Open-source multi-protocol VPN server preconfigured on Windows Server 2019. Supports SSL VPN, IPsec, L2TP, and SSTP on a single instance for secure remote access.
SoftEther VPN (Software Ethernet) is a powerful, open-source multi-protocol VPN solution originally developed at the University of Tsukuba and released under the Apache License 2.0. With millions of downloads worldwide and an active open-source community. This AMI delivers a preconfigured SoftEther VPN Server on Windows Server 2019, ready to provide secure remote access and site-to-site connectivity for your AWS workloads.
Why Choose SoftEther VPN Over Alternatives
Six protocols on one instance: Handle SSL VPN, OpenVPN, IPsec, L2TP, MS SSTP, L2TPv3, and EtherIP simultaneously - eliminating the need for separate VPN servers for different client types.
Faster: SoftEther's optimized VPN engine delivers 1 Gbps-class throughput with lower CPU and memory overhead.
Zero-client coverage: Windows, macOS, Linux, iOS, and Android devices connect using their built-in VPN clients - no additional software installation required for end users.
Firewall-proof connectivity: VPN over HTTPS (TCP 443), ICMP, and DNS passes through restrictive firewalls, proxies, and NATs that block traditional VPN protocols.
Secure Remote Access for Distributed Teams
Give employees and administrators encrypted access to private AWS resources from any device using either the SoftEther client or built-in OS VPN clients.
Site-to-Site VPN for Hybrid Environments
A mid-market IT team managing 200+ users across three branch offices can connect on-premises networks, remote offices, and AWS VPCs with stable Layer 2 or Layer 3 tunnels - consolidating what previously required multiple VPN appliances into a single EC2 instance.
Cloud Migration and Hybrid Networking
Bridge existing local networks into your VPC so servers appear on the same Ethernet segment during and after migration, reducing cutover complexity.
Bypass Restrictive Networks
Use SSL VPN, VPN over ICMP, or VPN over DNS to reach your servers from hotel, campus, or public networks that block normal VPN protocols.
Key Features
Protocols and Compatibility
SSL VPN (HTTPS) tunneling through NATs and firewalls
Six major VPN protocols supported simultaneously
VPN over ICMP and VPN over DNS for highly restricted networks
IPv4 / IPv6 dual stack
Networking
Ethernet bridging (L2) and IP routing (L3) over VPN
Embedded dynamic DNS and NAT traversal - no static IP required
Built-in virtual DHCP server and SecureNAT
Cascade connections for large multi-site networks
Security and Authentication
AES 256-bit and RSA 4096-bit encryption
RADIUS / LDAP / Active Directory authentication
RSA certificate authentication
Source IP address control lists
Deep-inspect packet logging
Management and Monitoring
SoftEther VPN Server Manager GUI or command-line administration
Syslog transfer for centralized log management
Detailed connection and security logs for auditing
What Is Included
Preconfigured SoftEther VPN Server on Windows Server 2019, ready to launch
Manage locally or remotely with the free SoftEther VPN Server Manager
Quick-start guidance for creating a Virtual Hub, adding users, and enabling SecureNAT or local bridge. Read our getting started guide under vendor resources below.
Highlights
Six VPN protocols on a single EC2 instance - SSL VPN, OpenVPN, IPsec, L2TP, MS SSTP, and L2TPv3 run simultaneously, eliminating the need for multiple VPN servers. SoftEther handles all major protocols at once so Windows, macOS, Linux, iOS, and Android devices connect using their built-in VPN clients without installing additional software.
Passes through any firewall via HTTPS, ICMP, or DNS tunneling - SoftEther transports VPN packets over TCP port 443 (HTTPS), making traffic indistinguishable from normal web browsing to deep-packet inspection firewalls. For networks that block even HTTPS, VPN over ICMP and VPN over DNS provide fallback connectivity.
1 Gbps-class throughput with AES-256 encryption and enterprise authentication - SoftEther's optimized engine delivers high-speed performance with low CPU and memory usage, outperforming other VPN solutions on equivalent instance types. Security includes AES 256-bit and RSA 4096-bit encryption, RADIUS/LDAP/Active Directory authentication, certificate-based access, and deep-inspect packet logging for compliance auditing.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the software running on an Amazon EC2 instance. The price you pay depends only on which EC2 instance type you choose. Each listed dimension maps to one instance type, from small general-purpose options to large compute-, memory-, storage-, and GPU-focused sizes. Larger instances with more CPU, memory, or specialized hardware carry higher hourly rates. You are billed for the hours you run, so costs scale with usage and your chosen instance size. Pick the instance type that matches your VPN server's performance and capacity needs.
Top-of-mind questions for buyers
What does one billing unit represent, and am I charged when the instance is stopped?
Each unit is one hour of the VPN software running on the EC2 instance type you select. You pay only for hours the instance actually runs. Stopped or powered-off instances do not accrue software charges. Note that underlying AWS storage or other resource fees may still apply while stopped.
What drives my cost — the number of VPN connections or the instance type I pick?
Your software cost is driven only by the EC2 instance type you choose, billed per running hour. The number of VPN users, tunnels, or connections does not change the hourly software rate. To handle more traffic or connections, pick a larger instance type, which carries a higher hourly rate.
If I need more throughput for site-to-site VPN, how do I scale, and does cost change automatically?
Scaling means selecting a different EC2 instance type with more CPU, memory, or network capacity. This is a manual choice, not automatic. The software supports high-speed throughput, remote-access, and site-to-site VPN across instance sizes. Your hourly rate changes only when you switch to a different instance type.
cloudinfrastructureservices.co.uk
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Latest Microsoft Windows Patches Installed. Simply run Windows Update to apply latest Windows Server security patches.
Our team assists with deployment, configuration and troubleshooting.
Getting Started
After launching your instance, connect via RDP (TCP 3389) using your key pair credentials. The SoftEther VPN Server is preconfigured and running. Open the SoftEther VPN Server Manager, create a Virtual Hub, add users, and enable SecureNAT or configure a local bridge. Estimated time from launch to first VPN connection is approximately 15 minutes.
Select your instance type based on expected concurrent connections and throughput needs:
t3.small: Suitable for testing and small teams (up to approximately 10-20 concurrent users)
t3.medium / m5.large: Recommended for small-to-mid workloads with moderate concurrent connections
c5.large or higher: Recommended for production deployments requiring higher throughput and larger user counts
Actual performance depends on VPN protocol, encryption overhead, and network conditions. We recommend launching a smaller instance to benchmark your specific workload before scaling.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Supports six VPN protocols simultaneously on a single instance: SSL VPN, OpenVPN, IPsec, L2TP, MS SSTP, and L2TPv3, enabling connectivity from Windows, macOS, Linux, iOS, and Android devices using built-in OS VPN clients.
Firewall Traversal Capabilities
Transports VPN traffic over TCP port 443 (HTTPS), ICMP, and DNS protocols to bypass restrictive firewalls, proxies, and NATs that block traditional VPN protocols.
Encryption and Authentication
Implements AES 256-bit and RSA 4096-bit encryption with support for RADIUS, LDAP, Active Directory, and RSA certificate-based authentication, including source IP address control lists and deep-inspect packet logging.
Network Connectivity Options
Provides Ethernet bridging (Layer 2) and IP routing (Layer 3) over VPN with embedded dynamic DNS, NAT traversal, virtual DHCP server, SecureNAT, and cascade connections for multi-site networks.
Performance and Throughput
Delivers 1 Gbps-class throughput with optimized VPN engine architecture designed for low CPU and memory overhead on equivalent instance types.
Protocol Support
Support for FTP, FTP over SSL/TLS (FTPS), and SFTP protocols for encrypted file transfer connections
User Management
Capability to create multiple users with customizable permission levels and access to specific files and directories
Data Protection
Strong password protection, encrypted connections, and daily configuration backups for data integrity and recovery
File Transfer Capabilities
Support for uploading, downloading, and transferring files between servers and multiple computers with handling of large file sizes
Secure File Transfer Protocol Support
Supports SFTP with full Host Key Authentication and secure FTP over TLS encryption protocols
Authentication Methods
Supports both password and SSH host key authentication with optional multi-factor authentication capability
Access Control and Permissions
Provides granular user permission settings with IP whitelisting and blacklisting capabilities
Attack Prevention and Protection
Includes protection against DoS attacks, password hacking attempts, and ability to ban or kick users
Optional Encryption
Supports optional PGP encryption for enhanced data protection during file transfers
Can't connect drop the connection all the time i used default firewall configuration disabled firewall on my own system and disable ip6 still it drops the connection after a few seconds.