How to Set Up a Personal VPN with OpenVPN

The fastest way to deploy a personal OpenVPN server is to run the PiVPN automated installer on a Debian-based host, then generate client configuration files using native pivpn commands.

The mikeroyal/Self-Hosting-Guide repository catalogs self-hosted infrastructure tools, including a dedicated section for VPN solutions. For users looking to set up a personal VPN with OpenVPN, the guide recommends PiVPN—a lightweight, community-maintained installer that automates server configuration on Raspberry Pi or any Ubuntu/Debian-based system.

Prerequisites

Before executing the installation script, prepare a fresh Debian-based system (Ubuntu Server, Raspberry Pi OS, or Debian) with a static IP address or a dynamic DNS hostname. Root privileges are required to modify network settings and install system packages.

Installing OpenVPN with PiVPN

The Self-Hosting-Guide points to PiVPN as the canonical method for rapid OpenVPN deployment, documenting the one-line installer in [README.md](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md).

Download and Run the Installer

Execute the official PiVPN installation script to automatically download dependencies, generate cryptographic keys, and configure the OpenVPN service.

curl -L https://install.pivpn.io | bash

This command, as referenced in the repository's VPN section, launches a text-based wizard that handles package installation, certificate generation, and service configuration without requiring manual editing of OpenVPN’s underlying configuration files.

Configure Server Settings

During the interactive installation, the script prompts for critical parameters:

  • VPN Protocol: Select OpenVPN when prompted (WireGuard is also available).
  • DNS Provider: Choose an upstream DNS resolver (e.g., Cloudflare, Google, or custom).
  • Server Name: Enter the hostname or public IP address reachable by external clients.
  • Port: Accept the default UDP 1194 or specify a custom port to bypass ISP restrictions.

Configuring Your OpenVPN Server

After the installer completes, you must configure your network infrastructure to allow inbound encrypted connections.

Port Forwarding and Firewall Rules

Forward the selected UDP port (default 1194) from your router to the internal IP address of your VPN host. If using ufw on the server, explicitly allow OpenVPN traffic:

sudo ufw allow 1194/udp

Additionally, ensure the server's kernel IP forwarding is enabled, which the PiVPN script typically configures in /etc/sysctl.conf by setting net.ipv4.ip_forward=1.

Creating OpenVPN Client Profiles

PiVPN simplifies client certificate management through wrapper commands that interface with OpenVPN’s Easy-RSA certificate authority.

Generate Client Certificates

Create a new client configuration file (.ovpn) using the add subcommand:

pivpn add

The utility prompts for a client name and optional password, then stores the resulting profile in the ~/ovpns/ directory.

Export Configurations to Devices

Transfer the client profile to remote devices. For mobile devices running the OpenVPN Connect app, generate a QR code for instant import:

pivpn -qr <client-name>

For desktop clients, securely copy the .ovpn file using SCP or a USB drive:

scp ~/ovpns/<client-name>.ovpn user@client-device:/path/to/config/

Connecting Clients to Your Personal VPN

Import the .ovpn file into your preferred OpenVPN client application—such as the official OpenVPN Connect for iOS/Android or the OpenVPN GUI for Windows/Linux. Once imported, activate the connection to establish an encrypted tunnel to your personal server, routing your internet traffic through the VPN.

Summary

  • PiVPN is the recommended automation tool for setting up a personal VPN with OpenVPN, as documented in the mikeroyal/Self-Hosting-Guide.
  • Execute curl -L https://install.pivpn.io | bash on a Debian-based host to install the OpenVPN server automatically.
  • Use pivpn add to create client certificates and pivpn -qr to export mobile-friendly configurations.
  • Forward UDP port 1194 on your router and configure firewall rules to permit remote connections.
  • Transfer .ovpn profiles to client devices to complete the setup without manual certificate generation.

Frequently Asked Questions

Can I install PiVPN on a cloud VPS instead of a Raspberry Pi?

Yes. PiVPN supports any Debian or Ubuntu system, including cloud virtual private servers. Ensure the VPS has a public IP address and that the server configuration binds to the network interface associated with that IP rather than default local settings.

What port does OpenVPN use and do I need to forward it?

By default, OpenVPN operates on UDP port 1194. You must forward this port on your router to the internal IP address of your VPN server to allow external clients to initiate connections. If your ISP blocks common VPN ports, select a custom high-numbered port during the PiVPN installation prompts.

How do I revoke a client certificate if a device is lost?

Use the pivpn revoke command followed by the client name. This removes the certificate from the server's Certificate Revocation List (CRL) and deletes the associated .ovpn file, immediately blocking that specific client from connecting while preserving server and other client configurations.

Is the PiVPN installer secure for production use?

PiVPN implements OpenVPN security best practices including strong encryption ciphers, HMAC authentication, and automated certificate generation via Easy-RSA. For high-security environments, audit the generated configuration files in /etc/openvpn/server.conf and run pivpn update regularly to patch OpenVPN and underlying system libraries.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →