OpenVPN is an open-source SSL/TLS VPN that gives admins, remote staff and home users a secure path into an office or home network, so RDP, SSH, VNC and file shares never have to be exposed to the internet. The OpenVPN download covers two pieces: OpenVPN Community (the free GPL-2.0 server and client, with OpenVPN GUI on Windows) and OpenVPN Connect, the free official client app from OpenVPN Inc.
For remote access the usual pattern is simple: run an OpenVPN server on a Linux box, firewall or router, give each user a certificate-based profile, and let them reach internal hosts by their private addresses. The current branch is 2.7, released in February 2026; it brought multi-socket servers, the in-kernel DCO data path on Linux and a reworked Windows client stack. Version 2.7.7 is mainly a security release with several fixes in the Windows service.
OpenVPN at a glance
| Item | Details |
|---|---|
| Latest version | OpenVPN Community 2.7.7 (3 September 2026); the older 2.6 branch receives security fixes only (2.6.23, 23 September 2026) |
| Licence | Free and open source, GPL-2.0 (OpenVPN Community); OpenVPN Connect is a free client |
| Platforms | Windows 10/11 and Windows Server (x64, ARM64, x86), Linux, FreeBSD and other Unix systems; OpenVPN Connect for Windows, macOS, Android and iOS |
| Developer | OpenVPN Inc. and the OpenVPN community |
| Official website | openvpn.net |
| Best for | Self-hosted remote access to internal networks, site-to-site links, VPNs that must work over TCP 443 |
What it does
- Builds routed (tun) or bridged (tap) tunnels between clients and a server, or between two sites.
- Authenticates with X.509 certificates, optionally combined with username/password checked by a script or plugin (LDAP, RADIUS, PAM).
- Runs over UDP or TCP on any port, which helps on hotel and guest networks that only allow outbound 443.
- Protects the control channel with
tls-cryptortls-crypt-v2, so unauthenticated packets are dropped before the TLS handshake. - Pushes routes, DNS servers and search domains to clients; 2.7 can update routes and DNS on connected clients without a reconnect.
- Offloads encryption to the kernel (DCO) on Linux and Windows for higher throughput.
- Serves several addresses, ports and protocols from one server process (new in 2.7).
- Exposes a management interface for scripting connects, disconnects and status.
How IT teams use it
Remote access to an office LAN
- Create a small PKI with Easy-RSA:
./easyrsa init-pki,./easyrsa build-ca,./easyrsa build-server-full server nopass, then./easyrsa build-client-full alice nopassfor each user. - Generate a control-channel key:
openvpn --genkey tls-crypt tc.key. - Write a server config and start it with systemd (
systemctl enable --now openvpn-server@serveron most distributions). - Allow UDP 1194 on the firewall and enable IP forwarding, or add a route on the LAN router back to the VPN subnet.
port 1194
proto udp
dev tun
topology subnet
server 10.8.0.0 255.255.255.0
push "route 192.168.10.0 255.255.255.0"
push "dhcp-option DNS 192.168.10.10"
ca ca.crt
cert server.crt
key server.key
dh none
tls-crypt tc.key
keepalive 10 60
persist-tun
Give a help-desk technician RDP without opening 3389
- Issue the technician a client profile (
.ovpnwith the CA, client certificate, key andtls-cryptkey embedded). - Push only the management subnet route, not a full tunnel, so their internet traffic stays local.
- Connect, then open RDP, SSH or a VNC viewer to the internal address. Revoke the certificate (
./easyrsa revoke alice, then./easyrsa gen-crlandcrl-verifyin the server config) when the person leaves.
Run a client profile on a Linux server or kiosk
- Copy the profile to
/etc/openvpn/client/office.conf. - Start it at boot with
systemctl enable --now openvpn-client@office. - Check the tunnel with
journalctl -u openvpn-client@officeandip addr show tun0.
Install and first run
Windows. The Community MSI (x64, ARM64 or x86) installs OpenVPN, OpenVPN GUI, the DCO driver with a TAP fallback, and the OpenVPN Interactive Service, which lets non-admin users connect without elevation. Admin rights are needed to install. Import a profile from the GUI tray icon or put it in %USERPROFILE%OpenVPNconfig; profiles that must start before logon go in C:Program FilesOpenVPNconfig-auto. Since 2.7 the wintun driver is gone and --windows-driver is ignored with a warning.
macOS, Android, iOS. The Community project ships no macOS or mobile GUI; use OpenVPN Connect, which imports .ovpn files and Access Server or CloudConnexa profiles. Connect for Windows is also an option if you prefer it over OpenVPN GUI.
Linux. Install the openvpn package from your distribution or the OpenVPN repositories. Desktop users can import profiles into NetworkManager with the network-manager-openvpn plugin.
Gotchas. The server needs an open UDP or TCP port (1194 by default) and forwarding; the client and server must agree on dev, proto and ciphers. Old configs that rely on --secret static keys or comp-lzo need updating: static-key mode is disabled by default in 2.7, and 2.7 never compresses outgoing data.
Limitations
- Setting up a PKI by hand takes time and is easy to get wrong; certificate revocation is your job.
- OpenVPN runs in user space unless DCO is active, so throughput on small routers is lower than with WireGuard.
- Config syntax is large and partly historical; many online guides use options that 2.7 rejects or ignores.
- There is no built-in web admin or user portal in the Community edition. OpenVPN Access Server and CloudConnexa add one, but they are separate commercial products.
- The VPN gives network-level access only. You still need RDP, SSH or VNC on top, plus their own authentication.
OpenVPN vs alternatives
WireGuard is faster to set up and usually faster on the wire, with a tiny config, but it is UDP-only and has no built-in user authentication beyond keys. OpenVPN is the better fit when you need TCP 443, certificate revocation or username/password checks against LDAP or RADIUS. If you do not want users on the network at all, a browser gateway such as Apache Guacamole gives access to specific RDP, SSH and VNC hosts instead of whole subnets.
FAQ
Is OpenVPN free to download?
Yes. OpenVPN Community is free and open source under GPL-2.0, and the OpenVPN Connect client is free to use. Only OpenVPN Access Server and CloudConnexa are commercial.
What is the difference between OpenVPN Connect and OpenVPN GUI?
OpenVPN GUI is the Windows front end that ships with the open-source Community package. OpenVPN Connect is OpenVPN Inc.’s own client for Windows, macOS, Android and iOS; both can import standard .ovpn profiles.
Which OpenVPN client should I use on a Mac?
OpenVPN Connect is the official option. Tunnelblick is a popular open-source third-party alternative that also uses standard profiles.
OpenVPN vs WireGuard: which is better?
WireGuard is simpler and generally faster. OpenVPN is more flexible: TCP support, certificate revocation, and password or MFA checks through plugins.
Which port does OpenVPN use?
UDP 1194 by default, but any UDP or TCP port works. TCP 443 is a common choice where outbound traffic is restricted.
Does OpenVPN still support Windows 7?
No. The 2.7 installers target Windows 10, Windows 11 and current Windows Server releases.
How do I import an .ovpn file on Windows?
Right-click the OpenVPN GUI tray icon and choose Import file, or copy the profile into %USERPROFILE%OpenVPNconfig and restart the GUI.
Last checked against official sources: 1 October 2026 (developer website: openvpn.net). Versions and licence terms change — confirm on the developer's site before deploying in production.