在咖啡馆、机场或酒店使用公共Wi-Fi而不加密,是许多人低估的安全风险。登录凭证、密码和会话令牌可能被中间人攻击(Man-in-the-Middle)或数据包嗅探所截获。最具性价比的解决方案是在VPS上自建OpenVPN服务器——你将拥有一个完全私有的VPN,不与陌生人共享,没有可疑的日志记录政策,并且100%由你掌控。

本教程将带你一步步将Ubuntu VPS配置为功能完善的OpenVPN服务器,涵盖安装、证书创建、客户端配置,以及最大化安全性的加固建议。

为什么要在VPS上自建OpenVPN?

OpenVPN是一款开源VPN解决方案,使用OpenSSL以AES-256进行流量加密——这是军事级别的加密标准。它同时支持UDP和TCP,在穿越防火墙方面比许多其他VPN协议更灵活。以下是在自己的VPS上运行OpenVPN的核心理由:

前置条件

开始之前,请确认你已具备以下条件:

要求 详情 备注
VPS RAM ≥ 512 MB,至少1个 vCPU 建议使用KVM而非OpenVZ(需要内核模块)
操作系统 Ubuntu 22.04 LTS 或 20.04 LTS 也支持 Debian 11/12
Root / sudo 权限 以root或sudo用户身份通过SSH登录 加载内核模块需要root权限
静态公网IP 一个静态IPv4地址 所有VPS套餐标配
UDP 1194 开放 VPS服务商防火墙已放行该端口 如有需要可切换为TCP 443

第一步 — 更新系统并安装 OpenVPN 与 Easy-RSA

以 root 身份通过 SSH 登录 VPS,先更新软件包列表并安装 OpenVPN 及 Easy-RSA。Easy-RSA 是一套证书颁发机构(CA)管理工具,负责处理 OpenVPN 所依赖的身份验证层。

# Update package list and upgrade installed packages
apt update && apt upgrade -y

# Install OpenVPN and Easy-RSA
apt install -y openvpn easy-rsa

# Verify installation
openvpn --version
ls /usr/share/easy-rsa/

接下来,为 PKI(公钥基础设施)创建一个专用目录。单独存放可以让备份和证书管理更加清晰有序。

# Create Easy-RSA working directory
mkdir -p /etc/openvpn/easy-rsa
cp -r /usr/share/easy-rsa/* /etc/openvpn/easy-rsa/
cd /etc/openvpn/easy-rsa

第二步 — 创建证书颁发机构与服务器证书

Easy-RSA 让创建 CA 和签发证书变得非常简单,无需手写繁琐的 OpenSSL 命令。请按顺序执行以下步骤:

cd /etc/openvpn/easy-rsa # Initialize the PKI directory ./easyrsa init-pki # Build the CA (press Enter at the Common Name prompt or enter a name) ./easyrsa build-ca nopass # Generate the server certificate request and sign it ./easyrsa gen-req server nopass ./easyrsa sign-req server server # Generate Diffie-Hellman parameters (may take a few minutes) ./easyrsa gen-dh # Generate a TLS authentication key for an extra security layer openvpn --genkey secret /etc/openvpn/ta.key

完成后,将所需文件复制到 OpenVPN 服务器目录:

# Copy certificates to /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/ca.crt /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/issued/server.crt /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/private/server.key /etc/openvpn/server/ cp /etc/openvpn/easy-rsa/pki/dh.pem /etc/openvpn/server/ cp /etc/openvpn/ta.key /etc/openvpn/server/

第三步 — 创建 OpenVPN 服务器配置文件

创建服务器主配置文件,该文件定义端口、协议、VPN 子网、DNS 推送设置以及加密参数。

cat > /etc/openvpn/server/server.conf << 'EOF'
# Network settings
port 1194
proto udp
dev tun

# Certificate files
ca   /etc/openvpn/server/ca.crt
cert /etc/openvpn/server/server.crt
key  /etc/openvpn/server/server.key
dh   /etc/openvpn/server/dh.pem

# TLS authentication
tls-auth /etc/openvpn/server/ta.key 0
tls-version-min 1.2
cipher AES-256-GCM
auth SHA256

# VPN subnet — assigns IPs in the 10.8.0.x range to clients
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist /var/log/openvpn/ipp.txt

# Route all client traffic through the VPN
push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 1.1.1.1"
push "dhcp-option DNS 8.8.8.8"

# Keepalive
keepalive 10 120
compress lz4-v2
push "compress lz4-v2"

# Drop privileges after startup
user nobody
group nogroup
persist-key
persist-tun

# Logging
status /var/log/openvpn/openvpn-status.log
log-append /var/log/openvpn/openvpn.log
verb 3
EOF

# Create log directory
mkdir -p /var/log/openvpn

几个关键设置说明:server 10.8.0.0 255.255.255.0 定义分配给 VPN 客户端的 IP 子网;redirect-gateway def1 强制所有客户端流量经过 VPN 隧道;cipher AES-256-GCM 启用 AES 256 位加密,是目前最强的常用加密算法。

第四步 — 启用 IP 转发并配置防火墙

IP 转发允许 VPS 在 VPN 隧道接口和主网络接口之间传递数据包。永久启用后,再配置 UFW 和 iptables NAT 规则。

# Enable IP forwarding permanently
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p

# Confirm it is active (should output: 1)
cat /proc/sys/net/ipv4/ip_forward

配置 UFW 之前,先确认你的主网络接口名称:

# Find the default network interface
ip route | grep default
# Example output: default via 192.168.1.1 dev eth0
# → interface is eth0

编辑 UFW 前置规则文件,在默认过滤规则之前插入 iptables NAT 规则。将 eth0 替换为你实际的网络接口名称:

# Add these lines at the very top of /etc/ufw/before.rules, before *filter # Open the file with: nano /etc/ufw/before.rules # --- Content to add at the top --- # NAT table rules *nat :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.8.0.0/8 -o eth0 -j MASQUERADE COMMIT

更新 UFW 默认转发策略并开放 OpenVPN 端口:

# Allow packet forwarding sed -i 's/DEFAULT_FORWARD_POLICY="DROP"/DEFAULT_FORWARD_POLICY="ACCEPT"/' /etc/default/ufw # Open port 1194/UDP for OpenVPN and ensure SSH stays open ufw allow 1194/udp ufw allow OpenSSH ufw disable && ufw enable # Verify status ufw status verbose

第五步 — 启动 OpenVPN 服务

完成所有配置后,启动 OpenVPN 服务并设置为开机自启:

# Start and enable the OpenVPN server systemctl start openvpn-server@server systemctl enable openvpn-server@server # Check status — should show "active (running)" systemctl status openvpn-server@server # View recent logs if there are issues journalctl -u openvpn-server@server -n 50 --no-pager

如果服务启动成功,将出现一个新的 tun0 网络接口:

# Confirm the tun0 interface is up ip addr show tun0 # Expected output includes: inet 10.8.0.1/24

第六步 — 创建客户端证书与 .ovpn 配置文件

每个客户端都需要自己的证书。以下为第一个用户(例如 client1)生成证书:

cd /etc/openvpn/easy-rsa # Generate and sign a client certificate ./easyrsa gen-req client1 nopass ./easyrsa sign-req client client1

然后创建一个包含所有证书的一体化 .ovpn 文件,可直接导入任意 OpenVPN 客户端应用:

#!/bin/bash # Save this as /root/make-client.sh, then run: bash /root/make-client.sh client1 CLIENT=$1 SERVER_IP="YOUR_VPS_IP" # Replace with your actual VPS IP address cat > /root/${CLIENT}.ovpn << EOF client dev tun proto udp remote ${SERVER_IP} 1194 resolv-retry infinite nobind persist-key persist-tun remote-cert-tls server cipher AES-256-GCM auth SHA256 compress lz4-v2 verb 3 key-direction 1 $(cat /etc/openvpn/easy-rsa/pki/ca.crt) $(openssl x509 -in /etc/openvpn/easy-rsa/pki/issued/${CLIENT}.crt) $(cat /etc/openvpn/easy-rsa/pki/private/${CLIENT}.key) $(cat /etc/openvpn/ta.key) EOF echo "Created /root/${CLIENT}.ovpn successfully"

运行脚本后,通过 SCP 下载 client1.ovpn,并将其导入 Windows/macOS 的 OpenVPN GUI 或 iOS/Android 的 OpenVPN Connect 应用。

安全提示:在将 .ovpn 文件发送给其他用户之前,请先使用 gpg --symmetric client1.ovpn 加密,并通过独立渠道(如电话或短信)分享密码。即使传递文件的邮件被截获,证书也无法被滥用。

验证连接

客户端成功连接后,验证流量是否已通过 VPN 路由:

  • 访问 https://ipinfo.io 或 https://whatismyip.com——显示的 IP 应为你的 VPS IP,而非本机 IP。
  • 在服务器上运行 cat /var/log/openvpn/openvpn-status.log,查看当前已连接的客户端。
  • 在客户端运行 ping 10.8.0.1,测试与 VPN 网关的连通性。
  • 在客户端运行 traceroute 8.8.8.8——第一跳应为 10.8.0.1。

如果连接失败,请查看服务器日志排查错误:

tail -f /var/log/openvpn/openvpn.log

吊销客户端证书

当用户离开团队或设备丢失时,应立即吊销该用户的证书以阻止进一步访问:

cd /etc/openvpn/easy-rsa # Revoke the certificate ./easyrsa revoke client1 # Regenerate the Certificate Revocation List ./easyrsa gen-crl # Deploy the CRL cp pki/crl.pem /etc/openvpn/server/ # Add this line to server.conf if not already present echo "crl-verify /etc/openvpn/server/crl.pem" >> /etc/openvpn/server/server.conf # Restart OpenVPN to apply systemctl restart openvpn-server@server

吊销后,即使客户端仍持有 .ovpn 文件,也无法再连接。服务器在每次新连接尝试时都会检查证书吊销列表(CRL)。

常见问题解答

OpenVPN 和 WireGuard 有什么区别?

OpenVPN 是经过二十余年实际部署验证的协议,同时支持 TCP 和 UDP,并采用基于证书的身份验证体系。WireGuard 是一种更新的协议,得益于其精简的代码库,配置速度更快、操作更简单。如需最大兼容性(旧设备或需要通过 TCP 443 穿越严格防火墙),选择 OpenVPN;若优先追求速度和易用性,则选择 WireGuard。

在 VPS 上运行 OpenVPN 能真正提升上网安全性吗?

可以。连接后,你设备上的所有流量都会加密并经由 VPS 转发至互联网。本地 ISP 或公共 Wi-Fi 管理员无法查看你的流量内容。目标服务器看到的 IP 将是你的 VPS IP,而非真实 IP。需要注意的是,你的 VPS 服务商仍可看到访问非 HTTPS 网站的流量,因为加密在 VPN 服务器处终止。

防火墙需要开放哪些端口?

OpenVPN 默认使用 UDP 1194 端口。通过 ufw allow 1194/udp 在 UFW 中开放该端口,并在 /etc/sysctl.conf 中设置 net.ipv4.ip_forward=1 以启用 IP 转发。同时还需要一条 iptables NAT 伪装规则,让 VPS 能将 VPN 客户端流量转发到主网络接口。如需穿越严格防火墙,可将协议切换为 TCP 443。

多个用户可以同时连接同一台 OpenVPN 服务器吗?

可以。OpenVPN 支持多用户并发连接。每个用户需要通过 Easy-RSA 生成独立的证书,并拥有自己的 .ovpn 客户端配置文件。最大并发连接数取决于 VPS 的 CPU 和内存。对于个人或小团队,配备 1–2 个 vCPU 和 1–2 GB 内存的 VPS 完全可以轻松应对。新证书可以随时从服务器上的 Easy-RSA 目录生成。

AsiaGB 高性能 KVM VPS

AsiaGB VPS 提供完整的 root 权限——运行 Docker、MySQL、Python、Node.js 以及你自己的 OpenVPN 服务器。月付仅需 399 泰铢起。

查看 VPS 方案

查看泰国VPS主机全部套餐 →