Skip to content

VPN types compared

All 34 types in one table, ordered by how widely they are deployed today. Everything here links through to a full explanation and a working config generator.

34 of 34 shown

Comparison of VPN types by connection scope, protocols, encryption and adoption
VPN typeWhat it connectsProtocolsEncryptionUsed todayMain use caseGenerator
WireGuardDevice/network → device/networkWireGuardEncryptedMost used98Fast, low-overhead tunnels for almost any topology. Generate
Remote-Access VPNIndividual device → private networkWireGuardIKEv2/IPsecOpenVPNSSL/TLSEncryptedMost used96Secure access to company resources from outside the office. Generate
Consumer VPNUser device → VPN providerWireGuardOpenVPNIKEv2/IPsecEncryptedMost used94Privacy on untrusted networks and changing apparent location. Generate
IPsec VPNDevice/network → device/networkIKEv2ESPAHEncryptedMost used92Both site-to-site links and standards-based remote access. Generate
Client-to-Site VPNVPN client → VPN gatewayOpenVPNWireGuardIKEv2/IPsecSSL VPNEncryptedMost used90Remote work with per-user authentication and access scoping. Generate
Site-to-Site VPNNetwork → networkIPsecGRE over IPsecWireGuardEncryptedMost used88Connecting branch offices and data centres. Generate
IKEv2/IPsecDevice → VPN gatewayIKEv2IPsec/ESPEncryptedMost used86Native OS remote access on iOS, macOS, Windows and Android. Generate
ZTNA / SASEUser/device → specific applicationTLSmTLSIdentity-aware proxiesEncryptedGrowing fast85Granting access to applications without exposing the network behind them. Generate
Cloud VPNOn-premises network → cloud networkIPsecIKEv2Provider-managed gatewaysEncryptedGrowing fast84Hybrid connectivity between a data centre and AWS, Azure or GCP. Generate
OpenVPNDevice/network → VPN serverOpenVPNEncryptedWidely used82General-purpose VPN where compatibility matters most. Generate
SD-WANSites, clouds and usersIPsecTLSVendor overlaysEncryptedGrowing fast80Replacing expensive private circuits with managed internet links. Generate
Corporate VPNEmployees → company networkIPsecSSL/TLSWireGuardEncryptedWidely used78Enterprise remote access under a single policy and audit trail. Generate
Peer-to-Peer / Mesh VPNDevice ↔ device/networkWireGuard-based overlaysProprietary mesh protocolsEncryptedGrowing fast76Connecting many devices without a central gateway to funnel through. Generate
SSL/TLS VPNUser/device → VPN gatewayTLSOpenConnectOpenVPNSSTPEncryptedWidely used74Remote access from hotel, airport and captive-portal networks. Generate
Mobile VPNMobile device → private networkIKEv2/IPsec (MOBIKE)WireGuardEncryptedWidely used72Keeping a session alive while moving between networks. Generate
Hub-and-Spoke VPNBranches → central hubIPsecWireGuardDMVPNEncryptedWidely used70Centralised branch connectivity and traffic inspection. Generate
Obfuscated VPN / proxyDevice → proxy/relay serverShadowsocksVMessVLESSTrojanEncryptedGrowing fast68Reaching the open internet where VPN protocols are detected and blocked. Generate
Intranet VPNOrganisation network → organisation networkIPsecMPLSSD-WANDepends on transportWidely used66One private network spanning every company location. Generate
Full-Mesh VPNEvery site ↔ every other siteWireGuardIPsecSD-WANEncryptedGrowing fast60Low-latency direct traffic between all locations. Generate
Extranet VPNOrganisation → partner organisationIPsecSSL/TLSEncryptedWidely used54Letting a partner reach a defined slice of your network. Generate
Dynamic VPNMultiple changing endpointsDMVPNSD-WANMesh overlaysEncryptedWidely used52Avoiding hand-configured tunnels in a network that keeps changing. Generate
OpenConnect / ocservClient → ocserv gatewayTLSDTLSAnyConnect-compatibleEncryptedNiche44Enterprise-style SSL VPN without proprietary licensing. Generate
MPLS VPNPrivate enterprise networksMPLSBGPVRFNot encryptedDeclining42Predictable, SLA-backed private WAN connectivity. Generate
GRE over IPsecRouter/network → router/networkGREIPsecEncryptedNiche40Carrying OSPF/EIGRP or multicast across an encrypted WAN. Generate
Clientless SSL VPNBrowser → VPN gateway / application portalSSL/TLSHTTPS reverse proxyEncryptedDeclining38Give unmanaged devices access to a handful of web applications. Generate
Layer-2 overlay networkDevice ↔ virtual LANZeroTier-style overlaysVXLANGENEVEEncryptedNiche36Making scattered machines behave like one LAN. Generate
DMVPNMany enterprise sitesmGRENHRPIPsecEncryptedDeclining34A WAN that behaves like a mesh without configuring every pair. Generate
Multi-hop VPNDevice → relay → exit → internetWireGuardOpenVPNShadowsocks chainsEncryptedNiche32Splitting trust between two independent servers. Generate
SSTPWindows device → VPN gatewaySSTPTLSPPPEncryptedDeclining30Remote access from networks that only allow HTTPS. Generate
VPLS / Layer-2 VPNLAN segment ↔ LAN segmentVPLSL2TPv3VXLANEoIPDepends on transportDeclining28Stretching a VLAN across locations. Generate
SoftEtherDevice/network → SoftEther serverSoftEtherOpenVPNL2TP/IPsecSSTPEncryptedNiche26Serving many different clients from a single gateway. Generate
L2TP/IPsecDevice → VPN gatewayL2TPIPsecEncryptedDeclining24Remote access on older equipment that offers nothing better. Generate
6in4 / IPv6 tunnelDevice/network → tunnel broker6in4GRETunnel brokersNot encryptedDeclining18Getting IPv6 connectivity where the ISP provides none. Generate
PPTPDevice → VPN serverPPTPGREMPPEBroken encryptionObsolete6Recognising and replacing an obsolete deployment. Generate

How to read this table

Encryption

“Not encrypted” means the technology isolates traffic without protecting it — MPLS and VXLAN both need IPsec on top if confidentiality matters.

Used today

A 0–100 score for real-world deployment in 2026. WireGuard leads on protocols; remote access leads on topologies.

Categories

Remote access, Site to site, Protocols, Overlay & managed, Legacy — filter by any of them in the catalogue.