PUQ Mautic

09. OpenVPN

Overview

OpenVPN is a mature, widely-supported VPN protocol based on SSL/TLS. PUQVPNCP manages OpenVPN with full PKI (Easy-RSA) integration.

Key advantages:

OpenVPN is the best choice when you need maximum compatibility or when clients are behind restrictive firewalls that block WireGuard and IKEv2 traffic.

Requirement: openvpn and easy-rsa packages must be installed.

Navigate to VPN Servers > OpenVPN to access OpenVPN management. The page has 6 tabs: Overview, Certificates, Settings, Networks, Online, Client Profiles.


Overview Tab

OpenVPN overview OpenVPN overview — service status, certificates, configuration, online connections

The Overview tab shows:

Card Description
Service Status Installed openvpn and easy-rsa package versions
Certificate Status Status of CA, Server Certificate, DH Parameters, and TLS Auth Key (Valid/Missing)
Configuration OpenVPN enabled/disabled, number of networks and clients
Online Connections Number of currently active OpenVPN connections with a link to view all

Certificates Tab

Before OpenVPN can be enabled, you must generate all required certificates. The Certificates tab guides you through the PKI setup step by step.

Step 1: Generate CA Certificate

Certificates — initial setup Certificates tab — initial state, CA certificate form

Fill in the CA Certificate fields:

Field Description Example
Common Name CA certificate name myserver.com CA
Organization Organization name myserver.com
Organizational Unit (optional) Department
Locality (optional) City
State / Province (optional) State
Country (optional) Country code

Click Generate CA Certificate to create the root CA.

Step 2: Generate Server Certificate and DH Parameters

Certificates — CA generated Certificates tab — CA generated, generating server certificate

After the CA is generated:

  1. Click Generate Server Certificate — creates the server's TLS certificate signed by the CA
  2. Click Generate DH Parameters — creates Diffie-Hellman parameters (takes ~1 minute)

Certificates — DH generating Certificates tab — DH parameters generating

Step 3: Generate TLS Auth Key

Certificates — generating TLS Auth Certificates tab — generating TLS Auth key

Click Generate TLS Auth Key to create the HMAC authentication key.

Step 4: All Certificates Ready

Certificates — all generated Certificates tab — all certificates and keys generated

Certificates — complete with details Certificates tab — all valid, certificate details panel

Once all 4 components are generated (CA, Server, DH, TLS Auth), you can enable OpenVPN:

Certificates — OpenVPN enabled Certificates tab — OpenVPN enabled

Set OpenVPN Enabled to YES and save. The right panel shows the CA certificate details (issuer, validity dates, fingerprint).


Settings Tab

OpenVPN settings OpenVPN settings — connection and performance defaults

Configure global defaults for OpenVPN. These settings are applied to all networks unless overridden at the network level.

Connection

Setting Description Default
Protocol UDP or TCP udp
Cipher Encryption cipher AES-256-GCM
Auth Digest HMAC authentication digest SHA256
TLS Cipher TLS cipher suite (optional) (empty)
Compression lz4-v2, lzo, or disabled lz4-v2
Port Start Starting port for network instances 1194
Client-to-Client Allow clients to communicate directly NO
Duplicate CN Allow multiple connections with same certificate NO
Persist Key Keep keys across restarts YES
Persist Tun Keep tunnel device across restarts YES

Performance & Limits

Setting Description Default
Keepalive (sec) Ping interval 10
Keepalive Timeout (sec) Connection timeout 120
Max Clients Maximum simultaneous clients per instance 100
Verbosity Log verbosity level (0-11) 3
MTU (tun-mtu) Tunnel MTU 1420
MSS Fix Clamp MSS to avoid fragmentation (0 = disabled) 0
Fragment Fragmentation size (0 = disabled) 0

Use the Restore defaults button to reset all settings to their original values.


Networks Tab

OpenVPN networks OpenVPN networks — list of all OpenVPN instances

Shows all networks that have OpenVPN enabled:

Column Description
Name Network name (link to network edit page)
Clients Number of OpenVPN clients in this network
Port UDP/TCP port for this network's OpenVPN instance
Proto Protocol (udp/tcp)
Network Subnet assigned to this network
Bandwidth Upload / download bandwidth limits

Online Tab

OpenVPN online OpenVPN online users — currently connected clients

Shows all active OpenVPN sessions:

Column Description
Name Client name (link to client page)
Username System user who owns this client
Virtual IP IP assigned inside the VPN tunnel
Real IP Client's real IP address and port
Bytes RX Bytes received from client
Bytes TX Bytes sent to client
Connected Since Connection start timestamp
Network Network name

Each row has buttons to edit the client or disconnect the session.


Client Profiles Tab

OpenVPN client profiles OpenVPN client profiles — all clients across all networks

Lists all OpenVPN clients across all networks:

Column Description
Client Name Client name (link to client page)
Username System user who owns this client
Network Network this client belongs to
Status Enable/Disable
Certificate Certificate status (Issued/Missing)

Each client row has buttons to edit the client and download the .ovpn configuration file.


Client Configuration

Each OpenVPN client automatically gets:

The .ovpn profile contains everything needed to connect:

Supported Client Apps

Platform App
Windows OpenVPN GUI, OpenVPN Connect
macOS Tunnelblick, OpenVPN Connect
Linux openvpn CLI, NetworkManager
Android OpenVPN Connect (Play Store)
iOS OpenVPN Connect (App Store)
Mikrotik RouterOS 7+ OVPN client

Per-Network Configuration

Each network has its own OpenVPN instance with:

See the OpenVPN tab in Networks for details.



Revision #5
Created 28 September 2026 17:05:30 by Ruslan
Updated 28 September 2026 18:58:36 by Ruslan