Customization¶
Client Configuration Template¶
The client .ovpn files are generated from a template at:
You can modify this template to add custom directives that will be included in all new client configurations.
Example: adding a custom route to push:
Note
Changes to the template only affect newly generated clients. Existing .ovpn files are not updated.
Server Configuration¶
The main server configuration file is at:
After modifying server.conf, restart the service:
Common Customizations¶
Client-to-Client Communication¶
New installs: pass --client-to-client to install, which also configures the matching firewall rules. See Network & DNS — Access Policy.
To enable it on an already-installed server without reinstalling, add the directive manually and restart:
Note
Adding the directive manually does not update the firewall rules that --client-to-client would have configured (see Firewall). Whether client-to-client traffic is actually forwarded then depends on your existing firewall setup.
Push LAN Routes¶
New installs: pass one or more --local-network <CIDR> options to install, which pushes the route and configures destination-scoped NAT and firewall rules automatically. See Network & DNS — Server-Side Network Access.
To give VPN clients access to a network on an already-installed server without reinstalling, push the route manually and restart:
Note
A manually added route does not configure the destination-scoped NAT and firewall rules that --local-network would add — see Firewall. Without matching firewall rules, the LAN host may not accept or return traffic from the VPN subnet.
Split Tunnel¶
New installs: pass --no-route-internet to install. This skips the default route, IPv6 leak-blocking directives, and DNS push entirely, and combines with --local-network to route only specific server-side networks through the VPN. See Network & DNS — Internet Routing.
To convert an already-installed full-tunnel server manually:
- Remove
push "redirect-gateway"(and, for IPv6,push "redirect-gateway ipv6"/push "route-ipv6 2000::/3") fromserver.conf - Add specific routes:
Custom Push Options¶
Batch Client Creation¶
Create multiple clients using a loop:
With password protection:
for client in alice bob charlie; do
sudo ./openvpn-install.sh client add "$client" --password "$(openssl rand -base64 16)"
done
Port 443 Multiplexing¶
If you need to run OpenVPN on TCP/443 alongside a web server, use a reverse proxy like HAProxy or SSLH to multiplex the port:
SSLH Example¶
Configure SSLH to listen on port 443 and forward:
- OpenVPN traffic to
localhost:1194 - HTTPS traffic to
localhost:8443
HAProxy Example¶
frontend https
bind *:443
mode tcp
tcp-request inspect-delay 5s
tcp-request content accept if { req.ssl_hello_type 1 }
use_backend openvpn if !{ req.ssl_hello_type 1 }
default_backend webserver
backend openvpn
mode tcp
server openvpn 127.0.0.1:1194
backend webserver
mode tcp
server web 127.0.0.1:8443
Logging¶
Custom Log Location¶
Disable File Logging¶
Use systemd journal only: