Community-driven coverage of elementary OS — news, guides & forums
Dark abstract low-poly geometric landscape with layered triangular facets in deep navy, charcoal, and muted teal, illuminated by a soft electric-blue glow near the horizon

News roundups, tutorials, application guides, and forums — built by users, for users of the elegant Linux distribution.

elementary weekly
#20
Latest roundup · 18 Apr 2015
Freya Release
Final
Covered in weekly #19 & #20
Forum Topics
Active
Installation, customization & more

Install and Configure OpenVPN on elementary OS for Safer Browsing

Australians who rely on public Wi-Fi at places like Melbourne's laneway cafés or the terminals of Sydney Airport know how exposed a connection can feel. Whether you're logging into a Commonwealth Bank or ANZ app from a hotel in Brisbane or trying to keep watching Stan or Kayo Sports while travelling overseas, a tunnel that encrypts traffic is no longer optional. Installing the OpenVPN client on elementary OS gives you a reliable, open-source way to route your traffic through a remote server, hide your IP from local network operators, and bypass the geo-restrictions that Australian streaming services enforce the moment you cross the border.

elementary OS is built on Ubuntu's long-term support base, which makes installing OpenVPN straightforward. The distribution ships with the AppCenter, a polished package front-end sitting on top of apt, and it uses the same NetworkManager service that GNOME, KDE, and Cinnamon desktops rely on for connections. That means you can configure a VPN either through a graphical applet in the wingpanel or directly through the terminal, depending on your comfort level and whether your provider supplied a single .ovpn file or a directory of certificates and keys.

This walkthrough covers both paths, the small extra steps an Australian user often needs (DNS leak protection, killing the tunnel on disconnect, and verifying the exit IP), and a few habits worth keeping so the connection stays healthy across kernel updates. You'll need a working elementary OS installation, an account with an OpenVPN-capable provider, and roughly fifteen minutes if you stick to the GUI route, or twenty if you prefer a systemd-controlled CLI setup.

Method Best for Strengths Trade-offs
NetworkManager GUI in Pantheon Most users, laptops that move between home and travel Familiar wingpanel toggle, secure credential store, easy server switching GUI imports can drop advanced flags; depends on the openvpn-gnome plugin
nmcli from a terminal Power users, scripted setups across several machines Scriptable, easy to version control, works over SSH Less forgiving for typos; no visible status indicator in the wingpanel
Plain openvpn CLI with a systemd unit Servers, always-on routers, headless installs Full control over flags, no GUI dependency, easier log inspection Must write and maintain a unit file; no built-in reconnection logic

The right pick depends on how you use your machine. A daily-driver laptop bouncing between a Brisbane office and a Melbourne hotel benefits from the GUI; a small home server running on an NBN FTTH link or a Raspberry Pi acting as a travel router will lean on the CLI.

Preparing the system and gathering your provider files

Before any package is installed, take a moment to tidy the system. Update the package index and apply any pending patches so the new openvpn binary lines up with the running kernel, and reboot if a kernel image was upgraded. Back up any existing connection profiles in /etc/NetworkManager/system-connections/ so you can restore them if a misconfiguration knocks your network offline. On Australian connections served by the NBN, a brief outage while you debug a wrong key is more disruptive than it sounds, especially if you're on FTTC or FTTN, where the router itself has to renegotiate the link before traffic flows again.

From your VPN provider, download the OpenVPN configuration bundle. Most providers issue a zip file containing one .ovpn profile per server location, alongside the certificates and the TLS-auth key that the file references. Some Australian-focused outfits bundle Sydney, Melbourne, Brisbane, and Perth endpoints under separate files; others collapse the country into a single "Australia" entry. Keep the bundle in your home directory for now, ideally in a folder called ~/vpn-configs, because NetworkManager will need to read it during import.

You'll also want to confirm that your user belongs to the netdev group, since elementary OS uses Polkit rules to gate network changes. A quick groups $USER in the terminal will show whether netdev is present; if not, add yourself with sudo usermod -aG netdev $USER and log out and back in. Skipping this step is the most common reason an Australian user sees "permission denied" errors when trying to raise the tunnel from the wingpanel, and it often surfaces only when the person is racing a deadline and a flaky café Wi-Fi link.

Installing OpenVPN and the NetworkManager plugin

elementary OS ships without the OpenVPN stack enabled by default, so you need to install two packages: openvpn itself, which carries the openvpn binary and the kernel tunnel module, and network-manager-openvpn-gnome, which gives NetworkManager the ability to import and manage .ovpn profiles. Both are available through the standard Ubuntu repositories that elementary OS inherits, so no extra PPA is needed.

The fastest path is the terminal. Open the elementary OS Terminal app from the Applications launcher and run:

sudo apt update
sudo apt install openvpn network-manager-openvpn-gnome

If you prefer to stay inside the graphical AppCenter, search for "OpenVPN" and install the package that appears with the same name. The AppCenter lists the package version and a short description, but the GUI does not bundle the NetworkManager plugin, so you still need a terminal window to grab network-manager-openvpn-gnome. After the install completes, restart NetworkManager with sudo systemctl restart NetworkManager so the new plugin is registered; if you skip the restart, the VPN menu in the wingpanel will appear greyed out.

If you run elementary OS on a laptop that travels between home, a Brisbane coworking space, and a hotel in Singapore, you may also want resolvconf for clean DNS handling. Resolvconf helps avoid the classic DNS leak where Australian ISPs such as Telstra, Optus, or Aussie Broadband still resolve lookups through their default servers even after the tunnel is up. A second package, network-manager-openvpn, can be useful if you script the connection from nmcli and want the alternative backend available.

Importing a provider profile into NetworkManager

With the packages in place, importing a profile is a short graphical routine. Click the network applet in the wingpanel, choose VPN → Connect to VPN → Add a VPN connection, then pick "Import from file…" and select the .ovpn profile you downloaded. NetworkManager reads the certificate paths, the remote server address, and any inline keys automatically. Give the connection a recognisable name such as "Sydney – provider X" so you can spot it among other entries.

In the dialog that follows, fill in your provider username and password if the profile expects user/pass authentication. Most modern Australian-facing providers also offer token-based or certificate-based auth; if your bundle includes a separate client.crt and client.key, point the relevant fields to them. The "CA certificate" field should already be populated by the import, but it is worth opening it and confirming that the certificate common name matches your provider's stated name, since mismatched CAs are a frequent cause of handshake failures.

For users who manage many profiles, the same routine can be run from the terminal using nmcli connection import type openvpn file ~/vpn-configs/melbourne.ovpn. This approach is helpful if you maintain a fleet of machines or want to script deployments across a small team. The imported connection appears under nmcli connection show immediately, and you can raise or lower it with nmcli connection up "Sydney – provider X" and nmcli connection down "Sydney – provider X" from any terminal session.

Hardening DNS, enabling a kill switch, and setting auto-connect

A tunnel that leaks DNS queries is barely better than no tunnel at all, so the first hardening step is forcing DNS through the VPN. In the IPv4 tab of the connection editor, open "Routes…" and tick "Use this connection only for resources on its network" only if you actually want split tunnelling; otherwise leave both boxes unchecked so all traffic, including DNS, goes through the provider. Switch the DNS method from "Automatic" to "Automatic (only addresses)" and add the provider's resolvers. Many Australian-aware providers publish 1.1.1.1 and 9.9.9.9 as fallbacks for their internal DNS, which keeps lookups fast on NBN connections.

A rudimentary kill switch can be enabled by adding a firewall rule that drops traffic on tun0 when the tunnel is down. On elementary OS, the easiest path is ufw, which is already installed:

sudo ufw default deny outgoing
sudo ufw allow out to any port 1194
sudo ufw allow out on tun0
sudo ufw enable

This blocks any traffic that would leave your machine through the physical network adapter and forces everything through the OpenVPN interface. If you want a smoother experience, especially when a flaky FTTN link in suburban Adelaide keeps dropping the handshake, leave the default "deny outgoing" rule and add exceptions only for the UDP port your provider uses, which is almost always 1194 or 443.

Auto-connect at login is handled in NetworkManager's "General" tab. Tick "Automatically connect to this VPN when it is available" and, if you want the tunnel to come up whenever you join an untrusted Wi-Fi network such as a Sydney café or a Brisbane bus station hotspot, set the connection's "Automatically connect" flag at the system level. Pantheon does not expose this toggle as cleanly as GNOME Shell does, so editing the connection file in /etc/NetworkManager/system-connections/ and setting connection.autoconnect=yes plus a seen-bssids rule for your home network is the most reliable workaround.

Verifying the tunnel and addressing common faults

Once everything is wired up, verify the tunnel rather than trusting it. Visit ipleak.net or dnsleaktest.com from the default elementary OS browser and confirm the IP and DNS resolvers reported match the provider's exit. If you chose a Sydney endpoint, the IP should geo-locate to Sydney and the resolvers should belong to your provider, not to Telstra, Optus, or Aussie Broadband. A quick curl ifconfig.me from the terminal gives the same answer in a single line and is useful when troubleshooting a connection that drops intermittently.

Frequent problems and their fixes:

  • The connection establishes but no traffic flows: usually a routing issue where the default route was not pushed by the server. Edit the connection, switch to the IPv4 tab, change "Method" from "Automatic" to "Automatic (VPN)" or manually set the routes.
  • Authentication fails repeatedly: the provider's username and password are case-sensitive, and many Australian providers require the user name in lowercase even if the marketing material uses Title Case. Re-enter them carefully.
  • Handshake fails with TLS errors: the system clock is wrong, or the server's certificate has expired. Run sudo timedatectl set-ntp true and try again.
  • The wingpanel applet shows the VPN but cannot toggle it: the netdev group membership is missing; see the preparation section above.
  • Speed is poor: pick a geographically closer endpoint, or choose a UDP port that your provider has not congested. Australian users on FTTN often see better speeds connecting to Sydney than to a US West Coast server, simply due to the shorter fibre path from the local exchange.

Keeping the connection healthy across updates

elementary OS pushes major upgrades every couple of years and minor point releases in between, and OpenVPN touches enough system components that an unattended upgrade can occasionally break the tunnel. After each kernel update, a quick sudo systemctl restart NetworkManager && sudo nmcli connection up "your-profile-name" will catch most regressions before they cost you a session. If you rely on a VPN for work and a stable connection matters more than convenience, pin the kernel version on the laptop you use for sensitive tasks; elementary OS exposes kernel management through the regular apt pipeline, so a sudo apt-mark hold linux-image-generic is enough to keep your current kernel in place until you have time to test a newer one.

It is also worth revisiting the provider's profile bundle every six to twelve months. Certificate authorities rotate, server addresses change, and Australian providers in particular have been migrating endpoints between Sydney, Melbourne, and newer points of presence in Perth as data-centre pricing shifts. Re-importing the updated .ovpn file and deleting the stale profile from NetworkManager keeps the menu tidy and avoids the subtle bug where the old profile still works but routes through a server the provider has decommissioned.

What stays with you is a small, repeatable routine: update, install, import, harden, verify, and revisit. The encrypted tunnel you build with that routine will travel with you from a beachside café in Noosa to a co-working space in Adelaide, keeping your banking apps, your ABC iView catch-up sessions, and your work calls inside a private channel regardless of which Australian network you happen to be on.

Browse the News Archive
Latest Updates

From the elementary weekly series

Low-poly faceted abstract render in dark charcoal and electric blue tones, suggesting a news bulletin or announcement
elementary news

elementary weekly #20

The first week with the final Freya release — community reactions, tips, and early impressions gathered in one roundup.

Abstract low-poly geometric scene in midnight blue and soft cyan, conveying a live broadcast or event atmosphere
elementary news

elementary SPECIAL

A live Hangouts event with the elementary OS founders, held on 11 April 2015, discussing the Freya final release.

Low-poly faceted render in deep navy and muted teal with subtle amber highlights, suggesting a tutorial or guide
Tips and Tricks

Timeshift Guide

How to use Timeshift — the intuitive system restore utility for elementary OS — to recover from configuration mishaps.

Explore

Topics & Resources

Dive into guides, application recommendations, and community discussions covering every aspect of elementary OS.