

We are going to create a security group to allow VPN access to our VPN Server.

Overview: security groups allow your servers to communicate with each other in a private cloud while exposing specific ports to the world. It will then cover how to grant and revoke access through the VPN Server. The following tutorial will take you through the steps of setting up an EC2 instance that will run the OpenVPN Server. The later is very useful if you need to revoke access for a former employee. We can then shutdown direct SSH access to our EC2 instances and also have the freedom to block access to our entire network just by revoking access via our VPN Server.

One extra step that we can take is to run a VPN Server that serves as the gateway to our protected EC2 instances. AWS has an awesome firewall built into its core services which can easily be used to make sure that only certain ports are open to the outside world.
