# OpenVPN general usage

**URL:** https://dietpi.com/forum/t/openvpn-general-usage/463
**Category:** General Discussion
**Created:** [18 July 2016 16:03 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463 "2016-07-18T16:03:42Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![keithellis](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/k/c4cdca/32.png) [@keithellis](https://dietpi.com/forum/u/keithellis)
#### Post date: [18 July 2016 16:03 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/1 "2016-07-18T16:03:42Z")

</div>

Hi there, Been using DietPi for a while now since I heard about it on the The Pi Podcast and really like how it works. I have a couple of questions about OpenVPN.

What I want to be able to do with this is connect to a Raspberry Pi OpenVPN server whilst I am out and about using public wifi hotspots, redirecting all traffic through the OpenVPN server thus creating a secure connection on an otherwise insecure network. I assume this is possible.

Does the default setup do this out of the box?

In my current setup I don’t think it does, but this may be related to my second question below.

On my home network I already have an ownCloud setup on a separate Raspberry Pi, so I have port 443 port forwarded to my ownCloud server. As such I cannot open up port 443 for my OpenVPN server. Is there a way around this, can I specify a different port for the OpenVPN https traffic?

Many thanks,  
Regards,  
Keith Ellis

---

<div class="post-metadata">

### Author: ![k-plan](https://dietpi.com/forum/user_avatar/dietpi.com/k-plan/32/12_2.png) [@k-plan](https://dietpi.com/forum/u/k-plan)
#### Post date: [18 July 2016 17:53 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/2 "2016-07-18T17:53:20Z")

</div>

Hi keithellis,

> [@keithellis](#):
>
> As such I cannot open up port 443 for my OpenVPN server.

You can as well use UDP Port:1194 for open VPN connections.  
Forward UDP (protocol 17) with port 1194 on your home router (with PAT/NAT) to ip address of you RPi running open VPN server.  
You have to edit your config file: DietPi\_OpenVPN\_Client.ovpn

No need for tcp port 443 or 943 ( [UDP hole punching - Wikipedia](https://en.wikipedia.org/wiki/UDP_hole_punching) )

Please have a look in Fourdee description: [https://dietpi.com/forum/t/dietpi-software-details-for-all-installation-options/22/37](https://dietpi.com/forum/t/dietpi-software-details-for-all-installation-options/22/37)

If you use UDP, a keepalive of the VPN connection is obligation, ( [https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage](https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage) )

If you have only dynamic ip address on your home router (with NAT/PAT), Dyn DNS for open VPN server entry will by usefull: [DietPi Community Forum - Welcome to the DietPi OS Community Forum](http://dietpi.com/phpbb/viewtopic.php?f=8&t=5&start=10#p58)

cu  
k-plan

---

<div class="post-metadata">

### Author: ![keithellis](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/k/c4cdca/32.png) [@keithellis](https://dietpi.com/forum/u/keithellis)
#### Post date: [28 July 2016 21:32 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/3 "2016-07-28T21:32:56Z")

</div>

> [@k-plan](#):
>
> Hi keithellis,
> 
> > [@keithellis](#):
> >
> > As such I cannot open up port 443 for my OpenVPN server.
> 
> You can as well use UDP Port:1194 for open VPN connections.  
> Forward UDP (protocol 17) with port 1194 on your home router (with PAT/NAT) to ip address of you RPi running open VPN server.  
> You have to edit your config file: DietPi\_OpenVPN\_Client.ovpn
> 
> No need for tcp port 443 or 943 ( [UDP hole punching - Wikipedia](https://en.wikipedia.org/wiki/UDP_hole_punching) )
> 
> Please have a look in Fourdee description: [https://dietpi.com/forum/t/dietpi-software-details-for-all-installation-options/22/37](https://dietpi.com/forum/t/dietpi-software-details-for-all-installation-options/22/37)
> 
> If you use UDP, a keepalive of the VPN connection is obligation, ( [https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage](https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage) )
> 
> If you have only dynamic ip address on your home router (with NAT/PAT), Dyn DNS for open VPN server entry will by usefull: [DietPi Community Forum - Welcome to the DietPi OS Community Forum](http://dietpi.com/phpbb/viewtopic.php?f=8&t=5&start=10#p58)
> 
> cu  
> k-plan

Hi k-plan,

thanks for this. I am now using UDP port 1194 and I can connect to my OpenVPN server. I have a static external IP address so all is good there. However once connected my client cannot connect to the internet. Probably an OpenVPN question more than a DietPi one, but since I don’t know how OpenVPN has been setup in DietPi are you able to give me any further guidance. Thank You  
Keith Ellis

---

<div class="post-metadata">

### Author: ![Gabba](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/g/bc8723/32.png) [@Gabba](https://dietpi.com/forum/u/Gabba)
#### Post date: [31 July 2016 01:45 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/4 "2016-07-31T01:45:41Z")

</div>

Just to tack on to the end of this, what’s the best way to load OpenVPN on startup?

To start it I use the below command or a sh file with the command in it. I’m just not sure how to start it. My rc.local file fails to load on startup.

```nohighlight
sudo openvpn --config /etc/openvpn/Startup.ovpn --script-security 2 --up /etc/openvpn/up.sh

```

Cheers,  
Gabbe

---

<div class="post-metadata">

### Author: ![k-plan](https://dietpi.com/forum/user_avatar/dietpi.com/k-plan/32/12_2.png) [@k-plan](https://dietpi.com/forum/u/k-plan)
#### Post date: [3 August 2016 17:57 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/5 "2016-08-03T17:57:48Z")

</div>

Hi keithellis,

> [@keithellis](#):
>
> Hi k-plan,
> 
> thanks for this. I am now using UDP port 1194 and I can connect to my OpenVPN server. I have a static external IP address so all is good there. However once connected my client cannot connect to the internet. Probably an OpenVPN question more than a DietPi one, but since I don’t know how OpenVPN has been setup in DietPi are you able to give me any further guidance. Thank You  
> Keith Ellis

Edit DietPi\_OpenVPN\_Client.ovpn :

```plaintext
client
proto udp
dev tun
link-mtu 1400

#IP/Domain name of DietPi system, running OpenVPN server plus Port-No.
remote !!!wan-ip-address-here!!! 1194

resolv-retry infinite
nobind

user nobody
group nogroup

persist-key
persist-tun

ns-cert-type server
comp-lzo
verb 3

## VPN Server is default Gateway for all connections
redirect-gateway

## Windows Client method
route-method exe
route-delay 2

## DNS Server from LAN for VPN Servers Clients (local DNS Server)
dhcp-option DNS 192.168.0.1

dhcp-option DNS 8.8.4.4

<ca>
-----BEGIN CERTIFICATE-----
....

```

ssh into your openVPN server and execute:

```plaintext
# delete all old iptables 
iptables -F
iptables -X
iptables -t nat -F

## Forwarding u. NAT for openVPN Cients
iptables -A INPUT -i tun+ -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -F POSTROUTING
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE

```

Test it. Will it works?  
The iptable rules are not persistent. After a reboot they are gone. So they must be set via start up script.

cu  
K-plan

---

<div class="post-metadata">

### Author: ![Ferdnand](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/f/ac91a4/32.png) [@Ferdnand](https://dietpi.com/forum/u/Ferdnand)
#### Post date: [11 August 2016 19:18 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/6 "2016-08-11T19:18:34Z")

</div>

Hello, was looking at dietPi, and was wondering if I can set this up as a wifi repeater, with a OpenVPN account I have from liquidvpn,

Any help will be greatly appreciated…

Thanks keep up the great work…

---

<div class="post-metadata">

### Author: ![helio58](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/h/ee7513/32.png) [@helio58](https://dietpi.com/forum/u/helio58)
#### Post date: [23 June 2017 06:22 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/7 "2017-06-23T06:22:02Z")

</div>

> [@k-plan](#):
>
> Hi keithellis,
> 
> > [@keithellis](#):
> >
> > Hi k-plan,
> > 
> > thanks for this. I am now using UDP port 1194 and I can connect to my OpenVPN server. I have a static external IP address so all is good there. However once connected my client cannot connect to the internet. Probably an OpenVPN question more than a DietPi one, but since I don’t know how OpenVPN has been setup in DietPi are you able to give me any further guidance. Thank You  
> > Keith Ellis
> 
> Edit DietPi\_OpenVPN\_Client.ovpn :
> 
> ```plaintext
> client
> proto udp
> dev tun
> link-mtu 1400
> 
> #IP/Domain name of DietPi system, running OpenVPN server plus Port-No.
> remote !!!wan-ip-address-here!!! 1194
> 
> resolv-retry infinite
> nobind
> 
> user nobody
> group nogroup
> 
> persist-key
> persist-tun
> 
> ns-cert-type server
> comp-lzo
> verb 3
> 
> ## VPN Server is default Gateway for all connections
> redirect-gateway
> 
> ## Windows Client method
> route-method exe
> route-delay 2
> 
> ## DNS Server from LAN for VPN Servers Clients (local DNS Server)
> dhcp-option DNS 192.168.0.1
> 
> dhcp-option DNS 8.8.4.4
> 
> <ca>
> -----BEGIN CERTIFICATE-----
> ....
> 
> ```
> 
> ssh into your openVPN server and execute:
> 
> ```plaintext
> # delete all old iptables 
> iptables -F
> iptables -X
> iptables -t nat -F
> 
> ## Forwarding u. NAT for openVPN Cients
> iptables -A INPUT -i tun+ -j ACCEPT
> iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
> iptables -t nat -F POSTROUTING
> iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
> 
> ```
> 
> Test it. Will it works?  
> The iptable rules are not persistent. After a reboot they are gone. So they must be set via start up script.
> 
> cu  
> K-plan

This worked 😃 , but please how can i make the iptable rules persistent ?  
Thanks

---

<div class="post-metadata">

### Author: ![k-plan](https://dietpi.com/forum/user_avatar/dietpi.com/k-plan/32/12_2.png) [@k-plan](https://dietpi.com/forum/u/k-plan)
#### Post date: [25 June 2017 15:14 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/8 "2017-06-25T15:14:29Z")

</div>

> [@helio58](#):
>
> This worked , but please how can i make the iptable rules persistent ?

> [@k-plan](#):
>
> So they must be set via start up script.

To get this changes persistent on every boot, you have to edit _/etc/rc.local_

Make a backup:

```plaintext
cp /etc/rc.local /etc/rc.local.bac

```

Edit:

```plaintext
nano /etc/rc.local

```

Add following lines before "_exit 0_ ":

```plaintext
. . . .

    /DietPi/dietpi/dietpi-services start

fi
/DietPi/dietpi/dietpi-banner 0
echo -e " Default Login:\n Username = root\n Password = dietpi\n"

### - addition for openVPN Cients - ###
## delete all old iptables 
iptables -F
iptables -X
iptables -t nat -F

## Forwarding a. NAT for openVPN Cients
iptables -A INPUT -i tun+ -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -F POSTROUTING
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE

exit 0

```

---

<div class="post-metadata">

### Author: ![helio58](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/h/ee7513/32.png) [@helio58](https://dietpi.com/forum/u/helio58)
#### Post date: [26 June 2017 18:42 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/9 "2017-06-26T18:42:46Z")

</div>

Thanks k-plan

---

<div class="post-metadata">

### Author: ![JimrMazk](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/j/35a633/32.png) [@JimrMazk](https://dietpi.com/forum/u/JimrMazk)
#### Post date: [16 February 2019 06:13 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/10 "2019-02-16T06:13:30Z")

</div>

> [@](#):
>
> Hello, was looking at dietPi, and was wondering if I can set this up as a [wifi repeater,](https://clevermicro.com/repeater-wifi-bo-kich-song/) with a OpenVPN account I have from liquidvpn,
> 
> Any help will be greatly appreciated…
> 
> Thanks keep up the great work…

This thread might help you. [Is it possible to configure WiFi AP on RPI Zero W?](https://dietpi.com/forum/t/is-it-possible-to-configure-wifi-ap-on-rpi-zero-w/2305/1)

---

<div class="post-metadata">

### Author: ![WarHawk](https://dietpi.com/forum/user_avatar/dietpi.com/warhawk/32/21_2.png) [@WarHawk](https://dietpi.com/forum/u/WarHawk)
#### Post date: [18 February 2019 04:01 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/11 "2019-02-18T04:01:35Z")

</div>

Default port to forward thru firewall is UDP/1194

Mine works like a champ…never had a problem

---

<div class="post-metadata">

### Author: ![Graybush](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/g/67e7ee/32.png) [@Graybush](https://dietpi.com/forum/u/Graybush)
#### Post date: [30 April 2019 21:01 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/12 "2019-04-30T21:01:37Z")

</div>

Will it work together with the tool from this [website](https://www.ptsecurity.com/ww-en/products/af/)? I’ve heard good reviews about positive technologies.

---

<div class="post-metadata">

### Author: ![WarHawk](https://dietpi.com/forum/user_avatar/dietpi.com/warhawk/32/21_2.png) [@WarHawk](https://dietpi.com/forum/u/WarHawk)
#### Post date: [1 May 2019 03:06 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/13 "2019-05-01T03:06:51Z")

</div>

> [@](#):
>
> Will it work together with the tool from this [website](https://www.ptsecurity.com/ww-en/products/af/)? I’ve heard good reviews about positive technologies.

No idea…what is that product?

---

<div class="post-metadata">

### Author: ![MichaIng](https://dietpi.com/forum/user_avatar/dietpi.com/michaing/32/7_2.png) [@MichaIng](https://dietpi.com/forum/u/MichaIng)
#### Post date: [1 May 2019 13:12 UTC](https://dietpi.com/forum/t/openvpn-general-usage/463/14 "2019-05-01T13:12:51Z")

</div>

As long as you allow incoming connections through the tun0 interface by this firewall it should generally work. But with pre-configured firewalls you never know exactly, e.g. in comparison to iptables where you explicitly need to block certain requests so you know exactly what is blocked in which circumstances.
