Skip to content
Open access

On the Resilience of Secure Remote-Access VPN Solutions: A System-Level Evaluation of WireGuard, OpenVPN and IPsec (strongSwan)

Aug 2026 · Cryptography · 0 citations · 9 references

TL;DR

R resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions, underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions.

Abstract

Remote-access virtual private networks (VPNs) are a key component of enterprise security infrastructures. In practice, the effectiveness of a remote-access VPN is determined not only by cryptographic mechanisms but also by its ability to remain available and recover quickly under realistic operating conditions, which directly affects the operational security guarantees provided by the underlying cryptographic protocols. Enterprise deployments are characterized by heterogeneous client platforms, wireless access networks, and frequent endpoint and network disruptions. In this paper, we execute an exploratory case study of the operation of remote-access VPNs in enterprise environments through an empirical evaluation of WireGuard, OpenVPN, and IPsec. Using a controlled but realistic testbed with a cloud-hosted gateway and heterogeneous client platforms, we evaluate baseline performance as well as behavior under endpoint CPU stress, network impairments, MTU variation, and mobility-related disruptions, reflecting constrained and dynamically changing deployment conditions. The results suggest that VPN operational characteristics are influenced by both protocol design and execution environment. Within the evaluated deployment scenarios, kernel-based implementations generally exhibited higher resilience under endpoint resource contention and faster recovery after disruptions, while layered and virtualized environments exhibited increased variability and sensitivity to network imperfections. These findings underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions.

Read PDF

Similar papers

Open access Aug 2026

Efficiency and Security Analysis of Self-Hosted Cloud Storage: A Containerized ZTNA, Docker, and PostgreSQL Approach

A secure, containerized self-hosted cloud architecture integrating Nextcloud, PostgreSQL, and Docker, secured via a Zero Trust Network Access (ZTNA) tunnel to achieve a "Closed-Default" security posture is proposed.

Zen Aufa Bahalwan, Arry Avorizano · 0 citations
Review Open access Aug 2026

Cloud-Native Identity and Access Management for Enterprise Platforms

A four-plane theoretical model can be introduced to separate authentication, authorization reasoning, enforcement, and auditability into four closely coupled but independent evolving planes for the system, providing a unified point of reference for both researchers and practitioners in the field of secure and scalable...

Ravi Kumar Kotapati · 0 citations
Review Sep 2026

From Hypervisor to Container: Cloud Security Vulnerabilities, Defense Mechanisms, and Open Challenges

This paper reviews over 120 security publications from 2008 to 2025, focusing on how these isolation boundaries can be breached, and introduces a quantitative scoring framework called ADPO, which rates defenses from 0 to 3 based on their Accuracy, Deployment ease, Performance impact, and Operational overhead.

Swapnil Vishwas Baviskar, R. Sanoj, Hiran V. Nath · 0 citations
Case report 2026

From HAL to SMC : a normal-world view of ARM TrustZone on Android

The findings show that kernel-level data-transport and synchronization choices directly influence the classes of concurrency and memory-sharing defects exposed by each TEE architecture.

David Ada · 0 citations
Open access Aug 2026

Cloud in the crosshairs: exposing vulnerabilities in web-based management interfaces of open-source IaaS platforms

This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.

Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al. · 0 citations
Review Open access Jul 2026

Security Challenges and Solutions in Cloud Computing Environments

This review examines the major security threats affecting cloud computing environments, including data breaches, account hijacking, insider threats, insecure application programming interfaces (APIs), cloud misconfigurations, distributed denial-of-service (DDoS) attacks, multi-tenancy risks, and regulatory compliance i...

Amat AL-latif H. Abo-Torkhoma, A. A. H. Abo-torkhoma, G. Ali · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.