# How to Set Up a Personal VPN with OpenVPN

> Learn to set up a personal VPN with OpenVPN quickly using the PiVPN installer on Debian. Generate client config files easily with native commands for secure remote access.

- Repository: [Michael Royal/Self-Hosting-Guide](https://github.com/mikeroyal/Self-Hosting-Guide)
- Tags: how-to-guide
- Published: 2026-06-17

---

**The fastest way to deploy a personal OpenVPN server is to run the PiVPN automated installer on a Debian-based host, then generate client configuration files using native `pivpn` commands.**

The mikeroyal/Self-Hosting-Guide repository catalogs self-hosted infrastructure tools, including a dedicated section for VPN solutions. For users looking to set up a personal VPN with OpenVPN, the guide recommends **PiVPN**—a lightweight, community-maintained installer that automates server configuration on Raspberry Pi or any Ubuntu/Debian-based system.

## Prerequisites

Before executing the installation script, prepare a fresh Debian-based system (Ubuntu Server, Raspberry Pi OS, or Debian) with a static IP address or a dynamic DNS hostname. Root privileges are required to modify network settings and install system packages.

## Installing OpenVPN with PiVPN

The Self-Hosting-Guide points to PiVPN as the canonical method for rapid OpenVPN deployment, documenting the one-line installer in [[`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md)](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md).

### Download and Run the Installer

Execute the official PiVPN installation script to automatically download dependencies, generate cryptographic keys, and configure the OpenVPN service.

```bash
curl -L https://install.pivpn.io | bash

```

This command, as referenced in the repository's VPN section, launches a text-based wizard that handles package installation, certificate generation, and service configuration without requiring manual editing of OpenVPN’s underlying configuration files.

### Configure Server Settings

During the interactive installation, the script prompts for critical parameters:
- **VPN Protocol**: Select **OpenVPN** when prompted (WireGuard is also available).
- **DNS Provider**: Choose an upstream DNS resolver (e.g., Cloudflare, Google, or custom).
- **Server Name**: Enter the hostname or public IP address reachable by external clients.
- **Port**: Accept the default **UDP 1194** or specify a custom port to bypass ISP restrictions.

## Configuring Your OpenVPN Server

After the installer completes, you must configure your network infrastructure to allow inbound encrypted connections.

### Port Forwarding and Firewall Rules

Forward the selected UDP port (default 1194) from your router to the internal IP address of your VPN host. If using `ufw` on the server, explicitly allow OpenVPN traffic:

```bash
sudo ufw allow 1194/udp

```

Additionally, ensure the server's kernel IP forwarding is enabled, which the PiVPN script typically configures in [`/etc/sysctl.conf`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main//etc/sysctl.conf) by setting `net.ipv4.ip_forward=1`.

## Creating OpenVPN Client Profiles

PiVPN simplifies client certificate management through wrapper commands that interface with OpenVPN’s Easy-RSA certificate authority.

### Generate Client Certificates

Create a new client configuration file (`.ovpn`) using the `add` subcommand:

```bash
pivpn add

```

The utility prompts for a client name and optional password, then stores the resulting profile in the `~/ovpns/` directory.

### Export Configurations to Devices

Transfer the client profile to remote devices. For mobile devices running the OpenVPN Connect app, generate a QR code for instant import:

```bash
pivpn -qr <client-name>

```

For desktop clients, securely copy the `.ovpn` file using SCP or a USB drive:

```bash
scp ~/ovpns/<client-name>.ovpn user@client-device:/path/to/config/

```

## Connecting Clients to Your Personal VPN

Import the `.ovpn` file into your preferred OpenVPN client application—such as the official OpenVPN Connect for iOS/Android or the OpenVPN GUI for Windows/Linux. Once imported, activate the connection to establish an encrypted tunnel to your personal server, routing your internet traffic through the VPN.

## Summary

- **PiVPN** is the recommended automation tool for setting up a personal VPN with OpenVPN, as documented in the mikeroyal/Self-Hosting-Guide.
- Execute `curl -L https://install.pivpn.io | bash` on a Debian-based host to install the OpenVPN server automatically.
- Use `pivpn add` to create client certificates and `pivpn -qr` to export mobile-friendly configurations.
- Forward UDP port 1194 on your router and configure firewall rules to permit remote connections.
- Transfer `.ovpn` profiles to client devices to complete the setup without manual certificate generation.

## Frequently Asked Questions

### Can I install PiVPN on a cloud VPS instead of a Raspberry Pi?

Yes. PiVPN supports any Debian or Ubuntu system, including cloud virtual private servers. Ensure the VPS has a public IP address and that the server configuration binds to the network interface associated with that IP rather than default local settings.

### What port does OpenVPN use and do I need to forward it?

By default, OpenVPN operates on **UDP port 1194**. You must forward this port on your router to the internal IP address of your VPN server to allow external clients to initiate connections. If your ISP blocks common VPN ports, select a custom high-numbered port during the PiVPN installation prompts.

### How do I revoke a client certificate if a device is lost?

Use the `pivpn revoke` command followed by the client name. This removes the certificate from the server's Certificate Revocation List (CRL) and deletes the associated `.ovpn` file, immediately blocking that specific client from connecting while preserving server and other client configurations.

### Is the PiVPN installer secure for production use?

PiVPN implements OpenVPN security best practices including strong encryption ciphers, HMAC authentication, and automated certificate generation via Easy-RSA. For high-security environments, audit the generated configuration files in [`/etc/openvpn/server.conf`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main//etc/openvpn/server.conf) and run `pivpn update` regularly to patch OpenVPN and underlying system libraries.