QS-WAN · Compare

The OpenVPN alternative for teams who'd rather not run the server

OpenVPN Access Server is software you install and then own: the host, the upgrades, the certificate authority, the profiles. QS-WAN moves that work to a control tower you still run yourself, but which governs a fleet instead of a box. Move if operating the server is the part that hurts. Stay if it isn’t.

Their design

What OpenVPN Access Server is, and what it's good at

OpenVPN calls it “a self-hosted business VPN solution. Deployed on Linux”. It ships an Admin Web UI they say makes configuration simple with or without Linux knowledge, a Client Web UI where people collect pre-configured clients, and the OpenVPN Connect app for Windows, macOS, Android, iOS and ChromeOS.

What they do well

What it’s good at isn’t in doubt.

It is everywhere

It’s everywhere, so the admin you hire next month has run one.

The host is yours

The host is yours, top to bottom.

It plugs into the directory you already have

It plugs into whatever directory you already have, PAM, RADIUS, LDAP, SAML, local or custom, with access control on three levels: global, group and user.

The difference

The architecture difference is the unit of administration

With Access Server the unit is a server. With QS-WAN the unit is the fleet.

Users, profiles, access rules and the certificate authority all belong to the installation on that Linux host. Scale it and a cluster keeps certificates and credentials in a central database you run. More capacity, same unit.

Your infrastructure Laptop Office LAN Cloud instance One installation Users and profiles Access control: global, group, user Certificate authority One host you can snapshot Unit of administration Add capacity and the unit repeats, with a central database Control tower Certificate authority Enrolment and key exchange More parts than one host Fleet level objects Device identity, certificate, algorithm choice and policy Gateway Gateway Unit of administration Your directory LDAP, RADIUS, SAML Unit of administration only. How traffic reaches a machine is not what this compares.
Users, profiles and the certificate authority belong to one installation

The diagram compares two units of administration, and both of them sit inside your own infrastructure: a dashed box holds a laptop, an office LAN and a cloud instance on one side and the administration on the other. In the first, one installation is the whole unit. The users, the profiles, the access rules on three levels and the certificate authority all belong to it, it is one host you can snapshot, and adding capacity repeats the same unit with a central database. In the second, a control tower, a band of fleet level objects and the gateways are one unit together, so a device identity, a certificate, an algorithm choice and a signed policy are set once and reach every gateway, at the cost of more parts than one host. The directory you already have stays outside the unit in both, because neither architecture moves it. The diagram compares units of administration only and says nothing about how traffic reaches a machine.

The control tower is a separate piece from the gateways, and it still runs on your own infrastructure, on premise, in a private cloud or air gapped. A device identity, a certificate, an algorithm choice and a policy are fleet level objects, not settings in one box.

Certificates show it best. Access Server renews its CA on startup once the one in use is over a year old, and then “a client gets the latest CA certificate whenever they download a new client profile”. The pull belongs to the user. In QS-WAN those are fleet settings, eight key exchange options, eight certificate authorities and three ciphers, applied fleet wide or per gateway, with the certificates re-signed and redistributed rather than fetched. Crypto agility is that screen, and rotating the CA is a scheduled operation rather than a button: it needs every gateway connected while it runs.

Your week

What changes in your week

Enrolment stops being a file you hand over

On Access Server you create the user, pick user-locked or auto-login, and the profile gets downloaded from the Client Web UI, the OpenVPN Connect app, or by hand. Device enrollment here issues one single-use token per device, valid 48 hours and stored as a hash. The device generates its own ML-KEM-768 and ML-DSA key pairs locally and registers only the public halves.

Revocation stops being a delete and a hope

Their docs are honest: remove a profile and the client needs a new one to connect again. Certificate lifecycle management gives you Revoke, Revoke all, Reinstate, Reissue cert and Resend enrollment per device, and when the lockdown code reaches the QNova Client it writes a persistent revoked state and stops reconnecting on purpose.

Policy arrives signed, carrying its own scope

A signed company policy of 16 rules, scoped per gateway, user or device, where a device override changes only the ids it sets.

Scope

What's outside their scope, stated carefully

Scope

What Access Server is for, in their own words

OpenVPN describes the job of Access Server as protecting "business data communications", securing IoT resources, "access control and network segmentation", and "encrypted remote access".

That's the access layer, fairly described, and they do it well. What they don't claim is the endpoint.

Moving

What moving would actually involve

The profiles already in the wild

The specific cost of leaving a self managed Access Server is the profiles already in the wild. Every user locked profile somebody downloaded last year is still on a laptop, and nothing about it expires on a schedule you control.

Keep the old server answering

So the migration has a shape: you keep the old server answering while devices enrol against the new one, and you retire profiles by revocation rather than by asking people to delete files.

What does not move

Your directory stays where it is. A gateway goes beside the LANs you already have rather than replacing them, so remote access lands where it lands today. The part nobody budgets for is the handful of machines that nobody can find.

Stay put

Don't switch if

Your Access Server is doing its job

One host, a directory it already talks to, a CA that renews itself on restart, a team that knows where the config lives. Trading a working system for a fleet console you don’t need is a bad deal.

You need iOS now

OpenVPN Connect covers Windows, macOS, Android, iOS and ChromeOS. Here Windows is the complete column, macOS ships with CIS benchmarks running against real hosts, and Android is there. Linux has gaps, and iOS is next rather than now.

You want one package you can snapshot and move

An installation on a Linux host you back up, migrate and version yourself is a real operational virtue. A control tower plus gateways is more parts than that.

You already bought endpoint protection

Consolidation only pays when it removes contracts. If your EDR has two years left, the arithmetic doesn’t work.

Questions

What people ask before they move

What is the best OpenVPN alternative for an air gapped network?

One where the thing deciding who joins has no route to the internet. Access Server is self-hosted, so it clears that bar for one site. The question is what governs twenty, and that's the control tower behind air gapped networking.

Do I have to give up self-hosting?

No. The control tower runs on premise, in a private cloud or air gapped. Enrolment, certificate issuance, key exchange and policy signing all happen inside your boundary.

How hard is it to change the cryptography later?

One screen, then a scheduled operation that needs every gateway connected. Today the tunnel negotiates X25519 with ML-KEM-768 for key exchange, ML-DSA-87 for authentication and AES-256-GCM, aligned to FIPS 203, FIPS 204 and CNSA 2.0.

Is this a managed service?

No. It's a product you operate. No analysts of ours reading your logs, nobody watching a wall at three in the morning.

Bring the server you already run

We’ll show you which parts of that job the tower takes, free, with nothing to sign and no clock running.

Scroll to Top