VyOS Networks is the global leader in open-source networking for organizations that need secure, scalable, automated networking across bare metal, cloud, and edge.
Designed with flexibility and scalability in mind, VyOS provides an enterprise-grade networking platform for consistent operations and automation at scale, delivering full control and high performance with zero vendor lock-in.
Our mission is to restore ownership of network infrastructure to our users through transparent, vendor-neutral networking. Your network, your rules.
VyOS on AWS is a versatile router and firewall solution, offering advanced networking features like VPN, NAT, and traffic management. It enhances security, improves connectivity, and ensures scalable network infrastructure within AWS environments. Ideal for optimizing cloud-based networks.
Experience the unparalleled functionality of the VyOS Universal Router.
An open-source network operating system underpinned by the robust Debian GNU/Linux.
Crafted with the modern IT landscape in mind, VyOS Universal Router delivers a command line interface similar to traditional hardware routers but without complex licensing or artificial limitations.
Its API-driven architecture and fully open-source code make it a game-changer in the industry.
VyOS Universal Router thrives on bare metal and all major hypervisors and cloud platforms.
Scales seamlessly from small devices to multi-core/nic instances
With this flexibility, you can harmonize your on-premises and cloud networks, eliminating the need for costly, proprietary VPN solutions.
Deploy VyOS Universal Router to create cost-effective, robust remote access VPNs for your off-site personnel or site-to-site VPNs
Equipped with an exhaustive suite of features, VyOS Universal Router goes beyond what's expected from a router.
From sophisticated routing protocols like BGP, OSPF, and RIP to advanced VPN and tunneling protocols, including IPsec, VTI, L2TP, OpenVPN, Wireguard, GRE, IPIP, SIT, VXLAN, L2TPv3, GENEVE, we have you covered.
Enjoy enhanced security with an interface and zone-based firewalls, NAT, and high availability features such as VRRP and connection table synchronization.
VyOS Universal Router also offers QoS, NetFlow, sFlow traffic accounting, and Telegraf for enhanced telemetry.
VyOS Universal Router simplifies network management like never before.
Benefit from image-based upgrades that allow you to revert to previous versions with ease
Stateful Command Line Interface (CLI) with commit and rollback capabilities, as well as built-in config versioning and archiving.
Automation is the cornerstone of modern IT management, and VyOS Universal Router doesn't fall short.
With built-in SaltStack integration and an official Ansible module, and Terraform support, automate your configuration workflow effortlessly. VyOS Universal Router provides an HTTP API for those bespoke automation solutions, offering endless possibilities for network configuration and management.
Experience the future of multi-cloud networking with VyOS Universal Router, where power, flexibility, and reliability come together for an unmatched networking solution.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
VyOS Universal Router for AWS (Standard Support) - Pay-as-You-Go
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the EC2 instance type you run. Each dimension maps to a specific AWS instance size, so there are no separate feature tiers or plans. All instances include the same router, firewall, and VPN software with Standard Support. Pricing scales with the compute capacity you choose: smaller shared instances like t3a.small cost less per hour, while larger compute-optimized and memory-optimized types, including bare metal, cost more. You add or remove capacity by launching or stopping instances, and billing follows actual usage.
Top-of-mind questions for buyers
What does one hourly charge cover, and what does the instance type in each dimension mean for me?
Each dimension is one AWS EC2 instance type running the router software. You pay per hour for each running instance. The instance type sets the compute, memory, and network capacity. Larger types handle more throughput and connections, so pick a size based on the bandwidth and traffic you expect.
Am I charged when an instance is stopped, for example a standby or DR node?
Software charges apply per running instance-hour. A stopped instance does not accrue software fees. You may still pay underlying AWS charges, such as storage for the instance volume, but the router software meters only the hours the instance actually runs.
How do I scale capacity, and does moving to a larger instance require reinstalling?
You scale by launching more instances or choosing a larger instance type. Hourly billing follows the instances you run. You can upgrade to a newer version and migrate the configuration to a fresh instance, so you avoid reconfiguring from scratch when you change sizes.
vyos.io
Helpful?
Vendor refund policy
There are no refunds but you have one month trial to decide if product fits your needs
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
VyOS 1.5.1 is a maintenance release in the VyOS 1.5 LTS series. It contains security fixes, new features, and a large number of bug fixes.
By default, the VyOS Universal Router includes Standard support, providing significant benefits for users:
Email Support with 10 annual tickets included, offering direct access to expert help.
Next-business-day SLA for Severity 1 / 2 incidents, ensuring rapid response to critical issues.
Access to system update images.
To activate these support benefits, customers need to contact support@vyos.io after deploying their first instance.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Supports BGP, OSPFv2/v3, and RIP with policy-based routing capabilities
VPN and Tunneling Protocols
Implements IPsec, VTI, L2TP, OpenVPN, WireGuard, GRE, IPIP, SIT, VXLAN, L2TPv3, and GENEVE
Firewall and Network Address Translation
Provides stateful firewall, zone-based firewall, and NAT functionality
High Availability and Traffic Management
Includes VRRP, connection table synchronization, QoS, NetFlow, and sFlow traffic accounting
Infrastructure Automation and Management
Offers SaltStack integration, Ansible module support, Terraform compatibility, HTTP API, CLI with commit/rollback, and config versioning
Next Generation Firewall Architecture
High-performance firewall solution with core firewall, VPN, NAT, and advanced L4-L7 security services including application security, IPS, and anti-virus capabilities.
Anti-Virus and Malware Protection
Cloud-based anti-virus protection that detects and blocks spyware, adware, viruses, keyloggers, and other malware over POP3, HTTP, SMTP, and FTP protocols.
Intrusion Detection and Prevention
Intrusion detection and prevention (IPS) system integrated with application visibility and control through AppSecure for threat detection and workload protection.
VPN and Secure Connectivity
IPsec and full mesh VPN termination services enabling secure connectivity from on-premises data centers, campuses, and branches to AWS cloud across geographically dispersed VPCs.
AWS Cloud Service Integration
Native integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, Elastic Network Adapter support, and Gateway Load Balancer with L3 gateway and L4 load balancer capabilities.
VPN Protocol Support
Supports IPsec, OpenVPN, and WireGuard VPN protocols for secure site-to-site and remote access connectivity
Encryption and Key Management
Encrypts all data in motion across cloud deployments with support for multiple encryption algorithms and cryptographic key control
Advanced Routing Capabilities
Provides BGP active-active connections, NAT gateway functionality, transit gateway capabilities, and preferred peer list configuration
Plugin Architecture for Network Services
Extensible plugin platform supporting integration of third-party network services including Suricata, Snort, Zeek, HAproxy, NGINX, Varnish, and Squid
Multi-Cloud Network Deployment
Enables overlay network spanning virtual networks, regions, and multiple cloud providers with address overlap handling and cross-cloud connectivity
Container automation has enabled complex routing and onboard services for mobile networks
Reviewed on Aug 10, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for VyOS Universal Router is that it is a very adaptive network-based platform that allows for complex, intricate routing-based requirements on many different platforms.
I have used VyOS Universal Router on trains within the UK as a POC for the Starlink LEO-based backhaul capability. I used VyOS specifically because of its extensive capability in running containers on the platform to the level of and capacity that other platforms cannot achieve.
What is most valuable?
The best features VyOS Universal Router offers are the ability to run containers and automation.
The container and automation features within VyOS Universal Router have allowed me to run an extensive number of disparate containers that perform different functions, anything from running a MySQL database server on the platform within a container, or an Influx database as a container, or even a GPS proxy-based container that can receive a GPS signal from a platform router and proxy that out to a number of internal systems.
VyOS Universal Router has positively affected me because it is both open source, actively developed, and a leading platform in routing, firewalling, and even switching if I want it to be. The addition of the container and security capabilities and the automation capabilities make it my first choice for a platform or solution development over and above commercial alternatives.
What needs improvement?
A web UI would be useful for VyOS Universal Router, but that is something that the community has been asking for for some time, yet has not been developed actively. There are alternative add-on platforms that allow some level of web UI-based capability, but there is nothing baked into the platform itself from install.
For how long have I used the solution?
I have been using VyOS Universal Router for around nine years.
What do I think about the stability of the solution?
VyOS Universal Router is very stable.
What do I think about the scalability of the solution?
VyOS Universal Router is extremely capable of being scaled to a very high degree given it's bare-metal, and virtualisation support.
How are customer service and support?
I have not needed to engage with customer support as of this time because the platform simply works as I required.
Which solution did I use previously and why did I switch?
I previously used a commercial-based platform, but I am unable to provide the platform's vendor name or the solution for security purposes.
How was the initial setup?
My experience with pricing, setup cost, and licensing has been extremely favorable.
What was our ROI?
VyOS Universal Router has saved extensive amounts of time because it is easy to deploy and quick to deploy and manage.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been extremely favorable.
Which other solutions did I evaluate?
I evaluated open source Linux-based platforms such as Ubuntu and Debian before choosing VyOS Universal Router because it is based on Debian, which is a trusted network operating system, and had the necessary features and capabilities baked into it already, so I did not need to build out my own.
What other advice do I have?
My advice to others looking into using VyOS Universal Router is to not be afraid to ask questions on the community forums.
My company does not have a business relationship with VyOS Universal Router currently other than being a customer. I would rate the VyOS platform as an 9.
Utkarsh s.
High-Performance Networking Lab for BGP/OSPF and VLAN Security Policies
Reviewed on Apr 29, 2026
Review provided by G2
What do you like best about the product?
I mean being a network engineer I have worked in Cisco ios , fortuner , csa firewall. I mean any network engineer can use bgp, ospf and clan to train himself . Even though I use eve-ng it also works perfectly there with high performance and no lag . I also love how I can manage security policies between vlans
What do you dislike about the product?
Without graphical user interface, the new network engineer can't learn easily . When I use complex routing policies it can't help there ..even the stable LTS is also not too stable and accessible
What problems is the product solving and how is that benefiting you?
See the enterprise labs are too costly and it hits mark there . It allows me to run full package enterprise router in EveNG and GNS 3. I mean I don't need physical components from my lab to study ospf and bgp
mohamed e.
Rock-Solid with VyOS
Reviewed on Apr 23, 2026
Review provided by G2
What do you like best about the product?
What I like most about VyOS is its incredible stability and the CLI-driven approach which feels very familiar to anyone used to enterprise-grade routers. Being open-source, it provides immense flexibility for customization without the heavy licensing costs of proprietary hardware. It's my go-to for building robust virtual routers
What do you dislike about the product?
The learning curve can be a bit steep for those who are used to graphical user interfaces (GUIs), as VyOS relies almost entirely on the CLI. Additionally, while the documentation is improving, it can sometimes be a bit fragmented when searching for very specific or advanced configurations
What problems is the product solving and how is that benefiting you?
VyOS solves the issue of high licensing costs and hardware vendor lock-in. By providing an open-source yet enterprise-grade routing platform, it allows us to deploy powerful network gateways on generic hardware or cloud environments. This has significantly reduced our capital expenditure while maintaining high performance.
Maushardt E.
Flexible, Cost-Effective Networking Solution
Reviewed on Jan 29, 2026
Review provided by G2
What do you like best about the product?
I love VyOS for its enterprise-grade feature parity with proprietary tools and its unmatched flexibility. The config-as-code native design and small but impactful quality-of-life features really streamline network management for me. The platform isn't just a 'free open-source router/firewall'; it stands out with these strong capabilities. Also, the initial setup is surprisingly straightforward for basic use cases, making it easy to get started.
What do you dislike about the product?
The documentation for VyOS is incomplete and disorganized. While the official docs cover the basic features well, they have gaps when it comes to advanced use cases like multi-WAN BGP load balancing or WireGuard site-to-site with VLANs. To set up advanced configurations, I often have to piece together information from various sources like forum posts or community blogs, since there's no single, curated 'enterprise playbook' like what you find with Cisco or Palo Alto.
What problems is the product solving and how is that benefiting you?
VyOS eliminates exorbitant proprietary network licensing/hardware costs and breaks vendor lock-in for network infrastructure.
Savaş Furkan A.
Powerful and Flexible, But Lacks Polished Support and GUI
Reviewed on Dec 12, 2025
Review provided by G2
What do you like best about the product?
VyOS gives you a proper network OS without vendor drama. Solid routing (FRR under the hood), a clean declarative config system, easy automation, runs anywhere like bare metal, VM, cloud, containers. For labs, PoCs, branch routers, tunnels, it feels powerful and lightweight at the same time.
What do you dislike about the product?
It’s still a community-driven distro, so support isn’t like calling TAC at 3 a.m. Some features lag behind big vendors, and upgrades sometimes feel a bit “Linux-y” rather than appliance-smooth. GUI basically doesn’t exist; you live in CLI and API.
What problems is the product solving and how is that benefiting you?
It gives you quick BGP/OSPF/MPLS labs, cheap branch routing, clean IPSec/OpenVPN/WireGuard setups, and automation-friendly configs that fit straight into GitOps or CI/CD.