Skip to content

Network & DNS

Access Policy

The script configures VPN client access along three independent axes. All three can be combined freely:

Axis Flags Default
Internet routing --route-internet / --no-route-internet Enabled (full-tunnel)
Client-to-client access --client-to-client / --no-client-to-client Disabled (isolated)
Server-side network access --local-network <CIDR> (repeatable) None

See CLI Reference — Access Policy for the full flag list.

Internet Routing (Full-Tunnel vs. Split-Tunnel)

By default (--route-internet), the script pushes redirect-gateway def1 bypass-dhcp (and redirect-gateway ipv6 / route-ipv6 2000::/3 for IPv6 clients) so that all client internet traffic goes through the VPN. Single-stack clients also get the unused protocol blocked — see Leak Prevention.

With --no-route-internet, the script does not push a default route, IPv6 leak-blocking directives, or DNS. The client's normal internet route and DNS configuration are left unchanged. This is a split-tunnel setup: only VPN subnet traffic and any local networks configured with --local-network go through the tunnel.

A DNS provider is required unless --no-route-internet is used — see DNS Configuration.

Client-to-Client Access

By default, VPN clients are isolated from each other. --client-to-client allows them to communicate directly. The installer adds the client-to-client directive to server.conf and configures matching firewall rules so the policy also applies when Data Channel Offload is active.

Server-Side Network Access

--local-network <CIDR> allows clients to reach a network on the server's side (for example, a home LAN), independent of internet routing. Repeat the flag to expose multiple networks.

  • Networks must be valid, network-aligned IPv4 or IPv6 CIDRs and must not overlap the VPN subnets (see Validation).
  • The installer pushes an explicit route for each network and adds destination-scoped NAT, so LAN devices see the connection as coming from the OpenVPN server and don't need a return route to the VPN subnet.
  • In interactive mode, the installer can suggest directly connected private networks — see Network Detection.
  • Non-interactive installs never auto-detect networks; each network needs an explicit --local-network.

Note

A LAN CIDR that overlaps the client's own local network (on the client side) can still prevent the route from working, since the client's OS would treat the network as already directly connected.

Network Configuration

Endpoint

The endpoint is the public IP address or domain name that clients use to connect to the server. It is auto-detected during installation but can be overridden:

sudo ./openvpn-install.sh install --endpoint vpn.example.com

For IPv6 endpoints:

sudo ./openvpn-install.sh install --endpoint-type 6 --endpoint 2001:db8::1

Port and Protocol

Setting Default Notes
Port 1194 Any port 1–65535 or --port-random
Protocol UDP TCP available for restrictive networks
# TCP on port 443 (bypasses most firewalls)
sudo ./openvpn-install.sh install --port 443 --protocol tcp

Tip

Use TCP/443 only when UDP is blocked. UDP provides better performance for VPN traffic.

MTU

Default tunnel MTU is 1500. Adjust if you experience fragmentation issues:

sudo ./openvpn-install.sh install --mtu 1400

Valid range: 576–65535.

IP Stack Configuration

The script supports flexible IPv4/IPv6 combinations:

Client Stack Options Description
IPv4 only --client-ipv4 (default) Clients get IPv4 addresses only
IPv6 only --no-client-ipv4 --client-ipv6 Clients get IPv6 addresses only
Dual-stack --client-ipv4 --client-ipv6 Clients get both IPv4 and IPv6

VPN Subnets

Subnet Default Option
IPv4 10.8.0.0/24 --subnet-ipv4 10.8.0.0
IPv6 fd42:42:42:42::/112 --subnet-ipv6 fd42:42:42:42::

Leak Prevention

When internet routing is enabled and a single-stack mode (IPv4-only or IPv6-only) is used, the script automatically blocks the unused protocol to prevent traffic leaks. On Windows 10+ clients, block-outside-dns is enabled to prevent DNS leaks. In split-tunnel mode (--no-route-internet), no leak-blocking directives are pushed.

DNS Configuration

DNS resolvers are only pushed to clients when internet routing is enabled (the default). With --no-route-internet, no --dns value is required and none is pushed — the client keeps its own DNS configuration.

DNS Providers

Select a DNS provider during installation with --dns <provider>:

Provider Servers Features
cloudflare 1.1.1.1, 1.0.0.1 Fast, privacy-focused (default)
google 8.8.8.8, 8.8.4.4 Widely used
quad9 9.9.9.9 Security-filtered
quad9-uncensored 9.9.9.10 Unfiltered
opendns 208.67.222.222 Content filtering
adguard 94.140.14.14 Ad-blocking DNS
nextdns — Customizable filtering
yandex 77.88.8.8 —
fdn 80.67.169.12 French Data Network
dnswatch 84.200.69.80 Privacy-focused
system — Uses system resolver
unbound — Self-hosted resolver
custom — Custom DNS servers

Custom DNS

sudo ./openvpn-install.sh install \
  --dns custom \
  --dns-primary 192.168.1.1 \
  --dns-secondary 192.168.1.2

Self-Hosted DNS with Unbound

Unbound provides a local recursive DNS resolver, improving privacy by not relying on third-party DNS servers:

sudo ./openvpn-install.sh install --dns unbound

The script handles:

  • Unbound package installation
  • Configuration at /etc/unbound/unbound.conf.d/openvpn.conf
  • Integration with existing Unbound installations
  • Automatic cleanup on uninstall

IP Forwarding

The script enables IP forwarding via /etc/sysctl.d/99-openvpn.conf, but only for address families that actually need it under the configured access policy — i.e. when internet routing, a local network, or client-to-client access is enabled for that family:

net.ipv4.ip_forward = 1               # IPv4 clients + (internet routing, a local network, or client-to-client)
net.ipv6.conf.all.forwarding = 1      # IPv6 clients + (internet routing, a local network, or client-to-client)

These settings are applied immediately and persist across reboots.