Network & DNS¶
Access Policy¶
The script configures VPN client access along three independent axes. All three can be combined freely:
| Axis | Flags | Default |
|---|---|---|
| Internet routing | --route-internet / --no-route-internet | Enabled (full-tunnel) |
| Client-to-client access | --client-to-client / --no-client-to-client | Disabled (isolated) |
| Server-side network access | --local-network <CIDR> (repeatable) | None |
See CLI Reference — Access Policy for the full flag list.
Internet Routing (Full-Tunnel vs. Split-Tunnel)¶
By default (--route-internet), the script pushes redirect-gateway def1 bypass-dhcp (and redirect-gateway ipv6 / route-ipv6 2000::/3 for IPv6 clients) so that all client internet traffic goes through the VPN. Single-stack clients also get the unused protocol blocked — see Leak Prevention.
With --no-route-internet, the script does not push a default route, IPv6 leak-blocking directives, or DNS. The client's normal internet route and DNS configuration are left unchanged. This is a split-tunnel setup: only VPN subnet traffic and any local networks configured with --local-network go through the tunnel.
A DNS provider is required unless --no-route-internet is used — see DNS Configuration.
Client-to-Client Access¶
By default, VPN clients are isolated from each other. --client-to-client allows them to communicate directly. The installer adds the client-to-client directive to server.conf and configures matching firewall rules so the policy also applies when Data Channel Offload is active.
Server-Side Network Access¶
--local-network <CIDR> allows clients to reach a network on the server's side (for example, a home LAN), independent of internet routing. Repeat the flag to expose multiple networks.
- Networks must be valid, network-aligned IPv4 or IPv6 CIDRs and must not overlap the VPN subnets (see Validation).
- The installer pushes an explicit route for each network and adds destination-scoped NAT, so LAN devices see the connection as coming from the OpenVPN server and don't need a return route to the VPN subnet.
- In interactive mode, the installer can suggest directly connected private networks — see Network Detection.
- Non-interactive installs never auto-detect networks; each network needs an explicit
--local-network.
Note
A LAN CIDR that overlaps the client's own local network (on the client side) can still prevent the route from working, since the client's OS would treat the network as already directly connected.
Network Configuration¶
Endpoint¶
The endpoint is the public IP address or domain name that clients use to connect to the server. It is auto-detected during installation but can be overridden:
For IPv6 endpoints:
Port and Protocol¶
| Setting | Default | Notes |
|---|---|---|
| Port | 1194 | Any port 1–65535 or --port-random |
| Protocol | UDP | TCP available for restrictive networks |
# TCP on port 443 (bypasses most firewalls)
sudo ./openvpn-install.sh install --port 443 --protocol tcp
Tip
Use TCP/443 only when UDP is blocked. UDP provides better performance for VPN traffic.
MTU¶
Default tunnel MTU is 1500. Adjust if you experience fragmentation issues:
Valid range: 576–65535.
IP Stack Configuration¶
The script supports flexible IPv4/IPv6 combinations:
| Client Stack | Options | Description |
|---|---|---|
| IPv4 only | --client-ipv4 (default) | Clients get IPv4 addresses only |
| IPv6 only | --no-client-ipv4 --client-ipv6 | Clients get IPv6 addresses only |
| Dual-stack | --client-ipv4 --client-ipv6 | Clients get both IPv4 and IPv6 |
VPN Subnets¶
| Subnet | Default | Option |
|---|---|---|
| IPv4 | 10.8.0.0/24 | --subnet-ipv4 10.8.0.0 |
| IPv6 | fd42:42:42:42::/112 | --subnet-ipv6 fd42:42:42:42:: |
Leak Prevention¶
When internet routing is enabled and a single-stack mode (IPv4-only or IPv6-only) is used, the script automatically blocks the unused protocol to prevent traffic leaks. On Windows 10+ clients, block-outside-dns is enabled to prevent DNS leaks. In split-tunnel mode (--no-route-internet), no leak-blocking directives are pushed.
DNS Configuration¶
DNS resolvers are only pushed to clients when internet routing is enabled (the default). With --no-route-internet, no --dns value is required and none is pushed — the client keeps its own DNS configuration.
DNS Providers¶
Select a DNS provider during installation with --dns <provider>:
| Provider | Servers | Features |
|---|---|---|
cloudflare | 1.1.1.1, 1.0.0.1 | Fast, privacy-focused (default) |
google | 8.8.8.8, 8.8.4.4 | Widely used |
quad9 | 9.9.9.9 | Security-filtered |
quad9-uncensored | 9.9.9.10 | Unfiltered |
opendns | 208.67.222.222 | Content filtering |
adguard | 94.140.14.14 | Ad-blocking DNS |
nextdns | — | Customizable filtering |
yandex | 77.88.8.8 | — |
fdn | 80.67.169.12 | French Data Network |
dnswatch | 84.200.69.80 | Privacy-focused |
system | — | Uses system resolver |
unbound | — | Self-hosted resolver |
custom | — | Custom DNS servers |
Custom DNS¶
sudo ./openvpn-install.sh install \
--dns custom \
--dns-primary 192.168.1.1 \
--dns-secondary 192.168.1.2
Self-Hosted DNS with Unbound¶
Unbound provides a local recursive DNS resolver, improving privacy by not relying on third-party DNS servers:
The script handles:
- Unbound package installation
- Configuration at
/etc/unbound/unbound.conf.d/openvpn.conf - Integration with existing Unbound installations
- Automatic cleanup on uninstall
IP Forwarding¶
The script enables IP forwarding via /etc/sysctl.d/99-openvpn.conf, but only for address families that actually need it under the configured access policy — i.e. when internet routing, a local network, or client-to-client access is enabled for that family:
net.ipv4.ip_forward = 1 # IPv4 clients + (internet routing, a local network, or client-to-client)
net.ipv6.conf.all.forwarding = 1 # IPv6 clients + (internet routing, a local network, or client-to-client)
These settings are applied immediately and persist across reboots.