Listing Thumbnail

    OpenVPN Access Server (BYOL) / Self-Hosted VPN & ZTNA

     Info
    Deployed on AWS
    AWS Free Tier
    Access Server is a self-hosted business VPN and ZTNA software solution developed by the creators of the OpenVPN protocol. Deploy on EC2 and get secure access to VPCs and other connected networks. Route traffic by domain name for application-aware access control, and leverage Data Channel Offload (DCO) for kernel-accelerated throughput that keeps pace with demanding AWS workloads. With MFA, granular access controls, SAML single sign-on via AWS IAM Identity Center, and Zero Trust-ready policies, Access Server is trusted by businesses to protect AWS infrastructure and beyond. After installation, get a free 2-connection key or start a trial from https://myaccount.openvpn.com/signup
    4.4

    Overview

    Play video

    If you want to purchase licenses directly from AWS, we recommend our PAYG listing instead: AWS Marketplace: OpenVPN Access Server / Self-Hosted VPN (PAYG) 

    Once you have launched from the AMI, sign up to retrieve your activation key for two free connections, or start a trial for higher capacity. The first time you open the Admin Web UI, a guided setup wizard walks you through initial configuration to get your VPN running quickly. Schedule a demo at Schedule a Demo with the OpenVPN Team 

    Access Server is a self-hosted business VPN and Zero Trust Network Access (ZTNA) software solution, developed and maintained by OpenVPN Inc., the company behind the open-source OpenVPN protocol. It delivers G2's #1-ranked VPN solution for secure, encrypted remote access to your business network and resources, with the controls needed to enforce least-privilege, zero-trust access policies.

    On AWS, Access Server runs in your own environment on Amazon EC2, giving your remote, hybrid, and in-office workforce protected access to VPCs, private subnets, hybrid networks, and on-premises resources without surrendering control of your infrastructure to a third-party service.

    Deployment Model:

    • Self-hosted on Amazon EC2 within your AWS account and VPC, so data and configuration stay under your control.
    • Deployed from a preconfigured AWS Marketplace image in minutes.
    • Managed through an intuitive web-based Admin Web UI, with REST API, and command-line configuration options available for advanced administration.
    • Supports remote-access and site-to-site VPN topologies.

    Typical Use Cases on AWS:

    • Provide secure remote access to applications and data hosted in your Amazon VPC
    • Connect AWS environments with other clouds and on-premise networks.
    • Protect SaaS and internal applications by making them reachable only through the VPN, reducing exposure to the public internet.
    • Enforce zero-trust access policies based on identity, device, and location.
    • Secure connectivity for devices, IoT, and machine-to-machine use cases.

    Key Features:

    Zero-Trust Access Controls

    • Zero Trust Application Broker: Access Server verifies user identity, location, and device ID during connection and assigns, during domain lookup, a synthetic intermediate IP scoped to a single authorized app - the device never gets a route to the entire private network, so lateral movement isn't merely limited; it's structurally impossible.
    • Define identity-based, role-driven access to specific applications, subnets, and private resources.
    • Enforce device verification and location-aware post-authentication checks to reject connections from unauthorized endpoints.
    • Use Access Control Lists to segment network access within your environment.

    Flexible Authentication

    • Supports local authentication and external authentication with PAM, RADIUS, LDAP, and SAML - including SAML single sign-on with AWS IAM Identity Center
    • Includes built-in multi-factor authentication using TOTP.
    • Allows to specify different authentication methods per user or group.
    • Includes built-in X.509 PKI and support for external PKI.

    High-Performance Connectivity

    • Supports OpenVPN Data Channel Offload (DCO) to move encryption and decryption into the OS kernel for improved VPN data-plane performance and reduced processing overhead.
    • Supports multi-threaded operation for demanding, high-throughput AWS workloads.
    • Supports NAT mode for remote-access deployments and routing mode for site-to-site deployments.
    • Supports routing by IP CIDR ranges and domain names for defining access policies for cloud-hosted, SaaS, and internal applications.
    • Supports split-tunnel and full-tunnel configurations.

    Availability and Scale

    • Supports clustering across multiple Access Server nodes to increase capacity and improve availability.
    • Supports DNS-based traffic distribution for directing users to available cluster nodes.

    Broad Client Support

    • OpenVPN Connect client is available for Windows, macOS, ChromeOS, iOS, and Android.
    • Supports all OpenVPN protocol-compatible clients.
    • Includes a Client Web UI for downloading connection profiles and client software.
    • Supports connection profile distribution by URL to streamline user onboarding.

    Highlights

    • Self-hosted control, built by the protocol's creators: Deploy a self-hosted business VPN and ZTNA solution on EC2, developed by OpenVPN Inc., the team behind the open-source OpenVPN protocol. Your policies, configuration, and data stay entirely within your AWS account and VPC.
    • Zero-trust remote access, site-to-site VPN & ZTNA: Move from a trusted-perimeter model to identity-based, least-privilege access to the resources that matter. Give users or groups access to specific private apps by domain name or hostname, without exposing entire networks or subnets. Allow-list approved SaaS, and route internet-bound traffic through a trusted gateway with a fixed egress IP. Enforce ACLs by destination IP, subnet, and domain with identity, device, and location controls.
    • High-performance connectivity with broad client & auth support: Data Channel Offload (DCO) moves encryption into the OS kernel for near wire-speed throughput on demanding AWS workloads, and you can cluster multiple servers for high availability and load distribution as usage grows. OpenVPN client software is available for Windows, macOS, Linux, Android, iOS, and ChromeOS. Authenticate with local credentials and 2FA, plus Active Directory, PAM, LDAP, RADIUS, SAML, or a custom Python3 module.

    Details

    Delivery method

    Delivery option
    Quick deploy with CloudFormation (single instance)
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04.4 LTS

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    OpenVPN Access Server (BYOL) / Self-Hosted VPN & ZTNA

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Refunds allowed up to 60 days after purchase, if license has not been activated.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    For instructions on using the OpenVPN Access Server appliance on the AWS Marketplace, please visit the Quick Start Guide .

    Support

    Vendor support

    Visit the OpenVPN Support Center  for access to technical support resources, troubleshooting guidance, and the option to submit a support ticket.

    For AWS-specific setup and troubleshooting information, review the Access Server on AWS support documentation .

    For answers to common AWS deployment, connectivity, configuration, licensing, and administration questions, review the Access Server on AWS FAQ .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    438 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    68%
    24%
    4%
    2%
    2%
    70 AWS reviews
    |
    368 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2882781

    Secure access to blocked sites has improved my travel safety and protected my online identity

    Reviewed on Aug 03, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for OpenVPN Access Server is to connect to blocked websites for safety. A specific example of how I use OpenVPN Access Server is when I travel to China and I used to open the VPN server for my real address. I was trying to achieve stable access to sites such as Google and YouTube in mainland China, and OpenVPN Access Server helped with that because it is very stable. Additionally, I use OpenVPN Access Server for my real IP address in my country.

    Another main use case for OpenVPN Access Server is that I use it when I am in a public area to connect with Go. It helps me to feel safe.

    What is most valuable?

    The best features OpenVPN Access Server offers include the ability to open the OpenVPN Access Server admin UI, where I can check my data and see how many people are connected to the server.

    I do not usually check the admin UI, but sometimes I can check who is connecting to OpenVPN Access Server and what data they are using.

    OpenVPN Access Server has positively impacted my organization mainly through improved security for myself. It improves my security because when I use Google to search for something, I connect to OpenVPN Access Server for security to hide my IP address.

    What needs improvement?

    I do not really think there is anything that needs improvement for OpenVPN Access Server. Everything is good, and nothing stands out to me that requires enhancement.

    For how long have I used the solution?

    I have been using OpenVPN Access Server for three years.

    What do I think about the stability of the solution?

    OpenVPN Access Server is stable. My impression of the connection speed using OpenVPN Access Server is that, compared to other VPN solutions, OpenVPN Access Server is a little bit slow, but it is very safe and always connects.

    How are customer service and support?

    Customer support for OpenVPN Access Server has not been a factor for me, as I have not needed to contact them.

    Which solution did I use previously and why did I switch?

    I have used other services such as WireGuard and V2Ray; I do not switch, but my main use is OpenVPN Access Server.

    Before choosing OpenVPN Access Server, I evaluated other options such as WireGuard.

    How was the initial setup?

    I think that installing and setting up OpenVPN Access Server within my organization is medium; it is not easy, but it is not difficult either.

    What was our ROI?

    I have seen a return on investment because I save time since it is really easy to deploy, and now my followers use it.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the pricing is a little bit expensive, but it is fine for the value it provides. It would be nice if the pricing were more affordable.

    Which other solutions did I evaluate?

    My advice for others looking into using OpenVPN Access Server is to try using AWS, not Azure, and then it will work fine. AWS is easy to deploy.

    What other advice do I have?

    OpenVPN Access Server is deployed in my organization through a public cloud; I use it at Amazon. I use AWS as my cloud provider, specifically AWS. I purchased OpenVPN Access Server through the AWS Marketplace.

    I do not use local, LDAP, RADIUS, PAM, or SAML authentication integration. I do not utilize the access controls feature of OpenVPN Access Server. I would describe the user interface of OpenVPN Access Server as really nice, and I can show my subscribers how to use OpenVPN Access Server to connect to the internet.

    I would rate this product a 10 out of 10.

    Nigel Spence

    Secure remote access has protected internal resources and supports controlled vendor connectivity

    Reviewed on Jul 31, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for OpenVPN Access Server is to provide secure remote access to our internal resources for our employees, allowing our users to connect from anywhere through an encrypted VPN tunnel while maintaining authentication and access control. I appreciate it because it is easy to deploy, integrates with Active Directory, supports multi-factor authentication, and gives us control over what people can do with it.

    As a network engineer, I use OpenVPN Access Server to connect to the corporate network, where I can manage our internal infrastructure such as our firewalls, switches, and routers instead of exposing those devices to the internet. This is accessible by using the VPN connection.

    What is most valuable?

    The best features OpenVPN Access Server offers include secure connectivity, support for multi-factor authentication, integration with Active Directory and other identity providers, and strong encryption. Administrators can control which users have access to their group, it is easy to deploy, and it can work across platforms such as Mac, Linux, and Android.

    Regarding the integration with Active Directory and other identity providers, the system teams handle the integration, and a simple flow would be OpenVPN, username, VPN access, Active Directory, RADIUS, essentially leading to OpenVPN being established. The system team is what really handled the integration with Active Directory.

    OpenVPN Access Server has positively impacted my organization by supporting remote work and improving security since users must authenticate through the VPN first before accessing services such as RDP and SSH, which reduces our attack surface. It also helps with centralized user management, and sometimes we provide our vendors access to the system they support so they can access a server without accessing the rest of my environment. It is also cost-effective.

    What needs improvement?

    OpenVPN Access Server is pretty solid. However, the biggest improvements I would recommend would be enhancing multi-factor authentication, implementing least privilege access, and perhaps stronger identity integration along with improved monitoring.

    For how long have I used the solution?

    I have been using OpenVPN Access Server for four years.

    What do I think about the stability of the solution?

    OpenVPN Access Server has been stable so far, and I have not had any issues.

    What do I think about the scalability of the solution?

    I rate it an eight because perfection quite frankly does not exist.

    How are customer service and support?

    The customer support for OpenVPN Access Server is acceptable, but it could be better.

    OpenVPN Access Server is a good tool. The downside is that most support is done through email, which can become annoying at times.

    Which solution did I use previously and why did I switch?

    When I came to this company, OpenVPN Access Server was what they always used, so I did not previously use a different solution.

    I did not evaluate other options before choosing OpenVPN Access Server since that was the choice made by the organization. We have other VPN solutions such as FortiClient, but for specific tasks, we utilize OpenVPN Access Server.

    How was the initial setup?

    Installing and setting up OpenVPN Access Server within our organization is not complicated. I have been familiar with the process for a long time, and we have documented our steps.

    What about the implementation team?

    We have a central control set up for users going to a security group, utilizing the access controls feature of OpenVPN Access Server.

    What other advice do I have?

    I have not used the artificial intelligence capability of OpenVPN Access Server, so I cannot answer questions about it.

    Since I have not used artificial intelligence with OpenVPN Access Server, I cannot comment on the accuracy and reliability of output from any artificial intelligence features.

    I have not used role-defining features within OpenVPN Access Server, so it has not impacted me.

    The connection speed when using OpenVPN Access Server is pretty much the same as other VPN solutions, and I do not see any significant difference.

    I rate OpenVPN Access Server an overall eight out of ten.

    reviewer2882280

    Secure remote access has protected fixed IP workflows but still needs stronger encryption

    Reviewed on Jul 30, 2026
    Review from a verified AWS customer

    What is our primary use case?

    OpenVPN Access Server was primarily used to secure a fixed IP address, as some of my customers needed to access resources remotely. A concrete example is that a client of my client had restricted access so that they would only accept connections from specific IP addresses. When my client delivered work to that end client, they had to go through OpenVPN Access Server; in other words, we used it as a proxy.

    In addition to the cloud, the client's company was using a NAS for internal sharing, so to access the NAS, they needed to go through OpenVPN Access Server.

    What is most valuable?

    One of the best features of OpenVPN Access Server is that its encryption is still more complex than L2TP, though it is weaker than WireGuard.

    Regarding the strength of the encryption, one aspect is certificates; you absolutely need certificates, and on top of that, you also need a username and password, so the encryption strength is higher. However, the standard itself is a bit old now, and it is true that it has quite a few vulnerabilities.

    The impact of OpenVPN Access Server for my company is really for my customers, but they have been able to provide their own customers with a safe remote environment and fixed IP addresses, which was the outcome.

    What needs improvement?

    OpenVPN Access Server could be improved in several areas. The encryption strength is inevitably lower compared with the latest technologies, and when I try to add features like two-factor authentication, the needed plugins and so on often are not really available or do not fit well. For my current customers and for myself, I try to have them use WireGuard instead.

    I think the way forward is to move to WireGuard and to two-factor authentication. With OpenVPN, you use TCP, so attackers tend to target the port, which makes it pretty easy to figure out which port is being used. With WireGuard, which is locked down over UDP, it is harder for attackers to probe ports. For my current customers and my other customers, I am planning to migrate them to WireGuard.

    For how long have I used the solution?

    I have been using OpenVPN Access Server at a customer site, and we operated it for about six years.

    What do I think about the stability of the solution?

    I would rate the stability of OpenVPN Access Server as unstable at first, but as we changed how we operated it, it rarely went down.

    What do I think about the scalability of the solution?

    Scalability was available depending on configuration, and I did test it. However, for this customer, there were not enough users to really make use of that scalability, so we did not actually leverage it.

    How are customer service and support?

    Customer support was basically via email only, but the person I dealt with was very technically knowledgeable. When I asked about SoftEther VPN, they gave very detailed answers.

    Which solution did I use previously and why did I switch?

    In the past, I had both on-premises deployments and public cloud deployments for OpenVPN Access Server.

    How was the initial setup?

    When I deployed SoftEther, it was very easy as I wrote my own script, and running that script was enough to get it up and running.

    What's my experience with pricing, setup cost, and licensing?

    I used the open-source version of SoftEther VPN, so there were essentially no license costs regarding my experience with pricing, implementation costs, and licensing.

    Which other solutions did I evaluate?

    I did consider other options; for example, I looked at Tailscale, but it would have been very costly, so we decided not to adopt it.

    What other advice do I have?

    I give OpenVPN Access Server an overall rating of seven out of ten because it supports certificate-based authentication. I give it that score because it lets you use certificates; if you do not have the certificate, you cannot access it, and that is the reason.

    We are gradually shutting down our OpenVPN servers and switching to WireGuard for deploying OpenVPN Access Server in our organization.

    I used RADIUS for authentication integration, but I stopped using it partway through. I would evaluate the effectiveness of RADIUS authentication as somewhat weak because the connection tends to drop fairly easily. Regarding some elements like usernames, it is not fully encrypted end-to-end, so that is a weakness and a concern, which is why I stopped using RADIUS.

    Configuring ports took a bit of time when I was using both L2TP and OpenVPN. I used the access control features of OpenVPN Access Server, but because the customer's scale was small, we did not set very granular permissions.

    As for SoftEther, I used SoftEther VPN, and it was relatively easy to understand, but I felt it could have had a few more configuration options. The connection speed was a bit slower compared with other VPN solutions because the headers become larger, so the speed inevitably drops somewhat. You also need to configure the MTU, so depending on the location, sometimes connections were easy, and sometimes they would not connect at all. When you tweak those settings, the speed can drop even further.

    I did not purchase OpenVPN Access Server through AWS Marketplace; at that time, I installed the SoftEther application myself.

    They should switch from OpenVPN to WireGuard. There are many areas where this interview could improve.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Mertcan Halegy

    Secure remote access to private company resources has protected data but setup still needs simplification

    Reviewed on Jul 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for OpenVPN Access Server is setting up security in a company where some private resources are not accessible, and some remote employees can use it as well.

    A specific example of how I use OpenVPN Access Server for this purpose is that we gave OpenVPN Access Server access to every employee and put a firewall behind our database, which is only accessible by the VPN.

    What is most valuable?

    The best features OpenVPN Access Server offers are ease of setup, and it is just easy. The ease of setup helps my team day-to-day because you set it up once and then you forget about it.

    OpenVPN Access Server has a significant positive impact on my organization for security, as it helps a lot.

    What needs improvement?

    I think OpenVPN Access Server's setup can be just one click; currently, it takes multiple steps, and when you forget the admin password, you are locked in.

    For how long have I used the solution?

    I have been using OpenVPN Access Server for the last five years.

    What do I think about the stability of the solution?

    OpenVPN Access Server is stable, definitely.

    What do I think about the scalability of the solution?

    I don't know how OpenVPN Access Server's scalability is; we only have one instance.

    How are customer service and support?

    We haven't used customer support for OpenVPN Access Server.

    Which solution did I use previously and why did I switch?

    We had another solution, but I cannot share which solution we used before switching to OpenVPN Access Server.

    How was the initial setup?

    It is easy to install and set up OpenVPN Access Server within my organization, but it could be easier. You just need to set up the application itself, then configure it for your needs. After that, you configure the firewall and distribute it to all the team members, and you're done.

    What about the implementation team?

    I am not the one who procured this product, as another team is handling it, so I cannot comment on pricing, setup cost, and licensing.

    What was our ROI?

    I have seen a return on investment, definitely for security, but I cannot share any metrics.

    What's my experience with pricing, setup cost, and licensing?

    I am not the one who procured this product, as another team is handling it, so I cannot comment on pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing OpenVPN Access Server.

    What other advice do I have?

    My advice to others looking into using OpenVPN Access Server is to just try it. If you don't like it, you don't like it.

    I don't know if I am using local, LDAP, RADIUS, PAM, or SAML authentication integration with OpenVPN Access Server.

    I don't know if we have utilized the Access Controls feature of OpenVPN Access Server; another team is handling that.

    I would describe the user interface of OpenVPN Access Server as not modern, but it works. The user experience could be better with all the statistics and everything.

    My impression of the connection speed when using OpenVPN Access Server compared to other VPN solutions is that it is solid compared to others.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Hardik Murdia

    Remote access has become smoother and security has improved, but availability needs work

    Reviewed on Jul 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for OpenVPN Access Server is that we have our VPN solution centered around this, and we use it for connecting to different VPNs, whether they be internal private subnets that we configured for specific environments. For accessing those, we specifically use OpenVPN Access Server for connecting to VPN, then accessing those boxes and other resources, so it basically provides remote access to private networks over the Internet.

    A quick specific example of how my team uses OpenVPN Access Server in a day-to-day scenario is that we have a public IP, which is basically our OpenVPN Access Server, over the Internet. Via that, we connect to the VPN tunnel service through the UI agent they provide, and from there, users connect and have access to different private sub-networks, whether they be databases, servers, or Kubernetes clusters, all of which are behind the VPN. To access those, we connect via OpenVPN Access Server.

    I extensively use OpenVPN Access Server for authentication of our backend services, where how it works is when the token generates, we always validate via the correct VPN route. The encryption engine is also very helpful, and as an SRE, I have set this up, so based on that information, I can say that we have used certain protocols to ensure smooth communication between the client and server. It was easier to set up; it is not that difficult, as we just have to provide proper IPs and addresses and proper permissions to use it.

    I have utilized the access controls feature of OpenVPN Access Server, which effectively allows us to know who is currently connected, a valuable asset for database-related inquiries in our production environments. The user controls significantly aid in maintaining this oversight.

    I have used role-defining features within OpenVPN Access Server, which creates a secure approach to enforcing least privilege effortlessly. Currently, we maintain around four roles: help desk, read-only auditors, administrators, and a VP of Engineering who serves as the super administrator. This setup minimizes the risk of unauthorized access or malpractices, allowing for easy group management whereby adding a new person to a group grants them access to all environments.

    What is most valuable?

    The best features OpenVPN Access Server offers include using a protocol called UDP over TCP, which gives comparatively lower latency and overall faster throughput. Once you are in a network, you will not see many bandwidth issues because it uses UDP for broadcasting or routing our request, making it better for streaming. The SSH access is also easier, requiring fewer configurations. The authentication methods are really good, allowing for local level authentication or LDAP, and we have also configured it with Okta for SSO login, providing a better edge as it allows users to log in without entering usernames and credentials each time.

    OpenVPN Access Server has positively impacted our organization by moving from TLS 1.1 to TLS 1.3, which has significantly improved our security constraints. The performance metrics demonstrate that previously used solutions were not optimal; with OpenVPN Access Server, we experience much less latency, making it easier to deploy, and it works well with firewalls. OpenVPN Access Server supports various authentication methods, reducing the need for manual username and password entry each time users connect, thereby creating less friction for those managing the VPN, resulting in a good impact overall.

    What needs improvement?

    OpenVPN Access Server can be improved by addressing the issue we faced with a single VPN server since it does not allow the creation of replicas without a load balancer, which we found to be an availability issue that could be easily fixed. Additionally, the certificate management—renewal and issuance for new certificates—is currently manual, which creates some friction. While it is not overly complex, it requires a subject matter expert to manage effectively.

    Regarding needed improvements, I think they are doing a good job overall. My main concern relates to user experience; there are common complaints about not being able to manually download a profile to access the VPN. Connections and setups can be a bit confusing on the UI, which some of my team members have reported. Currently, the portal is not self-service; it could benefit from a one-click configuration setup to make deployment and management easier since we are paying for these services.

    For how long have I used the solution?

    I have been using OpenVPN Access Server for almost two years now in Cloud Bold.

    What do I think about the stability of the solution?

    OpenVPN Access Server is stable.

    What do I think about the scalability of the solution?

    OpenVPN Access Server's scalability is good; I have not faced significant issues in that regard.

    Which solution did I use previously and why did I switch?

    We previously used Palo Alto GlobalProtect, primarily for the frustration it caused due to its inability to close properly. I suggested a switch because OpenVPN Access Server provides better visibility and a cleaner interface that does not annoy users the way GlobalProtect did, which constantly notified users when disconnected and lacks a straightforward closure method.

    How was the initial setup?

    The installation and setup of OpenVPN Access Server within my organization is straightforward as we need to open specific ports, namely 443 for TCP and 1194 for UDP. After opening these ports, we install the OpenVPN Access Server package in AWS, set the initial admin password, and usernames. The UI becomes accessible shortly thereafter, enabling us to manage other aspects.

    What was our ROI?

    We have seen a return on investment with OpenVPN Access Server, as the overall cost of management has decreased; one engineer can now handle what previously required more personnel, equating to a 66% reduction in engineering hours. Additionally, infrastructure costs have significantly dropped, thanks to the efficient SSO login process which minimizes user input. The integration with our existing services, such as Okta for MFA, has further enriched user experience while centralizing administration.

    What other advice do I have?

    Regarding the accuracy and reliability of OpenVPN Access Server's output, I have not encountered any major issues aside from a singular incident where availability was compromised due to a deployment issue. The accuracy has consistently been good; we have no trouble connecting to the VPN or accessing servers.

    My impression of the connection speed using OpenVPN Access Server is good; we switched due to previous performance issues with another vendor. OpenVPN Access Server has effectively managed enterprise-level workloads, with minimal resource consumption.

    The advice I would give to others looking into using OpenVPN Access Server is that it is suitable for companies with fewer than 10,000 employees. It works as claimed and the setup is easier, though for very large organizations with extensive user numbers, the scalability might need validation. I would rate this solution a 7 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews