How do VPN protocols differ?
They differ in how they establish encryption, how much code they contain, how fast they are, and how well they cope with changing networks — and the differences are large enough that protocol choice affects real-world experience more than provider marketing suggests.
The protocols in current use:
WireGuard. Modern, and deliberately very small — a few thousand lines of code against hundreds of thousands for older protocols. That matters because a smaller codebase is easier to audit and has less surface for vulnerabilities. It uses a fixed set of modern cryptographic primitives with no negotiation, which removes an entire class of downgrade attacks. Fast, with quick connection establishment, and the practical default for most users.
Its known trade-off: it assigns static internal IP addresses and keeps some connection state, which has privacy implications providers address with their own layers on top.
OpenVPN. Long-established, extensively audited, highly configurable, and available over TCP or UDP. Its TCP mode can traverse restrictive networks by resembling ordinary traffic, which is why it persists. Slower, with a large codebase.
IKEv2/IPsec. Fast, and notably good at handling network changes — it reconnects seamlessly when moving between Wi-Fi and mobile, which is why it is common on phones.
L2TP/IPsec and PPTP. Older. PPTP is broken and should not be used, and its presence in a provider's list is a warning sign.
Proprietary protocols, several of which are built on WireGuard with modifications, usually to address the trade-off above or to resist blocking.
What actually matters when choosing:
Speed, where WireGuard generally leads.
Reliability on mobile, where IKEv2 and WireGuard handle roaming well.
Getting through restrictive networks, where obfuscated or TCP-based options are needed.
Battery life, where efficient protocols matter on phones.
The protocol is not the main question, though. What a VPN protects depends far more on the provider's logging, jurisdiction and audit history than on which protocol carries the traffic.