VPN Too Slow? How to Diagnose Speed Loss and When to Switch

Some speed loss is expected because a VPN adds encryption and routes traffic through another server, but there is no universal acceptable percentage. The result depends on your original connection, device, protocol, server distance and load, Wi-Fi, router CPU, and time of day. Measure a baseline without the VPN, then test the nearest server using the provider's default modern protocol on the same device and test endpoint. Repeat several times before changing settings.

If one server is slow, switch servers. If a distant country is slow, test a closer location to separate distance from provider capacity. If the native app is fast but the router is slow, the router is probably the bottleneck. Change one variable at a time; do not disable encryption, certificate verification, firewall protection, or the kill switch simply to improve a benchmark.

Last verified: 2026-08-05

Quick test and what the result means

Test Interpretation Next action
Baseline is slow without VPN ISP, Wi-Fi, device, or local network issue Fix the underlying connection first
One VPN server is slow Server load or route Try a different server in the same region
All distant servers are slow, nearby is fine Distance and transit latency Use a nearer location unless the distant country is required
Router is slow, native app is fast Router CPU/firmware limit Use device apps or stronger router hardware
WireGuard is fast, OpenVPN TCP is slow Protocol overhead and TCP behavior Keep the secure faster protocol where it works
Speed collapses only at peak hours ISP transit or VPN-server congestion Repeat at several times and compare providers
Downloads are fine but games lag Latency, jitter, or loss rather than bandwidth Test route quality and a nearer server

For use-case selection, see best VPN for gaming and best VPN for streaming. Router-specific limits are covered in best VPN for routers.

A correct measurement method

Use a repeatable protocol:

  1. Connect the test device by Ethernet when possible, or remain in the same Wi-Fi position.
  2. Stop cloud backups, updates, large uploads, and other household tests.
  3. Record the device, OS, VPN app version, protocol, server, and time.
  4. Run three baseline tests without VPN against the same nearby endpoint.
  5. Connect to the nearest suitable VPN server using the default protocol.
  6. Wait 30–60 seconds for routes to settle, then run three tests.
  7. Record median latency, download, and upload rather than the single best number.
  8. Repeat with a second nearby server.
  9. For a distant-country requirement, test two cities in that country.
  10. Repeat during the period when the problem normally appears.

A browser speed test measures one flow to one test server. It does not fully represent video stability, game jitter, BitTorrent peers, or remote desktop responsiveness. Add a real workload test without claiming that it is a scientific benchmark.

Server distance, load, and routing

Distance increases round-trip time because data must travel farther. A route can also be indirect because ISPs and VPN providers exchange traffic through particular transit networks. The geographically nearest city is a good starting point, not a guarantee.

Server load is another factor. Proton VPN, for example, publishes server-load indicators and recommends trying a lower-load server. Other providers may automatically choose a server based on capacity and route. Avoid treating a percentage from one provider as directly comparable with another; the calculation and hardware differ.[1]

Try another server number or city rather than repeatedly reconnecting to the same endpoint. If every server in one country is slow while nearby countries are normal, the problem may be regional peering rather than the whole provider.

WireGuard, OpenVPN, and protocol choice

WireGuard is commonly the speed-first default because its design is compact and efficient. Providers may use a branded implementation such as NordLynx or a proprietary modern protocol such as Lightway. OpenVPN remains valuable for manual configurations, older routers, TCP fallback, and some restricted networks.

A practical order is:

  1. provider automatic/smart mode;
  2. WireGuard or modern provider protocol over UDP;
  3. another UDP protocol if offered;
  4. TCP mode for networks that block or degrade UDP;
  5. obfuscation only when needed.

TCP-based VPN transport can be slower on lossy links, particularly when the application also uses TCP. Multi-hop, Secure Core, Tor-over-VPN, and obfuscation add routes or processing and should not be included in a baseline speed comparison unless they are essential to your threat model.

Do not choose obsolete protocols such as PPTP for speed. Their security limitations make them unsuitable for a modern privacy VPN.

Wi-Fi, device, MTU, and router limits

Wi-Fi

Weak signal, interference, crowded channels, and 2.4 GHz congestion can dominate the result. Compare Ethernet or 5/6 GHz at close range. A VPN does not repair local radio problems.

Device CPU and power mode

Encryption is efficient on modern hardware, but old phones, low-power TV sticks, virtual machines, and NAS devices can become CPU-bound. Battery-saving modes may also reduce background performance. Check CPU utilization during the test.

Router

A router processes traffic for every connected device. OpenVPN performance can be much lower than ordinary routing, especially on entry-level hardware. WireGuard is often more efficient, but firmware implementation matters. Test the same provider through a native computer app. If that is much faster, replace or bypass the router rather than the subscription.

MTU

MTU defines the largest packet before fragmentation. A bad path MTU can cause stalls, partial page loads, or poor throughput. Do not change it as an early “speed tweak.” First test another protocol and network. Use the provider or router vendor's documented procedure and record the original value.

Virtual machines and containers

A VM adds virtual adapters, host routing, CPU allocation, and sometimes nested VPNs. Test on the host first. Ensure only one layer is tunneling unless double VPN is intentional.

Streaming, games, P2P, and remote work

Streaming

Stable throughput and low packet loss matter more than a peak. Netflix recommends about 15 Mbps for 4K, but a VPN test should include overhead, household traffic, and the actual service. Buffering can also be an IP block or app issue rather than speed.[2]

Gaming

Ping, jitter, and packet loss dominate. A VPN may occasionally improve a poor ISP route, but it normally adds another hop. Test a server near the game region and compare match telemetry over several sessions.

P2P

Torrent speed depends on swarm health, peer upload, disk, client limits, P2P server policy, and port reachability. Use a legal, well-seeded test file. One slow torrent is not a provider benchmark.

Remote work and calls

Upload capacity, jitter, and stability are crucial. Split tunneling can keep a video-call app outside the consumer VPN if company policy permits. A corporate VPN may be mandatory and should not be layered through a consumer VPN without IT approval.

Step-by-step improvement plan

  1. Fix a slow baseline without VPN.
  2. Update the VPN app and operating system.
  3. Restart the modem/router and device.
  4. Use the nearest suitable server.
  5. Try a different server in the same city or country.
  6. Select WireGuard or the provider's modern default.
  7. Disable optional multi-hop or obfuscation for the comparison only.
  8. Compare Ethernet with Wi-Fi.
  9. Test the native app instead of the router.
  10. Pause background uploads and security scans for a controlled test.
  11. Test another network, such as mobile data.
  12. Repeat at peak and off-peak times.
  13. Contact support with medians, not one screenshot.

Do not use unknown “VPN optimizer” software, registry cleaners, or scripts that disable network security.

Change server, plan, router, or provider?

Finding Best next decision
One endpoint is poor Change server
Free tier is congested or lacks location choice Consider a paid tier after checking terms
Router only is slow Upgrade hardware or use native apps
Required distant country is inherently high-latency Adjust expectations; choose best route, not a new brand blindly
Every nearby server is slow on two networks/devices Trial another provider
Service is fast off-peak but unusable at normal time Compare provider capacity and ISP route
Required protocol is blocked by your network Choose a provider with supported TCP/obfuscation options

A paid plan can offer more servers or features, but it cannot make old hardware fast or eliminate continental distance.

Criteria for a faster replacement

Use the best VPN guide and prioritize:

  • several nearby cities and alternative routes;
  • a modern protocol on every device;
  • visible server status or effective automatic selection;
  • native apps rather than router-only use;
  • a refund period applicable to your purchase channel;
  • support that accepts reproducible test data;
  • no required multi-hop for ordinary use;
  • router WireGuard files if router use is essential.

Test the candidate against the same baseline, endpoint, time, and workload. Otherwise, apparent improvement may come from a different test condition.

FAQ

What percentage speed loss is normal with a VPN?

There is no universal percentage. Baseline speed, distance, protocol, hardware, load, and route all change the result. Compare against your use requirements.

Why is my speed test fast but streaming buffers?

The service may be blocking the IP, the route may have jitter or loss, Wi-Fi can fluctuate, or the app may be using a different path. Test sustained playback and another server.

Is WireGuard always faster than OpenVPN?

Often, but not on every network or implementation. Restricted networks may handle TCP better, and route differences can outweigh protocol efficiency.

Can changing MTU make the VPN faster?

It can solve specific fragmentation or path-MTU problems, but arbitrary values can cause partial failures. Treat it as an advanced, documented step.

Why is a router VPN much slower?

The router may lack CPU acceleration or efficient firmware. Compare the provider's native app on a wired computer to isolate the hardware.

Can a VPN reduce ping?

Occasionally, if it finds a better route than the ISP. In most cases the extra hop adds latency. Measure the specific game route.

When should I switch providers for speed?

After nearby servers, protocols, devices, networks, and times all show a repeatable provider-side limit while the non-VPN baseline remains healthy.

Sources


  1. Proton VPN: Server load indicators ↩︎

  2. Netflix: Recommended internet connection speeds ↩︎