

- It is inefficient in both tunnel and transport mode, sacrificing 20-30% of available bandwidth.
- It is cryptographically expensive, making your clients work harder and costing the VPN provider more money to host nodes.
- It is complex to setup and deploy.
- Uses outdated crypto.
- Operates in Userspace.
- WireGuard is essentially better in every one of these regards.
People who want to use a VPN tunnel to access resources in a private network, but browse the rest of the internet freely without all the traffic being forced one way or the other.
Think of a pipe with a Y-junction in it.