OpenVPN on Arch

Import using systemctl

Copy OpenVPN client file to /etc directory:

sudo cp client.ovpn /etc/openvpn/client/myvpnconf.conf

Systemctl’s enable command turns on the service on boot, the --now flag also starts the service immediately:

# note the filename after @
systemctl enable --now openvpn-client@myvpnconf.service

This will start the VPN service with that configuration on boot, but this won’t integrate with networkmanager.

Integrating VPN connections with networkmanager

Disable the original systemctl service (if added previously)

systemctl disable --now openvpn-client@myvpnconf.service

Import OpenVPN connection

nmcli connection import type openvpn file myvpnconf.ovpn

Edit the connection to add username & password

nmcli connection modify myvpnconf \
    +vpn.data "connection-type=password-tls, username=$USERNAME" \
     vpn.user-name $USERNAME \
    +vpn.secrets "password=$PASSWORD"

Automatically connect to VPN

  • List connections
nmcli connection

NAME     UUID                                  TYPE      DEVICE
zrh-003  d46e4a92-778e-4792-b085-e1f638ecb8e3  vpn       enp1s0
enp1s0   1715b889-3c47-3e21-a86f-94ce207297a9  ethernet  enp1s0
tun0     7405f329-255d-4b50-b98d-c2e865a443a4  tun       tun0
  • Edit connection by adding the VPN UUID
# note if device name doesn't work use the UUID of the connection (not the VPN)
nmcli c edit enp1s0

nmcli> set connection.secondaries d46e4a92-778e-4792-b085-e1f638ecb8e3
nmcli> save persistent
Connection 'enp1s0' (1715b889-3c47-3e21-a86f-94ce207297a9) successfully updated.
 

cmac4603

A random assortment of notes.


Categories


2026-06-09