This product has charges associated with it for TurnKey Linux integration, automated security updates, backup tooling, and bundled support. It provides Wireguard on Debian 13.
This product has charges associated with it for TurnKey Linux integration, automated security updates, backup tooling, and bundled support. TurnKey with WireGuard helps save you time and money by providing a ready-to-run WireGuard VPN solution that is secure, supported and easy to maintain. The system auto-updates itself with security fixes and is built in a transparent 100% open source process free of hidden backdoors. WireGuard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPsec, while avoiding the massive headache. It intends to be considerably more performant than OpenVPN.
Note: WireGuard and the "WireGuard" logo are registered trademarks of Jason A. Donenfeld. TurnKey Linux is not affiliated with Jason A. Donenfeld or WireGuard. Neither this software appliance, or the TurnKey provided, custom configuration scripts are endorsed by Jason A. Donenfeld or WireGuard.
Highlights
Secure, supported and easy to maintain: auto-updated daily with latest security patches. Bundled support for no extra charge.
Free from hidden backdoors and vendor lock-in: transparent 100% opensource build of Debian GNU/Linux with no proprietary components or secret sauce.
Free 1-click backup, restore and migrate: bundled backup software saves changes to files, databases and package management to encrypted storage which servers can be automatically restored from.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 7 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour based on the Amazon EC2 instance size you choose to run this VPN server appliance. Each dimension maps to a specific EC2 instance type, grouped by family: general-purpose (m, t), compute-optimized (c), memory-optimized (r), and storage-optimized (i). Within each family, larger sizes carry higher hourly rates. Micro and nano options suit light workloads, while xlarge and 2xlarge options handle heavier traffic. The software cost is identical across all instances; your rate reflects the underlying compute you select. Billing is usage-based with no upfront commitment, so you pay only for hours running.
Top-of-mind questions for buyers
What does one hour of billing on this appliance actually cover?
One hour equals one hour of a single running EC2 instance in the size you select. The software charge is a per-hour rate added on top of the AWS compute cost for that instance. Each instance you launch is billed separately for every hour it runs.
Am I charged the software rate when the instance is stopped?
The hourly software charge applies only while the instance runs. A stopped instance stops accruing the software rate. Note that stopped instances may still incur AWS storage fees for attached volumes, and stopped AWS servers change their IP address when restarted unless you attach an Elastic IP.
How do I pick the right instance size, and can I change it later?
Micro and nano sizes suit light VPN traffic; xlarge and 2xlarge sizes handle heavier loads. Since billing is per hour with no upfront commitment, you can stop the instance and relaunch on a different size. Provide your server size and region when contacting support for guidance.
www.turnkeylinux.org+1
Helpful?
Vendor refund policy
90 day "no questions asked" refund policy.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
After launch, browse to http://<Public_DNS>/ and complete the first-boot configuration, or connect by SSH using the key pair selected at launch.
Operating system access
Connect using SSH as the Linux user admin with the selected EC2 key pair. Run privileged commands with sudo; this provides full OS-level administration.
Application access
Open http://<Public_DNS>/ in a web browser. The application may redirect to HTTPS after configuration.
Basic "getting started" type support when first starting, plus one free support incident per month. E-mail support is provided through the TurnKey Hub at no additional cost. Once you sign up to the TurnKey Hub, your AWS marketplace subscription will be automatically identified.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This VPN server is built on WireGuard technology and designed to provide the secure internet access for computers and mobile devices. It is easy to use: after launching, the server is immediately fully operational without the need for any setup. WireGuard technology is quite modern; it offers data transfer speeds through WireGuard tunnels that are higher than those using IKEv2 and significantly higher than the OpenVPN protocol. The server has a convenient and intuitive web control panel including user management features. Suitable for both individual users and companies offering VPN services.
Access Server is a self-hosted business VPN and ZTNA software solution developed by the creators of the OpenVPN protocol. Deploy on EC2 and get secure access to VPCs and other connected networks. Route traffic by domain name for application-aware access control, and leverage Data Channel Offload (DCO) for kernel-accelerated throughput that keeps pace with demanding AWS workloads. With MFA, granular access controls, and Zero Trust-ready policies, Access Server is trusted by businesses to protect AWS infrastructure and beyond.
WireGuard VPN Server on Linux/Debian for secure Internet access with UI (Web Interface) and IP rotation. This WireGuard server uses UDP protocol for VPN communication, ensuring high-speed VPN performance. After launching, the secure Wireguard VPN Server is immediately fully operational without the need for any setup. WireGuard is a modern VPN technology, and WireGuard tunnels provide higher data transfer speeds than IPSec or IKEv2 and significantly higher than those of OpenVPN. This WireGuard server provides a stable VPN connection at the highest possible speed. Wireguard VPN Server on Linux/Debian has a convenient and intuitive control web panel including user management features. Client configuration settings can be easily transferred to the WireGuard mobile application using a QR code. WireGuard VPN server is suitable for both individual users and companies offering VPN services.
Access Server is a self-hosted business VPN and ZTNA software developed by the creators of the OpenVPN protocol, deployed on EC2 and billed through AWS.
Get secure access to your VPCs and other connected networks, route traffic by domain name for application-aware access control, and leverage Data Channel Offload (DCO) for kernel-accelerated throughput that keeps pace with demanding AWS workloads. With MFA, granular access controls, SAML single sign-on via AWS IAM Identity Center, and Zero Trust-ready policies, Access Server is trusted by businesses to protect AWS infrastructure and beyond.
Purchase connections through AWS as a monthly or yearly contract and consolidate your VPN software and infrastructure costs onto a single AWS invoice.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.