OpenVPN: Difference between revisions

From Leo's Notes
This page was last edited on 16 August 2021, at 19:36.
m Added categories
No edit summary
Line 1: Line 1:
== Server ==


== Usage ==
=== Setup OpenVPN using docker ===
To quickly get a OpenVPN server up and running, the easiest solution would be to use docker and docker-compose and the image [https://hub.docker.com/r/kylemanna/openvpn/ kylemanna/docker-openvpn]. The following instructions are outlined in the [https://github.com/kylemanna/docker-openvpn/blob/master/docs/docker-compose.md project's documentation].
 
Create the following docker-compose file:
{{Highlight
| code = version: '2'
services:
  openvpn:
    cap_add:
    - NET_ADMIN
    image: kylemanna/openvpn
    container_name: openvpn
    ports:
    - "1194:1194/udp"
    restart: always
    volumes:
    - ./openvpn-data/conf:/etc/openvpn
| lang = yaml
}}
Setup the config and PKI keys:
{{Highlight
| code = ## Setup the config and PKI keys:
# docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM
# docker-compose run --rm openvpn ovpn_initpki
 
## Edit the OpenVPN configuration if desired.
# vi openvpn-data/conf/openvpn.conf
 
## Bring up the server
# docker-compose up -d openvpn
| lang = terminal
}}
Create clients by generating a new client certificate and the client configuration file:
{{Highlight
| code = ## with a passphrase (recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME
## -or- without a passphrase (not recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME nopass
 
## Generate the client config
# docker-compose run --rm openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn
| lang = terminal
}}
 
=== Configuration ===
The OpenVPN configuration is typically at <code>/etc/openvpn/openvpn.conf</code>.
{| class="wikitable"
!Description
!Option
|-
|Disable ping-restart. Defaults to <code>keepalive 10 30</code>, which corresponds to 10 second ping intervals and 30 second ping-restart.
|<code>keepalive 0 0</code>
|-
|Allow multiple c
|}
live / ping-restart
 
Allow multiple clients to connect
 
duplicate-cn
 
==Client==
===Usage===
To connect to a VPN, run:
To connect to a VPN, run:


Line 10: Line 73:




{{Navbox Linux}}[[Category:Linux]]
{{Navbox Linux}}
[[Category:Linux]]
[[Category:LinuxUtilities]]
[[Category:LinuxUtilities]]

Revision as of 19:36, 16 August 2021

Server

Setup OpenVPN using docker

To quickly get a OpenVPN server up and running, the easiest solution would be to use docker and docker-compose and the image kylemanna/docker-openvpn. The following instructions are outlined in the project's documentation.

Create the following docker-compose file:

version: '2'
services:
  openvpn:
    cap_add:
     - NET_ADMIN
    image: kylemanna/openvpn
    container_name: openvpn
    ports:
     - "1194:1194/udp"
    restart: always
    volumes:
     - ./openvpn-data/conf:/etc/openvpn

Setup the config and PKI keys:

## Setup the config and PKI keys:
# docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM
# docker-compose run --rm openvpn ovpn_initpki

## Edit the OpenVPN configuration if desired.
# vi openvpn-data/conf/openvpn.conf

## Bring up the server
# docker-compose up -d openvpn

Create clients by generating a new client certificate and the client configuration file:

## with a passphrase (recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME
## -or- without a passphrase (not recommended)
# docker-compose run --rm openvpn easyrsa build-client-full $CLIENTNAME nopass

## Generate the client config
# docker-compose run --rm openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn

Configuration

The OpenVPN configuration is typically at /etc/openvpn/openvpn.conf.

Description Option
Disable ping-restart. Defaults to keepalive 10 30, which corresponds to 10 second ping intervals and 30 second ping-restart. keepalive 0 0
Allow multiple c

live / ping-restart

Allow multiple clients to connect

duplicate-cn

Client

Usage

To connect to a VPN, run:

# openvpn --config config.ovpn

You will be prompted for a username and password if required.