// Engineering Log

OpenVPN: Part 1 — Protocol, Editions and Clients

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

OpenVPN is a VPN protocol and at the same time an open-source program that implements it. The project has existed since 2001 and runs on almost any system: Linux, Windows, macOS, BSD, Android, iOS, as well as on MikroTik, Keenetic routers and in the OpenWrt firmware. The tunnel is protected by TLS, so the parties use familiar X.509 certificates for authentication.

Several different products are released under the name OpenVPN, and they are often confused. Below is an explanation of what is what and which option to choose.

Protocol

An OpenVPN connection consists of two channels:

  • control channel — a TLS session in which the parties verify certificates, agree on a cipher and exchange keys;
  • data channel — the user packets themselves, encrypted with the agreed cipher.

OpenVPN runs over UDP (default port 1194) or TCP. The tunnel can be of two types: tun — routable, IP-level, used almost always; tap — bridged, Ethernet-level, needed in rare cases, for example for broadcast traffic of legacy applications.

The data cipher is negotiated by the parties themselves. Starting with version 2.6 the default list is AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305 (the last one if it is available in the crypto library).

Editions

OpenVPN Community

Free software under the GPLv2 license: server and console client in a single executable. The current branch is 2.7; on the project’s downloads page the current version is 2.7.7. For Windows the installer includes the OpenVPN GUI.

Community does not have a web interface: the server is configured with a text file, certificates are issued separately, most often using the easy-rsa utility. This is the most flexible option, but all setup and maintenance is performed by the administrator.

OpenVPN Access Server

A commercial server from OpenVPN Inc. with an admin web interface and a user portal where an employee can download a connection profile themselves. Access Server can connect LDAP, RADIUS and SAML, issues profiles automatically and does not require manual handling of certificates.

Access Server is licensed by the number of concurrent connections. Without a subscription two connections are available — enough for testing. According to the OpenVPN website as of September 2026, a subscription beyond that costs $7 per connection per month with annual billing. It cannot be paid with a Russian card: Visa and Mastercard have not been servicing Russian cards abroad since March 2022.

OpenVPN Connect

A free client application from OpenVPN Inc. for Windows, macOS, Android and iOS. It works with both Access Server and the Community server: just import the .ovpn profile. Connect is built on a separate OpenVPN 3 library, so it does not support all the rare parameters of classic OpenVPN 2.x — for example, tap mode does not work in it.

Third-party clients

Besides Connect, there are trusted clients from other developers:

  • OpenVPN GUI — included in the Community installer for Windows;
  • Tunnelblick — a free client for macOS;
  • NetworkManager-openvpn — a module for Linux desktops: the profile is imported via network settings;
  • OpenVPN for Android — a free Android client based on classic OpenVPN 2.x;
  • Viscosity — a paid client for Windows and macOS with convenient profile management.

On Linux servers the same openvpn package serves as the client: it is run with a client profile, usually as a systemd service.

The .ovpn profile

A profile is a text file with client settings. It contains the server address, protocol and port, and certificates and keys can be embedded directly in the file between <ca>, <cert>, <key> and <tls-crypt> tags. Such a file is convenient to give to a user as a whole: a client on any platform will import it with a single action.

An embedded key is a secret. The profile must not be sent in an open chat or placed in a shared folder. If the file leaks, the user’s certificate must be revoked on the server.

Which option to choose

SituationOption
Small company, has an administrator, need a free serverCommunity on Linux, clients — OpenVPN Connect or OpenVPN GUI
Access to the office via routerserver on MikroTik or Keenetic if it is already in the office
Need a web portal, SSO and automatic profile issuanceAccess Server (outside Russia — due to payment) or Community with external authentication
Mobile employeesOpenVPN Connect on phones, .ovpn profile with embedded keys

If you haven’t decided yet, compare OpenVPN with WireGuard: WireGuard is simpler to set up and faster, while OpenVPN is more flexible in authentication, works over TCP and is supported on a larger number of devices.

Common mistakes

  • One certificate for everyone. If several employees connect with the same key, you cannot disconnect one of them without disconnecting the others. Each user should have their own certificate.
  • Outdated server. Older installations may remain on version 2.4 or 2.5 with outdated cipher settings. Branches 2.6 and 2.7 negotiate ciphers automatically; upgrading usually does not require reworking clients.
  • Client does not support a profile parameter. OpenVPN Connect ignores or rejects some 2.x parameters. If a profile works in OpenVPN GUI but not in Connect, look for tap and deprecated directives in it.
  • Profiles without expiration. Certificates of dismissed employees are often forgotten and not revoked. Revocation and a Certificate Revocation List (CRL) should be part of the offboarding procedure.

Practical setup examples are on the site: OpenVPN server on MikroTik — “Setting up an OpenVPN server on MikroTik RouterOS”, server on Ubuntu and a Keenetic client — “OpenVPN: configuring an Ubuntu server and a Keenetic client”. If you need help with deployment, it can be ordered on the “VPN setup” page.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply