VPN protocols compared
VLESS, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, OpenVPN — how they work and which ones survive on networks that block VPNs.
Updated October 6, 2026 · Vetryx team
At a glance
| Protocol | How it hides | Speed | Hard to block? |
|---|---|---|---|
| VLESS + REALITY | Looks like HTTPS to a popular site | High | Yes |
| VLESS + XHTTP | Regular HTTP requests; can go through a CDN | Medium–high | Yes |
| VLESS + WebSocket | WebSocket over TLS, CDN-friendly | Medium | Medium |
| Hysteria2 | QUIC over UDP, optional Salamander obfuscation | Very high on lossy links | Medium (UDP can be throttled) |
| Trojan | TLS with a password, mimics HTTPS | High | Medium |
| VMess | Own encryption | Medium | Low–medium |
| Shadowsocks | Encrypted proxy stream | High | Low on modern filters |
| WireGuard, OpenVPN | Don't hide — recognizable patterns | High | No — blocked first |
VLESS vs VMess
Both come from the V2Ray/Xray family. VMess encrypts traffic itself and requires the client's clock to be close to the server's — a common cause of "it won't connect". VLESS drops built-in encryption and relies on TLS or REALITY instead, which makes it lighter and, with REALITY, much harder to fingerprint. For new setups, VLESS is the better choice.
Hysteria2 vs VLESS
Hysteria2 runs over QUIC (UDP) with its own congestion control, so it often outperforms TCP-based protocols on lossy mobile networks and long distances. On networks that throttle or block UDP, VLESS + REALITY over TCP tends to hold up better. The practical answer is to have both and switch when one stops working.
Trojan and Shadowsocks
Trojan wraps traffic in TLS with a password and looks like HTTPS; it works well but needs a real domain and certificate. Shadowsocks is simple and fast, but modern filtering systems have learned to detect many of its variants.
Why WireGuard and OpenVPN get blocked
They're great protocols for privacy on open networks, but they don't try to look like anything else. Filtering equipment recognizes their handshakes and blocks them — which is exactly what happens in Russia, China and other countries that block VPNs.
What to look for in a VPN
- Several modern protocols — so when one is blocked, another works.
- A subscription that replaces blocked servers automatically.
- Apps that let you switch protocols in one tap.
Four protocols in one subscription. Vetryx runs VLESS + REALITY, XHTTP, WebSocket and Hysteria2 — if one is blocked, switch to another. See pricing.
FAQ
VLESS vs VMess — which is better?
VLESS. It's lighter because encryption is left to TLS or REALITY, and with REALITY it's much harder to detect. VMess has its own encryption, is heavier and is sensitive to clock drift between client and server.
Hysteria2 vs VLESS — which is faster?
Hysteria2 runs over QUIC (UDP) and is often faster on lossy mobile and long-distance links. VLESS + REALITY runs over TCP and blends in better on networks that throttle or block UDP. Having both lets you switch when one is blocked.
Why don't WireGuard and OpenVPN work in some countries?
They have recognizable traffic patterns that filtering equipment can detect and block, which is what happens in Russia, China and other countries with VPN blocking.