Using public Wi-Fi at a coffee shop, airport, or hotel without encryption is a risk that many people underestimate. Login credentials, passwords, and session tokens can be intercepted through Man-in-the-Middle attacks or packet sniffing. The most cost-effective solution is to host your own OpenVPN server on a VPS — you get a private VPN that is not shared with strangers, has no suspicious logging policies, and is 100% under your control.

This guide walks you through turning your Ubuntu VPS into a fully functional OpenVPN server, from installation through certificate creation and client configuration, with hardening tips for maximum security.

Why Self-Host OpenVPN on a VPS?

OpenVPN is an open-source VPN solution that uses OpenSSL to encrypt traffic with AES-256 — military-grade encryption. It supports both UDP and TCP, making it more flexible than many other VPN protocols when it comes to bypassing firewalls. Here are the key reasons to run it on your own VPS:

Prerequisites

Before you begin, confirm you have the following:

Requirement Details Notes
VPS RAM ≥ 512 MB, 1 vCPU minimum KVM preferred over OpenVZ (kernel modules)
OS Ubuntu 22.04 LTS or 20.04 LTS Debian 11/12 is also supported
Root / sudo access SSH access as root or a sudo user Root required to load kernel module
Static public IP One static IPv4 address Standard with all VPS plans
UDP 1194 open Permitted by your VPS provider's firewall Can switch to TCP 443 if needed

Step 1 — Update the System and Install OpenVPN with Easy-RSA

SSH into your VPS as root and start by updating the package list and installing OpenVPN along with Easy-RSA. Easy-RSA is a Certificate Authority (CA) management toolkit that handles the authentication layer OpenVPN relies on.

# Update package list and upgrade installed packages
apt update && apt upgrade -y

# Install OpenVPN and Easy-RSA
apt install -y openvpn easy-rsa

# Verify installation
openvpn --version
ls /usr/share/easy-rsa/

Next, create a dedicated directory for your PKI (Public Key Infrastructure). Keeping it separate makes backups and certificate management much cleaner.

# Create Easy-RSA working directory
mkdir -p /etc/openvpn/easy-rsa
cp -r /usr/share/easy-rsa/* /etc/openvpn/easy-rsa/
cd /etc/openvpn/easy-rsa

Step 2 — Build the Certificate Authority and Server Certificate

Easy-RSA makes it straightforward to create a CA and issue certificates without having to write raw OpenSSL commands. Follow these steps in order:

cd /etc/openvpn/easy-rsa # Initialize the PKI directory ./easyrsa init-pki # Build the CA (press Enter at the Common Name prompt or enter a name) ./easyrsa build-ca nopass # Generate the server certificate request and sign it ./easyrsa gen-req server nopass ./easyrsa sign-req server server # Generate Diffie-Hellman parameters (may take a few minutes) ./easyrsa gen-dh # Generate a TLS authentication key for an extra security layer openvpn --genkey secret /etc/openvpn/ta.key

Once complete, copy the necessary files to the OpenVPN server directory:

# Copy certificates to /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/ca.crt /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/issued/server.crt /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/private/server.key /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/dh.pem /etc/openvpn/server/ cp /etc/openvpn/ta.key /etc/openvpn/server/

Step 3 — Create the OpenVPN Server Configuration File

Create the main server configuration file. This file defines the port, protocol, VPN subnet, DNS push settings, and encryption parameters.

cat > /etc/openvpn/server/server.conf << 'EOF'
# Network settings
port 1194
proto udp
dev tun

# Certificate files
ca   /etc/openvpn/server/ca.crt
cert /etc/openvpn/server/server.crt
key  /etc/openvpn/server/server.key
dh   /etc/openvpn/server/dh.pem

# TLS authentication
tls-auth /etc/openvpn/server/ta.key 0
tls-version-min 1.2
cipher AES-256-GCM
auth SHA256

# VPN subnet — assigns IPs in the 10.8.0.x range to clients
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist /var/log/openvpn/ipp.txt

# Route all client traffic through the VPN
push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 1.1.1.1"
push "dhcp-option DNS 8.8.8.8"

# Keepalive
keepalive 10 120
compress lz4-v2
push "compress lz4-v2"

# Drop privileges after startup
user nobody
group nogroup
persist-key
persist-tun

# Logging
status /var/log/openvpn/openvpn-status.log
log-append /var/log/openvpn/openvpn.log
verb 3
EOF

# Create log directory
mkdir -p /var/log/openvpn

Key settings to understand: server 10.8.0.0 255.255.255.0 defines the IP subnet assigned to VPN clients; redirect-gateway def1 forces all client traffic through the tunnel; cipher AES-256-GCM enables AES 256-bit encryption, currently the strongest cipher in common use.

Step 4 — Enable IP Forwarding and Configure the Firewall

IP forwarding allows the VPS to pass packets between the VPN tunnel interface and the primary network interface. Enable it permanently, then configure UFW and iptables NAT rules.

# Enable IP forwarding permanently
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p

# Confirm it is active (should output: 1)
cat /proc/sys/net/ipv4/ip_forward

Before configuring UFW, identify your primary network interface:

# Find the default network interface
ip route | grep default
# Example output: default via 192.168.1.1 dev eth0
# → interface is eth0

Edit the UFW before-rules file to insert the iptables NAT rule before the default filter rules. Replace eth0 with your actual interface name:

# Add these lines at the very top of /etc/ufw/before.rules, before *filter # Open the file with: nano /etc/ufw/before.rules # --- Content to add at the top --- # NAT table rules *nat :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.8.0.0/8 -o eth0 -j MASQUERADE COMMIT

Update the UFW default forward policy and open the OpenVPN port:

# Allow packet forwarding sed -i 's/DEFAULT_FORWARD_POLICY="DROP"/DEFAULT_FORWARD_POLICY="ACCEPT"/' /etc/default/ufw # Open port 1194/UDP for OpenVPN and ensure SSH stays open ufw allow 1194/udp ufw allow OpenSSH ufw disable && ufw enable # Verify status ufw status verbose

Step 5 — Start the OpenVPN Service

With all configuration in place, start the OpenVPN service and enable it to launch automatically on reboot:

# Start and enable the OpenVPN server systemctl start openvpn-server@server systemctl enable openvpn-server@server # Check status — should show "active (running)" systemctl status openvpn-server@server # View recent logs if there are issues journalctl -u openvpn-server@server -n 50 --no-pager

If the service started successfully, a new tun0 interface will appear:

# Confirm the tun0 interface is up ip addr show tun0 # Expected output includes: inet 10.8.0.1/24

Step 6 — Create a Client Certificate and .ovpn Config File

Each client needs its own certificate. Generate one for the first user (e.g., client1):

cd /etc/openvpn/easy-rsa # Generate and sign a client certificate ./easyrsa gen-req client1 nopass ./easyrsa sign-req client client1

Then create an all-in-one .ovpn file that embeds all certificates. This can be imported directly into any OpenVPN client application:

#!/bin/bash # Save this as /root/make-client.sh, then run: bash /root/make-client.sh client1 CLIENT=$1 SERVER_IP="YOUR_VPS_IP" # Replace with your actual VPS IP address cat > /root/${CLIENT}.ovpn << EOF client dev tun proto udp remote ${SERVER_IP} 1194 resolv-retry infinite nobind persist-key persist-tun remote-cert-tls server cipher AES-256-GCM auth SHA256 compress lz4-v2 verb 3 key-direction 1 $(cat /etc/openvpn/easy-rsa/pki/ca.crt) $(openssl x509 -in /etc/openvpn/easy-rsa/pki/issued/${CLIENT}.crt) $(cat /etc/openvpn/easy-rsa/pki/private/${CLIENT}.key) $(cat /etc/openvpn/ta.key) EOF echo "Created /root/${CLIENT}.ovpn successfully"

Run the script, then download client1.ovpn via SCP and import it into the OpenVPN GUI on Windows/macOS or OpenVPN Connect on iOS/Android.

Security tip: Before sending a .ovpn file to another user, encrypt it with gpg --symmetric client1.ovpn and share the passphrase via a separate channel (e.g., phone call or SMS). This ensures that a certificate cannot be abused even if the email delivering it is intercepted.

Verifying the Connection

Once the client connects successfully, verify that traffic is being routed through the VPN:

  • Open https://ipinfo.io or https://whatismyip.com — the IP shown should be your VPS IP, not your local IP.
  • On the server, run cat /var/log/openvpn/openvpn-status.log to see currently connected clients.
  • From the client, run ping 10.8.0.1 to test connectivity to the VPN gateway.
  • Run traceroute 8.8.8.8 from the client — the first hop should be 10.8.0.1.

If the connection fails, inspect the server log for errors:

tail -f /var/log/openvpn/openvpn.log

Revoking a Client Certificate

When a user leaves the team or a device is lost, revoke that user's certificate immediately to block further access:

cd /etc/openvpn/easy-rsa # Revoke the certificate ./easyrsa revoke client1 # Regenerate the Certificate Revocation List ./easyrsa gen-crl # Deploy the CRL cp pki/crl.pem /etc/openvpn/server/ # Add this line to server.conf if not already present echo "crl-verify /etc/openvpn/server/crl.pem" >> /etc/openvpn/server/server.conf # Restart OpenVPN to apply systemctl restart openvpn-server@server

After revocation, the client can no longer connect even if they still have their .ovpn file. The server checks the CRL on every new connection attempt.

Frequently Asked Questions

What is the difference between OpenVPN and WireGuard?

OpenVPN is a battle-tested protocol with over 20 years of deployment history. It supports both TCP and UDP and uses a certificate-based authentication system. WireGuard is a newer protocol that is significantly faster and simpler to configure thanks to its smaller codebase. Choose OpenVPN for maximum compatibility with legacy devices or when you need to traverse restrictive firewalls over TCP 443. Choose WireGuard for speed and simplicity.

Will running OpenVPN on my VPS actually make my internet more secure?

Yes. Once connected, all traffic from your device is encrypted and routed through your VPS before reaching the internet. Your local ISP or a public Wi-Fi administrator cannot inspect the content of your traffic. The IP seen by destination servers will be your VPS IP rather than your real IP. Note that your VPS provider can still see traffic to non-HTTPS sites, as encryption terminates at the VPN server.

Which ports need to be open in the firewall for OpenVPN?

OpenVPN uses UDP port 1194 by default. Open it in UFW with ufw allow 1194/udp and enable IP forwarding in /etc/sysctl.conf by setting net.ipv4.ip_forward=1. You also need an iptables NAT masquerade rule so the VPS can forward VPN client traffic through its primary interface. To bypass restrictive firewalls, switch the protocol to TCP 443.

Can multiple users connect to the same OpenVPN server simultaneously?

Yes. OpenVPN supports multiple concurrent users. Each user needs their own certificate (generated via Easy-RSA) and their own .ovpn client config file. The maximum number of simultaneous connections depends on the CPU and RAM of the VPS. For personal use or small teams, a VPS with 1–2 vCPUs and 1–2 GB RAM handles it comfortably. New certificates can be issued at any time from the Easy-RSA directory on the server.

High-Performance KVM VPS by AsiaGB

AsiaGB VPS gives you full root access — run Docker, MySQL, Python, Node.js, and your own OpenVPN server. Starting from 399 THB/month.

View VPS Plans

View all affordable VPS Thailand plans →