Tunnelblick Linux



The purpose of this document is to lead the users to configure theirs OpenVPN clients to access to a VPN server. We will see how to install and configure the most used OpenVPN’s GUI for Microsoft Windows, Linux, Mac OS X and Windows Mobile for Pocket PC. At the end of the document we will learn to use the OpenVPN’s command line interface. This last possibility is useful, because the openvpn command, which you can execute by using the prompt (Unix Shell or Windows Prompt) accepts the same parameters and has the same behavior regardless from which Operating System you use. In addition, you could use the openvpn command in a script to automatically start the VPN connection.
More precisely, we will see how to access to a VPN server builded with ZeroShell and configured with the default parameters. To obtain an OpenVPN server with the default behavior, you only need, after you have activated Zeroshell on your network, to enable the OpenVPN service by clicking on the Enabled flag in the [VPN]->[OpenVPN] section of the Zeroshell’s web interface. By default, the OpenVPN server of Zeroshell listens on the port 1194/TCP with TLS/SSL encryption and LZO compression enabled. The user authentication well be checked by using username and password credentials, but we will try the X.509 authentication as well.
For further details about the configuration of an OpenVPN server builded with ZeroShell, you can read the “An OpenVPN server using Zeroshell” how-to.

The sections in which this how-to is divided are as follows below. Keep in mind that the first section, which is related to the configuration file of OpenVPN, it is common to the other ones, because the configuration file do not depend on the GUI or Operating System that you use.

The configuration file of OpenVPN

Tunnelblick For Linux

To use Tunnelblick you need access to a VPN server: your computer is one end of the tunnel and the VPN server is the other end. For more information, see Getting VPN Service. Tunnelblick is licensed under the GNU General Public License, version 2 and may be distributed only in accordance with the terms of that license.

Because the large number of parameters you can define either in the configuration file or in the command line, you could configure OpenVPN in many different manners. In any case, to obtain a connection with a Zeroshell VPN server, you only need to define a small number of them in your client’s configuration file. In order to further simplify the configuration of the OpenVPN client, you could download an example of configuration file by clicking on the link OpenVPN Client configuration.The file has comments that explain the meaning of the parameters, but only 2 of them you surely need to change to obtain a VPN connection with Zeroshell:

  • remote zeroshell.example.com 1194You have to replace zeroshell.example.com with the hostname or the IP address of the OpenVPN server. The Zeroshell’s default configuration requires that the OpenVPN service listens on the port 1194/TCP and therefore you must not modify the second parameter (1194).
  • ca CA.pemThe ca parameter specify a file (in PEM format), that contains the X.509 Certification Authority with which the server certificate has been signed. To get the CA’s X.509 certificate, you only need to click on the CA hyperlink in the Zeroshell’s login page. If you save the CA’s certificate with the name CA.pem in the same directory of the configuration file, the you do not need to change the parameter. Otherwise, you must specify the absolute path of the file.
    Keep in mind that certificate of the Certification Authority is required also if you do not use the X.509 client authentication but the “Only Password” authentication (Default in Zeroshell).

Notice, that you will always have to manually edit the configuration file. This is because the Graphical User Interfaces that we are going to learn do not assist you in the creation and maintenance of the OpenVPN’s configuration. They only help you to connect and disconnect the VPN, and ask for the username and password if they are required.

  • Double-click on the downloaded Tunnelblick file to install the program. (It will be named Tunnelblick and contain information about what version it is. For example: the downloaded file for version 3.7.8 is named Tunnelblick3.7.8build5180.dmg) D.Double-click on the Tunnelblick icon (it looks like a tunnel) to begin installation.
  • OpenVPN provides flexible VPN solutions to secure your data communications, whether.
  • Download Tunnelblick: For more information, refer to the following article: Tunnelblick VPN Setup; Download Linux client v1.3 (for Linux): NOTE: Install openvpn-2.1 standard client and CURL. For more information, refer to the following article: Linux CLI OpenVPN Client; Download HMA Web Proxy Browser Extension.

OpenVPN GUI for Windows

To install OpenVPN GUI for Windows on a Microsoft Windows XP 32/64 bits, follow the steps below:

  • Download the installer from the URL https://openvpn.net/index.php/open-source/downloads.html. Choose he file that contains the GUI and the OpenVPN software already included;
  • Start with the installation. Select the default options and confirm the installation of the TAP-Win32 Adapter V8 device (it is a Virtual Ethernet interface used by OpenVPN).
    When the Installer has finished to work, the TrayBar contains the VPN icon with two red terminals and the Earth Globe symbol. Such terminals are yellow when OpenVPN is trying to establish the connection and they are green when you are finally connected with the VPN;
  • In the Windows Start Menu, click on [Start]->[All Programs]->[OpenVPN]->[OpenVPN configuration file directory]. You will be able to explore the folder:

    C:Program FilesOpenVPNconfig

    in which you must copy the files zeroshell.ovpn that contains the OpenVPN configuration and CA.pem that is the X.509 Certification Authority certificate. You can look at the previous section for details on how to obtain these files;

  • Edit the file zeroshell.ovpn and replace zeroshell.example.com with the hostname or the IP address of the OpenVPN router;
  • At this point, you have finished to install and configure the OpenVPN client and its GUI. With a double-click on the OpenVPN icon in the Tray Bar, you can try to start the VPN connection. A dialog box will appear and request you to type the username and the password to be authenticated (look at the note *). If the authentication step is successfully completed, then the VPN connection will be established and the two yellow terminals will become green.

Tunnelblick For Linux

By right-clicking on the OpenVPN icon in the Traybar appears a contextual menu with several useful options: Connect, Disconnect, Show Status, View Log, Edit Config, Proxy Settings. Particularly useful to solve connection problems is the item View Log that allows to know the reason of the failures.

If instead the VPN is connected (the two terminals are green), but you are not able to reach the remote LAN or Internet using the Virtual Private Network, then you should use the ipconfig /all command from the Windows Prompt. Buy adobe premiere pro cs6 for mac. Here there is an example of the lines of output about the virtual Ethernet interface:

To be sure that the IP traffic is actually routed across the VPN and hence encrypted, you must check that the IP Address and the Default Gateway assigned to the TAP Virtual Interface belong to the remote LAN you are connected. To better check this condition, you could also use the tracert /d <Remote IP Address> command: if the first hop that is printed belongs to a subnet of the remote LAN then your VPN works fine and the traffic that reaches the remote site is encrypted across Internet.

Tunnelblick for Mac OS X

A Graphical User Interface for OpenVPN on Mac OS X is a package called Tunnelblick. To install this GUI, follow the steps below:

  • Download the package from the site https://tunnelblick.net. It is a disk image file which contains the GUI, the OpenVPN software, and some documentation;
  • Double-click on the .dmg file;
  • A Finder window appears on the desktop. The window contains Tunnelblick.app. Double-click it;
  • A dialog box will ask you to confirm that you wish to install Tunnelblick.app to Applications. Click the Install button;
  • A dialog box will ask if you wish to launch Tunnelblick. Click the Launch button;
  • A dialog box will ask for an administrator username/password to secure Tunnelblick. Type administrator credentials and click the OK button;
  • A dialog box will appear welcoming you to Tunnelblick. Click the Create and open configuration folder button;
  • A Finder window will open with the configuration folder. The window will contain only an alias to Tunnelblick.app. Drag the files zeroshell.ovpn and CA.pem to the window. If you don’t know how to obtain these two files, please read the section The configuration file of OpenVPN
  • Double-click on the Launch Tunnelblick alias;
  • A dialog box will appear asking if you wish to check for updates to Tunnelblick automatically. Click Check Automatically or Don’t Check, as you prefer;
  • Tunnelblick is now installed. Its icon appears near the clock. Click on the Tunnelblick icon, then select the [Details…] item;
  • Click on the Edit Configuration button in the dialog box which appears. Replace zeroshell.example.com with the hostname or the IP address of the VPN server. Save the configuration file and quit;
  • Start the VPN connection by clicking on the Tunnelblick icon near the clock and selecting the Connect ‘Zeroshell’ item;
  • A dialog box will appear asking for an administrator username/password to secure the configuration file. Type administrator credentials and click OK;
  • A dialog box will appear asking for the VPN username and password. Type the VPN username and password and click “OK” (look at the Note *). You may save them in the Keychain by putting a check in the check box.

In the case in which there are connection problems, select the item [Details…] to check the OpenVPN’s log messages.
If you want to verify that the IP address that the VPN server has assigned to you, actually belongs to the remote LAN with which you are connected, you have to open a Mac OS X Terminal and at the prompt of the shell type the command:

ifconfig tap0

Realtek hd audio output driver for mac. the result looks like this: Is dualies dmg per shotbudgetbrown.

The line that starts with inet show you that the VPN IP address assigned to you is 192.168.250.1 (by default Zeroshell issues IP addresses which belong to the subnet 192.168.250.0/24 with 192.168.250.254 as Default Gateway). To be sure that the IP traffic is actually routed across the VPN and hence encrypted, you must check that the IP Address and the Default Gateway assigned to the TAP Virtual Interface belong to the remote LAN you are connected. To better check this condition, you could also use the traceroute -n <Remote IP Address> command: if the first hop that is printed belongs to a subnet of the remote LAN (192.168.250.254 by default) then your VPN works fine and the traffic that reaches the remote site is encrypted across Internet.

KVpnc for Linux

KVpnc is a Linux frontend that is able to manage many type of VPN clients such as: Cisco VPN, IPSec, PPTP, OpenVPN, L2TP. It has also the SmartCard support. Obviously, in this document we will see only the installation and configuration of KVpnc related to OpenVPN. Binary packages of KVpnc exist for many Linux distributions such as the RPM for Suse and Fedora. For Ubuntu and Kubuntu (and other Debian derived distributions), you can easily install KVpnc with OpenVPN by using the commands:

sudo apt-get install openvpn
sudo apt-get install kvpnc

Notice that, unlike the other GUIs, the packages of KVpnc do not include OpenVPN, but you must install it alone. In order to make this document regardless of the Linux Distribution used, we will build and install KVpnc by compiling the source code, but if a binary package exists for your Linux distribution, you should prefer to use it without waste your time in the building process.
Because KVpnc uses the QT libraries, their presence and their include files are required in the build process. In the next steps, we will assume that the OpenVPN package is already installed. If you are not in this situation, you should read the section Build and install OpenVPN to learn to install OpenVPN.
Now we are ready to install and configure KVpnc by following the steps given bellow:

  • Download the KVpnc’s source code package from the web page https://userbase.kde.org/KVpnc. We’ll use the release 0.8.9 of KVpnc, but you should get the latest one;
  • Extract the source code by using the command:
    tar xvfj kvpnc-0.8.9.tar.bz2
  • Build and install KVpnc by following this steps:
    cd kvpnc-0.8.9
    ./configure
    make
    sudo make installFor some Linux distributions, the ./configure command could be unable to locate the QT libraries. In this case, you must find out where the include files and the libraries are located and specify the paths by adding the parameters –with-qt-includes=/usr/lib64/qt-3.3/include/ –with-qt-libraries=/usr/lib64/qt-3.3/lib/ to the ./configure. Of course, you should replace the path /usr/lib64/qt-3.3/ with the one in which the QT libraries are located in your Linux system;
  • Make the directory /etc/openvpn/ with the command sudo mkdir /etc/openvpn and copy in the new directory the files zeroshell.ovpn and CA.pem. How to obtain such files is described in the section The configuration file of OpenVPN;
  • To use KVpnc with unprivileged users the sudo command is required and the line
    ALL ALL=NOPASSWD:/usr/bin/kvpncmust be added at the end of the file /etc/sudoers (notice that you need to have administrator privileges to change this file). After that, you are able to launch the kvpnc process by using the command:
    sudo /usr/bin/kvpnc

In this manner, the kvpnc will have the root‘s privileges needed to create the tap0 Virtual Ethernet Interface and add the static routes in the Kernel routing table;

  • Import the profile that allow you to create a VPN with Zeroshell by using the following command:kvpnc –openvpnimport=/etc/openvpn/zeroshell.ovpnBy using the Profile Manager that appears, make the following configuration changes:
    • From the General options, insert in the VPN gateway field the IP address or the hostname of the VPN server;
    • From the OpenVPN options, check that the Authentication method is the SHA1 hash function and not MD5 one;

    Press [Apply] and then [Ok] on the Profile Manager. After that, save the Zeroshell profile using the [Profile]->[Save Profile…] menu item and close kvpnc interface with [File]->[Quit] menu item;

  • Start the KVpnc GUI with the command sudo /usr/bin/kvpnc and click the [Connect] button to establish the VPN connection. At this point, you are requested for the username and the password to use to authenticate your identity against the VPN server (look at the Note *).

If you want to verify that the IP address that the VPN server has assigned to you, actually belongs to the remote LAN with which you are connected, you have to open a terminal and at the prompt of the shell type the command:

ifconfig tap0

the result looks like this:

The line that starts with inet show you that the VPN IP address assigned to you is 192.168.250.50 (by default Zeroshell issues IP addresses which belong to the subnet 192.168.250.0/24 with 192.168.250.254 as Default Gateway). To be sure that the IP traffic is actually routed across the VPN and hence encrypted, you must check that the IP Address and the Default Gateway assigned to the TAP Virtual Interface belong to the remote LAN you are connected. To better check this condition, you could also use the traceroute -n <Remote IP Address> command: if the first hop that is printed belongs to a subnet of the remote LAN (192.168.250.254 by default) then your VPN works fine and the traffic that reaches the remote site is encrypted across Internet.

OpenVPN for Windows Mobile on Pocket PC

OpenVPN for Pocket PC is still an Alpha release, but it worked fine during the test on Microsoft Windows Mobile v5.0 installed on a PDA i-Mate JASJAR (equivalent to a HTC Universal Qtek 9000). Before seeing how to install and configure this software, notice that you will have to manually modify the OpenVPN configuration file and therefore you should use Microsoft ActiveSync for editing from your Personal Computer. Another solution could be to install on your PPC the Total Commander CE that is a Freeware File Manager for Pocket PC, available at the URL http://www.ghisler.com/pocketpc.htm. This filemanager includes an Editor which allows you to edit the OpenVPN configuration file directly from your Palm Device.
Now, follow the steps below to install OpenVPN for Windows Mobile on your Pocket PC:

  • Download the OpenVPN for Pocket PC from the site http://ovpnppc.ziggurat29.com/ovpnppc-main.htm. There are two type of file: the .exe format that you can install from your Personal Computer connected to the PPC with ActiveSync; the .cab format that you can directly install on your Pocket PC. Pick the package in the format that you prefer and install it.
  • Supposing that you have installed OpenVPN for Pocket PC in the directory Program FilesOpenVPN of the device’s memory, copy the files zeroshell.ovpn and CA.pem in the folder Program FilesOpenVPNconfig. To know how to obtain these two files, read the section The configuration file of OpenVPN;
  • Edit the configuration file Program FilesOpenVPNconfigzeroshell.ovpn to connect to your OpenVPN server:
    • Replace zeroshell.example.com with the IP address or the hostname of the OpenVPN server;
    • Replace CA.pem with the path of the file that contains the Certification Authority. In your case the path is:ca “Program FilesOpenVPNconfigCA.pem”Notice the double quotes and the double backslashes that are requested by the syntax of this parameter;
  • Click on the icon of OpenVPN and from the submenu [Start from Config.] select zeroshell. At this point you are requested for the Username and Password (look at the Note *). If the client is authenticated against the server, the VPN connection is established.

If you have connection problems, check the log file Program FilesOpenVPNlogzeroshell.log. Finally, to verify that the traffic is actually routed and encrypted in the VPN you need to perform a traceroute operation at a remote host: if the first hop that is reported belongs to the remote LAN (by default the VPN box has the IP 192.168.250.254), you are sure that the VPN works as you expect. Windows Mobile has not a traceroute utility and therefore you need to install one. A free software to make network debugging is ceNetTools with which you are able to make the traceroute, the ping and whois operations.

The command line of OpenVPN

If the system you are using has not a Graphical User Interface for OpenVPN, you have to use the OpenVPN’s command line. This can also be used in the case in which you want to automatically start the VPN by using the startup scripts. By typing the command man openvpn from a Unix shell, the OpenVPN’s manual page will be displayed. A great number of parameters are available to directly use in the command line prefixed by two consecutive hyphens (–). The same parameters (not prefixed by –) can also be specified in the configuration file. Except for a few cases, it is better to specify the parameters in a configuration file rather than having them in a too long and heavy to read command line.
This section does not examine the parameters because they are already listed and described in the manual page of OpenVPN, but it only describe how to establish a VPN with a Zeroshell OpenVPN server by using the command line:

  • Put the files zeroshell.ovpn and CA.pem in a same directory (suppose /etc/openvpn/). For details about how to obtain these files, read the section The configuration file of OpenVPN;
  • Edit the configuration file zeroshell.ovpn replacing zeroshell.example.com with the IP address or hostname of the VPN server;
  • Change the current directory to /etc/openvpn/ and exec (with root privileges) the command:openvpn –config zeroshell.ovpnAt this point, you are requested for the Username and the Password (look at the Note *). If the client is authenticated against the server, the VPN connection is established.

Build and install OpenVPN

For the most operating system in which OpenVPN works, binary packages already compiled exist. Anyway, sometimes, above all for some Linux Distributions, you could need to build OpenVPN by starting with the source code. Below, it is described how to build OpenVPN:

  • Download the OpenVPN’s source code from the site http://openvpn.net. Pick the latest stable release that is available (suppose the release 2.0.9 in the rest of this document);
  • Extract the files which are stored in the zipped archive that you have downloaded by using the tar command in the following manner:
    tar xvfz openvpn-2.0.9.tar.gz
  • Change the current directory to openvpn-2.0.9 with the command:
    cd openvpn-2.0.9
  • Check the system and produce the Makefiles by using the following command:
    ./configure –prefix=/usrIf the ./configure procedure claims that the lzo libraries and headers are not found in the system, install the lzo compression software as follows below:
  • Download the source package of LZO from the site http://www.oberhumer.com/ and extract its content with the command:
    tar xvfz lzo-2.02.tar.gz
  • Change the current directory to lzo-2.02 and install the LZO software with the commands:
    • ./configure
    • make
    • make install (This command needs to be executed with root privileges to write in /usr)

    Once installed the lzo libraries and headers, came back to the directory openvpn-2.0.9 and launch again the command
    ./configure –prefix=/usr

  • Compile the source code with the Makefiles you have just created by using the command:
    make
  • Install the binary program openvpn and its manual pages with the command:
    make installBecause the files will be written below the system directory /usr, the last command must be executed with root privileges.

Notes

(*) The manner in which the users are authenticated depend on the OpenVPN server configuration. Zeroshell supports a multi-domain authentication system in which you have to configure the authentication source which can be a Kerberos 5 KDC (local, external and trusted) or an external RADIUS server. One of these authentication domains is set to be the default domain. The users of the default domain do not need to specify the username in the form of username@domain (ex. fulvio@example.com). Notice that the domain name is not case sensitive, because if the domain is configured to be a Kerberos V realm, it is automatically converted to uppercase.

What is a VPN?
Compatible Clients
Requesting a VPN key
Downloading and Installing the Client
Connecting/Disconnecting to the VPN

Tunnelblick Linux Mint

What is a VPN?

The math department's virtual private network (VPN) creates a secure connection from a public internet connection to the department's private network. This allows you to surf the web while off-campus as if you were physically connected to the math network in LGRT. All traffic is encrypted, ensuring online privacy and the protection of sensitive data. Benefits to using the VPN include, but are not limited to:

  • Access to academic journals subscribed to by UMass
  • Secure connection to gradebooks and other sensitive online data when connected to an insecure public network
  • Access to online resources only accessible from the math network, such as department printing, access to lab computers (without bouncing in via SSH), and the RCF cluster.

Compatible Clients

  • Windows: OpenVPN
  • Mac: Tunnelblick
  • Linux: OpenVPN3

Requesting a VPN key

To request a VPN key, send an email to support@math.umass.edu.

Note that after requesting a VPN key, you should expect two separate emails in return. One with the profile, and another with how to access the password/key.

Downloading and Installing the Client

Windows

  1. Click here to automatically start downloading the VPN client
  2. Click “Save File” when prompted, and run the installer once it has fully downloaded
  3. If you are not on an administrator account, you will need to enter an admin password at this point. Click through the installation and accept all the default options
  4. From the start menu, search for “OpenVPN GUI”, and open it. It may look like nothing has happened, but the client is now running in the background.
  5. In the bottom-right corner of your screen, click on the small upward-facing arrow in the tray to show the hidden icons. Find the icon that looks like the computer with a lock on it. Right-click on this icon and then select “Settings…” from the menu
  6. In the Settings window, check the boxes next to “Launch on Windows startup” and “Silent connection”. Click “OK”
  7. Find the email from root@vpn.math.umass.edu that contains your personal VPN profile. Download the attachment (the file will be named after your math username, and have extension “.ovpn”) and save it somewhere on your computer, such as your Downloads folder
  8. Find where you saved the .ovpn file. Now you have to decide if you would like the VPN configured for ALL USERS on the computer, or JUST YOUR ACCOUNT.
    • If you would like to configure the VPN for ALL USERS, move the .ovpn file to the following folder on your PC:
    • “This PC” > “Local Disk (C:)” > “Program Files” > “OpenVPN” > “config”.

      You will need to admin privileges to save to this location. Click “Continue”. If you are on a standard account, you will need to enter an admin password at this time.

    • If you would like to instead configure the VPN connection for JUST YOUR ACCOUNT: As in step 5, click the small upward-facing arrow in the bottom-right corner of your screen, and right-click on the computer with a lock on it. Select “Import file…”. Find the .ovpn file you saved, and click “Open”. If all goes well, you should see a popup window saying “File imported successfully”.

Mac

  1. Download the latest stable version of Tunnelblick here
  2. Launch the downloaded .dmg file, which will cause a window to open. On this window, double-click the Tunnelblick icon.
  3. You might need to allow your Mac to launch the Tunnelblick installer, in which case a window will pop up asking for your permission to open it. Accept it and the window will disappear.
  4. If a 'Tunnelblick VPN Configuration Installation' window pops up, then you have OpenVPN configurations that have not been converted to Tunnelblick VPN Configurations. Click on 'Convert Configurations', and the window will disappear.
  5. A 'Welcome to Tunnelblick' window should appear now. Click 'Continue', and enter your administrator password in the next window. When the installation has finished, a notification will be displayed.
  6. When there are no configurations (which is usually the case for a new installation of Tunnelblick), the configuration helper will appear. Click the appropriate button and the configuration helper will guide you through the installation of configurations.
  7. For more details on installing configurations, see Downloading and Installing Configurations.

Linux

  1. Instructions on how to install OpenVPN3 pre-built packages on Linux distributions can be found here

Connecting/Disconnecting to the VPN

Windows

Tunnelblick Linux
  1. In the bottom-right corner of your screen, click on the small upward-facing arrow in the tray. It should expand to a larger menu. Find the icon that looks like the computer with a lock on it. Right-click on this icon and then select “Connect” from the menu.
  2. When prompted, you will be asked for a password. This is your unique VPN password. If you have not been notified of your password, you should reach out to support@math.umass.edu
  3. If all goes well, you should see a notification in the bottom right corner that you are now connected! The VPN icon in the tray (the “computer with a lock on it”) should turn green, and if you click this link, google should report your public IP address as “128.119.47.34”
  4. [OPTIONAL] If you want the VPN to start automatically when you log in, you can take the additional step:
    • Open to the following folder:
    • “This PC” > “Local Disk (C:)” > “Users” > [your account name]

    • From the top menu, click the “View” tab, then check the box next to “Hidden items”. A folder named “AppData” should now appear. Open this folder, then continue to:
    • “Roaming” > “Microsoft” > “Windows” > “Start Menu” > “Programs” > “Startup”

    • Create a new desktop shortcut by right-clicking in this window, selecting “New” from the dropdown menu, and then “Shortcut”. In the bar underneath “Type the location of the item”, enter in the following (quotes included), replacing “username” with your own math username. Note there are TWO “-“s before the word “connect”:
    • “C:Program FilesOpenVPNbinopenvpn-gui.exe” --connect “username.ovpn”.

    • Click “Next”. Name the shortcut whatever you’d like. Something like “math vpn profile” is fine.
  5. To disconnect, click on the OpenVPN lock icon and choose 'Disconnect'.

Mac

Tunnelblick Kali Linux

  1. Click the tunnelblick icon in the menu bar (top right of your screen). If there's no icon, you will need to launch tunnelblick first (from Applications folder).
  2. This will open a drop down menu - select 'Connect <profile>'. A notification will appear in the top right corner, indicating the connection status. Once connected, if you click this link, google should report your public IP address as “128.119.47.34”
  3. To disconnect, repeat the same steps. The 'Connect ' option should now say 'Disconnect '

Tunnelblick Linux

Linux

Tunnelblick Vpn Linux

  1. Open a terminal window, and enter the following command to start the VPN session:

    openvpn3 session-start --config /path/to/your/profile.ovpn

  2. To disconnect, use:

    openvpn3 session-manage --config /path/to/your/profile.ovpn --disconnect