Zero Trust Application Broker for Per-Application Access

Access Server brokers access to individual applications by domain name, verifying identity and context before connecting a user to a single authorized app. The client never receives a route to your private network, so lateral movement isn't blocked by a firewall rule, it's structurally impossible.

Requires Access Server 3.1.0 or newer.

One login shouldn't unlock your whole network

Standard remote access works at the network level –– a user authenticates, lands on a subnet, and firewall rules downstream decide what they can reach. Giving someone the one internal tool they need often means handing over a route to everything sitting next to it, so a single set of stolen credentials reaches far beyond the app it was meant for.

Access Server closes that gap with Zero Trust, verifying every user before brokering their connection to authorized applications by name, so they reach the tools they're cleared for and there's no path left to anything else around them.

Enforce Zero Trust Network Access (ZTNA) with Access Server.

Rather than granting network access and then restricting it with Access Control, Access Server operates as a Zero Trust Application Broker, brokering traffic to specific authorized applications via stand-in IPs, without exposing the network itself.

Increase reliability

Verify first, connect second

Access Server checks identity through SAML, LDAP, or RADIUS with MFA before brokering anything, and can add device and location checks on top.

Folder with Lock Icon

Keep applications hidden from discovery

Access Server hands back a stand-in address, so clients never learn of your private network subnets or have a route to them.

Icon User Group

Enforce least privilege per user and per group

Scope applications globally, by group, or by user, so each user reaches only authorized applications.

Use an industry standard

Prove enforcement instead of asserting it

DNS proxy logs show every query forwarded, mapped, or denied in real time, and NAT tables show the translation behind each rule, so you can demonstrate least privilege instead of asserting it.

Universal compatibility

Write policies that survive IP changes

Rules evaluate against hostnames, so your access policies hold when IPs churn behind CDNs and load balancers, leaving no address changes to chase and no allowlists to correct.

FAQs

If you have any difficulties, we have collected all of the useful materials for this product in our video library, tutorials, and documentation. You can also browse Access Server's features.

See what nearly 20,000 customers, hundreds of partners, and all major cloud providers already know.

  1. Jason K.Jason K. REPAY
    Easy to configure options, add users, and that it has two factor authentication built in. You can configure the system to allow connections on common ports so that you're able to connect from pretty much anywhere in the world.
  2. Johnathan B.Johnathan B. Surry Telephone
    Configuring and updating my own server is super simple. In my experience, I've always had some difficulty setting up hardware VPN appliances, but OpenVPN was no-nonsense.
  3. Alex H.Alex H. DGDean
    The OpenVPN Access Server AMI is a great out of the box VPN solution for your AWS VPC...
  4. John G.John G. Anovys, LLC
    OpenVPN offers users a very simple and secure VPN option that is both economical and quick to install. Users are able to easily install it on their client devices.
  5. Jeremy F.Jeremy F. Intelligent Pathways
    The availability of client software for all operating systems and mobile devices means my customers can connect regardless of their setup.
  6. Josh Wc.Josh Wc. nexgen|packaging, LLC
    Excellent, flexible solution for our Azure environment.