@anav
depenс what u need , about the performance, yes with wireguard, u can get much more bandwidth then ovpn, but from other way ovpn has own advantages.
it's works same as physical interface (TAP), so you can add vlan on that or put in the bridge, choice btw udp/tcp & port.
I have yet to see a situation for the majority of users that wireguard doesnt solve.
If ovpn is so good, then why need port knocking.
So be consistent if you are going to espouse NOt wireguard at least have the courtesy to promote IKEv2. You also would do this knowing that OVPN is not fully implemented in ROS.