Easy to setup VPN Server using WireGuard® as underlying VPN technology. WireGuard® is a fast and modern VPN, integrated within the Linux Kernel. Supports TCP/UDP Packet inspection, SAML, OpenID Connect (OIDC), SCIM, and local auth with MFA. Packet logging allows administrators to inspect TCP/UDP packets to understand http/https/dns traffic patterns.
Fast, Secure, and Modern VPN Solution that uses WireGuard® as underlying VPN technology. Works with any WireGuard® VPN Client. The VPN can be configured using an easy-to-use administrator website. TLS Encryption with Let's Encrypt lets you easily enable TLS on the administrator website. Users can use the administrator website to create and download the VPN configuration file. OpenID (OIDC), SAML, and SCIM integrations are supported to work with Identity Providers like OneLogin, Azure AD, or any generic OIDC/SAML/SCIM implementation). If you wish not to use an Identity Provider, then local authentication is also available with optionally Multi-Factor Authentication (MFA).
An easy-to-use administrator website allows you to create, delete, and suspend new users. New users can download and use their VPN configuration with any WireGuard® VPN Client.
OpenID Connect, SAML, SCIM integrations available
WireGuard® is very fast, modern, and cryptographically sound. It's faster than competitors like OpenVPN.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 31 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the EC2 instance type you choose to run the VPN Server. Pricing is not tiered by features. Instead, each dimension maps to a specific instance size, so your rate scales with the compute capacity you select. Options range from small burstable instances (t2, t3, t3a, t4g families) to general-purpose sizes (m5, m5a, m6a, m6g, m6i, m7a, m7g, m7i families). Sizes span from nano up to 48xlarge. Larger instances also include more user licenses. To add licenses on the same instance, upgrade the instance or switch to the bring-your-own-license version.
Top-of-mind questions for buyers
What does one hour of billing cover for the VPN Server?
You pay for each hour the chosen EC2 instance runs. The rate is tied to that instance size, not to the number of connected users. The software charge meters running time, so stopped instances stop accruing software fees, though AWS storage costs may still apply.
How do I add more user licenses without changing my instance?
Larger instances include more user licenses. To add licenses on the same instance size, switch to the bring-your-own-license version available on the marketplace. Otherwise, upgrade to a larger instance to raise the included license count.
Does my cost change if I run a large instance but few users connect?
Yes. Your bill follows the instance size you select, billed per running hour. It does not scale with active users. A large instance with few connections costs the same hourly rate as a large instance running at capacity.
www.in4it.com
Helpful?
Vendor refund policy
Hourly users can stop the instance at any time to stop billing, and yearly users can cancel within 72 hours.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Version v1.1.18
Additional details
Usage instructions
Once the instance has started, you can go to http://<IP or hostname> to start the configuration. You can find the IP or hostname in the AWS EC2 Console. Make sure you use http:// as prefix and not https://, as TLS is not setup yet and will give you an error. You can set up TLS once logged in. You'll be asked for a secret to start the setup process. To get the secret, login using SSH in the server (login: ubuntu), and enter the command sudo cat /vpn/setup-code.txt. More details at https://vpn-documentation.in4it.com/. Terms & Conditions apply when using the VPN Server, see https://in4it.com/vpn-server-terms-conditions/
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Uses WireGuard as underlying VPN technology, integrated within the Linux Kernel for fast and modern VPN performance.
Authentication and Identity Management
Supports OpenID Connect (OIDC), SAML, SCIM integrations with Identity Providers, and local authentication with optional Multi-Factor Authentication (MFA).
Traffic Inspection and Logging
Includes TCP/UDP packet inspection and packet logging capabilities to allow administrators to inspect and understand HTTP/HTTPS/DNS traffic patterns.
TLS Encryption
Supports TLS encryption with Let's Encrypt integration for securing the administrator website.
User Management Interface
Provides an easy-to-use administrator website for creating, deleting, and suspending users, with capability for users to download VPN configuration files compatible with any WireGuard VPN client.
VPN Protocol and Communication
Uses WireGuard protocol with UDP 51820 for VPN communication, providing higher data transfer speeds compared to IPSec, IKEv2, and OpenVPN protocols.
Dual IP Address Configuration
Supports two separate public Elastic IP addresses for VPN Endpoint and outbound internet access, enabling IP rotation without requiring client configuration updates or server restart.
Encryption and Authentication
Implements modern cryptographic algorithms including Curve25519 and ChaCha20 for encryption, with security key-based user authentication.
Web-Based Management Interface
Provides intuitive web control panel with user management features and QR code-based client configuration transfer to mobile applications.
Minimal Resource Requirements
Operates efficiently on low-performance Linux instances such as t3.micro, t3.small, and t3.medium, with approximately 4,000 lines of code enabling reduced attack surface and improved auditability.
Encryption Protocol
Built on WireGuard protocol for peer-to-peer and encrypted connectivity across infrastructure
Identity-Based Access Control
Manages network access using user and service identities with integration to Google, Microsoft Entra ID, Okta, and other identity providers
Zero Trust Network Architecture
Implements decentralized peer-to-peer mesh network topology that eliminates single points of failure
DNS and IP Management
Provides MagicDNS and static IP addressing to ensure devices remain addressable across network changes
NAT and Firewall Traversal
Maintains connectivity across NATs, firewalls, and network topology changes with automatic key expiration
While OpenVPN was working well, it was cumbersome, especially with OneLogin and other VPNs.
The whole workflow became super simple when we moved to IN4IT VPN Server. Our team switched to the new system using WireGuard® in minutes. Upgrades to the VPN Server are as simple as a click.
Highly suggested, especially if you integrate with a SAML, OpenID Connect (OIDC), SCIM, and local auth with MFA solutions.