VPN protocols compared

VLESS, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, OpenVPN — how they work and which ones survive on networks that block VPNs.

Updated October 6, 2026 · Vetryx team

At a glance

ProtocolHow it hidesSpeedHard to block?
VLESS + REALITYLooks like HTTPS to a popular siteHighYes
VLESS + XHTTPRegular HTTP requests; can go through a CDNMedium–highYes
VLESS + WebSocketWebSocket over TLS, CDN-friendlyMediumMedium
Hysteria2QUIC over UDP, optional Salamander obfuscationVery high on lossy linksMedium (UDP can be throttled)
TrojanTLS with a password, mimics HTTPSHighMedium
VMessOwn encryptionMediumLow–medium
ShadowsocksEncrypted proxy streamHighLow on modern filters
WireGuard, OpenVPNDon't hide — recognizable patternsHighNo — blocked first

VLESS vs VMess

Both come from the V2Ray/Xray family. VMess encrypts traffic itself and requires the client's clock to be close to the server's — a common cause of "it won't connect". VLESS drops built-in encryption and relies on TLS or REALITY instead, which makes it lighter and, with REALITY, much harder to fingerprint. For new setups, VLESS is the better choice.

Hysteria2 vs VLESS

Hysteria2 runs over QUIC (UDP) with its own congestion control, so it often outperforms TCP-based protocols on lossy mobile networks and long distances. On networks that throttle or block UDP, VLESS + REALITY over TCP tends to hold up better. The practical answer is to have both and switch when one stops working.

Trojan and Shadowsocks

Trojan wraps traffic in TLS with a password and looks like HTTPS; it works well but needs a real domain and certificate. Shadowsocks is simple and fast, but modern filtering systems have learned to detect many of its variants.

Why WireGuard and OpenVPN get blocked

They're great protocols for privacy on open networks, but they don't try to look like anything else. Filtering equipment recognizes their handshakes and blocks them — which is exactly what happens in Russia, China and other countries that block VPNs.

What to look for in a VPN

  • Several modern protocols — so when one is blocked, another works.
  • A subscription that replaces blocked servers automatically.
  • Apps that let you switch protocols in one tap.

Four protocols in one subscription. Vetryx runs VLESS + REALITY, XHTTP, WebSocket and Hysteria2 — if one is blocked, switch to another. See pricing.

FAQ

VLESS vs VMess — which is better?

VLESS. It's lighter because encryption is left to TLS or REALITY, and with REALITY it's much harder to detect. VMess has its own encryption, is heavier and is sensitive to clock drift between client and server.

Hysteria2 vs VLESS — which is faster?

Hysteria2 runs over QUIC (UDP) and is often faster on lossy mobile and long-distance links. VLESS + REALITY runs over TCP and blends in better on networks that throttle or block UDP. Having both lets you switch when one is blocked.

Why don't WireGuard and OpenVPN work in some countries?

They have recognizable traffic patterns that filtering equipment can detect and block, which is what happens in Russia, China and other countries with VPN blocking.