Skip to content
Open access

On the Resilience of Secure Remote-Access VPN Solutions: A System-Level Evaluation of WireGuard, OpenVPN and IPsec (strongSwan)

Aug 2026 · Cryptography · 0 citations · 9 references

Abstract

Remote-access virtual private networks (VPNs) are a key component of enterprise security infrastructures. In practice, the effectiveness of a remote-access VPN is determined not only by cryptographic mechanisms but also by its ability to remain available and recover quickly under realistic operating conditions, which directly affects the operational security guarantees provided by the underlying cryptographic protocols. Enterprise deployments are characterized by heterogeneous client platforms, wireless access networks, and frequent endpoint and network disruptions. In this paper, we execute an exploratory case study of the operation of remote-access VPNs in enterprise environments through an empirical evaluation of WireGuard, OpenVPN, and IPsec. Using a controlled but realistic testbed with a cloud-hosted gateway and heterogeneous client platforms, we evaluate baseline performance as well as behavior under endpoint CPU stress, network impairments, MTU variation, and mobility-related disruptions, reflecting constrained and dynamically changing deployment conditions. The results suggest that VPN operational characteristics are influenced by both protocol design and execution environment. Within the evaluated deployment scenarios, kernel-based implementations generally exhibited higher resilience under endpoint resource contention and faster recovery after disruptions, while layered and virtualized environments exhibited increased variability and sensitivity to network imperfections. These findings underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions.

Read PDF