Always on VPN alongside Direct Access?

We currently are using DA which we are having constant connection issues with so I am wanting to try AOVPN. I’m assuming it needs to be installed onto a different server, are there any other considerations I need to be aware of?

I’d sperate it my self

It is best to deploy a separate server to support Always On VPN. It will save you a lot of headaches later, I can assure you. :slight_smile:

I’d work on figuring out your DA issues. It’s rock solid and has been for over a decade for us - so I’d look into underlying issues like connectivity. If you’re having connectivity issues, no matter what you use will have problems. One of the great things about DA imho is that Microsoft stopped updating it long ago - so they rarely break anything in it! It just works. It’s been officially deprecated yes, so eventually it will be removed at some point in the future, but it’s in Server 2025 and Win11 so it’s around and supported for the foreseeable future. AOVPN is absolutely trash and breaks constantly in all kind of new and fun ways - I would never rely on it unless/until it stabilizes. With SMB over QUIC also coming out in Server 2025 we plan to make the shift to that and Entra-native machines so will have no more need for DA at that point.