
Overview

Product video
If you want to purchase licenses directly from AWS, we recommend our PAYG listing instead: AWS Marketplace: OpenVPN Access Server / Self-Hosted VPN (PAYG)
Once you have launched from the AMI, sign up to retrieve your activation key for two free connections, or start a trial for higher capacity. The first time you open the Admin Web UI, a guided setup wizard walks you through initial configuration to get your VPN running quickly. Schedule a demo at Schedule a Demo with the OpenVPN Team
Access Server is a self-hosted business VPN and Zero Trust Network Access (ZTNA) software solution, developed and maintained by OpenVPN Inc., the company behind the open-source OpenVPN protocol. It delivers G2's #1-ranked VPN solution for secure, encrypted remote access to your business network and resources, with the controls needed to enforce least-privilege, zero-trust access policies.
On AWS, Access Server runs in your own environment on Amazon EC2, giving your remote, hybrid, and in-office workforce protected access to VPCs, private subnets, hybrid networks, and on-premises resources without surrendering control of your infrastructure to a third-party service.
Deployment Model:
- Self-hosted on Amazon EC2 within your AWS account and VPC, so data and configuration stay under your control.
- Deployed from a preconfigured AWS Marketplace image in minutes.
- Managed through an intuitive web-based Admin Web UI, with REST API, and command-line configuration options available for advanced administration.
- Supports remote-access and site-to-site VPN topologies.
Typical Use Cases on AWS:
- Provide secure remote access to applications and data hosted in your Amazon VPC
- Connect AWS environments with other clouds and on-premise networks.
- Protect SaaS and internal applications by making them reachable only through the VPN, reducing exposure to the public internet.
- Enforce zero-trust access policies based on identity, device, and location.
- Secure connectivity for devices, IoT, and machine-to-machine use cases.
Key Features:
Zero-Trust Access Controls
- Zero Trust Application Broker: Access Server verifies user identity, location, and device ID during connection and assigns, during domain lookup, a synthetic intermediate IP scoped to a single authorized app - the device never gets a route to the entire private network, so lateral movement isn't merely limited; it's structurally impossible.
- Define identity-based, role-driven access to specific applications, subnets, and private resources.
- Enforce device verification and location-aware post-authentication checks to reject connections from unauthorized endpoints.
- Use Access Control Lists to segment network access within your environment.
Flexible Authentication
- Supports local authentication and external authentication with PAM, RADIUS, LDAP, and SAML - including SAML single sign-on with AWS IAM Identity Center
- Includes built-in multi-factor authentication using TOTP.
- Allows to specify different authentication methods per user or group.
- Includes built-in X.509 PKI and support for external PKI.
High-Performance Connectivity
- Supports OpenVPN Data Channel Offload (DCO) to move encryption and decryption into the OS kernel for improved VPN data-plane performance and reduced processing overhead.
- Supports multi-threaded operation for demanding, high-throughput AWS workloads.
- Supports NAT mode for remote-access deployments and routing mode for site-to-site deployments.
- Supports routing by IP CIDR ranges and domain names for defining access policies for cloud-hosted, SaaS, and internal applications.
- Supports split-tunnel and full-tunnel configurations.
Availability and Scale
- Supports clustering across multiple Access Server nodes to increase capacity and improve availability.
- Supports DNS-based traffic distribution for directing users to available cluster nodes.
Broad Client Support
- OpenVPN Connect client is available for Windows, macOS, ChromeOS, iOS, and Android.
- Supports all OpenVPN protocol-compatible clients.
- Includes a Client Web UI for downloading connection profiles and client software.
- Supports connection profile distribution by URL to streamline user onboarding.
Highlights
- Self-hosted control, built by the protocol's creators: Deploy a self-hosted business VPN and ZTNA solution on EC2, developed by OpenVPN Inc., the team behind the open-source OpenVPN protocol. Your policies, configuration, and data stay entirely within your AWS account and VPC.
- Zero-trust remote access, site-to-site VPN & ZTNA: Move from a trusted-perimeter model to identity-based, least-privilege access to the resources that matter. Give users or groups access to specific private apps by domain name or hostname, without exposing entire networks or subnets. Allow-list approved SaaS, and route internet-bound traffic through a trusted gateway with a fixed egress IP. Enforce ACLs by destination IP, subnet, and domain with identity, device, and location controls.
- High-performance connectivity with broad client & auth support: Data Channel Offload (DCO) moves encryption into the OS kernel for near wire-speed throughput on demanding AWS workloads, and you can cluster multiple servers for high availability and load distribution as usage grows. OpenVPN client software is available for Windows, macOS, Linux, Android, iOS, and ChromeOS. Authenticate with local credentials and 2FA, plus Active Directory, PAM, LDAP, RADIUS, SAML, or a custom Python3 module.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Refunds allowed up to 60 days after purchase, if license has not been activated.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
For instructions on using the OpenVPN Access Server appliance on the AWS Marketplace, please visit the Quick Start Guide .
Resources
Vendor resources
Support
Vendor support
Visit the OpenVPN Support Center for access to technical support resources, troubleshooting guidance, and the option to submit a support ticket.
For AWS-specific setup and troubleshooting information, review the Access Server on AWS support documentation .
For answers to common AWS deployment, connectivity, configuration, licensing, and administration questions, review the Access Server on AWS FAQ .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Secure access to blocked sites has improved my travel safety and protected my online identity
What is our primary use case?
My main use case for OpenVPN Access Server is to connect to blocked websites for safety. A specific example of how I use OpenVPN Access Server is when I travel to China and I used to open the VPN server for my real address. I was trying to achieve stable access to sites such as Google and YouTube in mainland China, and OpenVPN Access Server helped with that because it is very stable. Additionally, I use OpenVPN Access Server for my real IP address in my country.
Another main use case for OpenVPN Access Server is that I use it when I am in a public area to connect with Go. It helps me to feel safe.
What is most valuable?
The best features OpenVPN Access Server offers include the ability to open the OpenVPN Access Server admin UI, where I can check my data and see how many people are connected to the server.
I do not usually check the admin UI, but sometimes I can check who is connecting to OpenVPN Access Server and what data they are using.
OpenVPN Access Server has positively impacted my organization mainly through improved security for myself. It improves my security because when I use Google to search for something, I connect to OpenVPN Access Server for security to hide my IP address.
What needs improvement?
I do not really think there is anything that needs improvement for OpenVPN Access Server. Everything is good, and nothing stands out to me that requires enhancement.
For how long have I used the solution?
I have been using OpenVPN Access Server for three years.
What do I think about the stability of the solution?
OpenVPN Access Server is stable. My impression of the connection speed using OpenVPN Access Server is that, compared to other VPN solutions, OpenVPN Access Server is a little bit slow, but it is very safe and always connects.
How are customer service and support?
Customer support for OpenVPN Access Server has not been a factor for me, as I have not needed to contact them.
Which solution did I use previously and why did I switch?
I have used other services such as WireGuard and V2Ray; I do not switch, but my main use is OpenVPN Access Server.
Before choosing OpenVPN Access Server, I evaluated other options such as WireGuard.
How was the initial setup?
I think that installing and setting up OpenVPN Access Server within my organization is medium; it is not easy, but it is not difficult either.
What was our ROI?
I have seen a return on investment because I save time since it is really easy to deploy, and now my followers use it.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that the pricing is a little bit expensive, but it is fine for the value it provides. It would be nice if the pricing were more affordable.
Which other solutions did I evaluate?
My advice for others looking into using OpenVPN Access Server is to try using AWS, not Azure, and then it will work fine. AWS is easy to deploy.
What other advice do I have?
OpenVPN Access Server is deployed in my organization through a public cloud; I use it at Amazon. I use AWS as my cloud provider, specifically AWS. I purchased OpenVPN Access Server through the AWS Marketplace.
I do not use local, LDAP, RADIUS, PAM, or SAML authentication integration. I do not utilize the access controls feature of OpenVPN Access Server. I would describe the user interface of OpenVPN Access Server as really nice, and I can show my subscribers how to use OpenVPN Access Server to connect to the internet.
I would rate this product a 10 out of 10.
Secure remote access has protected internal resources and supports controlled vendor connectivity
What is our primary use case?
My main use case for OpenVPN Access Server is to provide secure remote access to our internal resources for our employees, allowing our users to connect from anywhere through an encrypted VPN tunnel while maintaining authentication and access control. I appreciate it because it is easy to deploy, integrates with Active Directory, supports multi-factor authentication, and gives us control over what people can do with it.
As a network engineer, I use OpenVPN Access Server to connect to the corporate network, where I can manage our internal infrastructure such as our firewalls, switches, and routers instead of exposing those devices to the internet. This is accessible by using the VPN connection.
What is most valuable?
The best features OpenVPN Access Server offers include secure connectivity, support for multi-factor authentication, integration with Active Directory and other identity providers, and strong encryption. Administrators can control which users have access to their group, it is easy to deploy, and it can work across platforms such as Mac, Linux, and Android.
Regarding the integration with Active Directory and other identity providers, the system teams handle the integration, and a simple flow would be OpenVPN, username, VPN access, Active Directory, RADIUS, essentially leading to OpenVPN being established. The system team is what really handled the integration with Active Directory.
OpenVPN Access Server has positively impacted my organization by supporting remote work and improving security since users must authenticate through the VPN first before accessing services such as RDP and SSH, which reduces our attack surface. It also helps with centralized user management, and sometimes we provide our vendors access to the system they support so they can access a server without accessing the rest of my environment. It is also cost-effective.
What needs improvement?
OpenVPN Access Server is pretty solid. However, the biggest improvements I would recommend would be enhancing multi-factor authentication, implementing least privilege access, and perhaps stronger identity integration along with improved monitoring.
For how long have I used the solution?
I have been using OpenVPN Access Server for four years.
What do I think about the stability of the solution?
OpenVPN Access Server has been stable so far, and I have not had any issues.
What do I think about the scalability of the solution?
I rate it an eight because perfection quite frankly does not exist.
How are customer service and support?
The customer support for OpenVPN Access Server is acceptable, but it could be better.
OpenVPN Access Server is a good tool. The downside is that most support is done through email, which can become annoying at times.
Which solution did I use previously and why did I switch?
When I came to this company, OpenVPN Access Server was what they always used, so I did not previously use a different solution.
I did not evaluate other options before choosing OpenVPN Access Server since that was the choice made by the organization. We have other VPN solutions such as FortiClient, but for specific tasks, we utilize OpenVPN Access Server.
How was the initial setup?
Installing and setting up OpenVPN Access Server within our organization is not complicated. I have been familiar with the process for a long time, and we have documented our steps.
What about the implementation team?
We have a central control set up for users going to a security group, utilizing the access controls feature of OpenVPN Access Server.
What other advice do I have?
I have not used the artificial intelligence capability of OpenVPN Access Server, so I cannot answer questions about it.
Since I have not used artificial intelligence with OpenVPN Access Server, I cannot comment on the accuracy and reliability of output from any artificial intelligence features.
I have not used role-defining features within OpenVPN Access Server, so it has not impacted me.
The connection speed when using OpenVPN Access Server is pretty much the same as other VPN solutions, and I do not see any significant difference.
I rate OpenVPN Access Server an overall eight out of ten.
Secure remote access has protected fixed IP workflows but still needs stronger encryption
What is our primary use case?
OpenVPN Access Server was primarily used to secure a fixed IP address, as some of my customers needed to access resources remotely. A concrete example is that a client of my client had restricted access so that they would only accept connections from specific IP addresses. When my client delivered work to that end client, they had to go through OpenVPN Access Server; in other words, we used it as a proxy.
In addition to the cloud, the client's company was using a NAS for internal sharing, so to access the NAS, they needed to go through OpenVPN Access Server.
What is most valuable?
One of the best features of OpenVPN Access Server is that its encryption is still more complex than L2TP, though it is weaker than WireGuard.
Regarding the strength of the encryption, one aspect is certificates; you absolutely need certificates, and on top of that, you also need a username and password, so the encryption strength is higher. However, the standard itself is a bit old now, and it is true that it has quite a few vulnerabilities.
The impact of OpenVPN Access Server for my company is really for my customers, but they have been able to provide their own customers with a safe remote environment and fixed IP addresses, which was the outcome.
What needs improvement?
OpenVPN Access Server could be improved in several areas. The encryption strength is inevitably lower compared with the latest technologies, and when I try to add features like two-factor authentication, the needed plugins and so on often are not really available or do not fit well. For my current customers and for myself, I try to have them use WireGuard instead.
I think the way forward is to move to WireGuard and to two-factor authentication. With OpenVPN, you use TCP, so attackers tend to target the port, which makes it pretty easy to figure out which port is being used. With WireGuard, which is locked down over UDP, it is harder for attackers to probe ports. For my current customers and my other customers, I am planning to migrate them to WireGuard.
For how long have I used the solution?
I have been using OpenVPN Access Server at a customer site, and we operated it for about six years.
What do I think about the stability of the solution?
I would rate the stability of OpenVPN Access Server as unstable at first, but as we changed how we operated it, it rarely went down.
What do I think about the scalability of the solution?
Scalability was available depending on configuration, and I did test it. However, for this customer, there were not enough users to really make use of that scalability, so we did not actually leverage it.
How are customer service and support?
Customer support was basically via email only, but the person I dealt with was very technically knowledgeable. When I asked about SoftEther VPN, they gave very detailed answers.
Which solution did I use previously and why did I switch?
In the past, I had both on-premises deployments and public cloud deployments for OpenVPN Access Server.
How was the initial setup?
When I deployed SoftEther, it was very easy as I wrote my own script, and running that script was enough to get it up and running.
What's my experience with pricing, setup cost, and licensing?
I used the open-source version of SoftEther VPN, so there were essentially no license costs regarding my experience with pricing, implementation costs, and licensing.
Which other solutions did I evaluate?
I did consider other options; for example, I looked at Tailscale, but it would have been very costly, so we decided not to adopt it.
What other advice do I have?
I give OpenVPN Access Server an overall rating of seven out of ten because it supports certificate-based authentication. I give it that score because it lets you use certificates; if you do not have the certificate, you cannot access it, and that is the reason.
We are gradually shutting down our OpenVPN servers and switching to WireGuard for deploying OpenVPN Access Server in our organization.
I used RADIUS for authentication integration, but I stopped using it partway through. I would evaluate the effectiveness of RADIUS authentication as somewhat weak because the connection tends to drop fairly easily. Regarding some elements like usernames, it is not fully encrypted end-to-end, so that is a weakness and a concern, which is why I stopped using RADIUS.
Configuring ports took a bit of time when I was using both L2TP and OpenVPN. I used the access control features of OpenVPN Access Server, but because the customer's scale was small, we did not set very granular permissions.
As for SoftEther, I used SoftEther VPN, and it was relatively easy to understand, but I felt it could have had a few more configuration options. The connection speed was a bit slower compared with other VPN solutions because the headers become larger, so the speed inevitably drops somewhat. You also need to configure the MTU, so depending on the location, sometimes connections were easy, and sometimes they would not connect at all. When you tweak those settings, the speed can drop even further.
I did not purchase OpenVPN Access Server through AWS Marketplace; at that time, I installed the SoftEther application myself.
They should switch from OpenVPN to WireGuard. There are many areas where this interview could improve.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Secure remote access to private company resources has protected data but setup still needs simplification
What is our primary use case?
My main use case for OpenVPN Access Server is setting up security in a company where some private resources are not accessible, and some remote employees can use it as well.
A specific example of how I use OpenVPN Access Server for this purpose is that we gave OpenVPN Access Server access to every employee and put a firewall behind our database, which is only accessible by the VPN.
What is most valuable?
The best features OpenVPN Access Server offers are ease of setup, and it is just easy. The ease of setup helps my team day-to-day because you set it up once and then you forget about it.
OpenVPN Access Server has a significant positive impact on my organization for security, as it helps a lot.
What needs improvement?
I think OpenVPN Access Server's setup can be just one click; currently, it takes multiple steps, and when you forget the admin password, you are locked in.
For how long have I used the solution?
I have been using OpenVPN Access Server for the last five years.
What do I think about the stability of the solution?
OpenVPN Access Server is stable, definitely.
What do I think about the scalability of the solution?
I don't know how OpenVPN Access Server's scalability is; we only have one instance.
How are customer service and support?
We haven't used customer support for OpenVPN Access Server.
Which solution did I use previously and why did I switch?
We had another solution, but I cannot share which solution we used before switching to OpenVPN Access Server.
How was the initial setup?
It is easy to install and set up OpenVPN Access Server within my organization, but it could be easier. You just need to set up the application itself, then configure it for your needs. After that, you configure the firewall and distribute it to all the team members, and you're done.
What about the implementation team?
I am not the one who procured this product, as another team is handling it, so I cannot comment on pricing, setup cost, and licensing.
What was our ROI?
I have seen a return on investment, definitely for security, but I cannot share any metrics.
What's my experience with pricing, setup cost, and licensing?
I am not the one who procured this product, as another team is handling it, so I cannot comment on pricing, setup cost, and licensing.
Which other solutions did I evaluate?
I did not evaluate other options before choosing OpenVPN Access Server.
What other advice do I have?
My advice to others looking into using OpenVPN Access Server is to just try it. If you don't like it, you don't like it.
I don't know if I am using local, LDAP, RADIUS, PAM, or SAML authentication integration with OpenVPN Access Server.
I don't know if we have utilized the Access Controls feature of OpenVPN Access Server; another team is handling that.
I would describe the user interface of OpenVPN Access Server as not modern, but it works. The user experience could be better with all the statistics and everything.
My impression of the connection speed when using OpenVPN Access Server compared to other VPN solutions is that it is solid compared to others.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Remote access has become smoother and security has improved, but availability needs work
What is our primary use case?
My main use case for OpenVPN Access Server is that we have our VPN solution centered around this, and we use it for connecting to different VPNs, whether they be internal private subnets that we configured for specific environments. For accessing those, we specifically use OpenVPN Access Server for connecting to VPN, then accessing those boxes and other resources, so it basically provides remote access to private networks over the Internet.
A quick specific example of how my team uses OpenVPN Access Server in a day-to-day scenario is that we have a public IP, which is basically our OpenVPN Access Server, over the Internet. Via that, we connect to the VPN tunnel service through the UI agent they provide, and from there, users connect and have access to different private sub-networks, whether they be databases, servers, or Kubernetes clusters, all of which are behind the VPN. To access those, we connect via OpenVPN Access Server.
I extensively use OpenVPN Access Server for authentication of our backend services, where how it works is when the token generates, we always validate via the correct VPN route. The encryption engine is also very helpful, and as an SRE, I have set this up, so based on that information, I can say that we have used certain protocols to ensure smooth communication between the client and server. It was easier to set up; it is not that difficult, as we just have to provide proper IPs and addresses and proper permissions to use it.
I have utilized the access controls feature of OpenVPN Access Server, which effectively allows us to know who is currently connected, a valuable asset for database-related inquiries in our production environments. The user controls significantly aid in maintaining this oversight.
I have used role-defining features within OpenVPN Access Server, which creates a secure approach to enforcing least privilege effortlessly. Currently, we maintain around four roles: help desk, read-only auditors, administrators, and a VP of Engineering who serves as the super administrator. This setup minimizes the risk of unauthorized access or malpractices, allowing for easy group management whereby adding a new person to a group grants them access to all environments.
What is most valuable?
The best features OpenVPN Access Server offers include using a protocol called UDP over TCP, which gives comparatively lower latency and overall faster throughput. Once you are in a network, you will not see many bandwidth issues because it uses UDP for broadcasting or routing our request, making it better for streaming. The SSH access is also easier, requiring fewer configurations. The authentication methods are really good, allowing for local level authentication or LDAP, and we have also configured it with Okta for SSO login, providing a better edge as it allows users to log in without entering usernames and credentials each time.
OpenVPN Access Server has positively impacted our organization by moving from TLS 1.1 to TLS 1.3, which has significantly improved our security constraints. The performance metrics demonstrate that previously used solutions were not optimal; with OpenVPN Access Server, we experience much less latency, making it easier to deploy, and it works well with firewalls. OpenVPN Access Server supports various authentication methods, reducing the need for manual username and password entry each time users connect, thereby creating less friction for those managing the VPN, resulting in a good impact overall.
What needs improvement?
OpenVPN Access Server can be improved by addressing the issue we faced with a single VPN server since it does not allow the creation of replicas without a load balancer, which we found to be an availability issue that could be easily fixed. Additionally, the certificate management—renewal and issuance for new certificates—is currently manual, which creates some friction. While it is not overly complex, it requires a subject matter expert to manage effectively.
Regarding needed improvements, I think they are doing a good job overall. My main concern relates to user experience; there are common complaints about not being able to manually download a profile to access the VPN. Connections and setups can be a bit confusing on the UI, which some of my team members have reported. Currently, the portal is not self-service; it could benefit from a one-click configuration setup to make deployment and management easier since we are paying for these services.
For how long have I used the solution?
I have been using OpenVPN Access Server for almost two years now in Cloud Bold.
What do I think about the stability of the solution?
OpenVPN Access Server is stable.
What do I think about the scalability of the solution?
OpenVPN Access Server's scalability is good; I have not faced significant issues in that regard.
Which solution did I use previously and why did I switch?
We previously used Palo Alto GlobalProtect, primarily for the frustration it caused due to its inability to close properly. I suggested a switch because OpenVPN Access Server provides better visibility and a cleaner interface that does not annoy users the way GlobalProtect did, which constantly notified users when disconnected and lacks a straightforward closure method.
How was the initial setup?
The installation and setup of OpenVPN Access Server within my organization is straightforward as we need to open specific ports, namely 443 for TCP and 1194 for UDP. After opening these ports, we install the OpenVPN Access Server package in AWS, set the initial admin password, and usernames. The UI becomes accessible shortly thereafter, enabling us to manage other aspects.
What was our ROI?
We have seen a return on investment with OpenVPN Access Server, as the overall cost of management has decreased; one engineer can now handle what previously required more personnel, equating to a 66% reduction in engineering hours. Additionally, infrastructure costs have significantly dropped, thanks to the efficient SSO login process which minimizes user input. The integration with our existing services, such as Okta for MFA, has further enriched user experience while centralizing administration.
What other advice do I have?
Regarding the accuracy and reliability of OpenVPN Access Server's output, I have not encountered any major issues aside from a singular incident where availability was compromised due to a deployment issue. The accuracy has consistently been good; we have no trouble connecting to the VPN or accessing servers.
My impression of the connection speed using OpenVPN Access Server is good; we switched due to previous performance issues with another vendor. OpenVPN Access Server has effectively managed enterprise-level workloads, with minimal resource consumption.
The advice I would give to others looking into using OpenVPN Access Server is that it is suitable for companies with fewer than 10,000 employees. It works as claimed and the setup is easier, though for very large organizations with extensive user numbers, the scalability might need validation. I would rate this solution a 7 out of 10.