−25%

on annual Windows plans, until 31 Oct. See plans

EQVPS

How to set up an OpenVPN server on a VPS

Run your own OpenVPN server on Ubuntu or Debian with the openvpn-install script: UDP 1194 or TCP 443, client files, revoking access, and WireGuard.

WireGuard gets most of the attention these days, and for good reason. But OpenVPN still earns its place: it can run over TCP port 443, it's built into routers and corporate clients, and some networks let it through when UDP-based VPNs get blocked. If that's your situation, here's the shortest reliable way to get a server running.

What you need

1. Run the installer script

Setting up the certificate authority, keys and routing by hand is a long afternoon. The widely used openvpn-install script by angristan does it in one pass. Download it and read it before running — it's a shell script that will change your network config, and you should know what it does:

curl -O https://raw.githubusercontent.com/angristan/openvpn-install/master/openvpn-install.sh
chmod +x openvpn-install.sh
less openvpn-install.sh
sudo ./openvpn-install.sh

The script asks a handful of questions. Sensible answers:

At the end it creates the first client file, for example /root/phone.ovpn.

2. Open the port

The script sets up its own iptables rules. If you also use UFW, allow the VPN port explicitly:

sudo ufw allow 1194/udp
sudo ufw status

Swap in 443/tcp if you chose TCP.

3. Get the client file to your device

Copy the .ovpn file down over SSH:

scp -P 22 root@203.0.113.10:/root/phone.ovpn .

Import it into the OpenVPN Connect app, into NetworkManager on Linux, or into your router. The file contains the private key for that client, so treat it like a password: don't email it or leave it in a shared folder.

4. Check that it works

On the server:

systemctl list-units --type=service | grep -i openvpn
journalctl -u 'openvpn*' --since "10 min ago"

On the client, connect and look up your public IP. It should show the server's address.

Adding and revoking devices

Run the script again:

sudo ./openvpn-install.sh

It offers to add a new client, revoke one, or remove OpenVPN entirely. One client per device is worth the small effort — when a laptop gets stolen, you revoke that one file and nothing else changes.

The honest trade-offs

OpenVPN is older and heavier than WireGuard. It encrypts on one core, so on a 1-vCPU plan you won't get the full speed of a fast home connection. Handshakes are slower, and battery use on phones is higher. If none of the OpenVPN-specific features matter to you, follow our WireGuard guide instead — it's what we'd pick for most people.

Where OpenVPN wins is compatibility: TCP 443 looks like ordinary HTTPS traffic to a basic firewall, and many devices speak OpenVPN out of the box.

More background on running a personal VPN is on the VPN use-case page, and how IPv4/IPv6 work on our plans is in the network docs.

FAQ

OpenVPN or WireGuard?

WireGuard is faster, simpler and uses less CPU — pick it by default. Choose OpenVPN when you need TCP on port 443 for networks that block UDP, or when a device or company policy only supports OpenVPN.

Can I run OpenVPN on a NAT plan?

No. Clients must connect to the server from outside on UDP 1194 or TCP 443, and a NAT plan only forwards your personal SSH port. Use a dedicated-IP plan — Nano-IP at $8/month is enough for a personal VPN.

How fast will it be?

OpenVPN encrypts on a single CPU core, so one vCPU limits throughput. For browsing, streaming and remote work that's plenty; for saturating a fast home connection WireGuard does noticeably better.

How do I add or remove a device?

Run the script again. It offers to add a client (creates a new .ovpn file) or revoke an existing one. Give every device its own client so you can cut off one lost phone without touching the rest.

Does it support IPv6?

Yes. Dedicated-IP plans have both IPv4 and IPv6, and the script can route IPv6 through the tunnel when the server has an IPv6 address.

Comments

No comments yet. Be the first.

Leave a comment

Comments are moderated before they appear.