Technically the best cipher for both TLS1.2 and TLS1.3 is TLS_CHACHA20_POLY1305_SHA256 and TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256 respectively, as they offer the fastest software based decoding, since the GL routers don’t have a dedicated AES instruction on the processor. This is also why wireguard is much faster than OpenVPN with default config. AES is the best for VPN from PC to PC for example, where Intel and AMD processors have AES instructions.