-
1
OpenVPN Access Server
OpenVPN
Full control of your network. ZTNA, self-hosted, without giving up the keys.
OpenVPN Access Server is a self-hosted Zero Trust Network Access (ZTNA) solution that runs inside your own environment — on-prem or your AWS, Azure, or GCP account — keeping tunnel traffic and configuration off any third-party network. Access is scoped to the application, not the IP or subnet: each user is routed only to the specific app they're authorized for, identified by domain name, with nothing else on the network visible to them. That makes lateral movement structurally impossible, not just restricted by policy. Access Server Link turns setup into a guided flow (hostname, cloud, region, password), with SSL certificates provisioned and renewed automatically, eliminating manual certificate handling as a source of risk. Because entitlements are bound to hostname rather than IP, they hold up through IP changes and autoscaling with no manual rework. Your instance remains entirely under your control, giving you the data ownership and audit trail needed for HIPAA, SOC 2, and GDPR — full control of the stack, delivered with SaaS-level ease. Administration happens through a browser-based portal instead of SSH: users, certificates, and access rules are managed without shell access, narrowing your attack surface. The Zero Trust App Broker routes each connection through a placeholder IP tied to a single authorized app — the real destination stays hidden, so a stolen credential offers no way to scan or reach other systems. Least privilege is built into the architecture, not left to policy that can drift. Native clients cover Windows, macOS, iOS, Android, and Linux, keeping identity- and app-based controls consistent across every endpoint. Templated deployment on AWS, Azure, and GCP means security teams get standardized, auditable rollouts rather than one-off manual builds.
-
2
AWS Site-to-Site VPN is an all-encompassing service that establishes secure connections between your on-premises networks and AWS resources through the use of IPsec tunnels. Each VPN connection includes a pair of tunnels that conclude in different availability zones, which boosts the overall availability of your Virtual Private Cloud (VPC) infrastructure. Should one tunnel experience a failure, the system automatically transitions to the backup tunnel, maintaining consistent access without interruption. For globally distributed applications, the advanced Site-to-Site VPN feature enhances performance by working alongside AWS Global Accelerator, which smartly routes your traffic to the nearest AWS network endpoint for maximum efficiency. Furthermore, AWS Site-to-Site VPN supports both static and dynamic routing options, such as BGP peering, providing added flexibility for your routing configuration. It also enables NAT traversal, which permits the use of private IP addresses within private networks that rely on routers with a single public IP address. This adaptability positions AWS Site-to-Site VPN as a powerful solution capable of meeting a wide range of network configurations and requirements, making it suitable for various business needs. Additionally, its robust security protocols ensure that data remains protected during transmission, reinforcing its value as a reliable choice for organizations looking to connect their infrastructures securely.
-
3
AWS VPN
Amazon
Secure, resilient VPN connections for seamless cloud integration.
AWS VPN provides secure connections between on-premises networks and AWS Virtual Private Clouds (VPCs) through the use of IPsec VPN tunnels, which guarantees a strong and reliable link. To bolster availability, each VPN connection features dual tunnels that terminate in separate availability zones, enhancing overall resilience. This service supports both static and dynamic routing via BGP, while allowing for customizable tunnel configurations, including settings for inside tunnel IP addresses, pre-shared keys, and BGP Autonomous System Numbers (ASNs). The Accelerated Site-to-Site VPN option takes advantage of AWS Global Accelerator, improving traffic routing by directing it through the nearest AWS edge location, thereby reducing latency and jitter to enhance user experience. Furthermore, AWS Client VPN acts as a fully managed and elastic VPN service, allowing users to securely access AWS and on-premises resources from any location using an OpenVPN-based client. It accommodates a range of authentication methods, such as Active Directory, mutual certificate authentication, and SAML-based federated authentication, which ensures both flexibility and security for users. Ultimately, these various VPN solutions offered by AWS address a wide array of connectivity needs, all while placing a strong emphasis on security and performance for optimal operational efficiency. Additionally, the comprehensive nature of these services allows organizations to tailor their VPN setups to meet specific requirements, further enhancing their cloud infrastructure.