How to Make Your Own VPN – Complete 13-Steps Tutorial
Today, we present you with a complete guide on how to make your own VPN at home in just a few relatively painless steps. Our walkthrough will guide you through the process of installing and configuring your DIY VPN. Don’t be intimidated, you don’t need advanced coding skills; just follow our step by step instructions, and you’ll be up and running a powerful OpenVPN connection in no time.

Virtual private networks are gaining popularity among even the most casual of internet users. It’s no surprise, either, seeing as how they’re easy to use, affordable, and come with a ton of useful features that protect your online privacy. Instead of signing up with a VPN service, though, some people have decided to make their own VPN using a virtual private server and OpenVPN.
Making your own VPN isn’t easy, however. The process requires many steps, and includes a lot of work on the command line. We highly recommend that you brush up on your familiarity with encryption and command prompts or PowerShell before you begin. If you’re new to VPNs in general, you may want to review our VPN setup guide to understand the basics before diving into this advanced DIY approach.
Check out these hassle-free alternatives to making your own VPN:
- NordVPN – Best Overall VPN Provider – NordVPN strikes the right balance of useability and deep functionality. Unbreakable encryption, massive server network, no logs.
- Surfshark – Unlimited simultaneous connections, CleanWeb anti-malware/adware, and auto-obfuscation on every server.
- ExpressVPN – Searing speeds, military-grade cryptography, one-button interface.
- IPVanish – Tried and true, the heavy streamer’s favorite for buffer-free video and audio.
If you’re up to the task, a self-hosted VPN encrypts traffic between your device and your server — but it’s important to set the right expectations before you invest time in the setup. A DIY VPN is not an anonymity tool. Unlike a commercial VPN service that routes your traffic through a shared pool of IP addresses belonging to thousands of other users, your self-hosted VPN has a fixed, identifiable exit point. Your ISP can still see that you’re connecting to your server, and your hosting provider can see the traffic leaving it. This is a fundamentally different privacy model from a commercial VPN.
A self-hosted VPN is a great fit for these use cases:
- Secure remote access to your home network — connect back to devices, files, and services on your home LAN from anywhere.
- Protecting traffic on public Wi-Fi — encrypt your connection at coffee shops, airports, and hotels so local attackers can’t intercept your data.
- Accessing your own self-hosted services — reach a private media server, NAS, or home automation system securely over the internet.
A self-hosted VPN is not ideal for:
- Blending into shared IP pools — your server’s IP is yours alone, making it easier to identify and block than a commercial VPN’s shared addresses.
- Broad geo-unblocking — you’re tied to the location of your single server, whereas commercial VPNs offer dozens of countries at a click.
- Zero-maintenance privacy — you are responsible for keeping your server patched, your certificates rotated, and your configuration secure. There is no support team.
Recommended External VPN Hosts
Before we dive into the details of how to make your own VPN, it’s well worth a mention that there are a number of truly excellent services already out there. Unless you are a power user with very specific requirements, you’ll find that the following VPN services will more than meet your needs with minimal hassle. No need to go through lengthy installation processes or edit pages of configuration files; simply sign up, install, and you’re good to go! If you’re also comparing mainstream consumer options, our PureVPN deal page is worth a look. If you’re comparing business-focused options, our GlobalProtect VPN review is worth a look.
1. NordVPN
NordVPN has set the gold standard for VPN industry expectations, and that’s not just because it’s one of the most venerable, trusted names around. They continually refine and expand their offer, to the point where their massive worldwide network spans over 5,500 servers in 59 different countries.
With 256-bit encryption and modern tunneling protocols like OpenVPN as the backbone of your privacy suite, you can stealth your way past website blocks and dodge ad tracking and government snooping all with one click. You don’t even have to sacrifice on performance, either–NordVPN’s speeds are great for streaming and gaming without lag or stutter.
Finally, NordVPN has a zero-logs guarantee you can trust. Panamanian jurisdiction excludes them from subjection to 5, 9, and 14 Eyes international surveillance and data retention agreements.
Read our full NordVPN review.
- SPECIAL OFFER: 2-yr plan (70% off - link below)
- GooglePlay users rating: 4.3/5.0
- Torrenting is explicitly permitted
- Retains no metadata of your browsing
- Customer Service (24/7 Chat).
- Not much
- Sometimes slow in procesing refunds (but always do).
2. Surfshark
Surfshark is a newer VPN, but it hasn’t beat around the bush becoming one of the best in the industry. Powerful 256-bit encryption and modern tunneling protocols allow you to beat censorship and surveillance anywhere. Meanwhile, myriad cybersecurity extras keep you safer online: anti-malware, anti-adware, pop-up blocker, site blacklist, plus IP, DNS, and WebRTC leak protection.
While 800 servers in 50 countries may seem rather modest for a major VPN, every one of them has specialty server functionality including obfuscation. This helps you beat deep packet inspection to thwart everything from Netflix’s VPN blocking to Egypt’s OpenVPN ban.
Surfshark never limits your bandwidth, traffic, or server switches — not even your simultaneous connections. This makes it a great choice for families, students, project teams, and more. Their disk-free server infrastructure is physically incapable of storing your VPN usage metadata long-term, making good on their no-logs guarantee.
- Every server optimized for unblocking Netflix, BBC iPlayer, Hulu, and more
- Unlimited server switching
- Unbreakable AES-256-GCM encryption on every connection
- Based in the British Virgin Islands, where there are no data retention laws
- Get help any time of day via email, phone, or live chat.
- Connection speeds won't impress users of other high-end VPNs
- Relatively young VPN still has to prove itself trustworthy over the long haul.
Read our full Surfshark review.
3. ExpressVPN
ExpressVPN is fast, easy to use, and incredibly secure. The company operates a network of over 3,000 servers in 94 different countries, each delivering amazingly fast connection speeds around the world. You’ll get strong 256-bit encryption for all of your online traffic, as well as unlimited bandwidth, no torrent or P2P restrictions, and a strict zero-logging policy that keeps your data perfectly safe.
Read our full ExpressVPN review.
- Works with US Netflix, iPlayer, Hulu and other services
- Super fast servers (minimal speed loss)
- Govt-level AES-256 encryption
- No logs for personal data
- 24/7 Customer Service.
- Power-users configuration options.
4. IPVanish
IPVanish is another excellent choice for a fast and secure VPN. The service comes with wonderful privacy features such as 256-bit AES encryption, DNS leak protection, and an automatic kill switch, all of which are designed to ensure your identity never slips through the cracks. All of this is backed by a zero-logging policy and absolutely no limits on bandwidth or speed.
To top it all off, IPVanish runs a network of over 1,300 servers in 60 different countries, giving you plenty of options for bypassing censorship blocks and downloading torrent files anonymously.
Read our full IPVanish review, or check the latest IPVanish promo code before signing up.
Choose Where to Host Your Make Your Own VPN Server
Before you run a single command, the most important decision you’ll make is where your VPN server actually lives. There are three main models, each with different requirements, trade-offs, and ideal use cases. The step-by-step walkthrough later in this guide follows the cloud VPS model — it is not a true “at-home” deployment, and it’s worth understanding why that matters.
Home Server or Raspberry Pi
What you need: A always-on computer or Raspberry Pi, a static public IP address (or a dynamic DNS service like DuckDNS), port forwarding configured on your router, and enough upload bandwidth to handle your VPN traffic.
Main advantage: Your traffic never touches a third-party data center. You own the hardware end-to-end, and there are no monthly hosting fees beyond your home internet bill.
Main limitation: Many home ISPs use CGNAT (Carrier-Grade NAT), which means your home connection sits behind a shared public IP that you do not control. In that scenario, inbound VPN connections are blocked entirely and port forwarding won’t work. Your ISP may also prohibit running servers on residential plans. Home upload speeds can also bottleneck performance.
Best for: Secure remote access to your home network and self-hosted services when you have a standard residential connection with a publicly reachable IP. This is one of the most popular reasons people want to make their own VPN.
Cloud VPS (This Guide’s Approach)
What you need: A paid virtual private server account with a provider like DigitalOcean, Vultr, or Linode. Costs typically run $5–$6/month for a basic instance. The provider assigns you a dedicated public IP, so CGNAT is not a concern.
Main advantage: Reliable uptime, a static public IP, fast data-center bandwidth, and straightforward port access. This is the easiest environment in which to follow a setup guide reliably.
Main limitation: Your VPN traffic exits through your hosting provider’s network. The provider can see your server’s activity, and this is not an anonymous setup. You are also paying an ongoing monthly fee, which may exceed the cost of a budget commercial VPN subscription.
Best for: Users who want to make their own VPN with a dedicated, controllable server without the CGNAT and hardware headaches of a home setup.
Router-Based VPN
What you need: A router that supports OpenVPN or WireGuard server mode — typically a router running DD-WRT, OpenWrt, or certain Asus/Netgear models with built-in VPN server firmware. You’ll still need a publicly reachable IP (same CGNAT caveat as above applies).
Main advantage: No separate server hardware or hosting fees. Every device on your home network is automatically covered when you connect remotely, without installing software on each device.
Main limitation: Router hardware is generally underpowered for VPN encryption, which caps throughput. Firmware support varies widely, and misconfiguring a router can expose your whole network. Not all routers support server mode at all.
Best for: Users who want whole-home remote access and already have compatible router hardware, and who don’t need high VPN throughput.
OpenVPN vs WireGuard vs Simpler DIY Alternatives to Make Your Own VPN
OpenVPN is not the only serious route to a self-hosted VPN anymore. Before you commit to a setup path, here’s a plain-language comparison of your main options so you can pick the one that fits your goals.
OpenVPN
OpenVPN is battle-tested, extremely well-documented, and supported on virtually every platform — Windows, Mac, Linux, iOS, Android, and most routers. It gives you granular control over ciphers, authentication, routing, and certificate management. The trade-off is complexity: the setup involves multiple manual steps, and the config file format can be unforgiving. This guide walks you through the OpenVPN path when you make your own VPN.
WireGuard
WireGuard is a newer protocol built into the Linux kernel. It is significantly simpler to configure than OpenVPN (often just a handful of commands), uses modern cryptography by default, and typically delivers better throughput and lower latency. If you’re comfortable on the command line and don’t need legacy device support, WireGuard is worth serious consideration for new deployments. It is now included in Ubuntu 24.04 and can be installed with a single apt command.
Simpler DIY Alternatives
If the manual setup in this guide feels like more than you want to tackle, several projects dramatically reduce the complexity when you want to make your own VPN:
- PiVPN — a guided installer script designed specifically for Raspberry Pi that sets up either OpenVPN or WireGuard in minutes, handling certificate generation and config automatically.
- Outline — a project from Jigsaw (Google) that lets you deploy a Shadowsocks-based server on a VPS with a few clicks via a desktop manager app. It is aimed at ease of use and is well-suited to sharing access with others.
- Tailscale — takes a completely different approach. Instead of running a traditional VPN server with open ports, Tailscale creates an encrypted mesh network between your own devices using the WireGuard protocol under the hood. There is no manual port forwarding, no certificate management, and it works through CGNAT. The free tier covers personal use across multiple devices.
Choose this if…
- Remote access to your home network: PiVPN on a Raspberry Pi or Tailscale are the easiest paths. Tailscale is the better choice if your ISP uses CGNAT.
- Public Wi-Fi protection on a VPS: OpenVPN (this guide) or WireGuard on a cloud server both work well. WireGuard is simpler if you’re starting fresh.
- Private access between your own devices only: Tailscale is purpose-built for this and requires the least configuration of any option here.
How to Make Your Own VPN – Step-by-step Guide
Below we go through the process of how to make your own VPN. While the process takes some effort, DIY warriors and privacy nuts alike will revel in taking full control over their privacy. Without further ado, let’s get started.
Step 1: Get a Remote Server that Runs Ubuntu
There are a variety of services that offer scalable virtual private server options, but one of the easiest to use and most affordable is Digital Ocean. The company has a fantastic guide on installing and configuring your own Ubuntu 24.04 LTS server, which you should follow before beginning the rest of this guide on how to make your own VPN. Ubuntu 24.04 is the current long-term support release and will receive security updates until 2029. Once complete, you’ll have a droplet server configured and ready to go.
Step 2: Install OpenVPN
With your Ubuntu server up and running, your first step will be to install OpenVPN. First, log into your server using your user credentials through a command prompt. Next, run each of the following commands. This will install OpenVPN as well as easy-rsa, a package that will help us in the next step.
You can type the commands listed below, or you can copy/paste them.
$ sudo apt-get update $ sudo apt-get install openvpn easy-rsa
Step 3: Set Up the Easy-RSA Directory
In order for OpenVPN to encrypt traffic and send it between sources, it needs to be able to use trusted certificates. If you need a quick refresher on certificate chain basics, it helps to understand how the CA signs and validates the credentials used here. These generally come from an external Certificate Authority (CA), but because our VPN ecosystem is entirely closed (we run it, we manage it, only we will be using it), it’s possible to set up a simple CA on our Ubuntu server using Easy-RSA 3.
Start by copying the Easy-RSA template directory into your home folder:
$ make-cadir ~/openvpn-ca
Next, navigate to the folder you just created:
$ cd ~/openvpn-ca
Now initialise the PKI (Public Key Infrastructure) directory. This replaces the old source vars and clean-all workflow from Easy-RSA 2:
$ ./easyrsa init-pki
You should see a confirmation that the PKI directory has been created at ~/openvpn-ca/pki.
Step 4: Build the Certificate Authority
With the PKI directory initialised, it’s time to build the root Certificate Authority. Run the following command:
$ ./easyrsa build-ca
You will be prompted to set a CA passphrase and confirm a Common Name for your CA (you can press Enter to accept the default). Keep the passphrase safe — you will need it whenever you sign new certificates. Once complete, your CA certificate will be located at pki/ca.crt.
Step 5: Generate the Server Certificate and Key
With the Certificate Authority in place, we can now generate the server’s certificate request and then sign it. Make sure you’re still in the ~/openvpn-ca directory, then run:
$ ./easyrsa gen-req server nopass
Press Enter to confirm the Common Name. Next, sign the server certificate using your CA:
$ ./easyrsa sign-req server server
Type yes when prompted to confirm the signing. Enter your CA passphrase to complete the process. Now generate the Diffie-Hellman parameters (this may take a few minutes) and a TLS authentication key:
$ ./easyrsa gen-dh $ openvpn --genkey secret pki/ta.key
Step 6: Generate the Client Certificate and Key
In this step we’ll be creating a certificate and key pair for the client (your device) to use when connecting. While still in the ~/openvpn-ca directory, run:
$ ./easyrsa gen-req client1 nopass
Press Enter to accept the default Common Name. Then sign the client certificate:
$ ./easyrsa sign-req client client1
Type yes when prompted and enter your CA passphrase to complete signing.
Step 7: Copy Files to the OpenVPN Directory
With all certificates and keys generated, copy the necessary files into the OpenVPN configuration directory. Note that with Easy-RSA 3, all output lives under the pki/ subdirectory rather than the old keys/ folder:
$ sudo cp pki/ca.crt pki/issued/server.crt pki/private/server.key pki/dh.pem pki/ta.key /etc/openvpn
Step 8: Configure OpenVPN
With all the certificates and key pairs created, we can finally start setting up OpenVPN. We’ll begin by adding a sample configuration file so we can open and edit it ourselves:
$ gunzip -c /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gz | sudo tee /etc/openvpn/server.conf
When the unzip completes, type the following to open the configuration file:
$ sudo nano /etc/openvpn/server.conf
With the server.conf file open in the nano editor, look for the line that matches the text below:
;tls-auth ta.key 0 # This file is secret
Remove the semi-colon from the beginning of this line to uncomment it. On the line directly below it, add the following:
key-direction 0
Scroll to find the cipher section. Find the existing cipher line and replace or update it to use a modern AEAD cipher. AES-256-GCM is the recommended choice for current OpenVPN deployments because it provides authenticated encryption without needing a separate auth directive:
cipher AES-256-GCM
If you are running OpenVPN 2.5 or later (the version included with Ubuntu 24.04), you can also add the following line to negotiate the best available cipher automatically with compatible clients:
ncp-ciphers AES-256-GCM:AES-128-GCM
Next, search for the user and group settings and remove the semi-colon to uncomment them. The lines should look like this when you’re done:
user nobody group nogroup
While we have the server.conf file open, we might as well make some more convenience changes. First, locate the following line and remove the semi-colon so it’s no longer commented out. This allows the VPN to route all of your traffic:
;push "redirect-gateway def1 bypass-dhcp"
Below this line you’ll see a few lines marked dhcp-option. Uncomment them by removing the semi-colon:
;push "dhcp-option DNS 208.67.222.222" ;push "dhcp-option DNS 208.67.220.220"
Protocol and port: By default, OpenVPN uses UDP on port 1194, and that is the recommended setting for most deployments. UDP delivers better performance and lower latency than TCP for VPN tunnels, and you should keep it unless you have a specific reason to change it.
If you are on a restrictive network that blocks UDP or non-standard ports, you can switch to TCP on port 443 as a fallback — but be aware that TCP/443 alone does not make your OpenVPN traffic identical to regular HTTPS traffic, and some networks and firewalls can still detect it with deep packet inspection. To use the TCP fallback, find the protocol and port lines and change them:
# Optional fallback for restrictive networks only: proto tcp port 443
If you leave the defaults (UDP/1194), no changes are needed to these lines. Save the file and close it.
Step 9: Adjusting Network Settings
In this step we’ll be configuring OpenVPN so it can forward traffic, an essential function of any VPN. We’ll start by opening a config file and doing some editing.
$ sudo nano /etc/sysctl.conf
Search for the line listed below and remove the hash character (number sign, or #) to uncomment the setting:
# net.ipv4.ip_forward=1
Save and close the file, then run this command to adjust the values:
$ sudo sysctl -p
Now we'll set the server's firewall so it can properly manipulate traffic. The first thing to do is find the public network interface of our server machine. Type the following into the command prompt: $ ip route | grep default
The output will display a line of information. Just after the word “dev” should be an interface name. In the example below, that name is “wlp11s0”, though yours will likely be different:
default via 203.0.113.1 dev wlp11s0 proto static metric 600
Now we edit the rules file to add the above name in the appropriate place. Start by typing this into the command prompt:
$ sudo nano /etc/ufw/before.rules
Search for a block of text beginning with the following commented-out phrase:
# START OPENVPN RULES
Beneath that you’ll see a line that starts with “-A POSTROUTING”. Add your interface name from above here, replacing the XXXX with the correct text:
-A POSTROUTING -s 10.8.0.0/8 -o XXXX -j MASQUERADE
Now save and close the file.
Next on the list is telling our firewall to forward packets. Open the firewall file by typing the command below:
$ sudo nano /etc/default/ufw
Search for the line marked “DEFAULT_FORWARD_POLICY”. Change “DROP” to “ACCEPT”. When you’re done, it should look like the following:
DEFAULT_FORWARD_POLICY="ACCEPT"
Now save and close the file.
For the last part of this step we’ll adjust the firewall’s settings to allow traffic to OpenVPN. If you kept the default UDP/1194 setting, use the following commands. Adjust the port and protocol if you chose the TCP/443 fallback above:
$ sudo ufw allow 1194/udp $ sudo ufw allow OpenSSH
Now we’ll disable then re-enable the firewall to load the changes we just made. Enter each of these commands into the prompt:
$ sudo uwf disable $ sudo uwf enable
The server is now set up to handle OpenVPN traffic, and your VPN is a lot closer to being ready to go.
Step 10: Starting the OpenVPN Service
With most of the basic configurations taken care of, we can finally start OpenVPN and get our server going. Begin by typing the following line into the command prompt:
$ sudo systemctl start openvpn@server
You’ll get a screen of output text. The second line marked “active” should say “active (running) since…” followed by a date. Type the following line so OpenVPN starts automatically every time your server boots:
$ sudo systemctl enable openvpn@server
Step 11: Client Configurations
Now we’ll get your server ready to accept clients, also known as your internet connected devices. Most of these steps are security related and designed to ensure nothing gets into your server except your own computer. First we’ll create a directory to hold client related files, then change permissions to lock it down:
$ mkdir -p ~/client-configs/files $ chmod 700 ~/client-configs/files
Now we’ll copy an example configuration file so we can edit it:
$ cp /usr/share/doc/openvpn/examples/sample-config-files/client.conf ~/client-configs/base.conf
Open the file in a text editor:
$ nano ~/client-configs/base.conf
Scroll to find the line that starts with the “remote” directive. Edit it so it reflects the port you chose above — 1194 for the UDP default, or 443 if you switched to TCP:
remote server_IP_address 1194
If you chose the TCP/443 fallback, also change the line below marked “proto” to say “tcp”:
proto tcp
Find the “user” and “group” lines and uncomment them by removing the semi-colon:
user nobody group nogroup
Locate the ca, cert, and key lines and comment them out by adding a hash at the beginning. When you’re done, they should look like this:
#ca ca.crt #cert client.crt #key client.key
Update the “cipher” setting to match the one we set on the server. Remove or comment out any separate auth directive, as AES-256-GCM handles authentication internally:
cipher AES-256-GCM
Next, anywhere in the file add a new line and type the following:
key-direction 1
And finally, copy and paste the following commented out lines into the bottom of the file:
# script-security 2 # up /etc/openvpn/update-resolv-conf # down /etc/openvpn/update-resolv-conf
Save your changes and exit the editor.
The next step is to create a script that will compile everything we just made — configuration files, certificates, cipher keys, and all. Start by creating a file in the ~/client-configs directory called “make_config.sh”, then open it using nano. Paste the following code into the script:
#!/bin/bash
# First argument: Client identifier
KEY_DIR=~/openvpn-ca/pki
OUTPUT_DIR=~/client-configs/files
BASE_CONFIG=~/client-configs/base.conf
cat ${BASE_CONFIG} \
<(echo -e '') \
${KEY_DIR}/ca.crt \
<(echo -e ' \n') \
${KEY_DIR}/issued/${1}.crt \
<(echo -e ' \n') \
${KEY_DIR}/private/${1}.key \
<(echo -e ' \n') \
${KEY_DIR}/ta.key \
<(echo -e ' ') \
> ${OUTPUT_DIR}/${1}.ovpn
Save the file and exit. Next, make the file executable by typing the following command:
$ chmod 700 ~/client-configs/make_config.sh
Step 12: Setting Up Your Devices
You’re almost there! In this step we’ll create files that tell the server how to interact with clients. We’ve already made the base certificates in previous steps, now all we need to do is create configs by moving things into a new directory. Use the following commands to do that:
$ cd ~/client-configs $ ./make_config.sh client1
Now we’ll transfer these configuration files to our devices. You’ll need to download an FTP client that’s capable of SFTP connections to do this. Filezilla is a free and open source program that works on Windows, Linux, and Mac operating systems. Install the software and connect to your server through SFTP (not plain FTP) using your credentials above. Then navigate to the following directory on your server:
/client-configs/files
Download the file marked “client1.ovpn”. This contains all the information your local copy of OpenVPN will need to connect to your server.
Now you’ll need to install OpenVPN on your computer, smartphone, tablet, and any other device you plan on using with your VPN. If you’re setting things up on Apple’s tablet, our best iPad VPN guide covers some of the easiest options, while our manual iPhone VPN install guide can help if you’re configuring an iPhone. This is one of the final steps when you make your own VPN, so take care to install the client correctly on each device.
Windows:
- Download OpenVPN and install it to your computer.
- Copy the client1.ovpn file to OpenVPN’s installation directory and put it in the “config” directory.
- Right click on the OpenVPN desktop shortcut and go to “Properties”
- Click “Compatibility” then “Change settings for all users”
- In the next window, check “Run this program as administrator”
- Launch OpenVPN as an administrator. If it pops up warning messages, accept them.
- Enjoy surfing the web using your very own virtual private network!
Mac:
- Download and install Tunnelblick, the free and open source OpenVPN client for Mac.
- When the installation asks if you have any configuration files, simply say “No”.
- Afterwards, open a finder window and double click “client1.ovpn”.
- Launch Tunnelblick.
- Click on the icon in the top corner of the screen and choose “Connect”
- Select the “client1” connection.
- Enjoy your own personal VPN!
Linux:
Install OpenVPN by using the following command prompt lines:
$ sudo apt-get update $ sudo apt-get install openvpn
Now edit the configuration file you downloaded in the step above:
$ nano client1.ovpn
Uncomment the following three lines:
script-security 2 up /etc/openvpn/update-resolv-conf down /etc/openvpn/update-resolv-conf
Save and close the file. You can now connect to your VPN by using the following command:
$ sudo openvpn --config client1.ovpn
Android:
- Install the OpenVPN client for Android.
- Transfer client1.ovpn to your device, either through a USB connection or via cloud storage.
- Run the OpenVPN app and tap the menu button in the top right.
- Choose “Import”, then navigate to the ovpn file’s location and import the file
- Tap the “Connect” button from OpenVPN’s main menu.
iOS:
- Install OpenVPN for iOS.
- Connect your iOS device to a computer and copy the client1.ovpn file to OpenVPN through iTunes.
- Disconnect and launch OpenVPN. A notification will appear saying a new profile is available.
- Tap the green plus sign to import your settings.
- Slide the connect button to “on” to use your VPN.
Step 13: Test Your Make Your Own VPN Setup
Now that you’ve gone through this entire process to make your own VPN, it’s time to verify your VPN is working! All you have to do is disable your VPN, then go to DNSLeakTest. It should display your current, real location. Now enable the VPN and refresh the page. A new IP address should appear, which means you’re safe behind a wall of VPN encryption.
LEARN MORE: How to test for DNS leaks
So, Can You Make Your Own VPN? Does It Work?
We’ve given you exhaustive steps to make your own VPN using OpenVPN and a virtual private server. When you make your own VPN this way, you gain complete control over your privacy and data — something no third-party service can fully replicate. Did you run into any trouble along the way? Reach out to us in the comments below, and we’ll try to get you sorted out.
If you need a VPN for a short while when traveling for example, you can get our top ranked VPN free of charge. NordVPN includes a 30-day money-back guarantee. You will need to pay for the subscription, that’s a fact, but it allows full access for 30 days and then you cancel for a full refund. Their no-questions-asked cancellation policy lives up to its name.