---
title: "Create Your Own Self-Hosted ZTNA Solution in 2026 with Access Server: Complete Setup Guide"
description: "How to build your own self-hosted Zero Trust Network Access (ZTNA) solution in 2026 with OpenVPN Access Server: requirements, setup steps, and ZTNA features."
image: https://blog.openvpn.net/hubfs/self-hosted-ztna-with-access-server.png
---

- [Blog](https://blog.openvpn.net)
- [Cybersecurity](https://blog.openvpn.net/tag/cybersecurity)

# Create Your Own Self-Hosted ZTNA Solution in 2026 with Access Server: Complete Setup Guide

Sep 30, 2026 •  11 min read

![](https://blog.openvpn.net/hubfs/self-hosted-ztna-with-access-server.png)

Share

- <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.openvpn.net%2Fcreate-your-own-self-hosted-ztna-solution&title=Create%20Your%20Own%20Self-Hosted%20ZTNA%20Solution%20in%202026%20with%20Access%20Server%3A%20Complete%20Setup%20Guide&summary=How+to+build+your+own+self-hosted+Zero+Trust+Network+Access+%28ZTNA%29+solution+in+2026+with+OpenVPN+Access+Server%3A+requirements%2C+setup+steps%2C+and+ZTNA+features.&source=>
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.openvpn.net%2Fcreate-your-own-self-hosted-ztna-solution>
- <https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.openvpn.net%2Fcreate-your-own-self-hosted-ztna-solution&text=Create+Your+Own+Self-Hosted+ZTNA+Solution+in+2026+with+Access+Server%3A+Complete+Setup+Guide>
- <https://blog.openvpn.net/create-your-own-self-hosted-ztna-solution>

Create Your Own Self-Hosted ZTNA Solution in 2026 with Access Server: Complete Setup Guide

13:45

By Adam Bullock

A traditional VPN answers one question: is this user allowed on the network? Zero trust asks more. Who is this user, is this device allowed, where are they connecting from, and which specific apps do they actually need?

Zero Trust Network Access (ZTNA) replaces broad network access with least-privilege, identity-based access to specific resources. Many ZTNA products are cloud-only, which means your traffic, identities, and policies live on someone else's infrastructure. For teams that need to keep control of their data, meet strict compliance rules, or run in private or air-gapped environments, a [self-hosted ZTNA solution](https://openvpn.net/access-server/) is the better fit.

In this guide, you'll learn what ZTNA is, why self-hosting it makes sense, and how to set up your own self-hosted ZTNA solution step by step with OpenVPN Access Server. Prefer to watch? Check out our video "[How to use Access Server for ZTNA-Style Application Access](https://www.youtube.com/watch?v=u_HNNHEF72Q)" below.

<iframe width="560" height="315" src="https://www.youtube.com/embed/u_HNNHEF72Q?si=DNnVyBjSxz-65ygC" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen style="position: absolute; top: 0px; left: 0px; width: 100%; height: 100%; border-width: medium; border-style: none; border-color: currentcolor; border-image: none;"></iframe>

## What Is ZTNA and How Does It Work?

ZTNA is a security model built on one principle: never trust, always verify. Every connection is checked against identity, device, and context before access is granted, and access is limited to only the resources each user needs.

## ZTNA vs. Traditional VPN

|  | Traditional VPN | ZTNA |
| --- | --- | --- |
| *Trust model* | Trusted once connected | Verified on every connection |
| *Access scope* | Often the whole network | Specific apps, subnets, or ports |
| *Checks* | Username and password | Identity, MFA, device, and location |
| *Lateral movement* | Possible after login | Blocked by least-privilege rules |

 

ZTNA doesn't mean throwing out VPN technology. A modern ZTNA solution can use an encrypted VPN tunnel as its transport and layer zero trust policy on top. That is exactly how Access Server works.

## How ZTNA Verification Works

A ZTNA solution typically does three things on every connection:

- **Verifies identity:** Authenticates the user against a trusted identity provider, ideally with MFA.
- **Checks context:** Confirms the device and location meet policy.
- **Grants least-privilege access**: Opens only the resources that user or group is allowed to reach.

## Self-Hosted vs. Cloud-Delivered ZTNA

- **Self-hosted ZTNA:** You deploy and run the ZTNA server on your own infrastructure, in your data center, private cloud, or public cloud account. You control the data, logs, and policies.
- **Cloud-delivered ZTNA:** A vendor runs the service for you as SaaS. Less to maintain, but traffic and policy live on shared infrastructure.

If you want a fully managed option, OpenVPN also offers CloudConnexa. This guide focuses on self-hosting with Access Server.

## Why Create Your Own Self-Hosted ZTNA Solution with Access Server in 2026?

OpenVPN Access Server is a self-hosted business VPN with zero trust controls built in. You get the security of ZTNA without handing your network to a third party.

### Full Control Over Data and Policy

Access Server runs on infrastructure you own or control. Your user identities, connection logs, and access policies stay in your environment, which simplifies data residency and compliance conversations.

### Least-Privilege Access by Default

Instead of dropping users onto a flat network, Access Server lets you define which subnets, IP addresses, and even ports each user or group can reach. A contractor can get one app. An engineer can get the dev subnet. Nobody gets everything by accident.

### Verification Beyond Passwords

Access Server checks identity, device, and location before it allows a connection. Stolen credentials alone aren't enough to get in.

### Works in Private and Air-Gapped Environments

Because it's self-hosted, Access Server supports air-gapped installation. That's a common requirement in government, defense, healthcare, and industrial networks where cloud-only ZTNA isn't an option.

### Predictable, Usage-Based Cost

Access Server is priced by concurrent connections, not total headcount. If 100 employees work remotely but only 50 connect at once, you need a 50-connection plan. You can start free with two connections, no credit card required.

### Built on a Proven Protocol

Access Server is built on the OpenVPN protocol, one of the most widely used and audited VPN protocols. With Data Channel Offload (DCO), encryption runs in the kernel for near wire-speed performance.

 

### Create your own self-hosted ZTNA solution with Access Server

Free to use up to 2 connections.

[See More Details on the Free Plan](https://openvpn.net/access-server/pricing/)

## What You Need Before Setting Up Your Self-Hosted ZTNA Solution

### Hardware and System Requirements

- A server, virtual machine, or cloud instance you control
- A supported Linux OS: Ubuntu, Debian, or Red Hat Enterprise Linux
- Enough CPU and RAM for your expected concurrent connections (start small; you can scale with clustering later)

### Deployment Options

| Option | Best for |
| --- | --- |
| Cloud marketplace image (AWS, Google Cloud, Microsoft Azure, Oracle Cloud, IBM Cloud, DigitalOcean) | Fastest setup, remote teams |
| Linux package install | Existing servers, on-prem data centers |
| Virtual appliance (VMware ESXi, Hyper-V) | Virtualized on-prem environments |
| Docker container | Container-based infrastructure |
| Air-gapped install | Isolated or regulated networks |

### Network Prerequisites

- A public IP address or hostname clients can reach
- The ability to open the VPN and web UI ports on your firewall
- Admin (root) access to the server
- Knowledge of which internal subnets and apps users need to reach

### Identity Provider (Recommended)

ZTNA works best when access ties back to a central identity source. Have your IdP details ready: SAML (for SSO), LDAP or Active Directory, or RADIUS. Access Server also supports local and PAM authentication if you're just getting started.

### An Access Map

Before you install anything, list your user groups and the resources each one needs. This becomes your least-privilege policy, and it's the most important ZTNA planning step.

## Step-by-Step: Create Your Own Self-Hosted ZTNA Solution with Access Server

### Step 1: Deploy Access Server

Pick your deployment option. For most teams, a cloud marketplace image or a Linux package install on Ubuntu is the quickest path. After installation, you'll get the Admin Web UI URL and initial admin credentials.

### Step 2: Sign In to the Admin Web UI

Access Server 3.0 introduced a redesigned, React-based Admin Web UI backed by a REST API. From here you manage network settings, users and groups, authentication, and access controls without touching the command line. You can also protect the Admin Web UI itself with SAML SSO.

### Step 3: Connect Your Identity Provider

Under authentication settings, connect SAML, LDAP, RADIUS, or PAM. Access Server lets you mix and match methods and run multiple methods at once per user or group, which helps when you're migrating between IdPs.

### Step 4: Enforce Multi-Factor Authentication

Turn on TOTP-based MFA so users verify with an authenticator app. Admins can enroll, reset, enable, or disable MFA from the Admin Web UI.

### Step 5: Create Groups and Least-Privilege Access Rules

Using the access map you built earlier, create user groups and assign each one only the subnets, IP addresses, and ports it needs. This is the core of ZTNA: no one gets broad network access by default.

### Step 6: Add Device and Location Checks

Configure device posture checks to block devices with an unregistered MAC address or UUID, or devices running non-compliant applications. Add location rules to block connection attempts from unregistered IP addresses. For custom logic, use post-authentication scripts.

### Step 7: Distribute OpenVPN Connect to Users

Users sign in to the Client Web UI to download OpenVPN Connect and their connection profile. Clients are available for Windows, macOS, Linux, ChromeOS, iOS, and Android.

### Step 8: Test and Verify Access

Connect as a test user from each group and confirm:

- Authentication and MFA prompts work as expected
- The user can reach only their allowed resources
- Blocked resources, devices, and locations are actually denied
- Connections appear in the log reports

## Access Server ZTNA Features Explained

Access Server applies zero trust across three verification factors (identity, device, and location), then enforces least-privilege access to what each user needs.

### Identity-Based Access

- **Flexible authentication:** SAML, LDAP, RADIUS, PAM, local, or custom
- **Simultaneous auth methods:** Multiple active methods per user or group
- **MFA:** TOTP codes from authenticator apps
- **Built-in PKI:** An X.509 certificate authority, plus support for external PKI such as OpenSSL or Microsoft AD CS

### Least-Privilege Access Controls

Define exactly which users and groups can reach which networks, subnets, IP addresses, and ports. Role-based access gives each user personalized application access instead of the whole network.

### Device Posture Checks

Block connections from devices with an unregistered MAC address or UUID, or devices running non-compliant applications. Only known, approved devices get in.

### Location-Based Restrictions

Set trusted access points and geo-restrictions. Connection attempts from unregistered IP addresses are blocked, which reduces the risk from compromised credentials.

### Post-Authentication Scripts

Run custom logic after login for additional MFA or ZTNA checks tailored to your environment.

### Logging and Auditing

Log reports show past connections with user identity, IP address, and connection duration. Send logs to local or external syslog servers for centralized monitoring and compliance audits.

### High Availability and Performance

- **Clustering:** Distribute traffic across multiple Access Server nodes and scale horizontally
- **Failover:** A standby server takes over automatically if the primary fails
- **DCO:** Kernel-level encryption for near wire-speed throughput

### Modern Administration and API

The Access Server 3.0 Admin Web UI puts users, groups, access controls, and authentication in one place. The REST API lets you automate provisioning and integrate Access Server with your existing tools.

## Securing Your Self-Hosted ZTNA Solution

### Start with Least Privilege, Then Expand

Give each group the minimum access it needs. It's easier to grant more later than to claw back access nobody should have had.

### Require MFA for Everyone

Enable MFA for all users, including admins. Protect the Admin Web UI with SAML SSO so admin access follows the same identity rules.

### Register Devices

Use device posture checks so only registered devices can connect. Remove devices when employees leave or hardware is retired.

### Restrict by Location

Limit connections to trusted IP ranges or regions where your users actually work.

### Monitor Logs and Revoke Access Quickly

Forward logs to your syslog server or SIEM. Review unusual connection patterns and revoke users, certificates, or devices as soon as they're no longer needed.

### Keep Access Server Updated

Apply Access Server and OS updates promptly. Self-hosting means patching is your responsibility.

### Plan for High Availability

If ZTNA is how your team reaches critical apps, an outage stops work. Use clustering or failover for production deployments.

## Common Self-Hosted ZTNA Problems and How to Fix Them

1. **Users can't reach an app they need:** Check the group's access rules for the right subnet, IP, and port.
2. **Legitimate devices are blocked:** Confirm the device's MAC address or UUID is registered.
3. **Remote users are denied by location rules:** Add the user's trusted IP range or adjust geo-restrictions.
4. **SSO or MFA login fails:** Verify IdP settings, certificate validity, and server time sync.

## Costs of Running Your Own Self-Hosted ZTNA Solution

- **Access Server subscription:** Priced by concurrent connections. Free for two connections; paid plans start at five, with custom packages for 2,000+. Scale up or down on demand, and use one subscription across multiple servers and clusters.
- **Infrastructure:** Cloud instance fees or on-prem hardware.
- **Maintenance time:** Updates, policy reviews, and monitoring.

## Real-World Use Cases for Self-Hosted ZTNA

- **Replacing a legacy VPN:** Move from flat network access to least-privilege access without changing protocols.
- **Contractor and third-party access:** Grant access to a single app, not the network.
- **Regulated industries:** Keep identities, logs, and traffic in your own environment.
- **Hybrid and multi-cloud:** Secure access to resources across data centers and cloud VPCs.
- **Air-gapped networks:** Enforce zero trust where cloud ZTNA can't reach.

## FAQ: Creating Your Own Self-Hosted ZTNA Solution

### Can I create a self-hosted ZTNA solution for free?

Yes. Access Server is free for two concurrent connections with no credit card required, which is enough to test and pilot your setup.

### Is Access Server a VPN or a ZTNA solution?

Both. Access Server uses an encrypted OpenVPN tunnel and adds zero trust controls: identity verification, MFA, device posture checks, location restrictions, and least-privilege access rules.

### Do I need to replace my identity provider?

No. Access Server integrates with SAML, LDAP, RADIUS, and PAM, so you can use your existing IdP.

### Can I run Access Server on premises?

Yes. You can install it on Linux, run it as a virtual appliance or Docker container, deploy it from a public cloud marketplace, or install it in an air-gapped environment.

### What devices are supported?

OpenVPN Connect runs on Windows, macOS, Linux, ChromeOS, iOS, and Android.

### Should I self-host or use a managed ZTNA service?

Self-host with Access Server if you need control over data, policy, and infrastructure. If you'd rather not manage servers, CloudConnexa is OpenVPN's cloud-delivered option.

## Get Started with Your Own Self-Hosted ZTNA Solution

Zero trust doesn't have to mean giving up control of your network. With OpenVPN Access Server, you can build a self-hosted ZTNA solution that verifies identity, device, and location, then grants only the access each user needs, all on infrastructure you own.

**Try Access Server free with two connections. No credit card required.** [Get started](https://openvpn.net/access-server/)

 

 

![Adam Bullock](https://blog.openvpn.net/hs-fs/hubfs/adamheadshot.jpg?width=300&height=300&name=adamheadshot.jpg)

[Adam Bullock](https://blog.openvpn.net/author/adam-bullock)

Adam has loved tech since the days of the dial-up modem. Read his perspective on the OpenVPN blog.

## Related posts from OpenVPN

### [![Zero Trust With OpenVPN Protocol for Network Access = Our ZTNA-Capable Solutions](https://blog.openvpn.net/hubfs/Imported_Blog_Media/Copy-of-Featured-Image-2.png) Zero Trust Nov 1, 2023 Zero Trust With OpenVPN Protocol for Network Access = Our ZTNA-Capable Solutions](https://blog.openvpn.net/ztna-capable-solutions/)

### [![OpenVPN CloudConnexa vs. Microsoft Entra: A ZTNA, SSE, and Zero Trust Feature Comparison](https://blog.openvpn.net/hubfs/Blog_Insights_Blue_Glow%20(1).png) CloudConnexa Aug 10, 2026 OpenVPN CloudConnexa vs. Microsoft Entra: A ZTNA, SSE, and Zero Trust Feature Comparison](https://blog.openvpn.net/comparing-openvpn-cloudconnexa-and-microsoft-entra)

### [![Buy, Build, or Self-Host: A European Decision Framework for Replacing Your ZTNA Vendor](https://blog.openvpn.net/hubfs/openvpn-blog-header-latte.png) Network Security Tools Sep 4, 2026 Buy, Build, or Self-Host: A European Decision Framework for Replacing Your ZTNA Vendor](https://blog.openvpn.net/buy-build-or-self-host-ztna-vendor-europe)

### Subscribe for Blog Updates

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Adam Bullock",
    "url" : "https://blog.openvpn.net/author/adam-bullock"
  },
  "dateModified" : "2026-09-30T23:30:14.643Z",
  "datePublished" : "2026-09-30T23:21:54.000Z",
  "headline" : "Create Your Own Self-Hosted ZTNA Solution in 2026 with Access Server: Complete Setup Guide",
  "image" : [ "https://blog.openvpn.net/hubfs/self-hosted-ztna-with-access-server.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.openvpn.net/create-your-own-self-hosted-ztna-solution",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.openvpn.net/hubfs/Dark=True%20Medium.png"
    },
    "name" : "OpenVPN"
  }
}
```