The guide advocates an EC2 security group that allows everything, plus disabling the Windows firewall. That's quite insecure, and unnecessary.
It's probably better, and not more work, to create a security group that only allows:
* UDP on port 1194 (Openvpn server) * TCP on port 3389 (Remote Desktop) * ICMP (for ping)