OpenVPNAdmin

Sign in

New endpoint

AES-256-GCM is the strongest widely-supported option and hardware-accelerated on almost all modern CPUs. Pick CHACHA20-POLY1305 for older/ARM devices without AES-NI.

Defaults to Cloudflare (fast, private). Other good options: Google (8.8.8.8 / 8.8.4.4), Quad9 (9.9.9.9 / 149.112.112.112).

Delete ?

Anyone currently connected through it will be dropped. This can't be undone.

New client

Revoke ?

This immediately invalidates their .ovpn profile. This can't be undone.

Limits for

Static IP

Admin-assigned only — survives limit changes above, and is never something the client themselves can choose.

Renewing replaces the certificate — the client's current .ovpn file stops working immediately. Download a fresh one afterward.

Download config for

Pick which endpoint this profile should connect through.

OpenVPN logs · last 200 lines

Loading…

endpoint.conf read-only

Loading…

Restore from backup?

This overwrites the live PKI, endpoint configs, client database and admin settings, then restarts the panel. A safety snapshot of the current state is taken automatically first. Type RESTORE to confirm.

Add server

The address baked into every client's .ovpn for this server. A subdomain of a domain you already own works — no new domain needed.

Install the agent on

This install token is shown once. Copy the command now — if you lose it, remove this server and add it again.

Run this on the box you want to add. It installs the agent, which dials back to this dashboard over an outbound connection — no inbound port needed on that box.

Edit

The address baked into every client's .ovpn for this server.

Remove ?

This removes the server from this dashboard. The agent on that box keeps running independently — its clients stay connected, but you'll no longer be able to manage it from here unless you add it again with a new install token.