OpenVPN: Difference between revisions
Created page with " == Usage == To connect to a VPN, run: {{highlight|lang=terminal|code= # openvpn --config config.ovpn }} You will be prompted for a username and password if required." |
No edit summary |
||
| (4 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
==Server== | |||
== Usage == | ===Setup OpenVPN using docker=== | ||
To quickly get a OpenVPN server up and running, the easiest solution would be to use docker and docker-compose and the image [https://hub.docker.com/r/kylemanna/openvpn/ kylemanna/docker-openvpn]. The following instructions are outlined in the [https://github.com/kylemanna/docker-openvpn/blob/master/docs/docker-compose.md project's documentation]. | |||
Create the following docker-compose file: | |||
{{Highlight | |||
| code = version: '2' | |||
services: | |||
openvpn: | |||
cap_add: | |||
- NET_ADMIN | |||
image: kylemanna/openvpn | |||
container_name: openvpn | |||
ports: | |||
- "1194:1194/udp" | |||
restart: always | |||
volumes: | |||
- ./openvpn-data/conf:/etc/openvpn | |||
| lang = yaml | |||
}} | |||
Setup the config and PKI keys: | |||
{{Highlight | |||
| code = ## Setup the config and PKI keys: | |||
# docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM | |||
# docker-compose run --rm openvpn ovpn_initpki | |||
## Edit the OpenVPN configuration if desired. | |||
# vi openvpn-data/conf/openvpn.conf | |||
## Bring up the server | |||
# docker-compose up -d openvpn | |||
| lang = terminal | |||
}} | |||
Create clients by generating a new client certificate and the client configuration file: | |||
{{Highlight | |||
| code = ## with a passphrase (recommended) | |||
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME | |||
## -or- without a passphrase (not recommended) | |||
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME nopass | |||
## Generate the client config | |||
# docker-compose run --rm openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn | |||
| lang = terminal | |||
}} | |||
===Configuration=== | |||
The OpenVPN configuration is typically at <code>/etc/openvpn/openvpn.conf</code>. | |||
{| class="wikitable" | |||
!Description | |||
!Option | |||
|- | |||
|Disable ping-restart. Defaults to <code>keepalive 10 30</code>, which corresponds to 10 second ping intervals and 30 second ping-restart. | |||
|<code>keepalive 0 0</code> | |||
|- | |||
|Allow multiple clients to connect | |||
|<code>duplicate-cn</code> | |||
|- | |||
|Add additional subnets to route through the VPN. The client will add a route for this particular subnet via the VPN gateway. | |||
|<code>push "route 192.168.248.0 255.255.255.0"</code> | |||
|- | |||
|Use TCP or UDP protocol. It's one or the other. You can't do both at the same time. | |||
|<code>proto tcp</code> or <code>proto udp</code> | |||
|} | |||
==Client== | |||
===Usage=== | |||
To connect to a VPN, run: | To connect to a VPN, run: | ||
| Line 8: | Line 73: | ||
You will be prompted for a username and password if required. | You will be prompted for a username and password if required. | ||
== See Also == | |||
* OpenVPN 2.4 reference manual - https://openvpn.net/community-resources/reference-manual-for-openvpn-2-4/<br /> | |||
{{Navbox Linux}} | |||
[[Category:Linux]] | |||
[[Category:LinuxUtilities]] | |||
Latest revision as of 20:44, 16 August 2021
Server
Setup OpenVPN using docker
To quickly get a OpenVPN server up and running, the easiest solution would be to use docker and docker-compose and the image kylemanna/docker-openvpn. The following instructions are outlined in the project's documentation.
Create the following docker-compose file:
version: '2'
services:
openvpn:
cap_add:
- NET_ADMIN
image: kylemanna/openvpn
container_name: openvpn
ports:
- "1194:1194/udp"
restart: always
volumes:
- ./openvpn-data/conf:/etc/openvpn
Setup the config and PKI keys:
## Setup the config and PKI keys:
# docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM
# docker-compose run --rm openvpn ovpn_initpki
## Edit the OpenVPN configuration if desired.
# vi openvpn-data/conf/openvpn.conf
## Bring up the server
# docker-compose up -d openvpn
Create clients by generating a new client certificate and the client configuration file:
## with a passphrase (recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME
## -or- without a passphrase (not recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME nopass
## Generate the client config
# docker-compose run --rm openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn
Configuration
The OpenVPN configuration is typically at /etc/openvpn/openvpn.conf.
| Description | Option |
|---|---|
Disable ping-restart. Defaults to keepalive 10 30, which corresponds to 10 second ping intervals and 30 second ping-restart.
|
keepalive 0 0
|
| Allow multiple clients to connect | duplicate-cn
|
| Add additional subnets to route through the VPN. The client will add a route for this particular subnet via the VPN gateway. | push "route 192.168.248.0 255.255.255.0"
|
| Use TCP or UDP protocol. It's one or the other. You can't do both at the same time. | proto tcp or proto udp
|
Client
Usage
To connect to a VPN, run:
# openvpn --config config.ovpn
You will be prompted for a username and password if required.
See Also
- OpenVPN 2.4 reference manual - https://openvpn.net/community-resources/reference-manual-for-openvpn-2-4/