Setting up a VPN server used to take weeks t oget it right: fiddling with certificates, managing a CA, messing with iptables, and hoping it all works. This guide shows you how to get OpenVPN running in your own AWS account in about 5 minutes, and why doing it yourself beats renting one.
Why run your own VPN on AWS
If you run stuff on AWS, you've got private subnets holding sensitive things, databases, admin panels, internal tools, that should never be public. The real question isn't keeping them private, but how your team gets to them. The answer: a VPN in a public subnet of your VPC. Your team connects to it, and those private subnets act like they're local. You control access with certs you issue, set expiration, and can revoke anytime someone leaves.
This setup works great for offices too. Rather than installing a VPN on each laptop, you just connect the office router to the gateway. That way, everyone in the office accesses AWS resources like they're local. One tunnel, no client setup, everyone behind the router is covered.
The options
You have three choices:
- AWS Client VPN, managed, but pricey. You pay per subnet per hour plus per connected client. A small team can rack up hundreds every month.
- Build OpenVPN yourself, launch an EC2, install OpenVPN, set up the CA, manage certs, and routing. Cheap except your time, and cert management never ends.
- Prebuilt OpenVPN AMI from AWS Marketplace, the sweet spot. Setup in 5 minutes, cert management baked in, no headaches.
The 5 minute setup
We built Valdras Gate for this. Self-hosted OpenVPN in your AWS account, no license limits, unlimited users. Here's how:
- Subscribe at the Valdras Gate AWS Marketplace page.
- Launch the AMI in your VPC. A t3.nano handles a small team just fine, the network card is the only real bottleneck.
- After boot, SSH in and create your first user with one CLI command. The user profile with embedded certs is emailed automatically.
- Import the profile into any OpenVPN client and connect.
Done. No license servers, no fees per user, and the certificates manage themselves. User management is just a few CLI commands: create, list, revoke users. Each profile must have an expiration date set at creation, no exceptions. This is your safety net: if you forget to revoke a contractor's access, their certificate simply stops working once it expires. The server blocks it during handshake, so no manual cleanup is needed.
So, what about legit users who need ongoing access? They don't get locked out. Just enable auto-renewal for their profiles. The server will generate a new profile before the old one expires and email it with instructions. No one needs to keep track of expiry dates or submit tickets when VPN stops working Monday morning.
The cost
Valdras Gate is a straightforward $99 a month, no matter your user count. Other VPNs on AWS Marketplace charge per user and force you to manually renew profiles every year. Once you have more than a few users, costs skyrocket and maintaining profiles becomes a huge headache. With our flat fee and automatic renewals, those issues just vanish.
Closing thoughts
VPNs should be boring. Set it up once, let it run, revoke certs when people leave. Running your own in AWS means you control security, not someone else. If you want the 5-minute setup instead of a weekend stress fest, Valdras Gate is on AWS Marketplace.
Sharing is Caring
If you found this article useful, consider sharing it with someone you think could benefit from it.
Contact David Today
Please describe your situation and your cloud computing needs.


