OpenVPN Firewall Rules – How to Configure iptables, ufw, and firewalld on Linux?

A VPN connection may look active on the surface, yet traffic fails to pass through the server. In many cases, the firewall blocks the required port or prevents traffic from moving through the tunnel interface. Correct OpenVPN firewall rules resolve this by allowing the VPN port, enabling routing between interfaces, and permitting VPN clients to reach the internet.
This guide demonstrates the process of implementing OpenVPN firewall rules on a Linux VPS with the help of iptables, UFW, and firewalld. All sections are devoted to the commands that are applied by administrators who are already operating an OpenVPN server. If your server still needs the base configuration, consider the OpenVPN server setup guide before applying the firewall rules shown here.
Key Takeaways from the Article
- OpenVPN uses UDP port 1194 as its default port, and the firewall must permit that port.
- VPN traffic is sent via the TUN interface, and it also needs firewall permission.
- NAT masquerading permits the VPN clients access to the external networks through the public IP address of the server.
- Linux distributions have different firewall applications like iptables, ufw, or firewalld.
- Rules in the firewall should remain active during a reboot so as to have a stable OpenVPN firewall configuration.
Prerequisites
Before applying any OpenVPN firewall rules, confirm that the OpenVPN service runs properly on the server.
Check the service status:
systemctl status openvpn
Administrative access through root or sudo privileges is required to change firewall rules. You may also verify the installed OpenVPN version by following this guide to check your OpenVPN version. Most servers use the following network interfaces:
tun0– the OpenVPN tunnel interfaceeth0– the main network interface connected to the internet
Interface names can vary depending on the distribution. Always confirm the correct interface name before applying firewall commands.
Configuring OpenVPN Firewall Rules with iptables
Open UDP Port 1194
OpenVPN listens on UDP port 1194 by default. The firewall must allow inbound traffic to that port. Run the following command:
iptables -A INPUT -p udp --dport 1194 -j ACCEPT
This rule allows VPN clients to contact the OpenVPN service.
Allow TUN Interface Traffic
The tun0 interface handles encrypted VPN packets. Traffic from this interface must pass through the firewall. Add these rules:
iptables -A INPUT -i tun0 -j ACCEPT iptables -A FORWARD -i tun0 -j ACCEPT
These commands allow VPN packets to enter the system and move through the server.
Enable Forwarding Between Interfaces
A VPN server forwards traffic between the tunnel interface and the public network interface. Add the forwarding rules:
iptables -A FORWARD -i tun0 -o eth0 -j ACCEPT iptables -A FORWARD -i eth0 -o tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT
These rules allow VPN clients to send traffic to the internet and receive responses correctly.
Add NAT Masquerading
VPN clients receive private IP addresses. The server must translate those addresses when traffic leaves the VPS. Add the NAT rule:
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
This rule enables address translation for the OpenVPN subnet. A proper NAT rule is an essential part of any OpenVPN firewall setup on a Linux VPS.
Making iptables Rules Persistent
Iptables rules disappear after a reboot unless they are saved. Install the persistence package:
apt install iptables-persistent
Save the current rules:
netfilter-persistent save
The system now restores the OpenVPN firewall rules automatically after a restart.
Configuring OpenVPN Firewall Rules with ufw
Enable IP Forwarding for UFW
VPN traffic requires packet forwarding. Open the sysctl configuration file:
nano /etc/sysctl.conf
Locate the following line and ensure it appears exactly as shown:
net.ipv4.ip_forward=1
Apply the change:
sysctl -p
The system now allows traffic to move between network interfaces.
Add NAT and Masquerade Rules
Open the UFW configuration file:
nano /etc/ufw/before.rules
Add the following NAT section near the beginning of the file:
*nat :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE COMMIT
This rule allows VPN clients to reach the public internet.
Allow OpenVPN Port and Reload
Allow the OpenVPN service port:
ufw allow 1194/udp
Allow traffic to move through the tunnel interface:
ufw route allow in on tun0 out on eth0
Reload the firewall:
ufw disable ufw enable
The server now accepts VPN traffic through the firewall. This completes the OpenVPN firewall setup that Linux administrators commonly apply with UFW.
Making UFW Rules Persistent
UFW stores firewall rules automatically. Verify the active configuration with:
ufw status
Rules remain active even after a server reboot.
Configuring OpenVPN Firewall Rules with firewalld
Add the OpenVPN Port
Allow the VPN port with the command below:
firewall-cmd --permanent --add-port=1194/udp
This rule allows VPN traffic to reach the server.
Enable Masquerading
Masquerading allows VPN client traffic to leave the server using the VPS public IP address. Run:
firewall-cmd --permanent --add-masquerade
Add Forwarding and Interface Rules
Add the tunnel interface to a trusted zone:
firewall-cmd --permanent --zone=trusted --add-interface=tun0
Allow port forwarding:
firewall-cmd --permanent --add-forward-port=port=1194:proto=udp:toport=1194
These commands complete the OpenVPN firewall setup that Linux servers use with firewalld.
Reload and Verify firewalld Rules
Apply all firewall changes:
firewall-cmd --reload
Verify the configuration:
firewall-cmd --list-all
Making Firewalld Rules Persistent
The --permanent flag ensures the firewall rules remain active after reboot. The server will retain the OpenVPN firewall rules even after system restarts.
Using TCP Port 443 as a Fallback
Some networks block uncommon ports or restrict UDP traffic. OpenVPN can also operate on TCP port 443, which is the same port used for HTTPS traffic. Edit the OpenVPN server configuration file:
port 443 proto tcp
Restart the OpenVPN service afterward:
systemctl restart openvpn
This configuration often works on restrictive networks where other VPN ports are blocked.
The Bottom Line
A VPN server depends on proper firewall access. Proper OpenVPN firewall policies enable VPN port, tunnel traffic, and packet routing between interfaces. The commands vary based on the firewall tool installed on the server, i.e., iptables, ufw, or firewalld.
Stable deployments of VPN are also important in terms of reliable infrastructure. HostSailor high-performance Linux VPS has NVMe storage and allows full root access, which is why it is suitable to use it with secure VPN services. If OpenVPN stops working after system updates, review the OpenVPN troubleshooting guide.
Frequently Asked Questions About OpenVPN Firewall Rules
What port does OpenVPN use by default, and how do I open it in my firewall?
OpenVPN uses UDP port 1194 by default. Example using iptables:
iptables -A INPUT -p udp --dport 1194 -j ACCEPT
UFW and Firewalld provide similar commands to allow the same port.
How do I allow OpenVPN traffic through iptables on a Linux VPS?
A typical OpenVPN iptables configuration includes port access, forwarding rules, and NAT masquerading. Example commands:
iptables -A INPUT -p udp --dport 1194 -j ACCEPT iptables -A FORWARD -i tun0 -j ACCEPT iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
These commands allow VPN connections and route traffic through the server.
Why is my OpenVPN client connecting but unable to access the internet?
The issue usually occurs when NAT or forwarding rules are missing. Confirm that the MASQUERADE rule exists and verify that IP forwarding is enabled on the server.
How do I make my OpenVPN firewall rules persist after a server reboot?
Persistence depends on the firewall tool:
- iptables uses the
iptables-persistentpackage - UFW saves rules automatically
- firewalld requires the
--permanentoption
These steps ensure the OpenVPN firewall configuration remains active after reboot.
Can I run OpenVPN on TCP port 443 instead of UDP 1194?
Yes. OpenVPN supports TCP port 443 as an alternative configuration. This option helps when strict network firewalls block UDP traffic or uncommon ports. Restart the OpenVPN service after modifying the configuration.