Listing Thumbnail

    OpenVPN Access Server / Self-Hosted VPN (PAYG)

     Info
    Deployed on AWS
    Access Server is a self-hosted business VPN and ZTNA software developed by the creators of the OpenVPN protocol, deployed on EC2 and billed through AWS. Get secure access to your VPCs and other connected networks, route traffic by domain name for application-aware access control, and leverage Data Channel Offload (DCO) for kernel-accelerated throughput that keeps pace with demanding AWS workloads. With MFA, granular access controls, SAML single sign-on via AWS IAM Identity Center, and Zero Trust-ready policies, Access Server is trusted by businesses to protect AWS infrastructure and beyond. Purchase connections through AWS as a monthly or yearly contract and consolidate your VPN software and infrastructure costs onto a single AWS invoice.
    4.5

    Overview

    Play video

    Access Server is a self-hosted business VPN and Zero Trust Network Access (ZTNA) software solution, developed and maintained by OpenVPN Inc., the company behind the open-source OpenVPN protocol. It delivers secure, encrypted remote access to your business network and resources, with the controls needed to enforce least-privilege, zero-trust access policies.

    On AWS, Access Server runs in your own environment on Amazon EC2, giving your remote, hybrid, and in-office workforce protected access to VPCs, private subnets, hybrid networks, and on-premises resources without surrendering control of your infrastructure to a third-party service.

    Purchase Access Server connections directly through AWS Marketplace as a monthly or yearly contract. Choose the concurrent connection limit that fits your organization, adjust it at renewal as your needs change, and pay for your Zero Trust VPN and EC2 infrastructure on one AWS invoice.

    Deployment Model:

    • Self-hosted on Amazon EC2 within your AWS account and VPC, so data and configuration stay under your control.
    • Deployed in minutes from a preconfigured AWS CloudFormation script, with license activation applied automatically at launch.
    • Managed through an intuitive web-based Admin Web UI, with REST API, and command-line configuration options available for advanced administration.
    • Supports remote-access and site-to-site VPN topologies.

    Typical Use Cases on AWS:

    • Provide secure remote access to applications and data hosted in your Amazon VPC.
    • Connect AWS environments with other clouds and on-premise networks.
    • Protect SaaS and internal applications by making them reachable only through the VPN, reducing exposure to the public internet.
    • Enforce zero-trust access policies based on identity, device, and location.
    • Secure connectivity for devices, IoT, and machine-to-machine use cases.

    Key Features:

    Zero-Trust Access Controls

    • Zero Trust Application Broker: Access Server verifies user identity, location, and device ID during connection and assigns, during domain lookup, a synthetic intermediate IP scoped to a single authorized app - the device never gets a route to the entire private network, so lateral movement isn't merely limited; it's structurally impossible.
    • Define identity-based, role-driven access to specific applications by domain name or hostname, subnets, and private resources.
    • Enforce device verification and location-aware post-authentication checks to reject connections from unauthorized endpoints.
    • Use Access Control Lists to segment network access and limit lateral movement across your environment.

    Flexible Authentication

    • Supports local authentication and external authentication with PAM, RADIUS, LDAP, and SAML.
    • Supports a custom Python3 authentication module for non-standard identity requirements.
    • Includes built-in multi-factor authentication using TOTP.
    • Allows multiple authentication methods to be active simultaneously per user or user group.
    • Includes built-in X.509 PKI and support for external PKI.

    High-Performance Connectivity

    • Supports OpenVPN DCO to move encryption and decryption into the OS kernel for improved VPN data-plane performance and reduced processing overhead.
    • Supports multi-threaded operation for demanding, high-throughput AWS workloads.
    • Supports NAT mode for remote-access deployments and routing mode for site-to-site deployments.
    • Supports routing by IP CIDR ranges and domain names for defining access policies for cloud-hosted, SaaS, and internal applications.
    • Supports split-tunnel and full-tunnel configurations.

    Availability and Scale

    • Supports clustering across multiple Access Server nodes to increase capacity and improve availability.
    • Supports DNS-based traffic distribution for directing users to available cluster nodes.
    • Deploy multiple Access Servers that draw from a single shared pool of contracted connections.

    Broad Client Support

    • OpenVPN Connect client is available for Windows, macOS, ChromeOS, iOS, and Android.
    • Supports all OpenVPN protocol-compatible clients.
    • Includes a Client Web UI for downloading connection profiles and client software.
    • Supports connection profile distribution by URL to streamline user onboarding.

    Highlights

    • Self-hosted control, built by the protocol's creators: Deploy a self-hosted business VPN and ZTNA solution on EC2 in minutes, developed by OpenVPN Inc., the team behind the open-source OpenVPN protocol. Your access policies, configuration, and data stay entirely within your AWS account and VPC.
    • Zero-trust access to your AWS resources: Enforce least-privilege access with ACLs to destination IP subnets and domain names. Use identity, device, and location controls. Authenticate with SAML, LDAP, RADIUS, PAM, or local accounts, with built-in MFA and route traffic by domain name for application-aware control.
    • High-performance, scalable connectivity: Data Channel Offload (DCO) moves encryption into the OS kernel for near wire-speed throughput on demanding AWS workloads. Cluster multiple servers for high availability and load distribution as your usage grows.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    OpenVPN Access Server / Self-Hosted VPN (PAYG)

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (24)

     Info
    Dimension
    Description
    Cost/month
    2 Connection Plan
    FREE. Up to 2 concurrent connections to your Access Server
    $0.00
    5 Connection Plan
    up to 5 concurrent connections to your Access Server
    $70.00
    10 Connection Plan
    up to 10 concurrent connections to your Access Server
    $90.00
    15 Connection Plan
    up to 15 concurrent connections to your Access Server
    $135.00
    20 Connection Plan
    up to 20 concurrent connections to your Access Server
    $180.00
    25 Connection Plan
    up to 25 concurrent connections to your Access Server
    $225.00
    30 Connection Plan
    up to 30 concurrent connections to your Access Server
    $270.00
    35 Connection Plan
    up to 35 concurrent connections to your Access Server
    $315.00
    40 Connection Plan
    up to 40 concurrent connections to your Access Server
    $360.00
    45 Connection Plan
    up to 45 concurrent connections to your Access Server
    $405.00

    AI Insights

     Info

    Dimensions summary

    You pick one plan based on the number of simultaneous connections you need. A connection is one actively connected device, such as a laptop, tablet, or server. Plans scale from 2 connections up to 750, with the 2 Connection Plan offered free. You add more devices and users than your limit, but only the subscribed number can connect at the same time. All plans deliver the same features and performance; only the connection cap differs. You commit to a contract term of one month or one year, with optional auto-renewal.

    Top-of-mind questions for buyers

    A connection is one actively connected device, such as a headless server, a mobile tablet, or a remote laptop. You may add more devices and users than your plan allows, but only the subscribed number can be connected at the same moment.
    You can start with a smaller plan and upgrade as usage nears the cap. Email notifications warn you when usage crosses a set threshold. When you upgrade, the change takes effect immediately, giving you the higher connection count right away.
    No. There is no difference in data speeds or performance based on the plan you choose. All plans include the same features. Only the number of devices that can connect at the same time changes between plans.
    openvpn.net+1
    Helpful?

    Vendor refund policy

    Refund within 30 days of purchase, contact support@openvpn.net  to request a refund

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Visit the OpenVPN Support Center  for access to technical support resources, troubleshooting guidance, and the option to submit a support ticket.

    For AWS-specific setup and troubleshooting information, review the Access Server PAYG on AWS quick start guide  and support documentation .

    For answers to common AWS deployment, connectivity, configuration, licensing, and administration questions, review the Access Server on AWS FAQ .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.5
    391 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    71%
    24%
    3%
    1%
    1%
    23 AWS reviews
    |
    368 external reviews
    External reviews are from G2  and PeerSpot .
    Bibhor D.

    Easy Setup and User Management Made Simple

    Reviewed on Aug 19, 2026
    Review provided by G2
    What do you like best about the product?
    It was easy to set up and add users, and it’s also straightforward to manage.
    What do you dislike about the product?
    The pricing isn’t competitive compared with other VPN services.
    What problems is the product solving and how is that benefiting you?
    It gives access to people who are working remotely.
    AK sharma

    Secure access for global media teams has improved workflows but still needs lower latency

    Reviewed on Aug 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been in the media field for fourteen years, helping different global customers by streaming videos and utilizing secure environments. We have been using OpenVPN Access Server for around nine years now.

    Initially, we were using more traditional VPN solutions where we had to control the passwords carefully and be very cautious about whom to share those credentials with. Then we came across OpenVPN Access Server, which provides a self-hosted version for organizations, allowing us to avoid directly exposing internal applications to the Internet and instead offers a more secure channel between them. Our engineers work on laptops and used VPNs to connect to the Internet and the company network, which exposed internal applications. Instead, OpenVPN Access Server provides a controlled environment where engineers and vendors globally can access applications securely. With MFA implementation, it is very secure, using SSOs and encrypted secure tunnels, ensuring that if someone attempts to reach internal applications, everything is handled properly without compromising security, as access is granted only after extensive validation, verification, and authentication.

    It saves our environment and makes work easier by allowing LDAP integration for authentication where group members easily gain access to platforms necessary for their work. In our organization, we work on various infrastructures such as production Kubernetes clusters, AWS VPCs, internal Grafanas, and Kibanas, alongside ServiceNow integrations and multiple customer environments with thousands of SSH servers and various monitoring platforms and APIs. Having everything exposed to the Internet would pose a significant threat. Therefore, OpenVPN Access Server acts as a middle layer between our environments and the Internet, allowing access to applications only based on defined roles and granular rules tailored to the users' needs. For instance, our SREs can make changes on YAML and JSON files, while SROs can only read without making changes, ensuring secure access levels based on expertise. Vendors are granted access for their specific needs as well, making our work environment well-managed and organized.

    Recently, while working on the Olympics, there was a requirement involving two sets of customers; one was using OpenVPN Access Server, and the other was utilizing Cisco Secure. We were working with different tools for monitoring and needed to provide access through secure means to prevent data exposure. If security is compromised in any server, it can lead to threats and data breaches, so all data passing through environments must be monitored effectively by a specific set of individuals. When something goes wrong, those tasked with handling it must ensure that they investigate, troubleshoot, and fix any issues. Our team had three SREs working during this period, equipped to resolve high-severity events. The customer was simultaneously granted access to monitor data flows on their platform while management required detailed oversight on the services, encryption tests, and necessary adjustments. The environments were suitably hosted on Kubernetes in the cloud, and every team coordinated seamlessly without compromising security, resulting in smooth operations.

    What is most valuable?

    OpenVPN Access Server offers features such as local authentications, compatibility with LDAP, Redis, SAML, TOTP MFAs, and multi-factor authentication, which are great for security. It also supports SSO, which allows for easier management of user access without maintaining separate directories. Administrative tasks are straightforward, featuring a simple GUI that permits management of users, groups, authentication, VPN settings, and access policies effectively. This ease of management makes it a user-friendly tool for our needs.

    A standout feature is its compatibility with multiple operating systems used by our media-focused company. OpenVPN Access Server works incredibly well with platforms such as Windows, macOS, Linux, Android, and iOS, ensuring comprehensive client support across our diverse operations.

    OpenVPN Access Server saves us time compared to earlier VPNs where managing credentials had its challenges. We used to distribute VPN credentials, which required maintaining records and introduced security risks if anyone learned those passwords. Post-adoption of OpenVPN Access Server, it has positively structured roles based on tasks, troubleshooting, and support. Previously, one team handled user account management and password renewal, which was often tedious and prone to errors, complicating access for those in need. OpenVPN Access Server allows easy additions into LDAPS for secure access without complications, making work easier for everyone.

    What needs improvement?

    There are definitely areas for improvement. A broader network level access faces challenges, and the clustering configuration seems insufficient, posing a single point of failure. Moreover, patch management and monitoring are our ongoing responsibilities, which OpenVPN Access Server should consider addressing.

    I would rate OpenVPN Access Server around a seven. While it is effective, there are instances where infected devices or incorrect configurations can create problems. The VPN struggles under these circumstances, and latency issues need attention, leading to slower performance.

    The rating of seven reflects significant areas needing improvement such as latency, management issues, and vulnerabilities such as single points of failure. Managing certificates falls on us; any issues within the certificate or related layers can lead to complications that require extensive debugging, consuming valuable resources. Furthermore, the licensing cost is not user-oriented but based on the number of established connections, leading to elevated expenses.

    Security is satisfactory; however, the challenge lies with infected devices. The channels are well-secured, and periodic upgrades enhance its defenses further. The primary focus should be on configuring our VPNs properly for optimal security.

    The accuracy and reliability of OpenVPN Access Server's outputs are decent, albeit requiring improvements. I would appreciate a reduction in resource consumption, especially given the high costs associated with the infrastructure's current resource demands, particularly with OpenVPN Access Server's AI capabilities still in their developmental phase.

    The connection speed utilizing OpenVPN Access Server is notably slow, with high latency affecting performance.

    For how long have I used the solution?

    We have been using OpenVPN Access Server for around nine years now.

    What do I think about the stability of the solution?

    OpenVPN Access Server remains stable and scalable. I deem it quite flexible, bolstered by quality customer support.

    What do I think about the scalability of the solution?

    Scalability is efficient, allowing multiple concurrent connections easily. The customer support provided is commendable and always responsive when needed, ensuring we receive timely assistance.

    How are customer service and support?

    I would rate customer support as a solid nine out of ten due to the support and onboarding interactions we have experienced.

    Which solution did I use previously and why did I switch?

    Previously, we utilized a different solution which failed to deliver adequate control over applications and posed firewall limitations; it was not well-aligned with our primary needs. Transitioning to OpenVPN Access Server was initiated due to better performance outcomes and enhanced management capabilities.

    How was the initial setup?

    The installation and setup of OpenVPN Access Server is quite easy and efficient. The process involves a straightforward setup folder; clicking through within a minute can establish a working environment, facilitating quick onboarding for users.

    What about the implementation team?

    Certain applications are effectively managed within OpenVPN Access Server. We have obtained device management capabilities seamlessly, simplifying user access across various devices. The centralized administrative mode enhances user group management and client provisioning, making it straightforward to operate.

    What was our ROI?

    Regarding return on investment, we are saving time by managing users and groups more efficiently since adopting OpenVPN Access Server. We have transitioned to using licenses effectively within departments and trimmed down the number of licenses required. This change allows us to keep security tight without overwhelming workloads for administrative teams, thereby saving time. Financially, we observe that while costs were initially high, optimizing user connections has rendered better financial management in the long run, improving user access without extensive management needs.

    What's my experience with pricing, setup cost, and licensing?

    The pricing and setup costs for OpenVPN Access Server are on the high side since licenses are not user-dependent but based on the number of connections established. With two free simultaneous connections, the paid license hinges on concurrent active users, causing overhead for large enterprises due to the extensive number of simultaneous connections typically needed.

    Which other solutions did I evaluate?

    Before choosing OpenVPN Access Server, we evaluated others such as Wireguard and IPSec, but OpenVPN Access Server prevailed at that moment due to its superior control and simple self-hosting solutions.

    There is a need for improvements, especially considering alternative solutions such as ZITNA, which offer dedicated application-level approaches. Moreover, considering Wireguard could provide simpler side-to-side tunneling, which has been discussed internally as a potential alternative.

    What other advice do I have?

    For those looking into OpenVPN Access Server, I recommend it for its strong security, user-friendly access management, and operational scale. If you operate remotely or require easy scalability across multiple platforms, OpenVPN Access Server is a robust solution despite its latency concerns and slightly higher costs, making it a great asset for your organizational needs.

    OpenVPN Access Server is deployed on AWS, providing a public cloud environment for our organizational needs. We utilize AWS, which stands for Amazon Web Services. We purchased OpenVPN Access Server through the AWS Marketplace.

    Despite rising user levels causing potential complications, OpenVPN Access Server's effectiveness stands out. Our team, consisting of eighty people, finds that managing usernames and passwords becomes manageable with the help of LDAP, ensuring access aligns with specific roles and skill sets.

    The user interface of OpenVPN Access Server is simple and intuitive. It provides diverse options, displaying the server version, name, license status, and active users. The current active user count and options for authentication are readily visible, along with configuration details, making it user-friendly and efficient for quick management.

    I would rate this product overall a seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2882781

    Secure access to blocked sites has improved my travel safety and protected my online identity

    Reviewed on Aug 03, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for OpenVPN Access Server is to connect to blocked websites for safety. A specific example of how I use OpenVPN Access Server is when I travel to China and I used to open the VPN server for my real address. I was trying to achieve stable access to sites such as Google and YouTube in mainland China, and OpenVPN Access Server helped with that because it is very stable. Additionally, I use OpenVPN Access Server for my real IP address in my country.

    Another main use case for OpenVPN Access Server is that I use it when I am in a public area to connect with Go. It helps me to feel safe.

    What is most valuable?

    The best features OpenVPN Access Server offers include the ability to open the OpenVPN Access Server admin UI, where I can check my data and see how many people are connected to the server.

    I do not usually check the admin UI, but sometimes I can check who is connecting to OpenVPN Access Server and what data they are using.

    OpenVPN Access Server has positively impacted my organization mainly through improved security for myself. It improves my security because when I use Google to search for something, I connect to OpenVPN Access Server for security to hide my IP address.

    What needs improvement?

    I do not really think there is anything that needs improvement for OpenVPN Access Server. Everything is good, and nothing stands out to me that requires enhancement.

    For how long have I used the solution?

    I have been using OpenVPN Access Server for three years.

    What do I think about the stability of the solution?

    OpenVPN Access Server is stable. My impression of the connection speed using OpenVPN Access Server is that, compared to other VPN solutions, OpenVPN Access Server is a little bit slow, but it is very safe and always connects.

    How are customer service and support?

    Customer support for OpenVPN Access Server has not been a factor for me, as I have not needed to contact them.

    Which solution did I use previously and why did I switch?

    I have used other services such as WireGuard and V2Ray; I do not switch, but my main use is OpenVPN Access Server.

    Before choosing OpenVPN Access Server, I evaluated other options such as WireGuard.

    How was the initial setup?

    I think that installing and setting up OpenVPN Access Server within my organization is medium; it is not easy, but it is not difficult either.

    What was our ROI?

    I have seen a return on investment because I save time since it is really easy to deploy, and now my followers use it.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the pricing is a little bit expensive, but it is fine for the value it provides. It would be nice if the pricing were more affordable.

    Which other solutions did I evaluate?

    My advice for others looking into using OpenVPN Access Server is to try using AWS, not Azure, and then it will work fine. AWS is easy to deploy.

    What other advice do I have?

    OpenVPN Access Server is deployed in my organization through a public cloud; I use it at Amazon. I use AWS as my cloud provider, specifically AWS. I purchased OpenVPN Access Server through the AWS Marketplace.

    I do not use local, LDAP, RADIUS, PAM, or SAML authentication integration. I do not utilize the access controls feature of OpenVPN Access Server. I would describe the user interface of OpenVPN Access Server as really nice, and I can show my subscribers how to use OpenVPN Access Server to connect to the internet.

    I would rate this product a 10 out of 10.

    Nigel Spence

    Secure remote access has protected internal resources and supports controlled vendor connectivity

    Reviewed on Jul 31, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for OpenVPN Access Server is to provide secure remote access to our internal resources for our employees, allowing our users to connect from anywhere through an encrypted VPN tunnel while maintaining authentication and access control. I appreciate it because it is easy to deploy, integrates with Active Directory, supports multi-factor authentication, and gives us control over what people can do with it.

    As a network engineer, I use OpenVPN Access Server to connect to the corporate network, where I can manage our internal infrastructure such as our firewalls, switches, and routers instead of exposing those devices to the internet. This is accessible by using the VPN connection.

    What is most valuable?

    The best features OpenVPN Access Server offers include secure connectivity, support for multi-factor authentication, integration with Active Directory and other identity providers, and strong encryption. Administrators can control which users have access to their group, it is easy to deploy, and it can work across platforms such as Mac, Linux, and Android.

    Regarding the integration with Active Directory and other identity providers, the system teams handle the integration, and a simple flow would be OpenVPN, username, VPN access, Active Directory, RADIUS, essentially leading to OpenVPN being established. The system team is what really handled the integration with Active Directory.

    OpenVPN Access Server has positively impacted my organization by supporting remote work and improving security since users must authenticate through the VPN first before accessing services such as RDP and SSH, which reduces our attack surface. It also helps with centralized user management, and sometimes we provide our vendors access to the system they support so they can access a server without accessing the rest of my environment. It is also cost-effective.

    What needs improvement?

    OpenVPN Access Server is pretty solid. However, the biggest improvements I would recommend would be enhancing multi-factor authentication, implementing least privilege access, and perhaps stronger identity integration along with improved monitoring.

    For how long have I used the solution?

    I have been using OpenVPN Access Server for four years.

    What do I think about the stability of the solution?

    OpenVPN Access Server has been stable so far, and I have not had any issues.

    What do I think about the scalability of the solution?

    I rate it an eight because perfection quite frankly does not exist.

    How are customer service and support?

    The customer support for OpenVPN Access Server is acceptable, but it could be better.

    OpenVPN Access Server is a good tool. The downside is that most support is done through email, which can become annoying at times.

    Which solution did I use previously and why did I switch?

    When I came to this company, OpenVPN Access Server was what they always used, so I did not previously use a different solution.

    I did not evaluate other options before choosing OpenVPN Access Server since that was the choice made by the organization. We have other VPN solutions such as FortiClient, but for specific tasks, we utilize OpenVPN Access Server.

    How was the initial setup?

    Installing and setting up OpenVPN Access Server within our organization is not complicated. I have been familiar with the process for a long time, and we have documented our steps.

    What about the implementation team?

    We have a central control set up for users going to a security group, utilizing the access controls feature of OpenVPN Access Server.

    What other advice do I have?

    I have not used the artificial intelligence capability of OpenVPN Access Server, so I cannot answer questions about it.

    Since I have not used artificial intelligence with OpenVPN Access Server, I cannot comment on the accuracy and reliability of output from any artificial intelligence features.

    I have not used role-defining features within OpenVPN Access Server, so it has not impacted me.

    The connection speed when using OpenVPN Access Server is pretty much the same as other VPN solutions, and I do not see any significant difference.

    I rate OpenVPN Access Server an overall eight out of ten.

    reviewer2882280

    Secure remote access has protected fixed IP workflows but still needs stronger encryption

    Reviewed on Jul 30, 2026
    Review from a verified AWS customer

    What is our primary use case?

    OpenVPN Access Server was primarily used to secure a fixed IP address, as some of my customers needed to access resources remotely. A concrete example is that a client of my client had restricted access so that they would only accept connections from specific IP addresses. When my client delivered work to that end client, they had to go through OpenVPN Access Server; in other words, we used it as a proxy.

    In addition to the cloud, the client's company was using a NAS for internal sharing, so to access the NAS, they needed to go through OpenVPN Access Server.

    What is most valuable?

    One of the best features of OpenVPN Access Server is that its encryption is still more complex than L2TP, though it is weaker than WireGuard.

    Regarding the strength of the encryption, one aspect is certificates; you absolutely need certificates, and on top of that, you also need a username and password, so the encryption strength is higher. However, the standard itself is a bit old now, and it is true that it has quite a few vulnerabilities.

    The impact of OpenVPN Access Server for my company is really for my customers, but they have been able to provide their own customers with a safe remote environment and fixed IP addresses, which was the outcome.

    What needs improvement?

    OpenVPN Access Server could be improved in several areas. The encryption strength is inevitably lower compared with the latest technologies, and when I try to add features like two-factor authentication, the needed plugins and so on often are not really available or do not fit well. For my current customers and for myself, I try to have them use WireGuard instead.

    I think the way forward is to move to WireGuard and to two-factor authentication. With OpenVPN, you use TCP, so attackers tend to target the port, which makes it pretty easy to figure out which port is being used. With WireGuard, which is locked down over UDP, it is harder for attackers to probe ports. For my current customers and my other customers, I am planning to migrate them to WireGuard.

    For how long have I used the solution?

    I have been using OpenVPN Access Server at a customer site, and we operated it for about six years.

    What do I think about the stability of the solution?

    I would rate the stability of OpenVPN Access Server as unstable at first, but as we changed how we operated it, it rarely went down.

    What do I think about the scalability of the solution?

    Scalability was available depending on configuration, and I did test it. However, for this customer, there were not enough users to really make use of that scalability, so we did not actually leverage it.

    How are customer service and support?

    Customer support was basically via email only, but the person I dealt with was very technically knowledgeable. When I asked about SoftEther VPN, they gave very detailed answers.

    Which solution did I use previously and why did I switch?

    In the past, I had both on-premises deployments and public cloud deployments for OpenVPN Access Server.

    How was the initial setup?

    When I deployed SoftEther, it was very easy as I wrote my own script, and running that script was enough to get it up and running.

    What's my experience with pricing, setup cost, and licensing?

    I used the open-source version of SoftEther VPN, so there were essentially no license costs regarding my experience with pricing, implementation costs, and licensing.

    Which other solutions did I evaluate?

    I did consider other options; for example, I looked at Tailscale, but it would have been very costly, so we decided not to adopt it.

    What other advice do I have?

    I give OpenVPN Access Server an overall rating of seven out of ten because it supports certificate-based authentication. I give it that score because it lets you use certificates; if you do not have the certificate, you cannot access it, and that is the reason.

    We are gradually shutting down our OpenVPN servers and switching to WireGuard for deploying OpenVPN Access Server in our organization.

    I used RADIUS for authentication integration, but I stopped using it partway through. I would evaluate the effectiveness of RADIUS authentication as somewhat weak because the connection tends to drop fairly easily. Regarding some elements like usernames, it is not fully encrypted end-to-end, so that is a weakness and a concern, which is why I stopped using RADIUS.

    Configuring ports took a bit of time when I was using both L2TP and OpenVPN. I used the access control features of OpenVPN Access Server, but because the customer's scale was small, we did not set very granular permissions.

    As for SoftEther, I used SoftEther VPN, and it was relatively easy to understand, but I felt it could have had a few more configuration options. The connection speed was a bit slower compared with other VPN solutions because the headers become larger, so the speed inevitably drops somewhat. You also need to configure the MTU, so depending on the location, sometimes connections were easy, and sometimes they would not connect at all. When you tweak those settings, the speed can drop even further.

    I did not purchase OpenVPN Access Server through AWS Marketplace; at that time, I installed the SoftEther application myself.

    They should switch from OpenVPN to WireGuard. There are many areas where this interview could improve.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews