I wouldn't ding someone using SSH tunnels (carefully), but in a de novo design, I would always recommend WireGuard first.
> WireGuard .. has higher performance ...
Note there are circumstances where ssh port forwarding (-L, -R, -D) is faster than any L2/L3 vpn because it breaks TCP connections in two segments, so any flaky retransmission causing issues are localized, RTTs are smaller, TCP ramp-up is faster, etc.
On the other hand, ssh tun/tap forwarding will almost certainly be slower.
If you are connecting over a flaky wifi/2g/3g connection, possibly to a flaky/distant counterpart, and have performance issues, I would recommend trying (L4 is it?) ssh/socks or even http forwarding via a stable middle host.
Openwrt 18.06.4 32-bit
wireguard: 645 Mbit/s ping 1.1ms
openvpn: 164 Mbit/s ping 1.2ms
Openwrt 19 (snapshot r11159) 64-bit:
wireguard: 1.16 Gbit/s ping 1.1ms
openvpn: 230 Mbit/s ping 1.2ms
pfsense 2.4.4-p3 (amd64):
openvpn: 115 Mbit/s ping 1.2ms
It was tested by moving traffic between two virtual bridges, Debian>router>Debian, on KVM (libvirt), CPU E3-1270, kernel:
4.19.0-4-amd64 #1 SMP Debian 4.19.28-2 (2019-03-15) x86_641 core, 2GB per VM
iperf3 -t 60
Settings:
Wireguard: defaults
OpenVPN: no compression, udp, tun, defaults
I would also note that I setting wg took about 5-10 minutes while setting openvpn took about an hour.Also see the endless discussions on how to deliver 100 Mbit/s for single connections on OpenVPN. It is absolutely insane, you have to spend many hundreds of dollars on hardware to have a fighting chance. And even if you get hardware acceleration that doesn't help nearly as much as you'd expect. And aside from cost the power consumption required for such hardware is very prohibitive for most.
Meanwhile my phone (first gen. Pixel (so three generations behind)), over wifi, gets at least 60 mbit/s over wireguard to a weak home router and then out to internet.
You wouldn't have an independent benchmark comparing a GTR and a semi truck.
Try switching between IPv4 and IPv6 networks, or reaching a peer on non-default/primary network on Windows.
Not denying it would usually have better connectivity than TCP based ssh.
Cellular networks abroad.