OpenVPN Access Server (BYOL) - Self-Hosted VPN & ZTNA with FREE Connections
بواسطة OpenVPN
Self-hosted VPN and ZTNA on your Azure VM for encrypted network access, with Entra ID SSO, kernel-accelerated throughput, and two free connections.
If you'd rather purchase connections directly through Microsoft and apply the cost to your existing Azure prepayment, we recommend our Pay-As-You-Go listing instead: OpenVPN Access Server / Self-Hosted VPN (PAYG)
Access Server is a self-hosted business VPN and ZTNA software solution developed by the creators of the OpenVPN protocol. Route traffic by domain name for application-aware access control, and leverage Data Channel Offload (DCO) for kernel-accelerated throughput. With MFA, granular access controls, SAML single sign-on (SSO) with Microsoft Entra ID, and Zero Trust policies, businesses trust Access Server to protect cloud infrastructure.
Migrating off Azure SSTP? Microsoft is retiring SSTP from Azure VPN Gateway and new gateways can no longer enable it, and existing SSTP connections stop working on March 31, 2027. Microsoft’s guidance on migrating off SSTP recommends OpenVPN as a replacement - the protocol Access Server is built on.
Once you've deployed from the Microsoft Marketplace, sign up at OpenVPN MyAccount to retrieve your activation key for two free connections, or start a trial for higher capacity.
Deployment Model
- Self-hosted on an Azure Virtual Machine within your own Azure subscription, resource group, and virtual network, so data and configuration stay under your control.
- Deployed from a preconfigured Microsoft Marketplace image in minutes.
- Managed through an intuitive web-based Admin Web UI, with REST API, and command-line configuration options available for advanced administration.
- Supports remote-access and site-to-site VPN topologies.
Typical Use Cases on Microsoft Azure
- Provide secure remote access to applications and data hosted in your Azure virtual network.
- Reach Azure SQL Database, Azure Cache for Redis, AKS clusters, and Private Link endpoints privately, without exposing public endpoints.
- Protect SaaS and internal applications by making them reachable only through the VPN, reducing exposure to the public internet.
- Route internet-bound traffic through a trusted gateway with a fixed egress IP using a reserved static external IP address, so approved SaaS applications can allow-list a single, stable address.
- Secure connectivity for devices, IoT, and machine-to-machine use cases.
Zero-Trust Access Controls
- Zero Trust Application Broker: Access Server verifies user identity, location, and device ID during connection and assigns, during domain lookup, a synthetic intermediate IP scoped to a single authorized app - the device never gets a route to the entire private network, so lateral movement isn't merely limited; it's structurally impossible.
- Define identity-based, role-driven access to specific applications by domain name or hostname
- Enforce device verification and location-aware post-authentication checks to reject connections from unauthorized endpoints.
- Use Access Control Lists to segment network access within your environment.
Flexible Authentication
- Supports PAM, RADIUS, LDAP, and SAML - including SSO with providers such as Microsoft Entra ID, Active Directory, Okta, and Google Workspace.
- Supports a custom Python3 authentication module for non-standard identity requirements.
- Includes built-in multi-factor authentication using TOTP, X.509 PKI, and support for external PKI.
High-Performance Connectivity
- Supports OpenVPN DCO to move encryption and decryption into the OS kernel for improved VPN data-plane performance and reduced processing overhead.
- Supports multi-threaded operation for demanding, high-throughput workloads.
- Supports NAT mode for remote-access and routing mode for site-to-site connectivity.
- Supports routing by IP CIDR ranges and domain names for defining access policies for cloud-hosted, SaaS, and internal applications.
- Supports split-tunnel and full-tunnel configurations.
Availability and Scale
- Supports clustering across multiple Access Server nodes to increase capacity and improve availability.
- Supports DNS-based traffic distribution for directing users to available cluster nodes.