OpenVPN on Linux

OpenVPN On A Machine You Already Own

A rented VPS, a dedicated server, a mini PC under the desk, or a Raspberry Pi that has been sitting in a drawer since you bought it. Any of them runs a VPN server perfectly well. We install it, harden the machine around it, and hand you config files for Windows, macOS, Linux, Android and iOS.

OpenVPN is the older choice and still the useful one, because it runs over TCP port 443 where the traffic looks like ordinary web browsing. That is why it connects on hotel and office networks that quietly drop everything else, and why it is worth having even when something faster is your daily driver.

Ubuntu, Debian, Red Hat and most things descended from them. Root access is all we need, and the credentials come back to you when the work is finished.

What It Runs On

OpenVPN asks very little of a machine, so the choice is about where the server sits rather than how powerful it is. A box in your house gives you your own home address and is limited by your upload speed. A rented one gives you speed and a different country. Both are fine, and they solve genuinely different problems.

Most common

A VPS You Rent

Five to fifteen dollars a month, in whatever country suits you, on a connection far faster than anything at home. Nothing to keep powered, nothing to replace when it dies, and the whole thing is rebuilt in an afternoon if you ever want to move region.

Best for speed, a country that is not yours, and never thinking about hardware.
Home hardware

A Raspberry Pi

A Pi 4 or 5 handles a household comfortably and draws about as much power as a phone charger, so leaving it running costs a few dollars a year. It is the cheapest way to reach your own home network from outside, and the one most people already have the parts for.

Best for reaching home from elsewhere, on a budget that is basically zero.
Home hardware

A Mini PC Or Old Laptop

More capable than a Pi and still quiet enough to sit on a shelf. If you already run something at home for files or media, the VPN goes on the same machine rather than adding another one, and it will not notice the extra work.

Best for households already running a home server for something else.
Rented

A Dedicated Server

More machine than a VPN needs on its own, which is why this usually makes sense when the box is already doing something else. The tunnel becomes one more service on hardware you are paying for anyway rather than a reason to rent anything.

Best for adding a tunnel to a server that already earns its keep.
Cloud

AWS, Azure Or Google Cloud

Worth it when the point is reaching a private network you already run there. As a plain VPN it costs more than a small provider and bills you for outbound traffic, which surprises people the first month if nobody warned them.

Best for tunnels into cloud infrastructure you already have.
Already yours

Something Else Entirely

An old NAS running Linux, a virtual machine on a desktop, a spare instance somebody set up years ago and forgot. If it runs a supported distribution and you can reach it, it will almost certainly do this job as well.

Best for using what is already there rather than buying anything.

The one number that decides a home setup

Whatever your house can upload is the fastest you will ever download through it. A forty megabit upload means about forty megabits in your hotel room on a good night, no matter which Pi or mini PC is doing the work. Symmetric fibre makes this a non issue, and an older line sitting at ten will feel it the moment you move anything large.

If the real goal is arriving on your home address while you travel rather than running a server, the travel router setup does that with less to go wrong. And if the destination is China, the protocol choice matters more than the hardware, which the server built for those conditions covers properly.

What Goes On The Machine

The install itself is quick, and the settings around it are what decide whether the tunnel actually works everywhere you take it. Everything below happens in one session, and nothing is left half configured for you to finish off later.

The tunnel

OpenVPN on TCP port 443

Which is the whole reason to choose it. Traffic on that port looks like ordinary web browsing to anything inspecting the connection, so it gets through hotel, airport and office networks that block everything else. A UDP profile goes on as well for the days you want the speed instead.

Certificates rather than a shared password

Each device gets its own certificate, so a lost phone means revoking one and nothing changes for anything else you own. The certificate authority stays on the server and the keys are handed to you, with no copy kept on our side.

The packet size sorted properly

Get this wrong and the tunnel connects, small pages load, and anything larger hangs forever with no error. It is the single most common reason a self installed OpenVPN feels broken, and it takes two minutes to fix when you know to look.

Around it

DNS pointed down the tunnel

Otherwise your traffic is encrypted while the list of everywhere you are going still goes to whatever the local network hands out. On a home server this also means your own internal names keep resolving from outside the house.

A firewall that drops rather than answers

Everything closed except the tunnel and your own way in. Key based login only, root login off, and automatic blocking for whatever keeps trying, because a machine on a public address collects login attempts from the hour it appears.

It comes back after a reboot

The service starts on its own after a power cut, and on a home box that matters more than anything else here. A Pi that needs somebody to log in and start it is no use at all when you are the one who is away.

Getting on it

A file for every device you own

Windows, macOS, Linux, Android and iOS, each with its own profile rather than one passed around. Phones connect by scanning a code, and the desktop clients are the standard free ones, so there is nothing branded to install or keep licensed.

Reaching a home network, not just the internet

Where the server sits at your house, the setup can route you into the whole network rather than only out to the internet. Printer, network drive, cameras and anything else on it, available from wherever you happen to be.

Adding a device later, written down

Issuing another profile is a short procedure, and you get it in plain language rather than a link to a forum thread. New laptop next year does not mean coming back to us unless you want to.

The part worth paying for

Installing OpenVPN takes about ten minutes and there are a hundred guides showing you how. What takes an evening the first time is the packet size, the DNS handling, the firewall rules and getting certificates right, and every one of those produces a tunnel that looks connected while something quietly does not work.

If you would rather do it yourself, the guides are genuinely fine and we would not pretend otherwise. This is for people who want it working today and documented well enough that the next change is easy.

Packages And What They Cost

Priced per job, paid once, with no subscription attached to anything we hand over. Pick by how many devices need to connect and whether the machine is going to reach your home network as well as the internet.

One machine

Standard Install

One server, up to five devices. The right pick for a VPS you rent and want a tunnel on, nothing more complicated than that.

$20
One off, per server
  • OpenVPN on TCP 443 with a UDP profile alongside
  • A certificate per device, up to five
  • DNS routed through the tunnel
  • Firewall closed except the tunnel and your access
  • Key based login, root login disabled
  • Starts on its own after a reboot
  • Config files for Windows, macOS, Linux, Android and iOS
  • Written notes for adding a device later
Ask about this one
Most common

Home Server Setup

A Pi, mini PC or home box, routed into your whole network rather than only out to the internet. Printers, drives and cameras reachable from anywhere.

$100
One off, per server
  • Everything in Standard Install
  • Up to ten devices
  • Full access to your home network, not just the internet
  • Dynamic DNS so the tunnel survives an address change
  • Router port forwarding sorted with you
  • Internal names resolving from outside the house
  • Upload speed checked before anything is promised
  • Tested from an outside connection before handover
Start with this one
Bigger jobs

Multi Server Or Custom

Several machines, more than ten people, an existing setup to fix, or something that does not fit either box on the left.

Quoted
After we have looked at it
  • Multiple servers built the same way
  • Unlimited devices and certificate management
  • Existing broken installs diagnosed and repaired
  • Migration from another provider or protocol
  • WireGuard added alongside OpenVPN
  • Site to site links between locations
  • Access split by group where several people share it
  • Full documentation for whoever inherits it
Request a quote

Added To Any Package

  • Each additional device beyond the package $5
  • Each additional server on the same job $20
  • Full server hardening, beyond the tunnel $50
  • Hardware chosen and sourced with you $80]
  • Support after handover, monthly $100 / mo

Hosting is billed to you directly by whichever provider you pick and never runs through us, so a VPS at five to fifteen dollars a month is the only ongoing cost on a rented setup. A home server costs a few dollars a year in electricity and nothing else.

Tell Us What The Machine Is And Where It Sits

A VPS, a Pi on the shelf, a mini PC in the office, or nothing yet and you want a hand picking one. Say which distribution it runs and how many devices need to connect, and that is enough for a price and a timeline. Most of these are finished the same day the access arrives.

Talk about your setup
Works on hardware you already own A certificate per device, revoked in seconds Root access handed back, nothing kept