Raspberry Pi VPN

How to make your own Raspberry Pi VPN

Create your own Raspberry Pi OpenVPN server.
  • by Ash (63)
  • Time to complete: 30 minutes

If you're looking to add a little extra security to your network, you may want to install a VPN (Virtual Private Network). This adds an extra layer between you and those you connect to online. VPNs provide a login interface through which only pre-approved machines can connect. In this guide, we'll cover how to set up our own VPN interface on a Raspberry Pi.

The software we’re using is called PiVPN. It’s based on OpenVPN and works with many OpenVPN clients. This works well in our favor, you’ll see why later.

Note: I'm using a Raspberry Pi 3 B+, but you can experiment with other Raspberry Pis as well.

1

We'll use Raspbian as a starting point for our project. Download the latest version from the Raspbian downloads page. Check out our guide for help updating Raspbian on the Raspberry Pi.

2

pivpn install terminal

We need access to the Pi via terminal. You will need to enable SSH on the Pi before you can access the terminal remotely. Visit our guide for steps on how to enable SSH on Raspbian. You can log into the terminal using a command line interface. For more details, check out our SSH Raspberry Pi login guide.

Once you're in the terminal window, run the following:

curl -L https://install.pivpn.io | bash

The package will begin installation automatically. When prompted with "This installer will transform your Raspberry Pi into an Open VPN server!" Choose OK.

3

The installation wizard will walk you through the setup process. Here's a quick overview of each step.

Define a static IP address

You will be prompted to edit your network settings. Our Raspberry Pi VPN needs a static IP address. You can leave the default value or choose one of your own if your ISP supports static IPs.

Choose a user to manage VPN settings

You will see a dialogue that states “Choose a local user that will hold your ovpn configurations.” Select OK and choose an account to use. I’m leaving mine set to the default account, but you can use any account you want here.

Set up "Unattended Upgrades"

The next prompt will ask about "Unattended Upgrades". This automatically downloads updates, but it won’t reboot your Pi. You’ll have to reboot the Pi manually from time to time. If you want to use these enable them now.

Choose TCP or UDP

You will be asked to choose between TCP or UDP. If you're not sure what to put here, UDP is a safe bet.

Set a port number

On the next screen, you can set a custom port number or leave the default value of 1194. You will be prompted to confirm the port settings.

OpenVPN settings

If you have clients running OpenVPN 2.4 or later, you can integrate features for it by choosing Yes. Otherwise, choose No.

Choose encryption settings

Choosing what level of encryption to use it up to you. 1024 bit is on the lower end and hardly recommended. 4096 bit offers the greatest security but also causes the most latency. 2048 bit seems to be in the sweet spot for what we want to accomplish.

Server key is generated

Up next, PiVPN will create a server key. This may take a little while, just leave the Pi running while it generates the key. The creator stated this process took up to 45 minutes on his Pi 3B+, however, I experienced a much shorter wait time on mine.

DNS settings

When prompted for DNS settings, you can opt to use a DNS. However, I'll be using my public IP.

Select the DNS provider

Choose one of the DNS providers from the list or select "custom" to use your own.

4

router pivpn port

The default port value used by PiVPN is 1194. If you changed this port number, now is the time to open it on your router. You will need to log into your router in order to set up port forwarding. Visit our guide for help logging in and resetting your router password.

5

Adding PiVPN profile in terminal

We want to create a whitelist of clients that can use our new PiVPN. To do this, we will create a file known as an ovpn profile. Open a terminal window for the Pi and run the following:

pivpn add

Choose a name for the client you want to add and create a password. We can use this ovpn profile file to create a connection.

6

winscp pivpn ovpn profile

Move the ovpn file we just created to the client (computer, mobile device, tablet, etc) you want to connect. I'll be transferring the file using WinSCP, but you can use your favorite FTP software.

7

Operating SystemClient URL
WindowsOpenVPN Client
MacOpenVPN Client
AndroidOpenVPN Client
IOSOpenVPN Client
LinuxOpenVPN Client

To connect the two devices, we need to put software on the client that can read the profile we created. I'll be installing the Windows 10 OpenVPN desktop client. You can find other versions, check the table to find the client you need.

Once you’ve uploaded the profile into the client, you should be given prompts to connect to your PiVPN setup.

8

pivpn help terminal

You can find additional help and resources on the official PiVPN website or by entering the following into a terminal:

pivpn help

This provides a complete list of commands that can be used to configure and optimize PiVPN.

9

Congratulations! You’re now the owner of a personal VPN. We trust you’ll use your SysAdmin powers wisely.

If you’re looking for more ways to fine-tune your network, why not set up a Raspberry Pi adblocker? Check out our Pi-Hole setup guide to get started.