Optimisering av VPN topologier och tjänster för förbättrad prestanda och säkerhet

Dumitru Laso · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2026

With the rise of remote workforces and cloud-based applications, organizations face growing demand for secure, high-performance Virtual Private Networks (VPNs), yet the design and implementation remain challenging due to competing requirements for security, performance and cost. Hence, this thesis presents a comparative analysis of VPN performance in three different topologies: Site-to-Site, Full Mesh andHub-and-Spoke based on Quality-of-Service metrics such as latency, jitter, bandwidth and packet loss. Hence a comparative analysis is presented, also mitigation strategies are proposed. The study was conducted using physical network equipment, including Cisco firewalls and switches.The comparative analysis concluded that while all topologies provided secure communications, Hub-and-Spoke topology showed lowest performance of three topologies. This topology had higher one-way latency, jitter and packet loss before implementing mitigation strategies. Mitigation strategies were implemented across all three topologies. In order to improve the performance of the topologies, including the worst performing topology, a batch of performance tests was conducted. The results demonstrated slight improvements in throughput, packet delivery, and reducedone-way latency.This study highlights the critical impact of topology selection and optimization techniques on VPN performance. These findings may contribute to further work and optimization in scenarios where VPN topologies need to be adjusted for better performance and reliability.

Read the paper · More papers on PaperTik