VPN for IBM i Executives: What It Is, and Why “Free” Is Usually the Wrong Box

  • Home
  • /
  • Blog
  • /
  • VPN for IBM i Executives: What It Is, and Why “Free” Is Usually the Wrong Box

September 20, 2026

VPN, in plain English

A VPN is a private tunnel across the public internet.

Think of the internet as a busy high street. Without a VPN, your staff walk that street carrying the company keys. Anyone standing nearby can watch. With a VPN they go through a locked corridor. Same destination. Far fewer strangers.

That is all a VPN is: prove who you are, then send the traffic through an encrypted pipe so hotel Wi-Fi, home broadband and the public internet cannot read it.

How you will use it

You are moving a physical IBM i system into a cloud Power environment. The programs can stay as they are. The box will no longer sit in your own room.

Staff will still need to sign on, run the green screen, look at files and use the same tools they use today. They should not do that by typing a public address into the internet. The cloud system should stay private, like the old locked rack.

So the working day looks like this:

  1. The person starts the company VPN (from a laptop, or the office network does it for them).
  2. The laptop is now on your private road.
  3. They open the usual IBM i tools and work as before.

Office staff can have a permanent link from the building. Home and travelling staff connect when they need to. When someone leaves, you switch their VPN access off.

What it does not do

A VPN is not antivirus. It does not replace passwords, backups, or good IBM i user control. It is the front gate. You still lock the filing cabinets inside.

“Free VPN” apps from a phone store are for hiding a laptop on cafe Wi-Fi. They are not the design for payroll. You want a proper business VPN with named users, a second factor at login, and someone to call if the tunnel fails on a Thursday.

The one sentence version

Staff connect to the company tunnel first. Then they use IBM i. The system never sits on the open/insecure internet.

That is how you keep the move to the cloud from becoming a new way to leave the door open.

Do I need to use VPN? If so, which one? Is it Free? And other questions…

If you are moving a physical Power System to a cloud IBM i partition, someone will eventually say “we can just use a free VPN for connection” That sentence mixes up two different products. One is a consumer app for hiding a laptop on public Wi-Fi. The other is the private road your payroll system will travel on. This is the short version for people who sign the cheque.

What a VPN actually is

VPN means virtual private network. In plain English: an encrypted tunnel across a network you do not own, usually the public internet.

Without a tunnel, a laptop in a hotel talks to your IBM i addresses in the open. With a tunnel, that laptop (or the office firewall) first proves who it is, then all the IBM i traffic rides inside an encrypted pipe to a private network. Access Client Solutions, 5250, SQL and IFS then see private addresses, as if the LPAR was still in your computer room.

That last point matters on IBM i. Green screen, Navigator, Run SQL Scripts and IFS are not one website on port 443. They open a set of host server ports. A VPN is how you avoid publishing that whole set to the world.

A VPN is not antivirus, not a backup, and not a replacement for IBM i user security. It is the fence around the field.

Two things people call “VPN”

Consumer VPN.
An app on a phone or laptop that sends your traffic through someone else’s server so coffee-shop Wi-Fi is less ugly. Fine for a sales director on a train. Useless as the design for production IBM i.

Business VPN.
A site-to-site or client-to-site service that joins your office and your approved laptops to your cloud network (for example IBM Cloud VPC, then into Power Virtual Server). Users connect, then ACS points at a private IP. This is the one that belongs in the migration design.

If the proposal is “download a free app and type the public IP of the LPAR,” that is not a design. That is hope.

Free versus commercial

Free / DIYCommercial / enterprise
What you getA consumer app, or software such as OpenVPN or WireGuard that your team buildsA supported service: IBM Cloud VPN, a firewall vendor, or a managed SASE product
Who it is forIndividuals, labs, a proof of conceptProduction IBM i, auditors, home workers, suppliers
CostLicence looks free. Staff time, outages and incidents are notSubscription or appliance plus support. Predictable
SLA and supportNone you can put in a contractNamed support, uptime targets, someone to ring at 2 a.m.
IdentityShared password if you are luckyMFA, SSO, named users, revoke a leaver in one place
AuditLittle or no usable logConnection logs you can show an auditor
IBM i fitRarely speaks site-to-site into PowerVS the way IBM documents itSite-to-site for the office, client VPN for laptops, routing into the Power workspace
RiskFree consumer VPNs have a long history of logging, selling data, or simply vanishing. DIY means you own every certificate and every CIDR typoYou pay for a grown-up boundary. You still own IBM i profiles and *PUBLIC authorities

Open source tools are excellent components. They are not a free operations department. If you have network engineers who already run strongSwan or WireGuard properly, that can be a commercial-grade answer with a free licence. Most IBM i shops do not have that spare capacity. They have a cutover date.

What I tell the client in the room

Use a commercial path that IBM already documents for Power Virtual Server: VPN into VPC, then into the Power workspace. Client VPN for people with ACS on a sofa. Site-to-site for the office that needs the LPAR all day. MFA on the VPN login. Keep the IBM i partition off the public internet.

If someone offers a free consumer VPN as the production design, smile, thank them, and ask who is on the hook when the tunnel dies on payroll Thursday.

The applications can stay on IBM i. The rack can go to the cloud. The path in should not be the cheapest app in the store.

Until next time, keep those IBM i systems humming. And keep port 23 off the internet.

NickLitten


IBM i Software Developer, Digital Dad, AS400 Anarchist, RPG Modernizer, Shameless Trekkie, Belligerent Nerd, Englishman Abroad and Passionate Eater of Cheese and Biscuits.

Nick Litten Dot Com is a mixture of blog posts that can be sometimes serious, frequently playful and probably down-right pointless all in the space of a day.

Enjoy your stay, feel free to comment and remember: If at first you don't succeed then skydiving probably isn't a hobby you should look into.

Nick Litten

related posts:

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}

Subscribe NOW
7-day free trial

Take This Course with ALL ACCESS

Unlock your Learning Potential with instant access to every course and all new courses as they are released.
 [ For Serious Software Developers only ]

Online Learning for IBM i Software Technology Professionals

“The more that you read, the more things you will know. The more that you learn, the more places you’ll go.” – Dr. Seuss

>