WireGuard gets most of the attention these days, and for good reason. But OpenVPN still earns its place: it can run over TCP port 443, it's built into routers and corporate clients, and some networks let it through when UDP-based VPNs get blocked. If that's your situation, here's the shortest reliable way to get a server running.
What you need
- A VPS with its own public IP. Clients connect in from the internet, so a NAT plan won't work — Nano-IP at $8/month is plenty for personal use.
- Ubuntu 22.04/24.04 or Debian 12, and root or a sudo user.
- About ten minutes.
1. Run the installer script
Setting up the certificate authority, keys and routing by hand is a long afternoon. The widely used openvpn-install script by angristan does it in one pass. Download it and read it before running — it's a shell script that will change your network config, and you should know what it does:
curl -O https://raw.githubusercontent.com/angristan/openvpn-install/master/openvpn-install.sh
chmod +x openvpn-install.sh
less openvpn-install.sh
sudo ./openvpn-install.sh
The script asks a handful of questions. Sensible answers:
- IP address: your server's public IPv4 (it detects it).
- IPv6: yes, if you want IPv6 through the tunnel.
- Port:
1194for the default, or443if you plan to use TCP. - Protocol: UDP is faster; TCP gets through strict firewalls.
- DNS: any public resolver you trust.
- Compression: no. It has known security issues with encryption.
At the end it creates the first client file, for example /root/phone.ovpn.
2. Open the port
The script sets up its own iptables rules. If you also use UFW, allow the VPN port explicitly:
sudo ufw allow 1194/udp
sudo ufw status
Swap in 443/tcp if you chose TCP.
3. Get the client file to your device
Copy the .ovpn file down over SSH:
scp -P 22 root@203.0.113.10:/root/phone.ovpn .
Import it into the OpenVPN Connect app, into NetworkManager on Linux, or into your router. The file contains the private key for that client, so treat it like a password: don't email it or leave it in a shared folder.
4. Check that it works
On the server:
systemctl list-units --type=service | grep -i openvpn
journalctl -u 'openvpn*' --since "10 min ago"
On the client, connect and look up your public IP. It should show the server's address.
Adding and revoking devices
Run the script again:
sudo ./openvpn-install.sh
It offers to add a new client, revoke one, or remove OpenVPN entirely. One client per device is worth the small effort — when a laptop gets stolen, you revoke that one file and nothing else changes.
The honest trade-offs
OpenVPN is older and heavier than WireGuard. It encrypts on one core, so on a 1-vCPU plan you won't get the full speed of a fast home connection. Handshakes are slower, and battery use on phones is higher. If none of the OpenVPN-specific features matter to you, follow our WireGuard guide instead — it's what we'd pick for most people.
Where OpenVPN wins is compatibility: TCP 443 looks like ordinary HTTPS traffic to a basic firewall, and many devices speak OpenVPN out of the box.
More background on running a personal VPN is on the VPN use-case page, and how IPv4/IPv6 work on our plans is in the network docs.
Comments
No comments yet. Be the first.