From Jump Hosts to Zero Trust: How One NOC Team Locked Down AWS Access with OpenVPN Access Server on AWS Marketplace
By Adam Bullock
How using Access Server changed daily operations for the better.
Enterprise engineering teams don't outgrow their VPN overnight. It happens gradually, a jump host here, a manually issued key there, until one day the network operations center (NOC) is spending more time managing access than managing infrastructure. That's exactly where Shashikanth Aitha, Senior Network Operations Engineer at Accolite Digital, and his team found themselves before deploying OpenVPN Access Server through AWS Marketplace.
We sat down with Shashikanth to talk through why they moved off ad hoc jump hosts, why AWS Marketplace was the only procurement path that made sense, and how Access Server's SAML integration and role-based access control changed daily operations on their AWS infrastructure.
The problem: access control that couldn't scale with AWS
Before bringing in a dedicated VPN platform, the team's biggest exposure was secure, controlled access to private staging environments and databases running in AWS.
"We were relying on basic jump hosts and disjointed configurations, which became a massive risk as our engineering teams grew," he said. "Managing individual user keys manually was turning into a major bottleneck, and we desperately needed a way to enforce strict least privilege access control without complicating life for the end users."
That combination, least privilege access enforcement, scale, and zero added friction for engineers, is what shaped their evaluation criteria for a remote access solution built for AWS.
Why AWS Marketplace was the only procurement path that made sense
The team purchased Access Server directly through AWS Marketplace, and it wasn't a close call.
"Going through AWS Marketplace was a no-brainer for us because it simplified procurement entirely," Aitha noted. "Instead of dealing with a separate vendor approval process, custom invoicing, and legal cycles, it just rolls directly into our existing consolidated AWS billing."
The architectural fit was just as important as the procurement fit. Using a pre-configured AMI, the team deployed Access Server directly inside their existing VPC, wired it into their network interfaces, and had it running in their AWS environment in under an hour — with no custom scripting and no infrastructure rebuild.
OpenVPN Access Server vs. AWS Client VPN
Before settling on Access Server, the team evaluated AWS Client VPN and a handful of legacy options. Two things tipped the decision: cost predictability and day-to-day manageability.
"AWS Client VPN charges per-hour endpoints plus connection fees, which can scale up aggressively and unpredictably," he explained. "From a management side, the OpenVPN Admin Web UI is far more intuitive for mapping subnets and managing roles compared to working through the AWS console or complex IAM routing policies for client access."
"The admin web UI handles about 90% of what you need... it moves away from complex command-line configuration and lays out user management, routing rules, and authentication settings in a very logical menu system."
SAML, role mapping, and least privilege in practice
For a NOC engineer running real traffic every day, the workflow comes down to Group Management: define target subnets — database ranges, staging environments — and map them to corresponding SAML or Active Directory groups.
"When running real traffic through it, it's basically set it and forget it," he said. "The traffic routing is rock solid, packets flow smoothly without weird MTU issues, and the built-in status logs let you see exactly who is connected and what paths they are hitting in real time."
"Because it integrates so well with our identity provider via SAML, users are automatically placed into their respective groups based on their actual roles the moment they authenticate... the server reads the group role and immediately locks down or opens up access to a specific subnet based on the profile." Access control here goes even further. Rather than letting everyone onto the network once they connect, admins can restrict access strictly by group or role — a practical way to enforce zero trust principles at the network level without piling extra complexity onto administrators.
The results: fewer incidents, faster onboarding, near-perfect uptime
The operational payoff shows up in two places: incident volume and onboarding time.
"Since deploying it, connection-related network incidents have dropped to almost zero," he explained. "We used to constantly chase down issues where connections would randomly drop mid-session or profiles would get corrupted. The uptime on Access Server has been practically perfect, and because the connection stability is so high, the NOC team isn't wasting time troubleshooting remote access issues anymore."
"Access Server has positively impacted our organization by giving us a highly reliable, stable environment for remote work."
Manual key generation and profile distribution used to take 20 to 30 minutes per user. With SAML and Active Directory integration handling group assignment automatically, that's now under two minutes per user — freeing senior engineers to work on infrastructure instead of access tickets.
What the team would tell other enterprise IT and NOC teams
Asked what advice he'd give another team evaluating Access Server on AWS Marketplace, Aitha focused on three things: procurement, licensing, and identity integration.
"Absolutely do it through AWS Marketplace if you want to skip the corporate procurement headache," he said. "On pricing and scaling, just keep an eye on your concurrent user counts, as the licensing fees can scale up fast — calculate your peak concurrent usage, not just total employee count. For daily operations, take advantage of the identity provider integration right out of the gate. It completely automates user lifecycle management and saves your team massive administration hours."
The bottom line
For enterprise teams running critical workloads in AWS, the pattern here is a familiar one: jump hosts and manual key management work until they don't. Deploying Access Server through AWS Marketplace gave this NOC team a way to enforce least privilege access control through SAML-based role mapping, cut manual onboarding from half an hour to under two minutes, and eliminate the connection drops that used to eat up NOC troubleshooting time — all without leaving their existing AWS billing and VPC architecture.
Ready to see what a SAML-integrated, AWS Marketplace deployment of Access Server could do for your team? Get started with Access Server through the AWS Marketplace.
Adam has loved tech since the days of the dial-up modem. Read his perspective on the OpenVPN blog.