OpenVPN Setup (VPS, TP-Link Omada, PCs)
Budget: €30 – €250 EUR
We are looking for an administrator to set up OpenVPN (VPS->TP-Link Omada + PC)
Objective:
Set up and configure an OpenVPN server on our Linux VPS and connect a router (TP-Link Omada VPN) to it as an OpenVPN client + end PCs/laptops.
The result must be: functional communication between a remote PC connected via VPN and our internal server in the LAN behind the router (e.g., 192.168.10.0/24). PCs connected via VPN must be able to see devices in this LAN (ping, RDP/HTTP/SMB, etc.).
Scope of work
Installation and security of the OpenVPN server (Debian/Ubuntu, systemd).
Creation of CA, server certificate, and unique client certificates.
Setting up the Omada router as an OpenVPN client (TUN, TCP, without TLS-Auth/ta.key).
Routing:
iroute/CCD for LAN behind the router (e.g., 192.168.10.0/24),
push route for VPN clients to see LAN,
allow VPN → LAN in firewall (Omada).
Network policies:
split-tunnel (do not redirect all internet traffic to VPN),
ip_forward=1, NAT only if necessary,
port 1194/TCP (alternatively 443/TCP) if necessary.
Transfer of .ovpn profiles:
for router (cert-only, TCP, without tls-crypt),
for Windows/macOS/Android/iOS (inline certs).
Brief documentation: adding/removing a client, certificate renewal/revocation (CRL), paths to logs.
Acceptance criteria
The openvpn@server service is running, tun0 has an IP (e.g. 10.8.0.1/24).
The router is connected as a client; its CN and assigned VPN IP can be seen in openvpn-status.log.
From a PC connected via VPN, we can access our internal server in the LAN behind the router:
ping to the internal server IP (e.g., 192.168.10.x) goes through,
access to services (RDP/HTTP/SMB as needed) works.
The PC in the VPN also sees other devices in the LAN behind the router (according to the defined subnet).
The configuration is persistent after reboot (both server and router).
The transferred profiles work on at least 4 × Windows PCs.
Required experience
OpenVPN (2.5/2.6), routing (iroute/CCD), iptables/nftables.
TP-Link Omada SDN (OpenVPN client).
Basic Linux server hardening.
What we provide
SSH access to VPS (public IPv4 available).
Access to Omada Controller
LAN information (e.g., 192.168.10.0/24) and IP of our internal server (e.g., 192.168.10.X).
Outputs
Functional configuration, configuration backups.
.ovpn profiles (router + min. 2 end users).
Brief documentation (1–2 pages) and short handover consultation.
Objective:
Set up and configure an OpenVPN server on our Linux VPS and connect a router (TP-Link Omada VPN) to it as an OpenVPN client + end PCs/laptops.
The result must be: functional communication between a remote PC connected via VPN and our internal server in the LAN behind the router (e.g., 192.168.10.0/24). PCs connected via VPN must be able to see devices in this LAN (ping, RDP/HTTP/SMB, etc.).
Scope of work
Installation and security of the OpenVPN server (Debian/Ubuntu, systemd).
Creation of CA, server certificate, and unique client certificates.
Setting up the Omada router as an OpenVPN client (TUN, TCP, without TLS-Auth/ta.key).
Routing:
iroute/CCD for LAN behind the router (e.g., 192.168.10.0/24),
push route for VPN clients to see LAN,
allow VPN → LAN in firewall (Omada).
Network policies:
split-tunnel (do not redirect all internet traffic to VPN),
ip_forward=1, NAT only if necessary,
port 1194/TCP (alternatively 443/TCP) if necessary.
Transfer of .ovpn profiles:
for router (cert-only, TCP, without tls-crypt),
for Windows/macOS/Android/iOS (inline certs).
Brief documentation: adding/removing a client, certificate renewal/revocation (CRL), paths to logs.
Acceptance criteria
The openvpn@server service is running, tun0 has an IP (e.g. 10.8.0.1/24).
The router is connected as a client; its CN and assigned VPN IP can be seen in openvpn-status.log.
From a PC connected via VPN, we can access our internal server in the LAN behind the router:
ping to the internal server IP (e.g., 192.168.10.x) goes through,
access to services (RDP/HTTP/SMB as needed) works.
The PC in the VPN also sees other devices in the LAN behind the router (according to the defined subnet).
The configuration is persistent after reboot (both server and router).
The transferred profiles work on at least 4 × Windows PCs.
Required experience
OpenVPN (2.5/2.6), routing (iroute/CCD), iptables/nftables.
TP-Link Omada SDN (OpenVPN client).
Basic Linux server hardening.
What we provide
SSH access to VPS (public IPv4 available).
Access to Omada Controller
LAN information (e.g., 192.168.10.0/24) and IP of our internal server (e.g., 192.168.10.X).
Outputs
Functional configuration, configuration backups.
.ovpn profiles (router + min. 2 end users).
Brief documentation (1–2 pages) and short handover consultation.
Related categories:
System Admin
Linux
VPS
Ubuntu
Network Administration
OpenVPN
Network Security
VPN