I remember spending a whole day configuring OpenVPN, lots of packages, certificates, key files, no clue what half of the things I was doing were for. I also didn't particularly like the OpenVPN iOS client. Setting up WireGuard took less than an hour, every step of the process made sense, and it allowed me to remove a whole lot of cruft from my server.
wget https://git.io/vpn -O vpn.sh
* inspect the file manually for malware etc.*
sudo bash ./vpn.sh
You enter your IP, port, protocol, client name and it generates a .ovpn file that you import into any client and it just works.
If you need to revoke a client or add another one, re-run the script and it will ask you what to do. It can also uninstall itself safely.
I still haven't managed to setup WireGuard.
OpenVPN gets about 40 Mbps for me on the Pi, but my upload is less, so I don't need more. On a VPS, it gets about 90 Mbps.
I used this guide to configure OpenVPN [1], which you could almost publish as a paperback ;-)
[1] https://www.digitalocean.com/community/tutorials/how-to-set-...
It's magic in that it does everything itself, it's not a black box.
It's only 460 lines with whitespace and comments, including the files it's writing to the filesystem.
What I am wondering - it is using a pregenerated dh param file (I can understsand why - to make the initial process faster). I am not much into crypto, with all the other elements being created during the setup process, how big no-no is having a predefined dh file?
[0] https://github.com/WireGuard/wg-dynamic/blob/master/docs/ide...
OpenVPN is generally well supported.