Eighteen tunnel protocols compared on cipher suite, port, roaming, and how a censor spots each one.
Configuration and key handling break more deployments than cipher choice. A WireGuard server with a world-readable private key is worse than a careful OpenVPN server, which the cipher column never shows.
Two questions matter. Is it still safe to run (Security status), and will it survive your network (DPI fingerprint).
The DPI column says how cheaply a network operator can identify the protocol on the wire. It says nothing about whether your traffic can be read.
WireGuard is marked obvious and carries the strongest cryptography on this page. Trojan is marked resistant and is only as strong as the TLS certificate behind it. Read the two columns separately.
A reference table, hand-checked against protocol specifications and published research. No live measurements. For what is blocked in a country, use the Censorship Radar, which scores providers on measurements from probes inside it. To check a config file, use the Config Audit.
Fields missing below are ones we could not state with confidence.