WGTCP LINUX KERNEL VPN · TCP TRANSPORT · 2026
Two years of development and tuningUDP remains the default
It works · It's fast · It's reliable · We beat TCP meltdown

WGTCP

TCP transport patch for WireGuard

Firewall compatibilityIt gets through.

Carry WireGuard traffic across networks that permit TCP while restricting raw UDP—without a proxy, relay, or userspace encapsulation hop.

Measured performanceIt is fast.
Up to +21.1%.

519.3 Mb/s TCP-WG versus 428.9 Mb/s UDP-WG in the measured x64 56 ms bulk-transfer cell.

Reliability proven under pressureWe beat TCP meltdown.

Zero formal meltdowns across 122 valid post-repair executions under the campaign's predeclared three-part definition.

One crypto layerTwo carrier paths
Inner IP packet
WireGuard encrypt + authenticate
Default pathUDP socketStock carrier behavior remains available and unchanged.
WGTCP pathFrame → TCP streamPersistent, reliable carrier for UDP-blocking networks.

Same WireGuard keys, Noise protocol, peer identities, AllowedIPs, rekeying, and authentication. WGTCP changes the carrier—not the cryptography.

Open
source
Firewall friendlyUp to 21.1% fasterLower CPU utilizationIPv4 + IPv6 readyx64 + ARM64Open source

Tested across x64 and ARM64

Faster in measured workloads

WGTCP adds an opt-in TCP path beneath the existing WireGuard encryption layer. It beat UDP-WG in several measured clean-path workloads while adding reliable reach across UDP-blocking networks.

Clean 56 ms path · x64+21.1%

Bulk TCP

519.3 Mb/s through TCP-WG versus 428.9 Mb/s through UDP-WG in the measured cell.

Sequential HTTPS · clean LAN+16.3%

Requests

152.55 versus 131.14 requests per second in the measured x64 cell.

ARM64 · sequential HTTPS · clean LAN16.6%

Lower mean CPU

51.2% mean CPU through WGTCP versus 61.3% through UDP-WG in the measured cell. Clean-LAN bulk transfer also used 6.7–10.9% less mean CPU across x64 and ARM64.

Physical-carrier campaign122

Valid runs

Zero formal meltdowns under the campaign's predeclared three-part definition. Read the report for limits and exceptions.

Across the test matrix

Four application workloads across clean and lossy paths. Each cell is the mean of three end-to-end runs; architecture is labeled where relevant. Bar lengths compare WGTCP with UDP-WG only within that row.

WGTCPUDP-WGMeasured end-to-end means
Bulk transfer · ~56 ms RTT

Four-stream TCP goodput

Cross-continent file-transfer workload · Mbps received.

Clean · 0%+21.1%
WGTCP
519.3 Mb/s
UDP-WG
428.9 Mb/s
Light loss · 0.5%+2,296%
WGTCP
416.2 Mb/s
UDP-WG
17.4 Mb/s
Heavy loss · 5%+9,517%
WGTCP
377.8 Mb/s
UDP-WG
3.9 Mb/s
HTTP/2 web mix · ~195 ms RTT

Multiplexed web requests

5,000 objects · 50 TLS connections × 10 streams · requests/s.

Clean · 0%+2.6%
WGTCP
2,060.65 req/s
UDP-WG
2,008.99 req/s
Light loss · 0.5%+29.4%
WGTCP
2,063.41 req/s
UDP-WG
1,595.13 req/s
Heavy loss · 5%+77.7%
WGTCP
1,970.41 req/s
UDP-WG
1,108.90 req/s
Fresh-TLS web requests · ~0.4 ms RTT

Sequential HTTPS

200 GETs · new TLS 1.3 connection per request · requests/s.

Clean · 0%+16.3%
WGTCP
152.55 req/s
UDP-WG
131.14 req/s
Light loss · 0.5%+66.9%
WGTCP
152.87 req/s
UDP-WG
91.57 req/s
Heavy loss · 5%+983%
WGTCP
154.98 req/s
UDP-WG
14.31 req/s
Interactive control path · selected cells

Lower measured latency

1,000 ICMP probes alongside a pre-warmed SSH session · mean inner RTT · lower is better.

ARM · 56 ms · clean31.7% lower
WGTCP
55.95 ms
UDP-WG
81.88 ms
x64 · 195 ms · clean1.7% lower
WGTCP
202.12 ms
UDP-WG
205.62 ms
x64 · 227 ms · 0.5%1.1% lower
WGTCP
230.50 ms
UDP-WG
232.97 ms

Results are measured comparisons, not universal guarantees. Path latency, packet loss, workload, queueing, concurrency, architecture, and kernel configuration affect outcomes. Important: clean x64 bulk-TCP runs at approximately 195–227 ms favored UDP-WG by 14–23%; benchmark the path you intend to operate.

What changes—and what does not

WireGuard crypto.
TCP transport.

Handshakes, keepalives, and encrypted data are framed inside a long-lived per-peer TCP stream. WireGuard authentication remains authoritative. UDP mode is unchanged and remains the default.

TCP mode requires WGTCP at both endpoints and does not make a TCP interface interoperable with an unmodified UDP-only peer.

Framing, sockets, lifecycle, and semanticsRead the transport design docs
IPv4 +
IPv6
ready
INNER IP
WIREGUARD ENCRYPT / AUTHENTICATE
DEFAULT
UDP SOCKET
WGTCP MODE
FRAME → TCP STREAM
TCP framing preserves record boundaries. It adds no encryption and does not replace WireGuard's authenticated Noise protocol.

Build it, install it, or inspect the change

Get the source, binaries, or the patch

Binaries

Prebuilt Ubuntu 24.04 packages for the exact 6.8.0-136-generic kernel. Verify the ABI, architecture, and checksums first.

AMD64 ↓ARM64 ↓