The classic open-source VPN versus an identity-based AmneziaWG network. One changed the world in 2001; networking has since moved.
| OpenVLAN | OpenVPN | |
|---|---|---|
| Protocol | AmneziaWG (~4k lines, kernel speed) | TLS-based (mature, heavier) |
| Topology | Mesh, peer-to-peer | Hub-and-spoke via server |
| Config per peer | Login once, managed | .ovpn profiles + certs |
| Certificate lifecycle | Invisible, automatic | easy-rsa or your PKI |
| Performance | Kernel-line-rate, low latency | Userspace overhead |
| Reconnect on network change | Instant roaming | Noticeable renegotiation |
| Access control | Per-user ACLs + posture | CCD files + firewall rules |
You need deeply customized TLS setups, TCP/444 fallback everywhere, or have existing OpenVPN expertise and configs that work.
Running OpenVPN today? Our switch guide covers the parallel-run pattern: join both networks, move users by group, retire the server when the graph empties.