Skip to main content

Deploy Access Server on AWS — Choose Your Licensing Model

Abstract

Deploy OpenVPN Access Server on AWS — choose from three Marketplace licensing options: BYOL (bring your own license), PAYG (pay-as-you-go, billed through AWS), or Tiered (pre-licensed for a fixed connection count). Guidance on which model fits your use case.

Overview

You can deploy Access Server on Amazon Web Services (AWS) in several ways, depending on how you want to install Access Server and purchase your license.

You can start from the Access Server Hub or directly from AWS Marketplace. Use this page to choose the option that best fits your deployment.

Choose an AWS deployment option

AWS CloudFormation

Use the CloudFormation Script option in the Access Server Hub to create an Access Server deployment in your AWS account.

The Access Server Hub generates the CloudFormation deployment and sends you to AWS, where you configure and create the stack.

Choose this option if you:

  • Want to deploy Access Server using an OpenVPN subscription.

  • Want AWS CloudFormation to create the required AWS resources.

  • Prefer to start the deployment from the Access Server Hub rather than the AWS Marketplace.

You must sign in to your AWS account to create the CloudFormation stack.

Linux on AWS

Use Linux on AWS if you want to create your own supported Linux instance in AWS and install Access Server with the installation script.

Choose this option if you:

  • Want to manage the underlying Linux instance yourself.

  • Already have AWS infrastructure where you want to install Access Server.

  • Prefer a standard Linux installation rather than an AWS Marketplace image.

Deployment options are supported on Ubuntu, Debian, and Red Hat.

Docker on AWS

Use Docker on AWS if you want to run Access Server as a Docker container on AWS.

The Access Server Hub provides the docker pull and docker run commands needed to deploy the container.

Choose this option if your environment already uses Docker or you prefer a container-based deployment.

AWS Marketplace

AWS Marketplace provides three Access Server licensing options. Choose the model that matches how you want to purchase and manage your license.

Bring Your Own License (BYOL)

Choose BYOL if you want to use an Access Server subscription purchased directly from OpenVPN.

BYOL is a good choice if you:

  • Already have an Access Server subscription.

  • Want to purchase and manage your subscription through OpenVPN.

  • Want the flexibility to use your subscription with another Access Server deployment later.

AWS bills the infrastructure charges separately from your OpenVPN subscription. The AWS Marketplace BYOL offering supports deployment with AWS CloudFormation or an Amazon Machine Image (AMI).

Pay As You Go (PAYG)

Choose PAYG if you want to purchase Access Server through AWS Marketplace and include Access Server charges with your AWS billing.

Choose PAYG if you:

  • Prefer to manage Access Server costs through AWS.

  • Don't want to purchase or activate a separate OpenVPN subscription.

  • Prefer usage-based licensing.

Tiered licensing

Choose Tiered if you want to purchase an AWS Marketplace instance with a predefined number of simultaneous VPN connections.

Choose Tiered if you:

  • Know how many simultaneous VPN connections you need.

  • Prefer a fixed connection tier.

  • Want Access Server licensing and AWS infrastructure charges billed through AWS.

Compare the AWS licensing options

Licensing option

Billing

Best for

BYOL

Access Server subscription through OpenVPN; AWS infrastructure billed through AWS.

Customers who already have or want to manage an OpenVPN subscription.

PAYG

Access Server and AWS charges billed through AWS Marketplace.

Customers who prefer AWS billing and usage-based licensing.

Tiered

Access Server and AWS charges billed through AWS Marketplace for a predefined connection tier.

Customers who want a fixed number of VPN connections.

Where should I start?

Use the Access Server Hub if you want to:

  • Deploy with Access Server Link.

  • Generate an AWS CloudFormation deployment.

  • Install Access Server manually on a Linux instance.

  • Deploy Access Server with Docker.

  • Choose an AWS Marketplace offering from the OpenVPN deployment page.

Use AWS Marketplace directly if you already work primarily in AWS and want to choose a BYOL, PAYG, or Tiered Access Server offering there.

For most customers using an OpenVPN subscription, AWS CloudFormation provides an automated way to deploy Access Server resources in their AWS account.