- Newest
- Most votes
- Most comments
This appears to be a known compatibility issue between newer versions of the AWS VPN Client (including 5.x) and recent Windows builds. The issue you're describing with Windows 25H2 follows a similar pattern to what was observed with Windows 24H2, where the AWS VPN Client fails to connect properly after Windows updates.
The root cause appears to be that the OpenVPN process that the AWS VPN Client relies on cannot initialize correctly on these newer Windows builds. In the case of Windows 24H2, users reported errors like "OpenVPN Process Failed to Start" or issues with port 35001 not being properly opened for SAML-based authentication.
Based on the pattern you're describing, it seems the Windows 25H2 update is causing similar compatibility problems with AWS VPN Client 5.3.1, even though this version had resolved the issues with Windows 24H2.
For now, the most reliable solution appears to be:
- Rolling back to Windows 24H2 (which you've already done successfully)
- Pausing Windows updates until a compatible AWS VPN Client version is released
If you need a more immediate solution while waiting for an updated client version, you could try:
- Running the AWS VPN Client as administrator
- Checking that the AWS VPN Client service is running and set to Automatic startup
- Temporarily disabling any third-party antivirus or security software
- Verifying there are no conflicting VPN software applications installed
For your testing purposes, when you update your workstation to 25H2, you might also want to try downgrading to AWS VPN Client version 4.1.0, as this version has been noted to work better with some recent Windows builds in similar situations.
From the VPN endpoint side, there are no specific changes needed as this appears to be a client-side compatibility issue between the AWS VPN Client and Windows 25H2.
Sources
AWS VPN Client cannot reach 127.0.0.1/35001 and fails after Windows restart | AWS re:Post
AWS VPN Client does not work since Version 5.x (5.2.2) | AWS re:Post
answered 9 months ago
Hi, if you are using Federated authentication then we are observing authentication failures as well.
We are aware of an issue affecting Client VPN users after Windows Updates KB5066835 and KB5065789 (in a few cases), which can cause SAML authentication failures. This results in "cannot reach page" errors in browsers and connection timeouts.
Affected platforms: Client: Windows 11, version 25H2; Windows 11, version 24H2 Server: Windows Server 2025
Recommended workaround: Check for updates and restart the device. Follow the recommendation from Microsoft - https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3592msgdesc
answered 9 months ago
Relevant content
asked a year ago
asked 9 months ago
- AWS OFFICIALUpdated 4 months ago
