Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

VPN

66 Topics 515 Posts
  • How to debug slow VPN?

    Moved
    8
    1 Votes
    8 Posts
    4k Views
    dsp76D
    Check the network speed with an SFTP connection directly to your server. Upload / download a file from your location to your server. The speed check on our server performed by our hoster was also fine. No surprise - as the speed test software connects to the best available server, which might be connected on a different network than yours. The direct test without VPN showed the same issue - so it was not related to VPN, but to the general connection between my office, homeoffice + other places and our server.
  • OpenVPN Split Tunnel?

    2
    1 Votes
    2 Posts
    2k Views
    girishG
    @teamcrw the split tunnel happens because of client side vpn configs. Atleast on linux, I can override this when I set up the connection. [image: 1719991445531-8321cb50-c667-47fc-8745-bd7368a61564-image.png]
  • 2FA in OpenVPN App

    11
    2 Votes
    11 Posts
    6k Views
    S
    @girish I believe so. We were using the "OpenVPN Connect" Mac app on the front-end, which supports this. My understanding is that the Cloudron build of the OpenVPN server would need to be built with the libpam-google-authenticator package, in order to enable a user to enable it from the app-specific terminal (and to configure the server app to require it.) I ended up going a different route (switching to AWS Client VPN) so this is no longer pressing for us, but I do think it would enable a nice security enhancement.
  • OpenVPN only supports one person connected to the server

    7
    0 Votes
    7 Posts
    4k Views
    girishG
    @santabroo I haven't tested but I think if you add duplicate-cn directive in /app/data/openvpn.conf and restart the app, it will support multiple connections on one certificate.
  • OpenVPN login with password

    2
    1 Votes
    2 Posts
    1k Views
    girishG
    You have to use the ovpn file to connect.
  • OpenVPN with AdGuard ?

    4
    1 Votes
    4 Posts
    5k Views
    girishG
    I tried following setup and it works: Install AdGuard Home Install VPN app in same cloudron In VPN app, set DNS to public IP of cloudron (where AdGuard is installed). Connected from linux I can see all DNS requests are going via AdGuard. I can see that in systemctl status systemd-resolved the DNS of tun0 is set correctly.
  • OpenVPN Limitations ?

    6
    1 Votes
    6 Posts
    3k Views
    girishG
    Ah, I see why. You are referring to OpenVPN AS maybe - https://openvpn.net/vpn-server-resources/limitations-of-an-unlicensed-openvpn-access-server/ ? @santabroo the OpenVPN app on Cloudron is completely different from OpenVPN AS. The OpenVPN UI was initially written by @mehdi, further developed now by the Cloudron team and not feature compatible or comparable with OpenVPN AS.
  • OpenVPN chain multiple servers

    2
    1 Votes
    2 Posts
    2k Views
    robiR
    @santabroo No. VPNs are point-to-point. What you may be wanting is a Tailscale/Headscale type solution that is a VPN mesh concept (not-point to-point).
  • Built-in DNS Server - Not resolving connected clients

    Solved
    2
    1 Votes
    2 Posts
    1k Views
    G
    I continued debugging the issue and fortunately, I finally found the root cause and solution. Turns out the Ubuntu client wasn't updating the DHCP settings automatically, so I added the following lines to the ovpn file: up /etc/openvpn/update-systemd-resolved down /etc/openvpn/update-systemd-resolved And also installed the following dependencies: sudo apt install resolvconf openvpn-systemd-resolved With that, I was able to solve the issue and now all the clients are resolving automatically.
  • OpenVPN app and privacy

    Moved
    4
    3 Votes
    4 Posts
    3k Views
    svtxS
    @girish That's excellent news indeed!
  • OpenVPN with IPv4 and IPv6

    Solved
    9
    0 Votes
    9 Posts
    5k Views
    svtxS
    @archos Do what most other sensible IT Pros do: Disable IPv6 for as long as possible
  • Purpose of OpenVPN

    Moved
    7
    3 Votes
    7 Posts
    4k Views
    svtxS
    I would be fantastic to integrate other apps to "require Cloudron VPN connection" in order to access them. It would solve many of our problems.
  • Not able to make user openvpn admin

    Moved Solved
    4
    0 Votes
    4 Posts
    2k Views
    W
    This seems to have resolved the issue. Many thanks
  • Throttling

    7
    0 Votes
    7 Posts
    3k Views
    girishG
    I can see 3,4 being generally useful to have. 1,2 are for service providers. Happy to accept any PRs at https://git.cloudron.io/cloudron/openvpn-app . This has the complete app along with the UI.
  • Log location?

    2
    0 Votes
    2 Posts
    761 Views
    girishG
    @RazielKanos they should be in log viewer (atleast whatever openvpn writes out). Maybe you can turn up the log level for more output.
  • OpenVPN DNS leaks?

    openvpn dns leaks security
    7
    0 Votes
    7 Posts
    4k Views
    girishG
    Maybe @mehdi has some ideas here since he wrote the initial app. If I understand correctly, you are trying to put the OpenVPN certs into openwrt and this somehow leaks DNS. How are you testing this?
  • Missing logo.png

    Solved
    3
    0 Votes
    3 Posts
    1k Views
    nebulonN
    Fixed with latest package version now.
  • OpenVPN Access Server Question

    openvpn access server ubqiuiti unifi udm-pro
    4
    0 Votes
    4 Posts
    2k Views
    M
    Thx a lot, I can try it but is there any way someone can create a package? Not for free for sure..
  • password

    Solved
    9
    0 Votes
    9 Posts
    3k Views
    dynimightiD
    @girish, good day. sorry, should have said, fixed. i was using the same subdomain name as before the reinstall and for whatever reason that stopped everything from working.
  • OpenVPN - TLS verify error

    Solved
    4
    0 Votes
    4 Posts
    4k Views
    robiR
    @nebulon Update: after restarting the OpenVPN App, it connects and verifies TLS just fine. Shrug, restart fixed it.