| Subcribe via RSS

Installing and Configuring OpenVPN Server on CentOS using Webmin (part 3)

July 17th, 2011 Posted in Linux, Security, Windows

OpenVPN Configuration
Here are the steps to configure OpenVPN using Webmin:

1. Create Certification Authority
To create the Certification Authority, go to Server -> OpenVPN + CA, click on Certification Authority List.
createca1
In the New Certification Authority form page, fill in the fields with the required informations and click Save.
createca2
The system will generate required parameters, ca.key and ca.crt for the Certification Authority.
createca3
createca4
When finished, the Certificate Authority name will be displayed in the Certification Authority List.createca6

2. Create Key for server
To create the Server key, go to Server -> OpenVPN + CA, click on the Certication Authority List, then click on Keys list.
create-server-key1
In the New key to Certification Authority: alambil-ca form page, fill in the required fields, make sure to choose “server” for the Key Server type and don’t put any password in the key password field. Click Save when finished.
create-server-key2
The system will generate the server key.
create-server-key3

3. Create New VPN server and configure the server
We will use the Certification Authority to create the VPN Server. Go to Servers -> OpenVPN + CA, click on VPN List, then click on the New VPN server.
new-vpn-server
In the New VPN Server form page, fill in the required fields.
create-vpn-server1
create-vpn-server2
create-vpn-server3
create-vpn-server4
create-vpn-server5

The port use in the VPN server should be allowed access in the firewall.
In the NetIP assign, allocate a network address range that will be used for the TUN interface of the VPN server and for the connecting clients. Make sure that this network range is routable in the LAN.
In the vpn server configuration, we put additional configuration:

route 10.22.1.0 255.255.255.0
route 10.22.2.0 255.255.255.0
route 10.22.3.0 255.255.255.0
push "route 10.180.0.0 255.255.252.0"
push "route 10.22.1.0 255.255.255.0"
push "route 10.22.2.0 255.255.255.0"
push "route 10.22.3.0 255.255.255.0"
push "dhcp-option DNS 10.180.3.12"
client-to-client

The route entries are added on the server to adjust the server local routing table, telling it to route those networks over the vpn. The push routes are added on the clients connecting, telling them to route those networks over the vpn connection. The push dhcp-option are added on the clients connecting, so that they can use the specified private DNS server. The client-to-client are added so that client can connect to other client over the vpn connection.

4. Create client Key and VPN client account for each client
We need to create client Key and VPN client account for each client that will use VPN connection. To create the client key, go to Servers -> OpenVPN + CA, click on the Certication Authority List, then click on Keys list.
In the New key to Certification Authority: alambil-ca form page, fill in the required fields, make sure to choose “client” for the Key Server type. Click Save when finished.
create-client-key1
The system will generate the client key.
create-client-key2

To create the OpenVPN client account for the client key, go to Server -> OpenVPN +CA, click on VPN List. In the VPN Server list page, client on Client List of the VPN Server.
vpn-server-list
Then click on New VPN Client button.
new-vpn-client
In the New VPN Client form page, fill in the required fields.
new-vpn-client1
new-vpn-client2
new-vpn-client3

In the remote IP field, fill in with the public IP of the VPN server. Make sure that the port is opened in the firewall.
In the ccd file content field for client site-1, we put:

iroute  10.22.1.0  255.255.255.0

The iroute entry is useful for site-to-site VPN. The iroute entry tells the openvpn server that client site-1 is responsible for or the owner of the network 10.22.1.0/24. When creating VPN client for mobile user, there is no need to add the iroute entry.

5. Enable IP forwarding on the server
To enable IP forwarding on the server, in the webmin, go to Networking -> Network Configuration, then click on Routing and Gateways.
ip-forwarding1
Make sure to choose Yes on the Act as router, then in the network configuration page, click Apply Configuration button.
ip-forwarding2

You can also use the shell command to enable ip forwarding:

# echo 1 >> /proc/sys/net/ipv4/ip_forward

To check if the configuration have been applied correctly, use cat to display the value. It should be 1.

# cat /proc/sys/net/ipv4/ip_forward

6. Configure the firewall
In the firewall, we should configure:
– NAT policies to associate public IP and private IP used by the OpenVPN server
– Access rule from the Internet to the public IP of the OpenVPN server on port 1194
– Access rule from DMZ to LAN for VPN client to access resources on the LAN
– Access rule from LAN to DMZ for computers on the LAN that need access to the VPN client
If needed, we can also enable firewall/iptables on the Linux server. If we do it, then we need to put access rule for the VPN client to access resources outside the OpenVPN server and vice versa.

In the next section, we will discuss about the client side of  OpenVPN configuration.

33,343 Responses to “Installing and Configuring OpenVPN Server on CentOS using Webmin (part 3)”

  1. CharlesHig Says:

    online pharmacy generic cialis no prescription online pharmacy no prescription


  2. CharlesHig Says:

    onlinepharmacy cialis without a prescription canada pharmacy 24 hour drug store


  3. BerrySuisa Says:


  4. CharlesHig Says:

    canadian pharmacy cialis 20mg buy cialis without prescription canadian pharmacy


  5. BerrySuisa Says:


  6. CharlesHig Says:

    canada pharmacy 24 hour drug store buy cialis without prescription canadian pharmacy cialis 20mg


  7. BerrySuisa Says:


  8. CharlesHig Says:

    online pharmacy no prescription cialis online no prescription canadian pharmacy cialis


  9. CharlesHig Says:

    online pharmacy no prescription cheap cialis no prescription canadian pharmacy


  10. CharlesHig Says:

    canadian pharmacy online no script cialis without a prescription canada pharmacy 24 hour drug store


  11. BerrySuisa Says:


  12. CharlesHig Says:

    canadian pharmacy cialis cialis without prescription online pharmacy


  13. CharlesHig Says:

    online pharmacy cialis without a doctor’s prescription online pharmacy india


  14. BerrySuisa Says:


  15. CharlesHig Says:

    pharmacy rx one viagra cialis without a prescription canadian pharmacy


  16. CharlesHig Says:

    canadian pharmacy cialis online no prescription viagra from usa pharmacy


  17. CharlesHig Says:

    canadian pharmacy cialis cialis without prescription canadian pharmacy 24h


  18. BerrySuisa Says:


  19. CharlesHig Says:

    canada pharmacy 24 hour drug store cialis without prescription sky pharmacy online drugstore


  20. BerrySuisa Says:


  21. CharlesHig Says:

    canada pharmacy 24 hour drug store cialis without prescription cialis india pharmacy


  22. CharlesHig Says:

    on line pharmacy generic cialis without prescription viagra from usa pharmacy


  23. BerrySuisa Says:

    canadian pharmacy cialis 20mg canadian pharmacies mail order pharmacy online


  24. Edwardhix Says:

    on line pharmacy online pharmacies


  25. Edwardcex Says:


  26. BerrySuisa Says:

    pharmacy online online pharmacies canada canadian pharmacy cialis 20mg


  27. Edwardhix Says:

    pharmacy online healthy man viagra


  28. Edwardcex Says:

    canadian pharmacy online no script viagra online


  29. Edwardhix Says:

    canada pharmacy 24 hour drug store healthy man viagra


  30. Edwardcex Says:


  31. BerrySuisa Says:

    onlinepharmacy sky pharmacy wellbutrin onlinepharmacy


  32. ThomasSix Says:


  33. Edwardhix Says:

    247 overnight pharmacy canadian nizagara


  34. Edwardcex Says:


  35. BerrySuisa Says:

    cialis canadian pharmacy canadian pharmacy no prescription onlinepharmacy


  36. Edwardhix Says:

    canadian pharmacy express northwest pharmacy canada


  37. Edwardcex Says:

    4 corners pharmacy viagra no prescription


  38. BerrySuisa Says:

    canadian pharmacy no prescription canada pharmacy 24h canadian pharmacy no prescription


  39. Edwardhix Says:

    canadianpharmacy healthy man viagra


  40. Edwardcex Says:

    viagra from usa pharmacy viagra without a doctor prescription


  41. ThomasSix Says:


  42. Edwardhix Says:

    cialis india pharmacy azithromycin


  43. Edwardcex Says:

    pharmacy rx one viagra no prescription viagra


Leave a Reply