Skip to content

OpenVPN from the Command Line (Linux, macOS, Windows)

For headless servers, Raspberry Pis, scripts, or anyone who just prefers a terminal: OpenVPN’s command line is the same everywhere. One command connects, and the only real differences between systems are how you install the client and whether you run it as a service. We ran every Linux step below on Ubuntu 24.04.

On a desktop?

The native VPNBaron app is the easier path on Windows, macOS and Linux, with Baron Pathfinder switching protocols automatically. On Linux it also gives you VPNBaron CLI, which connects from a terminal in one command, without any config files.

Setup

  1. Get a config file

    Log in at vpnbaron.com/openvpn and download a config for the server you want: UDP (faster, the default choice) or TCP (firewall-friendly fallback). For a remote machine, download locally and copy it over with scp.

  2. Install the OpenVPN client

    Terminal window
    sudo apt update && sudo apt install openvpn
  3. Connect

    In the folder with your config file:

    Terminal window
    sudo openvpn --config GB_london_openvpn_udp.ovpn

    You’ll be asked for your VPN username and password: they’re on the same OpenVPN page, top card, and they are separate from your website login. The tunnel is up when the log prints Initialization Sequence Completed. Stop it with Ctrl+C.

    Terminal: sudo openvpn --config GB_london_openvpn_udp.ovpn asks for the auth username and password, connects to the server and prints Initialization Sequence Completed
  4. Verify

    From a second terminal:

    Terminal window
    curl -s https://api.ipify.org

    If it prints the server’s address, not yours, you’re tunnelled. On Ubuntu and Debian, do the DNS fix below too.

Fix DNS on Ubuntu and Debian

The server sends its own DNS resolver to the client, but plain openvpn on Ubuntu and Debian doesn’t apply it: your lookups keep going to your router or internet provider, outside the tunnel. We checked on Ubuntu 24.04: with the plain command, every lookup left on the normal network connection. To send them through the tunnel:

  1. Install the helper (it may already be there):

    Terminal window
    sudo apt install openvpn-systemd-resolved
  2. Add these lines to the end of your .ovpn file:

    script-security 2
    up /etc/openvpn/update-systemd-resolved
    down /etc/openvpn/update-systemd-resolved
    down-pre
    dhcp-option DOMAIN-ROUTE .
  3. Connect again. To check, resolvectl dns tun0 should show the VPN’s resolver, and watching your real network connection for DNS while you browse should show nothing. Find its name with ip route show default (after dev), then:

    Terminal window
    sudo tcpdump -ni enp0s1 port 53

    Open a few websites, then stop it with Ctrl+C:

    Terminal: resolvectl dns tun0 shows the VPN's DNS server, and tcpdump on the network interface captures 0 DNS packets while websites load

Other distributions handle DNS differently; resolvectl status shows which resolver the tunnel is actually using.

Unattended connections (no password prompt)

Put your username and password in a file only root can read:

Terminal window
sudo install -m 600 /dev/null /etc/openvpn/client/vpnbaron.auth
sudo nano /etc/openvpn/client/vpnbaron.auth

Write the username on the first line and the password on the second, save, then connect with:

Terminal window
sudo openvpn --config GB_london_openvpn_udp.ovpn --auth-user-pass /etc/openvpn/client/vpnbaron.auth

Run it as a service (Linux, systemd)

Copy your config, with the DNS lines above, to the client folder, and point its auth-user-pass line at your password file:

Terminal window
sudo cp GB_london_openvpn_udp.ovpn /etc/openvpn/client/vpnbaron.conf
sudo sed -i 's#^auth-user-pass.*#auth-user-pass /etc/openvpn/client/vpnbaron.auth#' /etc/openvpn/client/vpnbaron.conf
sudo systemctl enable --now openvpn-client@vpnbaron

The VPN now starts with the computer. systemctl status openvpn-client@vpnbaron shows it running:

Terminal: systemctl enable --now openvpn-client@vpnbaron, then systemctl status shows the service active (running) with status Initialization Sequence Completed

Logs: journalctl -u openvpn-client@vpnbaron -f. To stop it and keep it from starting: sudo systemctl disable --now openvpn-client@vpnbaron.

Troubleshooting