Skip to content

Quick Start

Common deployment scenarios for the OpenVPN server.

Scenario 1: Default Installation

sudo ./openvpn-install.sh install --client laptop

Result:

  • OpenVPN on port 1194/UDP
  • AES-128-GCM encryption
  • Cloudflare DNS
  • ECDSA certificate (prime256v1)
  • ~/laptop.ovpn file ready to use

Scenario 2: Corporate VPN via TCP/443

To bypass restrictive corporate/hotel/airport networks:

sudo ./openvpn-install.sh install \
  --port 443 \
  --protocol tcp \
  --dns cloudflare \
  --cipher AES-256-GCM \
  --client office-laptop

Scenario 3: Maximum Security

sudo ./openvpn-install.sh install \
  --cipher AES-256-GCM \
  --cert-type ecdsa \
  --cert-curve secp384r1 \
  --hmac SHA384 \
  --tls-version-min 1.3 \
  --tls-sig crypt-v2 \
  --client secure-device

Scenario 4: Dual-Stack IPv4 + IPv6

sudo ./openvpn-install.sh install \
  --client-ipv4 \
  --client-ipv6 \
  --subnet-ipv4 10.8.0.0 \
  --subnet-ipv6 fd42:42:42:42:: \
  --client dual-stack-device

Scenario 5: Self-Hosted DNS (Unbound)

sudo ./openvpn-install.sh install \
  --dns unbound \
  --client private-client

Scenario 6: Home VPN (Access the Home LAN, Skip Internet Routing)

Reach devices on the server's home network without routing client internet traffic through the VPN:

sudo ./openvpn-install.sh install \
  --no-route-internet \
  --local-network 192.168.1.0/24 \
  --client home-lan

Scenario 7: Client-to-Client Access

Allow VPN clients to communicate with each other directly (isolated by default):

sudo ./openvpn-install.sh install \
  --client-to-client \
  --client peer1

See Network & DNS — Access Policy for how internet routing, client-to-client access, and local-network access combine.

Connecting the Client

After installation, transfer the .ovpn file to the client device:

# Copy the file to the client
scp ~/laptop.ovpn user@client-machine:~/

# On the client machine (Linux)
sudo openvpn --config ~/laptop.ovpn

Verifying the connection

After connecting, verify the VPN is working:

# Check VPN interface
ip a show tun0

# Check routes
ip route | grep tun0

# Check public IP
curl ifconfig.me

Next Steps