Using public Wi-Fi at a coffee shop, airport, or hotel without encryption is a risk that many people underestimate. Login credentials, passwords, and session tokens can be intercepted through Man-in-the-Middle attacks or packet sniffing. The most cost-effective solution is to host your own OpenVPN server on a VPS — you get a private VPN that is not shared with strangers, has no suspicious logging policies, and is 100% under your control.
This guide walks you through turning your Ubuntu VPS into a fully functional OpenVPN server, from installation through certificate creation and client configuration, with hardening tips for maximum security.
Why Self-Host OpenVPN on a VPS?
OpenVPN is an open-source VPN solution that uses OpenSSL to encrypt traffic with AES-256 — military-grade encryption. It supports both UDP and TCP, making it more flexible than many other VPN protocols when it comes to bypassing firewalls. Here are the key reasons to run it on your own VPS:
- True privacy — You own the server. No third party is logging your activity.
- No expensive monthly subscription — A VPS costing a few hundred baht per month gives you unlimited VPN access at no extra charge.
- Control your IP — The VPS IP is what destination servers see, useful for testing your applications from a specific geographic location.
- Multi-user support — Issue separate certificates to each team member at no additional cost.
- Universal client support — Free OpenVPN clients exist for Windows, macOS, Linux, iOS, and Android.
Prerequisites
Before you begin, confirm you have the following:
| Requirement | Details | Notes |
|---|---|---|
| VPS | RAM ≥ 512 MB, 1 vCPU minimum | KVM preferred over OpenVZ (kernel modules) |
| OS | Ubuntu 22.04 LTS or 20.04 LTS | Debian 11/12 is also supported |
| Root / sudo access | SSH access as root or a sudo user | Root required to load kernel module |
| Static public IP | One static IPv4 address | Standard with all VPS plans |
| UDP 1194 open | Permitted by your VPS provider's firewall | Can switch to TCP 443 if needed |
Step 1 — Update the System and Install OpenVPN with Easy-RSA
SSH into your VPS as root and start by updating the package list and installing OpenVPN along with Easy-RSA. Easy-RSA is a Certificate Authority (CA) management toolkit that handles the authentication layer OpenVPN relies on.
# Update package list and upgrade installed packages apt update && apt upgrade -y # Install OpenVPN and Easy-RSA apt install -y openvpn easy-rsa # Verify installation openvpn --version ls /usr/share/easy-rsa/
Next, create a dedicated directory for your PKI (Public Key Infrastructure). Keeping it separate makes backups and certificate management much cleaner.
# Create Easy-RSA working directory mkdir -p /etc/openvpn/easy-rsa cp -r /usr/share/easy-rsa/* /etc/openvpn/easy-rsa/ cd /etc/openvpn/easy-rsa
Step 2 — Build the Certificate Authority and Server Certificate
Easy-RSA makes it straightforward to create a CA and issue certificates without having to write raw OpenSSL commands. Follow these steps in order:
cd /etc/openvpn/easy-rsa # Initialize the PKI directory ./easyrsa init-pki # Build the CA (press Enter at the Common Name prompt or enter a name) ./easyrsa build-ca nopass # Generate the server certificate request and sign it ./easyrsa gen-req server nopass ./easyrsa sign-req server server # Generate Diffie-Hellman parameters (may take a few minutes) ./easyrsa gen-dh # Generate a TLS authentication key for an extra security layer openvpn --genkey secret /etc/openvpn/ta.key
Once complete, copy the necessary files to the OpenVPN server directory:
# Copy certificates to /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/ca.crt /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/issued/server.crt /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/private/server.key /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/dh.pem /etc/openvpn/server/ cp /etc/openvpn/ta.key /etc/openvpn/server/
Step 3 — Create the OpenVPN Server Configuration File
Create the main server configuration file. This file defines the port, protocol, VPN subnet, DNS push settings, and encryption parameters.
cat > /etc/openvpn/server/server.conf << 'EOF' # Network settings port 1194 proto udp dev tun # Certificate files ca /etc/openvpn/server/ca.crt cert /etc/openvpn/server/server.crt key /etc/openvpn/server/server.key dh /etc/openvpn/server/dh.pem # TLS authentication tls-auth /etc/openvpn/server/ta.key 0 tls-version-min 1.2 cipher AES-256-GCM auth SHA256 # VPN subnet — assigns IPs in the 10.8.0.x range to clients server 10.8.0.0 255.255.255.0 ifconfig-pool-persist /var/log/openvpn/ipp.txt # Route all client traffic through the VPN push "redirect-gateway def1 bypass-dhcp" push "dhcp-option DNS 1.1.1.1" push "dhcp-option DNS 8.8.8.8" # Keepalive keepalive 10 120 compress lz4-v2 push "compress lz4-v2" # Drop privileges after startup user nobody group nogroup persist-key persist-tun # Logging status /var/log/openvpn/openvpn-status.log log-append /var/log/openvpn/openvpn.log verb 3 EOF # Create log directory mkdir -p /var/log/openvpn
Key settings to understand: server 10.8.0.0 255.255.255.0 defines the IP subnet assigned to VPN clients; redirect-gateway def1 forces all client traffic through the tunnel; cipher AES-256-GCM enables AES 256-bit encryption, currently the strongest cipher in common use.
Step 4 — Enable IP Forwarding and Configure the Firewall
IP forwarding allows the VPS to pass packets between the VPN tunnel interface and the primary network interface. Enable it permanently, then configure UFW and iptables NAT rules.
# Enable IP forwarding permanently echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf sysctl -p # Confirm it is active (should output: 1) cat /proc/sys/net/ipv4/ip_forward
Before configuring UFW, identify your primary network interface:
# Find the default network interface ip route | grep default # Example output: default via 192.168.1.1 dev eth0 # → interface is eth0
Edit the UFW before-rules file to insert the iptables NAT rule before the default filter rules. Replace eth0 with your actual interface name:
# Add these lines at the very top of /etc/ufw/before.rules, before *filter # Open the file with: nano /etc/ufw/before.rules # --- Content to add at the top --- # NAT table rules *nat :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.8.0.0/8 -o eth0 -j MASQUERADE COMMIT
Update the UFW default forward policy and open the OpenVPN port:
# Allow packet forwarding sed -i 's/DEFAULT_FORWARD_POLICY="DROP"/DEFAULT_FORWARD_POLICY="ACCEPT"/' /etc/default/ufw # Open port 1194/UDP for OpenVPN and ensure SSH stays open ufw allow 1194/udp ufw allow OpenSSH ufw disable && ufw enable # Verify status ufw status verbose
Step 5 — Start the OpenVPN Service
With all configuration in place, start the OpenVPN service and enable it to launch automatically on reboot:
# Start and enable the OpenVPN server systemctl start openvpn-server@server systemctl enable openvpn-server@server # Check status — should show "active (running)" systemctl status openvpn-server@server # View recent logs if there are issues journalctl -u openvpn-server@server -n 50 --no-pager
If the service started successfully, a new tun0 interface will appear:
# Confirm the tun0 interface is up ip addr show tun0 # Expected output includes: inet 10.8.0.1/24
Step 6 — Create a Client Certificate and .ovpn Config File
Each client needs its own certificate. Generate one for the first user (e.g., client1):
cd /etc/openvpn/easy-rsa # Generate and sign a client certificate ./easyrsa gen-req client1 nopass ./easyrsa sign-req client client1
Then create an all-in-one .ovpn file that embeds all certificates. This can be imported directly into any OpenVPN client application:
#!/bin/bash
# Save this as /root/make-client.sh, then run: bash /root/make-client.sh client1
CLIENT=$1
SERVER_IP="YOUR_VPS_IP" # Replace with your actual VPS IP address
cat > /root/${CLIENT}.ovpn << EOF
client
dev tun
proto udp
remote ${SERVER_IP} 1194
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
cipher AES-256-GCM
auth SHA256
compress lz4-v2
verb 3
key-direction 1
$(cat /etc/openvpn/easy-rsa/pki/ca.crt)
$(openssl x509 -in /etc/openvpn/easy-rsa/pki/issued/${CLIENT}.crt)
$(cat /etc/openvpn/easy-rsa/pki/private/${CLIENT}.key)
$(cat /etc/openvpn/ta.key)
EOF
echo "Created /root/${CLIENT}.ovpn successfully"
Run the script, then download client1.ovpn via SCP and import it into the OpenVPN GUI on Windows/macOS or OpenVPN Connect on iOS/Android.
Security tip: Before sending a .ovpn file to another user, encrypt it with gpg --symmetric client1.ovpn and share the passphrase via a separate channel (e.g., phone call or SMS). This ensures that a certificate cannot be abused even if the email delivering it is intercepted.
Verifying the Connection
Once the client connects successfully, verify that traffic is being routed through the VPN:
- Open
https://ipinfo.ioorhttps://whatismyip.com— the IP shown should be your VPS IP, not your local IP. - On the server, run
cat /var/log/openvpn/openvpn-status.logto see currently connected clients. - From the client, run
ping 10.8.0.1to test connectivity to the VPN gateway. - Run
traceroute 8.8.8.8from the client — the first hop should be10.8.0.1.
If the connection fails, inspect the server log for errors:
tail -f /var/log/openvpn/openvpn.log
Revoking a Client Certificate
When a user leaves the team or a device is lost, revoke that user's certificate immediately to block further access:
cd /etc/openvpn/easy-rsa # Revoke the certificate ./easyrsa revoke client1 # Regenerate the Certificate Revocation List ./easyrsa gen-crl # Deploy the CRL cp pki/crl.pem /etc/openvpn/server/ # Add this line to server.conf if not already present echo "crl-verify /etc/openvpn/server/crl.pem" >> /etc/openvpn/server/server.conf # Restart OpenVPN to apply systemctl restart openvpn-server@server
After revocation, the client can no longer connect even if they still have their .ovpn file. The server checks the CRL on every new connection attempt.
Frequently Asked Questions
What is the difference between OpenVPN and WireGuard?
OpenVPN is a battle-tested protocol with over 20 years of deployment history. It supports both TCP and UDP and uses a certificate-based authentication system. WireGuard is a newer protocol that is significantly faster and simpler to configure thanks to its smaller codebase. Choose OpenVPN for maximum compatibility with legacy devices or when you need to traverse restrictive firewalls over TCP 443. Choose WireGuard for speed and simplicity.
Will running OpenVPN on my VPS actually make my internet more secure?
Yes. Once connected, all traffic from your device is encrypted and routed through your VPS before reaching the internet. Your local ISP or a public Wi-Fi administrator cannot inspect the content of your traffic. The IP seen by destination servers will be your VPS IP rather than your real IP. Note that your VPS provider can still see traffic to non-HTTPS sites, as encryption terminates at the VPN server.
Which ports need to be open in the firewall for OpenVPN?
OpenVPN uses UDP port 1194 by default. Open it in UFW with ufw allow 1194/udp and enable IP forwarding in /etc/sysctl.conf by setting net.ipv4.ip_forward=1. You also need an iptables NAT masquerade rule so the VPS can forward VPN client traffic through its primary interface. To bypass restrictive firewalls, switch the protocol to TCP 443.
Can multiple users connect to the same OpenVPN server simultaneously?
Yes. OpenVPN supports multiple concurrent users. Each user needs their own certificate (generated via Easy-RSA) and their own .ovpn client config file. The maximum number of simultaneous connections depends on the CPU and RAM of the VPS. For personal use or small teams, a VPS with 1–2 vCPUs and 1–2 GB RAM handles it comfortably. New certificates can be issued at any time from the Easy-RSA directory on the server.
High-Performance KVM VPS by AsiaGB
AsiaGB VPS gives you full root access — run Docker, MySQL, Python, Node.js, and your own OpenVPN server. Starting from 399 THB/month.
View VPS Plans