Guides - Deploy OpenVPN through the Linode Marketplace
Quickly deploy a Compute Instance with many various software applications pre-installed and ready to use.
OpenVPN is a widely trusted, free, and open-source VPN (virtual private network) application that creates encrypted tunnels for secure data transfer between computers that are not on the same local network. Your traffic is encrypted by OpenVPN using OpenSSL. You can use OpenVPN to:
- Connect your computer to the public Internet through a dedicated OpenVPN server. By encrypting your traffic and routing it through an OpenVPN server that you control, you can protect yourself from network attacks when using public Wi-Fi. 
- Connect your computer to services that you don’t want to expose to the public Internet. Keep your sensitive applications isolated on your servers’ private networking and use OpenVPN to access them remotely. 
Deploying a Marketplace App
The Linode Marketplace allows you to easily deploy software on a Compute Instance using the Cloud Manager. See Get Started with Marketplace Apps for complete steps.
- Log in to the Cloud Manager and select the Marketplace link from the left navigation menu. This displays the Linode Create page with the Marketplace tab pre-selected. 
- Under the Select App section, select the app you would like to deploy. 
- Complete the form by following the steps and advice within the Creating a Compute Instance guide. Depending on the Marketplace App you selected, there may be additional configuration options available. See the Configuration Options section below for compatible distributions, recommended plans, and any additional configuration options available for this Marketplace App. 
- Click the Create Linode button. Once the Compute Instance has been provisioned and has fully powered on, wait for the software installation to complete. If the instance is powered off or restarted before this time, the software installation will likely fail. 
To verify that the app has been fully installed, see Get Started with Marketplace Apps > Verify Installation. Once installed, follow the instructions within the Getting Started After Deployment section to access the application and start using it.
Configuration Options
- Supported distributions: Ubuntu 22.04 LTS
- Recommended minimum plan: All plan types and sizes can be used, though consider the amount of traffic needed for the VPN and select a plan with enough Outbound Network Transfer to handle the expected traffic.
OpenVPN Options
Limited Sudo User
You need to fill out the following fields to automatically create a limited sudo user, with a strong generated password for your new Compute Instance. This account will be assigned to the sudo group, which provides elevated permissions when running commands with the sudo prefix.
- Limited sudo user: Enter your preferred username for the limited user. No Capital Letters, Spaces, or Special Characters. - Locating The Generated Sudo Password - A password is generated for the limited user and stored in a - .credentialsfile in their home directory, along with application specific passwords. This can be viewed by running:- cat /home/$USERNAME/.credentials- For best results, add an account SSH key for the Cloud Manager user that is deploying the instance, and select that user as an - authorized_userin the API or by selecting that option in the Cloud Manager. Their SSH pubkey will be assigned to both root and the limited user.
- Disable root access over SSH: To block the root user from logging in over SSH, select Yes. You can still switch to the root user once logged in, and you can also log in as root through Lish. - Accessing The Instance Without SSH If you disable root access for your deployment and do not provide a valid Account SSH Key assigned to the- authorized_user, you will need to login as the root user via the Lish console and run- cat /home/$USERNAME/.credentialsto view the generated password for the limited user.
Custom Domain (Optional)
If you wish to automatically configure a custom domain, you first need to configure your domain to use Linode’s name servers. This is typically accomplished directly through your registrar. See Use Linode’s Name Servers with Your Domain. Once that is finished, you can fill out the following fields for the Marketplace App:
- Linode API Token: If you wish to use the Linode’s DNS Manager to manage DNS records for your custom domain, create a Linode API Personal Access Token on your account with Read/Write access to Domains. If this is provided along with the subdomain and domain fields (outlined below), the installation attempts to create DNS records via the Linode API. See Get an API Access Token. If you do not provide this field, you need to manually configure your DNS records through your DNS provider and point them to the IP address of the new instance. 
- Subdomain: The subdomain you wish to use, such as www for - www.example.com.
- Domain: The domain name you wish to use, such as example.com. 
- Email address for Let’s Encrypt SSL Certificate (required): Start of Authority address for free Let’s Encrypt SSL. 
- Email address for the SOA record: The start of authority (SOA) email address for this server. This is a required field if you want the installer to create DNS records. 
") within any of the App-specific configuration fields, including user and database password fields. This special character may cause issues during deployment.Getting Started After Deployment
Access Details
OpenVPN Admin Interface:
- URL: https://192-0-2-1.ip.linodeusercontent.com, where192-0-2-1represents the IPv4 address of your new Compute Instance. See the Managing IP Addresses guide for information on viewing the rDNS value.
- Username: openvpn
- Password: See Obtaining the Admin Password below.
For more details on logging in to the OpenVPN admin interface for the first time (as well as changing the initial password), see the Access Server Admin Web UI First Login article within OpenVPN’s docs.
OpenVPN Client Interface:
- URL: https://192.0.2.1:943/, where your Linode’s IPv4 address should take the place of the192.0.2.1example address. The client interface includes links to download the OpenVPN client software for your computer.
Obtaining the Admin Password
The password for the main administrator account was automatically generated during the initial install process. To find this password, log in to your Compute Instance through the
LISH Console. The credentials are available in the file /root/.credentials
cat /root/.credentials
Sudo Username: $SUDO_USER
Sudo Password: 2e7cmU8z157xJbGV8LNU0KbUG
OpenVPN Username: openvpn
OpenVPN Password: 9oxKqQT098DV
To obtain your OpenVPN password, run this command:
cat /usr/local/openvpn_as/init.log | grep 'To login'
Open a Connection to your VPN
To open a connection to your OpenVPN server from your computer, you’ll need to install the OpenVPN client software. Follow the instructions in the Client Software Installation section of our OpenVPN guide for a detailed explanation of how to install and use this software.
More Information
You may wish to consult the following resources for additional information on this topic. While these are provided in the hope that they will be useful, please note that we cannot vouch for the accuracy or timeliness of externally hosted materials.
This page was originally published on