OpenVPN: Difference between revisions
m Added categories |
No edit summary |
||
| Line 1: | Line 1: | ||
== Server == | |||
== Usage == | === Setup OpenVPN using docker === | ||
To quickly get a OpenVPN server up and running, the easiest solution would be to use docker and docker-compose and the image [https://hub.docker.com/r/kylemanna/openvpn/ kylemanna/docker-openvpn]. The following instructions are outlined in the [https://github.com/kylemanna/docker-openvpn/blob/master/docs/docker-compose.md project's documentation]. | |||
Create the following docker-compose file: | |||
{{Highlight | |||
| code = version: '2' | |||
services: | |||
openvpn: | |||
cap_add: | |||
- NET_ADMIN | |||
image: kylemanna/openvpn | |||
container_name: openvpn | |||
ports: | |||
- "1194:1194/udp" | |||
restart: always | |||
volumes: | |||
- ./openvpn-data/conf:/etc/openvpn | |||
| lang = yaml | |||
}} | |||
Setup the config and PKI keys: | |||
{{Highlight | |||
| code = ## Setup the config and PKI keys: | |||
# docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM | |||
# docker-compose run --rm openvpn ovpn_initpki | |||
## Edit the OpenVPN configuration if desired. | |||
# vi openvpn-data/conf/openvpn.conf | |||
## Bring up the server | |||
# docker-compose up -d openvpn | |||
| lang = terminal | |||
}} | |||
Create clients by generating a new client certificate and the client configuration file: | |||
{{Highlight | |||
| code = ## with a passphrase (recommended) | |||
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME | |||
## -or- without a passphrase (not recommended) | |||
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME nopass | |||
## Generate the client config | |||
# docker-compose run --rm openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn | |||
| lang = terminal | |||
}} | |||
=== Configuration === | |||
The OpenVPN configuration is typically at <code>/etc/openvpn/openvpn.conf</code>. | |||
{| class="wikitable" | |||
!Description | |||
!Option | |||
|- | |||
|Disable ping-restart. Defaults to <code>keepalive 10 30</code>, which corresponds to 10 second ping intervals and 30 second ping-restart. | |||
|<code>keepalive 0 0</code> | |||
|- | |||
|Allow multiple c | |||
|} | |||
live / ping-restart | |||
Allow multiple clients to connect | |||
duplicate-cn | |||
==Client== | |||
===Usage=== | |||
To connect to a VPN, run: | To connect to a VPN, run: | ||
| Line 10: | Line 73: | ||
{{Navbox Linux}}[[Category:Linux]] | {{Navbox Linux}} | ||
[[Category:Linux]] | |||
[[Category:LinuxUtilities]] | [[Category:LinuxUtilities]] | ||
Revision as of 19:36, 16 August 2021
Server
Setup OpenVPN using docker
To quickly get a OpenVPN server up and running, the easiest solution would be to use docker and docker-compose and the image kylemanna/docker-openvpn. The following instructions are outlined in the project's documentation.
Create the following docker-compose file:
version: '2'
services:
openvpn:
cap_add:
- NET_ADMIN
image: kylemanna/openvpn
container_name: openvpn
ports:
- "1194:1194/udp"
restart: always
volumes:
- ./openvpn-data/conf:/etc/openvpn
Setup the config and PKI keys:
## Setup the config and PKI keys:
# docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM
# docker-compose run --rm openvpn ovpn_initpki
## Edit the OpenVPN configuration if desired.
# vi openvpn-data/conf/openvpn.conf
## Bring up the server
# docker-compose up -d openvpn
Create clients by generating a new client certificate and the client configuration file:
## with a passphrase (recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME
## -or- without a passphrase (not recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME nopass
## Generate the client config
# docker-compose run --rm openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn
Configuration
The OpenVPN configuration is typically at /etc/openvpn/openvpn.conf.
| Description | Option |
|---|---|
Disable ping-restart. Defaults to keepalive 10 30, which corresponds to 10 second ping intervals and 30 second ping-restart.
|
keepalive 0 0
|
| Allow multiple c |
live / ping-restart
Allow multiple clients to connect
duplicate-cn
Client
Usage
To connect to a VPN, run:
# openvpn --config config.ovpn
You will be prompted for a username and password if required.