsocks cover enterprise-locked and censorship-heavy paths. Hotels that eat datagrams. Campuses that only smile at TCP 443. Offices that treat unknown UDP as a hobby they do not fund.
This is not the OpenVPN TCP vs UDP: Which to Choose essay. That piece is transport inside OpenVPN once you already picked OpenVPN. This is which protocol you pick on Klox, and which names we will not pretend to ship. We do not ship IKEv2 as a Klox protocol. Windows Settings can speak IKEv2. That is Windows. That is not us.
A VPN is a tunnel. Wikipedia's VPN page will not pick your button. RFC 8446 will not either.
Five devices. Yearly from $2.83 a month. Seven-day money-back. Download if you want the client. Pricing if you want the number. I will not publish a millisecond benchmark so a farm can screenshot it next to a number they invented in a lab I do not run.
I have a bias. WireGuard until it fails. Then OpenVPN, OpenConnect, or Shadowsocks. Stop collecting competitor protocol names. If a review table lists six protocols under our logo, the table is wrong. Screenshot the picker in the app you actually installed. Believe that.
Related reading: WireGuard on a White-Label VPN Stack and Leak Test After You Connect a VPN. Family VPN on Five Devices and What is a VPN?. WireGuard vs OpenVPN.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Four protocols, not a protocol zoo
The farm article wants a matrix of six protocols and a winner. That is a ranking page. Klox is a client with four tunnels: WireGuard, OpenVPN, OpenConnect, and Shadowsocks. If a fifth name appears in a screenshot of our app, write to support, because that is a bug in the screenshot, not a secret SKU.
I keep seeing people ask for IKEv2 because Windows Settings offers it. That is the OS. It is not our stack. People ask for NordLynx because they read a competitor page. That is their wrapper. It is not ours. People ask which is "the fastest" as if I will hand them a millisecond. I will not. Your cafe is not my lab.
The picker is the product. A default that works on most networks, and fallbacks that work on rude ones. Everything else is a brochure. Download the app. Sign in. Connect. If it comes up, you are done with this essay. If it does not, switch protocol — do not invent a sixth name.
- 1Skim the seating / order diagram.
- 2Do the numbered steps once on your real network.
- 3Use the FAQ if a sentence was too long.
- 4Follow one related article — not ten tabs.
How to read this page
| Situation | Start with | Switch to | Not a Klox button |
|---|---|---|---|
| Home broadband, most cafes | WireGuard | Stay if it connects | IKEv2, Lightway, NordLynx |
| Hotel or campus, UDP dies | WireGuard once | OpenVPN (then OC / SS) | SSTP, L2TP, PPTP |
| UDP still dead after OpenVPN | OpenVPN TCP / OpenConnect / Shadowsocks | Stay on what works | A trademarked UDP fork |
| Windows Settings VPN screen | Do not use this for Klox | The Klox app | IKEv2 in the OS |
| You want a ms crown | WireGuard | Nothing | A farm's speed table |
Four protocols. WireGuard until the network is rude. OpenVPN, OpenConnect, or Shadowsocks when it is. We will not sell you IKEv2.
— KloxVPN operator notes
Cloudflare Learning: What is a VPN?
The picker is the product
If the UI hides the switch, you still have four protocols. You just cannot reach them without a ticket. I want the switch labeled: WireGuard, OpenVPN, OpenConnect, Shadowsocks. If OpenVPN then has UDP and TCP, that is a second decision, covered in the OpenVPN TCP vs UDP: Which to Choose post. Do not merge those decisions in your head. First pick the family. Then pick the transport inside OpenVPN if you landed there.
Do not hunt for a third name
PPTP is a museum. L2TP is a Windows field. SSTP is Microsoft's HTTPS-shaped VPN. Lightway is ExpressVPN's. NordLynx is Nord's WireGuard clothing. None of those are Klox buttons. Collecting them will not make this PC faster. It will make your settings screen a junk drawer.
What WireGuard is on a Klox client
WireGuard is a small, modern tunnel. Cryptography is a fixed set, not a buffet. It speaks UDP. There is no TCP mode hiding in the protocol. That is a feature on a clean path and a tax on a filtered one.
On a Klox app, WireGuard is the default I want you to try. Handshake is usually quick. CPU cost is usually low. Battery stories from 2018 are stale. I will not pretend it is magic. I will not pretend it survives every hotel AP. The honest sentence is: WireGuard is the right first press on a network that will pass UDP to a VPN endpoint.
You do not need to know the cipher names to use it. You need to know that a timeout after you tap Connect is often the network dropping UDP, not your password being wrong. Try the password once if you are unsure. Then switch protocol. Sitting on WireGuard for ten minutes on a rude AP is how people refund a working product.
Connected means the client says connected and a site you actually use loads. Connecting forever is not a personality. If the glyph flips to connected and then Chrome still shows your home ISP on a what-is-my-IP check, you are not in a protocol debate yet. You are in a client that did not take the route. Reconnect. Then switch. Then read the leak checklist. Do not start with a farm's WireGuard-versus-OpenVPN matrix while the tunnel is still a wish.
UDP is the whole transport
There is no WireGuard-over-TCP button on Klox, because WireGuard is not that design. If someone on a forum told you to "put WireGuard on 443 TCP," they are describing a different stack, a wrapper, or a wish. Our fallback is OpenVPN. Say the real name.
Keys are not a consumer homework assignment
You do not paste a wg0.conf unless you are doing router work on purpose. The app issues the peer. Log in. Connect. If you are hand-editing keys on a laptop because a blog said so, you have left the consumer path. Come back. The download page is the path.
What OpenVPN is on a Klox client
OpenVPN is the older, patient tunnel. It has been through more firewalls than any of us. It can ride UDP when the network allows it. It can ride TCP when the network only allows things that look like a web session. That second trick is why it still exists on a product that already has WireGuard.
It starts slower. It costs more CPU. On a good home line you will feel that as "fine, a bit heavier," not as a disaster. On a lossy cafe you may feel TCP-over-TCP as sticky pages. That is physics, not a secret throttle. I would still rather a sticky page than a handshake that never finishes.
OpenVPN is not the "more secure" button. Both protocols, configured as we ship them, are the tunnel. Security theater that says OpenVPN is for adults and WireGuard is for kids is leftover marketing. Use the one that connects. Then Leak Test After You Connect a VPN if you care what the internet sees.
I still keep OpenVPN in the app because I have been in the room where WireGuard was religion and the only network that night was a hotel that dropped 51820. The people who "only use WireGuard" sat offline. The people who pressed the other button read email. That is the whole argument for keeping a protocol that farms call legacy.
UDP and TCP live inside OpenVPN
Once you picked OpenVPN, you may still choose UDP or TCP. That is the other essay. Short version: UDP if it works, TCP if it does not, often on 443. Do not come back to this page to re-litigate acknowledgements. This page is the family. That page is the transport.
OpenVPN is not a third protocol
People talk as if "OpenVPN UDP" and "OpenVPN TCP" and "WireGuard" are three equal SKUs. On Klox they are part of four protocols; OpenVPN also has a transport switch. Counting three makes the picker look like a zoo we keep to four families. Keep the count honest.
WireGuard first on a normal network
Normal means: you paid for the path, or the cafe is ordinary, or you are on a phone hotspot you control. The packets leave. They come back. Nobody in the middle is proud of a UDP filter. That is most evenings at home. That is a lot of travel days too, once the portal is done.
Press WireGuard. Wait for connected, not for connecting. Open a site you actually use. If it loads, stop. Do not flip to OpenVPN "to compare." You will spend the evening chasing feelings. Feelings are not a lab.
If you want a check, do the leak checklist after connect. IP changed. DNS not your ISP. That is the adult version of a speed test. A speed test on a shared AP measures the AP. I will not pretend otherwise.
Home fiber is not a protocol debate
If WireGuard comes up at home and stays up, you do not have a protocol problem. You have a working tunnel. Save OpenVPN for the hotel. Teaching yourself the protocol picker at home is useful once. Making it a nightly ritual is a hobby.
Phone hotspot is usually WireGuard territory
Tethering from your phone is a path you control. UDP usually lives. Use WireGuard. If it fails, your carrier may be weird, or the phone is still on a captive hotel LAN through the phone. Fix the path. Then retry WireGuard before you assume OpenVPN is the lifestyle.
When UDP is rude
Rude looks like: Connect, wait, timeout. Or connecting forever. Or connected for two seconds and then dead. Your password worked yesterday. The app is the same build. You changed networks. That is the clue.
Hotels, airports, conference Wi-Fi, some campuses, some offices: they drop unknown UDP, or they only route a short list of ports, or they inspect in a way that WireGuard does not enjoy. I will not diagnose their vendor. I will tell you to switch to OpenVPN and, if needed, TCP.
A timeout is not proof the account is dead. Check five devices if you recently hit the cap. Check you are signed in. Then switch protocol. Reinstall is the last move, not the first. Reinstall-as-superstition is how people spend an hour and still have UDP blocked.
I treat "rude UDP" as a place, not as a brand failure. The same account that was fine on fiber will look dead in a conference center. That is the center. Take OpenVPN with you the way you take a charger. You hope not to need it. You look silly when you left it at home and the AP only speaks TCP 443.
Handshake timeout is a network
The client tried to complete a WireGuard handshake. The reply did not arrive in time. That is UDP not returning, a bad exit, or a radio that is lying about being connected. Try one other server on WireGuard. Then OpenVPN. Do not try twelve cities as if geography were the filter. Geography is rarely the filter. Policy is.
Do not confuse portal with protocol
If you never completed the hotel splash page, no protocol will save you. Disconnect, open a browser, log in to the AP, then connect again, WireGuard first. Protocol essays do not replace captive-portal physics. The Windows checklist covers the laptop version of that dance.
OpenVPN TCP is the fallback, not a speed mode
TCP is how OpenVPN pretends to be patient web traffic. Firewalls that would never pass WireGuard's UDP will often pass TCP 443 because blocking it breaks "the internet" as they sell it. That is the job. It is not a turbo. It is not "more encrypted." It is a worse path that still exists.
I see people leave TCP on at home because it finally worked in a hotel last month. Then they complain the laptop feels heavy. Switch back. The spare tire is not the daily driver. Put WireGuard back on when you are on a network that allows it.
If TCP is the only thing that works on a network you live on, a locked-down office or a dorm, then live on TCP and stop mourning WireGuard. Mourning does not open a UDP hole. A ticket to IT might. I would not bet on it.
This is not the TCP vs UDP lesson
Retransmits, congestion control, TCP-over-TCP stickiness: that is the OpenVPN TCP vs UDP: Which to Choose post. I am not repeating it so this page can rank for both queries. If you already chose OpenVPN and you are choosing a port, go there. If you have not chosen OpenVPN yet, you are still on this page.
TCP does not make WireGuard
Wrapping WireGuard in a TCP shell is someone else's product. We did not ship that. Asking support to "enable WireGuard TCP" is a sentence that will get you a polite no and a pointer to OpenVPN. Ask for OpenVPN TCP. Use the words we have.
What Klox does not ship
IKEv2 is not a Klox consumer protocol. I will say that until the search snippet believes me. Microsoft ships IKEv2 in Windows. Other VPNs ship it because mobile roaming stories from a decade ago still sell. We ship WireGuard, OpenVPN, OpenConnect, and Shadowsocks. If a review site lists IKEv2 under our name, the review site did not look at the app.
We do not ship PPTP. We do not ship L2TP as a Klox button. We do not ship SSTP. We do not ship Lightway. We do not ship NordLynx. We do not ship a trademarked UDP fork so we can claim a unique protocol on a comparison table. The tunnel is WireGuard, OpenVPN, OpenConnect, or Shadowsocks. The brand is Klox. Those are different sentences.
White-label partners can brand the same four-protocol core. That is an operator article. You are reading the consumer one. Your Klox app ships four protocols. If you bought white-label, go read WireGuard on a White-Label VPN Stack and stop borrowing this page's promises.
Support will still get "please add IKEv2 for Windows roaming." The answer is OpenVPN on this PC, and WireGuard on the phone if the phone's network is sane. Roaming stories from 2012 are why other brands still print IKEv2. They are allowed to. We are allowed not to. I would rather document two honest buttons than ship a third so a comparison table has a checkmark.
Windows built-in is not Klox
Settings, Network, VPN, Add VPN, type IKEv2, paste a hostname from a forum: that is a different product, often a broken one, sometimes a trap. The Klox Windows client is an installer from download. It is not a row you typed into Windows. Do not mix them. Two tunnels fighting is how you get no internet and a headache.
Obfuscation is not a secret third protocol here
Some brands sell "stealth" or Shadowsocks as a named mode. Klox consumer copy for this app is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, including OpenVPN TCP when you need camouflage-by-patience. I will not invent a stealth SKU in this post so we look like a farm matrix. If a later build adds a labeled mode, the changelog should say so. This page is what we ship now.
We will not publish a millisecond table
Farms love a chart with a crowned winner, measured on a Tuesday in a lab with a short path and a sponsored disclosure in six-point type. I will not give them a Klox-branded version of that chart. Your number depends on the exit, the AP, the time of day, the CPU, the other tabs, and whether the hotel is full. A single ms figure is a costume.
What you can feel without a lab: WireGuard usually comes up faster and feels lighter on a clean path. OpenVPN TCP usually feels heavier, especially under loss. That is enough to pick a default. It is not enough to print a leaderboard.
I also will not print a Netflix unlock rate, a city count as a personality, or an SLA percentage so this article looks enterprise. You are buying five devices and four protocols from $2.83 a month, with seven-day money-back. Use the seven days to try the protocol picker on the networks you actually live on. That is the only benchmark that counts.
If a YouTuber's overlay says WireGuard won by a gap that looks like a product photo, ask what AP they were on. Fiber to a nearby exit is a compliment to the ISP, not a protocol religion. I will not chase that overlay with a Klox-branded overlay. Boring, on purpose.
Speedtest.net is not a protocol oracle
Run it if you want. Run it twice, VPN off and on, same server, same hour, and you will learn something about that hour. Do not average three runs and email us a percentage. Do not compare your cafe to a YouTuber's fiber. I will not argue with a screenshot.
Farms will still crown a winner
The Nord-style WireGuard vs OpenVPN page exists to rank. Read it as a specimen. Their wrapper is not our button. Their chart is not our chart. If you came from that query, you now have the Klox answer: four protocols, WireGuard default, fallbacks when needed, no ms theater.
Five devices, four protocols
A connected session is a slot. Protocol is a setting on that session. Switching this laptop from WireGuard to OpenVPN does not consume a second device. It is still this laptop. The Family VPN on Five Devices is about who is connected. This page is about how each of those five talks to the network.
Each gadget can pick independently. Phone on WireGuard at home. Laptop on OpenVPN TCP at the office. That is allowed. That is the point of two buttons. Do not force the whole household onto TCP because one hotel was rude. The hotel is not the house.
Ghost sessions still count. A tablet that auto-connected and went to sleep still holds a seat. Protocol will not free it. Disconnect will. Remove the device in the portal if you replaced the tablet and it keeps climbing back.
Router configs are still one slot
A router using a WireGuard or OpenVPN profile is one device covering many gadgets behind it. Protocol choice is still four families. Do not run the laptop app and the router tunnel on the same account without counting both if both are up. Nested VPN is how evenings disappear.
Do not share the account to get a sixth protocol
There is no sixth protocol. There is no sixth device. A neighbor with your password is a stranger on your slot. If you need more seats, that is a different conversation than WireGuard vs OpenVPN. Stay inside five. Pick the button that connects.
How to live with two buttons
Rule card I actually want on a sticky note: WireGuard at home and on ordinary Wi-Fi. If Connect fails or dies in seconds, one other server, then OpenVPN. If OpenVPN UDP fails, OpenVPN TCP. Complete hotel portals before any of that. Count this gadget as one of five. Then go do the thing you opened the laptop for.
If you are still flipping after that card, you have a different problem. Wrong password. Device cap. App that is not ours. Local firewall you turned into a science fair. A second VPN running. Fix those. Protocol will not.
Print the card. I am serious. People re-read this essay in a lobby with 8% battery and still start on WireGuard for the twelfth timeout. The card is faster than the essay. The essay is for the evening you are not in the lobby.
Seven-day money-back exists so you can try this on your networks, not so you can demand a protocol we do not ship. If WireGuard, OpenVPN, OpenConnect, and Shadowsocks both fail on a path you cannot change, write support with the network type and which buttons you pressed. "It doesn't work" with no protocol name is how tickets go in circles.
Write support with the button names
WireGuard timeout on hotel SSID, then OpenVPN UDP timeout, then OpenVPN TCP connected. That is a useful paragraph. "VPN broken" is not. Include OS. Include whether you installed from download. Include that you are not using Windows' built-in IKEv2 by accident.
When to stop reading protocol essays
When the tunnel is up and the leak check is boring. Bookmark this page for the next rude network. Do not make protocol identity a personality. The internet does not care which button you love. It cares whether the packets arrived.
Key Takeaways
Klox ships WireGuard, OpenVPN, OpenConnect, and Shadowsocks. WireGuard first on a normal network. OpenVPN, OpenConnect, or Shadowsocks when the path is rude. TCP lives inside OpenVPN, which is why the OpenVPN TCP vs UDP: Which to Choose post exists and this one does not steal it.
We do not ship IKEv2 as a Klox protocol. We do not ship a zoo so a farm can score us. We will not publish a millisecond table. Five devices. Yearly from $2.83 a month. Seven-day money-back so you can try the protocol picker on the networks you actually use.
Download the client. Press WireGuard. If the handshake dies, switch to OpenVPN, OpenConnect, or Shadowsocks. That is the whole product, said slowly. If someone tells you we are slow because we skipped a trademarked UDP fork, they are ranking a zoo. We shipped a client. Use it.
Related Resources
Two protocols. Download the one app that has both.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. Install from the download page, connect on WireGuard, and keep OpenVPN for the network that will not pass UDP.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.