One is a VPN service attached to your VPC. The other is an identity-based network for your whole company — AWS included.
| OpenVLAN | AWS Client VPN | |
|---|---|---|
| Access model | Identity-based per user & device | Certificate or IdP-federated per endpoint |
| Topology | Mesh (peer-to-peer) + subnet routing | Hub: all traffic via AWS VPN endpoints |
| Cloud coverage | Any cloud + on-prem + devices | AWS only |
| Pricing | Per user, published | Per endpoint association-hour + data transfer |
| Non-VPC resources | First-class (homelab, colo, SaaS) | Requires transit plumbing |
| Policy as code | ACLs + Terraform + API | CloudFormation/Terraform for infra, auth rules separate |
| NAT traversal | Automatic | Client-side handled |
If every resource you touch lives in one AWS account and stays there, the native service is fine — one less vendor.
Consolidating under the AWS bill simplifies procurement for some orgs.
The bill scales with association hours, so always-on teams pay for sleep time. Multi-cloud or on-prem resources need extra plumbing. And developers still SSHing to "anywhere in the VPC" get no per-resource granularity.