How to Configure OpenVPN Server on Linux? Step-by-Step Guide

Rajdeep Singh

Last Updated:

hero-image

Running your own VPN server will give you total command of your network. Instead of going to third-party providers, you can install a secure tunnel in your VPS. This approach provides greater privacy, flexibility, and control over encryption and routing policies.

ra. It is well encrypted, multifaceted, authenticated, and compatible with a variety of operating systems. OpenVPN is frequently used in production VPN environments by administrators for its stability.

This is a tutorial on how to create an entire OpenVPN server system Linux environment under Ubuntu 22.04 or Debian 12. You will also create the profile of a client and validate the VPN connection. Before starting this configuration, you should consider comparing OpenVPN and WireGuard in case you are still trying to decide what VPN protocol to use.

Key Takeaways from the Article

  • Installing OpenVPN and Easy-RSA constructs an OpenVPN VPS complete environment on Linux.

  • The OpenVPN server configuration file comprises ports, encryption, DNS, and routing.

  • VPN clients can use the internet via IP forwarding and firewall regulations.

  • Testing commands ensure that traffic flows through the VPN tunnel.

Prerequisites for Configuring OpenVPN Server on Linux

The following OpenVPN Linux tutorial is targeted at a VPS environment, although a couple of requirements are necessary. These prerequisites are useful in preventing a configuration error in the process.

To begin with, you must have a Linux VPS running Ubuntu 22.04 or Debian 12. These distributions have current system libraries and systemd service administration. OpenVPN and Easy-RSA packages are supported in both operating systems via official repositories.

Your server should also have:

  • At least 256 MB RAM, though 1 GB is recommended for multiple users

  • A static public IP address

  • Root or sudo access

  • SSH connectivity

Also, you are expected to be at ease with simple terminal commands. The majority of the configuration processes involve modification of files, execution of services in the system, and issuing certificates via command lines.

If OpenVPN is installed on your server, make sure the version installed is compatible. Older constructions can introduce configuration bugs or cipher compatibility issues. To check version details, you may use the following guide: Check your OpenVPN version before starting.

 

Lastly, make sure that your VPS supports custom firewall rules and IP forwarding. These are the features that are needed when addressing VPN traffic. Once these are ready, one can safely install OpenVPN on Linux and continue working on configuring the VPN server.

A Detailed Process to Configure an OpenVPN Server on Linux

The step-by-step process of configuring OpenVPN Ubuntu systems is described as follows. Each configuration builds on the previous configuration. So be careful of the order.

Step 1: Install OpenVPN and Easy-RSA

The first step is the installation of two core elements of a VPN server. The VPN Daemon is run using OpenVPN, and the certificates and keys are handled using Easy-RSA.

 

Start by updating a package repository.

 

sudo apt update

 



Install OpenVPN and Easy-RSA now.

 

 

sudo apt install openvpn easy-rsa -y



Once installed, check the software versions.

openvpn --version

easyrsa --version



In case both commands provide version output, the installation was successful. Here we have the basic software needed to install OpenVPN on Linux. Nevertheless, even OpenVPN, prior to starting up, needs cryptographic certificates. Thus, the next step is to generate the certificate authority that will sign all VPN certificates.

 

Step 2: Set Up the Certificate Authority (CA)

The Certificate Authority signs each certificate you use in the VPN. It serves as the basis of trust for the server as well as for all future clients. With this configuration, CA resides in the same machine as the VPN server.

 

The first thing you need to do is to make a specific directory with Easy-RSA and begin the PKI:

 

make-cadir ~/easy-rsa

cd ~/easy-rsa

./easyrsa init-pki

 

Next, build the CA. The following command will require you to enter a Common Name. You are either able to take the default or put something descriptive, such as OpenVPN-CA:

 

./easyrsa build-ca nopass

The nopass flag generates a key in CA with no passphrase. This can be tolerated in a dedicated VPS in which the key does not leave the server.

Step 3: Generate Server Certificates and Keys

Having the CA, create files signifying your OpenVPN server: a certificate, a private key, Diffie-Hellman parameters, and a TLS-auth HMAC key.

 

Create the server certificate request and sign it with the CA:

 

./easyrsa gen-req server nopass

./easyrsa sign-req server server

 

Type “Yes” when Easy-RSA requires confirmation. Then make the Diffie-Hellman parameters:

 

./easyrsa gen-dh



Lastly, create a TLS-auth key. This provides an additional HMAC layer of protection on the control channel against a denial-of-service attack:

 

openvpn --genkey secret ta.key

 

At this point, make a copy of all the necessary files into the OpenVPN configuration directory:

 

sudo cp pki/ca.crt pki/issued/server.crt pki/private/server.key pki/dh.pem ta.key /etc/openvpn/server/

 

This is where /etc/openvPN/server/ is supposed to have five files: ca.crt, server.crt, server.key, dh.pem, and ta.key.

Step 4: Configure the OpenVPN Server Configuration File

In the OpenVPN server configuration file, you define the VPN's behaviour. Each directive governs a certain section within the tunnel. Spend time in this stage, as most of the post-set-up problems are related to a misconfigured command.

 

Prepare the configuration file in the directory /etc/openvpn/server.conf:

 

sudo nano /etc/openvpn/server.conf

 

Add the following directives. They are described in-line below the block:

 

port 1194

proto udp

dev tun

ca /etc/openvpn/server/ca.crt

cert /etc/openvpn/server/server.crt

key /etc/openvpn/server/server.key

dh /etc/openvpn/server/dh.pem

tls-auth /etc/openvpn/server/ta.key 0

server 10.8.0.0 255.255.255.0

push "redirect-gateway def1 bypass-dhcp"

push "dhcp-option DNS 1.1.1.1"

push "dhcp-option DNS 9.9.9.9"

keepalive 10 120

data-ciphers AES-256-GCM:AES-128-GCM

cipher AES-256-GCM

user nobody

group nogroup

persist-key

persist-tun

status /var/log/openvpn-status.log

verb 3



Key Configuration Directives

OpenVPN has a number of major directives determining the manner in which the VPN server is run. These settings regulate the port that is listened to, the protocol, the network interface, the client subnet, the DNS behavior, and the stability of connections. Knowing them will enable you to have a stable and predictable VPN environment.

  • port 1194: The port directive is a listening port of open VPN. The default port of the server is 1194. The majority of deployments retain this value since it corresponds to the default OpenVPN settings, and it is easy to set up clients. Clients make contact with this port in order to create the VPN tunnel.

  • proto udp: The proto directive specifies the transport protocol. UDP is more resistant to overhead and faster at packet transmission than TCP. Consequently, VPN traffic tends to perform better in UDP. Many administrators select UDP unless the network blocks it.

  • dev tun: The directive dev determines the type of virtual interface. Setting dev tun will set up a routed interface, which will pass IP packets through the tunnel. This creates an OpenVPN tun interface on Linux, through which encrypted traffic is passed between the server and the clients.

  • server 10.8.0.0/24: The server directive determines the inner VPN subnet. The network 10.8.0.0/24 has addresses for client connections. The server normally acquires the first address, with other devices getting the rest of the addresses.

  • push DNS directives: These commands provide DNS resolver configurations to customers. Consequently, the client devices are used to resolve domain names via the VPN tunnel.

  • keepalive settings: Keepalive messages are periodic messages that are sent between the server and clients. This is used to ensure steady connections between NAT devices.

Step 5: Enable IP Forwarding

Your VPS will have packets to pass between the VPN subnet and the public internet. Without IP forwarding, clients can make connections, but they cannot access external addresses.

 

Open the sysctl configuration file:

 

sudo nano /etc/sysctl.conf

 

Find the next line and uncomment it (or insert it if it is not present):

 

net.ipv4.ip_forward = 1

 

Implement the change as soon as possible:

 

sudo sysctl -p

 

Output should indicate that net.ipv4.ip_forward = 1. With it, now your server is ready to pass VPN traffic to the external world.

Step 6: Configure Firewall Rules

Two modifications will be required of the firewall: permit inbound traffic over the OpenVPN port, and masquerade outbound VPN traffic in order to appear to have originated at the public IP address of the server.

 

In case you use UFW, the following commands should be run:



sudo ufw allow 1194/udp

sudo ufw allow OpenSSH

 

Then add a NAT masquerade rule. Open the UFW before.rules file:

 

sudo nano /etc/ufw/before.rules

 

The following lines should be placed at the beginning of the file, above the current *filter block. Substitute eth0 with the real name of the public interface of your server, in case they are not the same:

 

*nat

:POSTROUTING ACCEPT [0:0]

-A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE

COMMIT

 

Then enable UFW:

 

sudo ufw enable



These policies permit VPN users to use other networks. Details of configuring the firewall, if required, are detailed in the OpenVPN firewall configuration guide.

Step 7: Configure DNS

You have already done this in Step 4 by pushing DNS resolver addresses to customers through the server configuration file. This section discusses what occurs on the client side when such pushed settings have reached the client side.

 

Server side (already done): The push of the DHCP option DNS and parameters in the server.conf instruct each client as to which DNS servers to use when the tunnel is up.

 

Client side (systemd-resolved): The majority of current Ubuntu and Debian systems employ systemd-resolved to handle DNS. The update-systemd-resolved script is required to make the pushed DNS settings effective. Install it on the client machine:



sudo apt install openvpn-systemd-resolved -y

 

Then append the following lines to the .ovpn profile of the client:

 

script-security 2

up /etc/openvpn/update-systemd-resolved

down /etc/openvpn/update-systemd-resolved

down-pre

 

Client side (update-resolv-conf) On systems without systemd-resolved, write the update-resolv-conf script and add up/down directives similar to /etc/openvpn/update-resolv-conf in the client profile.

 

To check the DNS resolution over the tunnel, connect a client and run:



resolvectl status tun0

 

The output would list the DNS servers you pushed to the server configuration.

 

Step 8: Start and Enable the OpenVPN Service

Everything is in place. Start the OpenVPN service and enable it in such a way that it starts automatically only after a reboot:

 

sudo systemctl start openvpn@server

sudo systemctl enable openvpn@server

 

To verify that the service is active, check its status:

 

sudo systemctl status openvpn@server

 

In the output, you should see "active (running)". Check also that the TUN interface is present:

 

ip addr show tun0



When tun0 is shown with address 10.8.0.1 the server is ready and listening to connections.

Step 9: Generate Client Configuration

Every client should have its certificate and a single .ovpn profile. Create a certificate and key out of your Easy-RSA directory:

 

cd ~/easy-rsa

./easyrsa gen-req client1 nopass

./easyrsa sign-req client client1

 

Now create a single .ovpn that incorporates all the certificates and keys:

 

cat > ~/client1.ovpn <<'EOF'

client

dev tun

proto udp

remote YOUR_SERVER_IP 1194

resolv-retry infinite

nobind

persist-key

persist-tun

remote-cert-tls server

data-ciphers AES-256-GCM:AES-128-GCM

cipher AES-256-GCM

key-direction 1

verb 3

EOF



Then attach the certificate and key materials:



echo '<ca>'>> ~/client1.ovpn

cat ~/easy-rsa/pki/ca.crt >> ~/client1.ovpn

echo '</ca>'>> ~/client1.ovpn

 

echo '<cert>'>> ~/client1.ovpn

sed -n '/BEGIN/,/END/p' ~/easy-rsa/pki/issued/client1.crt >> ~/client1.ovpn

echo '</cert>'>> ~/client1.ovpn

 

echo '<key>'>> ~/client1.ovpn

cat ~/easy-rsa/pki/private/client1.key >> ~/client1.ovpn

echo '</key>'>> ~/client1.ovpn

 

echo '<tls-auth>'>> ~/client1.ovpn

cat /etc/openvpn/server/ta.key >> ~/client1.ovpn

echo '</tls-auth>'>> ~/client1.ovpn



Change YOUR_SERVER_IP with your VPS public IP address. Copy the completed. ovpn file to your client device with scp or sftp:

 

scp ~/client1.ovpn user@client-machine:~/

 

Step 10: Test the Connection

Connect to the client machine with the profile you have just transferred:

 

sudo openvpn --config ~/client1.ovpn

 

Wait until one gets the message "Initialization Sequence Completed". Next, open a second terminal on a client and do the following checks:

 

Check VPN IP assignment: 

 

ip addr show tun0



There should be an address in the range of 10.8.0.0/24.

 

Check traffic paths using the VPN: 



curl ifconfig.me



The output must show your VPS public IP and not the local IP of the client. This is to make sure that the tunnel is directing all the traffic.

 

Ping the server's VPN address: 

 

ping -c 4 10.8.0.1

 

Once all three checks are successful, your OpenVPN server is fully operational.

Troubleshooting Quick Checks

When something goes wrong, but you are not sure what, begin by checking these four quick things, and then you can get down to business:

 

  1. Check OpenVPN logs. To view recent log entries, run journalctl -u openvpn@server -no-pager -n 50. Check for certificate errors, port conflicts, or missing files.

  2. Verify the TUN interface. Run ip addr show tun0. The non-existence of the interface prevented OpenVPN from starting. Return to the logs of the particular error.

  3. Confirm IP forwarding. Run sysctl net.ipv4.ip_forward. If the value is 0, revisit Step 5.

  4. Check the firewall. Check sudo ufw status verbose and ensure port 1194/udp is open. Check also that there is the NAT masquerade rule in /etc/ufw/before.rules.

 

To get more information about troubleshooting, see the OpenVPN troubleshooting guide.

The Bottom Line 

OpenVPN on a Linux VPS is a potent and versatile solution for a personal network. This guide has installed OpenVPN, a certificate authority, and the encryption keys. You have also configured the file of the OpenVPN server configuration, turned on IP forwarding, and firewall rules.

Lastly, you created a client profile and ensured that the VPN tunnel functioned properly.

Constant VPN performance requires a dependable VPS platform. In case you are interested in having a high-performing, but stable server for VPN, consider a Linux VPS with HostSailor. Our KVM NVMe infrastructure is fast and scalable enough to handle secure VPNs.

Frequently Asked Questions About OpenVPN Configuration

What is the default port of OpenVPN, and would you change it?

The default port of OpenVPN is 1194 in UDP. This port tends to be appropriate in most deployments, and it is the default port of the OpenVPN servers. However, some administrators change the port to go around blocking firewalls or Internet service provider blocking. Remember to make amends to firewall rules and all the client configuration files when you make changes to the port in the server configuration.

How many connections can the OpenVPN server of a single VPS have?

The major factors that define the number of clients that can be supported are CPU power, RAM, and bandwidth. The average VPS is 10-20 users online and browsing at the same time, with a memory RAM of 1 GB and a single-core CPU, and moderate traffic. In the case of acceleration of encryption and bandwidth to accommodate the acceleration, the faster the servers, the more dozens, or even hundreds, of clients can be served.

Can OpenVPN and WireGuard be used in the same VPS?

No, neither OpenVPN nor WireGuard will be competing. The VPN protocols create a virtual network interface each and are listening on different ports. For example, OpenVPN may utilise tun0, but in the case of WireGuard, we may utilise wg0. The two services are able to operate simultaneously, provided there is no overlap in the VPN subnets.

How can a client certificate in Open VPN be revoked?

Client certificate revocation must not enable a device to renew a login to the VPN. The said client certificate can be revoked using Easy-RSA. On revocation, issue a certificate revocation list (CRL) and place a copy in the open VPN configuration directory. Finally, restart OpenVPN to reload the revocation list on the server.

Does OpenVPN work with non-permissive NAT or firewall?

Yes, OpenVPN can be configured as a NAT-behind configuration because it periodically sends keepalive packets. These packets guarantee the connection with the help of the router and firewalls. In case a network blocks UDP traffic, the administrators tend to configure Open VPN to TCP port 443. This will allow the VPN traffic to be presented as if it is linked with HTTPS, which will help to circumvent network filters.

Reliable Hosting You Can Trust

Experience lightning-fast, secure hosting that easily scales as your business grows, empowering you to succeed online effortlessly.

Start Hosting Now

Join Our Newsletter

Your information will never be Shared with third parties, and you can unsubscribe from our updates at any time.