OpenVPN Firewall Rules – How to Configure iptables, ufw, and firewalld on Linux?

Rajdeep Singh

Last Updated:

hero-image

A VPN connection may look active on the surface, yet traffic fails to pass through the server. In many cases, the firewall blocks the required port or prevents traffic from moving through the tunnel interface. Correct OpenVPN firewall rules resolve this by allowing the VPN port, enabling routing between interfaces, and permitting VPN clients to reach the internet.

This guide demonstrates the process of implementing OpenVPN firewall rules on a Linux VPS with the help of iptables, UFW, and firewalld. All sections are devoted to the commands that are applied by administrators who are already operating an OpenVPN server. If your server still needs the base configuration, consider the OpenVPN server setup guide before applying the firewall rules shown here.

Key Takeaways from the Article

  • OpenVPN uses UDP port 1194 as its default port, and the firewall must permit that port.
  • VPN traffic is sent via the TUN interface, and it also needs firewall permission.
  • NAT masquerading permits the VPN clients access to the external networks through the public IP address of the server.
  • Linux distributions have different firewall applications like iptables, ufw, or firewalld.
  • Rules in the firewall should remain active during a reboot so as to have a stable OpenVPN firewall configuration.

Prerequisites

Before applying any OpenVPN firewall rules, confirm that the OpenVPN service runs properly on the server.

Check the service status:

systemctl status openvpn

Administrative access through root or sudo privileges is required to change firewall rules. You may also verify the installed OpenVPN version by following this guide to check your OpenVPN version. Most servers use the following network interfaces:

  • tun0 – the OpenVPN tunnel interface
  • eth0 – the main network interface connected to the internet

Interface names can vary depending on the distribution. Always confirm the correct interface name before applying firewall commands.

Configuring OpenVPN Firewall Rules with iptables

Open UDP Port 1194

OpenVPN listens on UDP port 1194 by default. The firewall must allow inbound traffic to that port. Run the following command:

iptables -A INPUT -p udp --dport 1194 -j ACCEPT

This rule allows VPN clients to contact the OpenVPN service.

Allow TUN Interface Traffic

The tun0 interface handles encrypted VPN packets. Traffic from this interface must pass through the firewall. Add these rules:

iptables -A INPUT -i tun0 -j ACCEPT
iptables -A FORWARD -i tun0 -j ACCEPT

These commands allow VPN packets to enter the system and move through the server.

Enable Forwarding Between Interfaces

A VPN server forwards traffic between the tunnel interface and the public network interface. Add the forwarding rules:

iptables -A FORWARD -i tun0 -o eth0 -j ACCEPT
iptables -A FORWARD -i eth0 -o tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT

These rules allow VPN clients to send traffic to the internet and receive responses correctly.

Add NAT Masquerading

VPN clients receive private IP addresses. The server must translate those addresses when traffic leaves the VPS. Add the NAT rule:

iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE

This rule enables address translation for the OpenVPN subnet. A proper NAT rule is an essential part of any OpenVPN firewall setup on a Linux VPS.

Making iptables Rules Persistent

Iptables rules disappear after a reboot unless they are saved. Install the persistence package:

apt install iptables-persistent

Save the current rules:

netfilter-persistent save

The system now restores the OpenVPN firewall rules automatically after a restart.

Configuring OpenVPN Firewall Rules with ufw

Enable IP Forwarding for UFW

VPN traffic requires packet forwarding. Open the sysctl configuration file:

nano /etc/sysctl.conf

Locate the following line and ensure it appears exactly as shown:

net.ipv4.ip_forward=1

Apply the change:

sysctl -p

The system now allows traffic to move between network interfaces.

Add NAT and Masquerade Rules

Open the UFW configuration file:

nano /etc/ufw/before.rules

Add the following NAT section near the beginning of the file:

*nat
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
COMMIT

This rule allows VPN clients to reach the public internet.

Allow OpenVPN Port and Reload

Allow the OpenVPN service port:

ufw allow 1194/udp

Allow traffic to move through the tunnel interface:

ufw route allow in on tun0 out on eth0

Reload the firewall:

ufw disable
ufw enable

The server now accepts VPN traffic through the firewall. This completes the OpenVPN firewall setup that Linux administrators commonly apply with UFW.

Making UFW Rules Persistent

UFW stores firewall rules automatically. Verify the active configuration with:

ufw status

Rules remain active even after a server reboot.

Configuring OpenVPN Firewall Rules with firewalld

Add the OpenVPN Port

Allow the VPN port with the command below:

firewall-cmd --permanent --add-port=1194/udp

This rule allows VPN traffic to reach the server.

Enable Masquerading

Masquerading allows VPN client traffic to leave the server using the VPS public IP address. Run:

firewall-cmd --permanent --add-masquerade

Add Forwarding and Interface Rules

Add the tunnel interface to a trusted zone:

firewall-cmd --permanent --zone=trusted --add-interface=tun0

Allow port forwarding:

firewall-cmd --permanent --add-forward-port=port=1194:proto=udp:toport=1194

These commands complete the OpenVPN firewall setup that Linux servers use with firewalld.

Reload and Verify firewalld Rules

Apply all firewall changes:

firewall-cmd --reload

Verify the configuration:

firewall-cmd --list-all

Making Firewalld Rules Persistent

The --permanent flag ensures the firewall rules remain active after reboot. The server will retain the OpenVPN firewall rules even after system restarts.

Using TCP Port 443 as a Fallback

Some networks block uncommon ports or restrict UDP traffic. OpenVPN can also operate on TCP port 443, which is the same port used for HTTPS traffic. Edit the OpenVPN server configuration file:

port 443
proto tcp

Restart the OpenVPN service afterward:

systemctl restart openvpn

This configuration often works on restrictive networks where other VPN ports are blocked.

The Bottom Line

A VPN server depends on proper firewall access. Proper OpenVPN firewall policies enable VPN port, tunnel traffic, and packet routing between interfaces. The commands vary based on the firewall tool installed on the server, i.e., iptables, ufw, or firewalld.

Stable deployments of VPN are also important in terms of reliable infrastructure. HostSailor high-performance Linux VPS has NVMe storage and allows full root access, which is why it is suitable to use it with secure VPN services. If OpenVPN stops working after system updates, review the OpenVPN troubleshooting guide.

Frequently Asked Questions About OpenVPN Firewall Rules

What port does OpenVPN use by default, and how do I open it in my firewall?

OpenVPN uses UDP port 1194 by default. Example using iptables:

iptables -A INPUT -p udp --dport 1194 -j ACCEPT

UFW and Firewalld provide similar commands to allow the same port.

How do I allow OpenVPN traffic through iptables on a Linux VPS?

A typical OpenVPN iptables configuration includes port access, forwarding rules, and NAT masquerading. Example commands:

iptables -A INPUT -p udp --dport 1194 -j ACCEPT
iptables -A FORWARD -i tun0 -j ACCEPT
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE

These commands allow VPN connections and route traffic through the server.

Why is my OpenVPN client connecting but unable to access the internet?

The issue usually occurs when NAT or forwarding rules are missing. Confirm that the MASQUERADE rule exists and verify that IP forwarding is enabled on the server.

How do I make my OpenVPN firewall rules persist after a server reboot?

Persistence depends on the firewall tool:

  • iptables uses the iptables-persistent package
  • UFW saves rules automatically
  • firewalld requires the --permanent option

These steps ensure the OpenVPN firewall configuration remains active after reboot.

Can I run OpenVPN on TCP port 443 instead of UDP 1194?

Yes. OpenVPN supports TCP port 443 as an alternative configuration. This option helps when strict network firewalls block UDP traffic or uncommon ports. Restart the OpenVPN service after modifying the configuration.

Reliable Hosting You Can Trust

Experience lightning-fast, secure hosting that easily scales as your business grows, empowering you to succeed online effortlessly.

Start Hosting Now

Join Our Newsletter

Your information will never be Shared with third parties, and you can unsubscribe from our updates at any time.