# OpenVPN Client connection configuration in OPNsense

Applied to OPNsense v26.7.1

## Client config

Order matters

Hint: when copy-past avoid whitespaces (trailing spaces, new lines breaks), includ only from '---BEGIN' until 'END---'

Trust, Authorities: Import CA

(img)

Trust, Certificates: Import client certificate and private key

(img)

VPN, OpenVPN, instances, Static keys,: Import static key

(img)

VPN, OpenVPN, instances, Instances: Add

(img)

Interfaces, Assignments, Add, choose unassigned interface, assign it

[![](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/scaled-1680-/LnNRjBtoXAAOe6XQ-image-1787800702616.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/LnNRjBtoXAAOe6XQ-image-1787800702616.png)

Enable new interface and, optionally, configure MTU/MSS to match the server side (use same values, or leave unconfigured)

[![](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/scaled-1680-/lkTUzXluDwA3BfLz-image-1787800792951.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/lkTUzXluDwA3BfLz-image-1787800792951.png)

System, Gateways, Configuration, Add

[![](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/scaled-1680-/TxGFsVbSPWmtKxFX-image-1787800929099.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/TxGFsVbSPWmtKxFX-image-1787800929099.png)

Now it is possible to add routes (if necessary). Although, routes should be pushed from the VPN server to the client.

[![](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/scaled-1680-/DfadoNQluQIvm1cB-image-1787801151027.png)](https://storage.googleapis.com/iau-data-dox/uploads/images/gallery/2026-08/DfadoNQluQIvm1cB-image-1787801151027.png)