<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>VyOS - Blog</title>
    <link>https://blog.vyos.io</link>
    <description>VyOS Platform Project news and updates 
All about development and project life in  our blog</description>
    <language>en</language>
    <pubDate>Fri, 29 May 2026 11:15:49 GMT</pubDate>
    <dc:date>2026-05-29T11:15:49Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>VyOS Project May 2026 Update</title>
      <link>https://blog.vyos.io/vyos-project-may-2026-update</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-project-may-2026-update" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/vyos_mothly_update_may2026_blogpost.png" alt="VyOS Project May 2026 Update" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;The May development update is here. Despite the fact that we had to deal with a downpour of vulnerabilities such as Copy Fail, Dirty Frag, and others (they are all fixed in rolling and in emergency LTS release updates available to subscription holders now!), the VyOS team and community members still added quite a lot of new features and bug fixes this month.&lt;/p&gt; 
&lt;p&gt;They include a fix for the long-standing, very annoying bug that led to needless OpenVPN server restarts on config changes that only affected user settings that go to the client config dir, multiple new options for DHCPv4 and DHCPv6 servers, initial support for traffic engineering in segment routing, and more.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-project-may-2026-update" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/vyos_mothly_update_may2026_blogpost.png" alt="VyOS Project May 2026 Update" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;The May development update is here. Despite the fact that we had to deal with a downpour of vulnerabilities such as Copy Fail, Dirty Frag, and others (they are all fixed in rolling and in emergency LTS release updates available to subscription holders now!), the VyOS team and community members still added quite a lot of new features and bug fixes this month.&lt;/p&gt; 
&lt;p&gt;They include a fix for the long-standing, very annoying bug that led to needless OpenVPN server restarts on config changes that only affected user settings that go to the client config dir, multiple new options for DHCPv4 and DHCPv6 servers, initial support for traffic engineering in segment routing, and more.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Fvyos-project-may-2026-update&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>high availability</category>
      <category>ipsec</category>
      <category>openvpn</category>
      <category>Segment Routing</category>
      <pubDate>Fri, 29 May 2026 10:45:00 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/vyos-project-may-2026-update</guid>
      <dc:date>2026-05-29T10:45:00Z</dc:date>
    </item>
    <item>
      <title>VyOS 1.5.0 GA release</title>
      <link>https://blog.vyos.io/vyos-1.5.0-ga-release</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-1.5.0-ga-release" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/vyos_datasheet_lts_1.5_linkedin-1.png" alt="VyOS 1.5.0 GA release" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;VyOS 1.5.0 LTS release is now finalized and its CLI is frozen for any non-compatible changes. Right now subscribers can already download the generic ISO and other on-premises flavors for x86-64 systems. If you are contributing to VyOS and want LTS release images for personal use, remember that we are happy to share them through &lt;a href="https://vyos.net/get/contributor-subscriptions/"&gt;contributor subscriptions&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;Its development started in 2024 and followed the usual two-year LTS release cycle. In those two years we introduced multiple big features including a long-awaited accelerated dataplane and a huge amount of bug fixes.&lt;/p&gt; 
&lt;h3 style="font-weight: bold; text-align: center;"&gt;&lt;a href="https://blog.vyos.io/hubfs/VyOS%201.5.0%20Circinus%20-%20Release%20Notes.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #ff9902; text-decoration: underline;"&gt;Download the full release notes&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/h3&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-1.5.0-ga-release" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/vyos_datasheet_lts_1.5_linkedin-1.png" alt="VyOS 1.5.0 GA release" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;VyOS 1.5.0 LTS release is now finalized and its CLI is frozen for any non-compatible changes. Right now subscribers can already download the generic ISO and other on-premises flavors for x86-64 systems. If you are contributing to VyOS and want LTS release images for personal use, remember that we are happy to share them through &lt;a href="https://vyos.net/get/contributor-subscriptions/"&gt;contributor subscriptions&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;Its development started in 2024 and followed the usual two-year LTS release cycle. In those two years we introduced multiple big features including a long-awaited accelerated dataplane and a huge amount of bug fixes.&lt;/p&gt; 
&lt;h3 style="font-weight: bold; text-align: center;"&gt;&lt;a href="https://blog.vyos.io/hubfs/VyOS%201.5.0%20Circinus%20-%20Release%20Notes.pdf"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="color: #ff9902; text-decoration: underline;"&gt;Download the full release notes&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/h3&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Fvyos-1.5.0-ga-release&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>ipsec</category>
      <category>openvpn</category>
      <category>press release</category>
      <category>dmvpn</category>
      <category>vpp</category>
      <category>1.5</category>
      <category>load balancing</category>
      <category>dhcp</category>
      <category>netflow</category>
      <pubDate>Tue, 31 Mar 2026 00:30:00 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/vyos-1.5.0-ga-release</guid>
      <dc:date>2026-03-31T00:30:00Z</dc:date>
    </item>
    <item>
      <title>VyOS Project September 2024 Update</title>
      <link>https://blog.vyos.io/vyos-project-september-2024-update</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-project-september-2024-update" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/VyOS%20Project%20-%20september%202024.png" alt="VyOS Project September 2024 Update" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;Summer is over now, and many people are returning to their routines. Check out what we've done in the last month of the summer: that includes a few small config syntax changes, multiple improvements in OpenVPN, an API endpoint for importing PKI objects, and a whole bunch of bug fixes!&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-project-september-2024-update" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/VyOS%20Project%20-%20september%202024.png" alt="VyOS Project September 2024 Update" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;Summer is over now, and many people are returning to their routines. Check out what we've done in the last month of the summer: that includes a few small config syntax changes, multiple improvements in OpenVPN, an API endpoint for importing PKI objects, and a whole bunch of bug fixes!&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Fvyos-project-september-2024-update&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>openvpn</category>
      <category>1.5</category>
      <category>ipoe</category>
      <pubDate>Sun, 22 Sep 2024 21:42:55 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/vyos-project-september-2024-update</guid>
      <dc:date>2024-09-22T21:42:55Z</dc:date>
    </item>
    <item>
      <title>What's coming for OpenVPN in VyOS 1.4?</title>
      <link>https://blog.vyos.io/whats-coming-for-openvpn-in-vyos-1.4</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/whats-coming-for-openvpn-in-vyos-1.4" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/OpenVPN%20in%20VyOS%201.4.png" alt="OpenVPN in VyOS 1.4" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;OpenVPN is one of the oldest open-source VPN protocols and implementations. It took the world by storm in the early 2000s because it was a huge improvement over VPN solutions of the time: PPTP that used a patent-encumbered cipher with questionable security; IPsec or L2TP/IPsec, which was hard to set up and very unfriendly to NATed and poorly configured networks; and a variety of proprietary SSL VPNs. OpenVPN was trivial to set up on the client ­— give it a single config file, and you are done, and it was open-source and available for all popular OSes.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/whats-coming-for-openvpn-in-vyos-1.4" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/OpenVPN%20in%20VyOS%201.4.png" alt="OpenVPN in VyOS 1.4" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, Community!&lt;/p&gt; 
&lt;p&gt;OpenVPN is one of the oldest open-source VPN protocols and implementations. It took the world by storm in the early 2000s because it was a huge improvement over VPN solutions of the time: PPTP that used a patent-encumbered cipher with questionable security; IPsec or L2TP/IPsec, which was hard to set up and very unfriendly to NATed and poorly configured networks; and a variety of proprietary SSL VPNs. OpenVPN was trivial to set up on the client ­— give it a single config file, and you are done, and it was open-source and available for all popular OSes.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Fwhats-coming-for-openvpn-in-vyos-1.4&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>openvpn</category>
      <category>security</category>
      <category>1.4</category>
      <pubDate>Tue, 26 Sep 2023 13:00:00 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/whats-coming-for-openvpn-in-vyos-1.4</guid>
      <dc:date>2023-09-26T13:00:00Z</dc:date>
    </item>
    <item>
      <title>VyOS Project September 2023 Update</title>
      <link>https://blog.vyos.io/vyos-project-september-2023-update</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-project-september-2023-update" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/VyOS%20Project%20September%202023%20Update.png" alt="VyOS Project September 2023 Update" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, community!&lt;/p&gt; 
&lt;p&gt;We're back with an end-of-summer update. We've been quite busy cleaning up legacy code, fixing bugs, and adding remaining features planned for the future 1.4.0 (Sagitta) LTS release that we hope to finish by 2024. Soon, we'll create a sagitta branch in our git repositories to stabilize the codebase that will become the new 1.4.0 LTS release. Rolling release development will continue in the current branch, and the future 1.5 LTS release will be "Circinus". Meanwhile, the minor release 1.3.4 of the Equuleus branch is in its final stages, and we'll soon build and release its images. Here's what's happened in August.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/vyos-project-september-2023-update" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/VyOS%20Project%20September%202023%20Update.png" alt="VyOS Project September 2023 Update" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello, community!&lt;/p&gt; 
&lt;p&gt;We're back with an end-of-summer update. We've been quite busy cleaning up legacy code, fixing bugs, and adding remaining features planned for the future 1.4.0 (Sagitta) LTS release that we hope to finish by 2024. Soon, we'll create a sagitta branch in our git repositories to stabilize the codebase that will become the new 1.4.0 LTS release. Rolling release development will continue in the current branch, and the future 1.5 LTS release will be "Circinus". Meanwhile, the minor release 1.3.4 of the Equuleus branch is in its final stages, and we'll soon build and release its images. Here's what's happened in August.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Fvyos-project-september-2023-update&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>openvpn</category>
      <category>project updates</category>
      <category>1.3</category>
      <category>1.4</category>
      <category>monitoring</category>
      <pubDate>Thu, 14 Sep 2023 18:43:26 GMT</pubDate>
      <author>e.altunbas@vyos.io (Erkin Batu Altunbas)</author>
      <guid>https://blog.vyos.io/vyos-project-september-2023-update</guid>
      <dc:date>2023-09-14T18:43:26Z</dc:date>
    </item>
    <item>
      <title>CVE-2022-0778: remote DoS in OpenSSL, VyOS 1.3.0 is affected</title>
      <link>https://blog.vyos.io/cve-2022-0778</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/cve-2022-0778" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/CVE-2022-0778.png" alt="CVE-2022-0778" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello Community!&lt;/p&gt; 
&lt;p&gt;Yesterday the OpenSSL team disclosed a remote DoS vulnerability in OpenSSL versions 1.0.2, 1.1.1, and 3.0. You can find a complete description here in their&amp;nbsp; &lt;a href="https://www.openssl.org/news/secadv/20220315.txt"&gt;CVE-202200778&lt;/a&gt; report. In short, any remote attacker can cause an infinite loop in OpenSSL by attempting to establish a TLS connection with a specially crafted malformed certificate, and cause a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.vyos.io/cve-2022-0778" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.vyos.io/hubfs/CVE-2022-0778.png" alt="CVE-2022-0778" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Hello Community!&lt;/p&gt; 
&lt;p&gt;Yesterday the OpenSSL team disclosed a remote DoS vulnerability in OpenSSL versions 1.0.2, 1.1.1, and 3.0. You can find a complete description here in their&amp;nbsp; &lt;a href="https://www.openssl.org/news/secadv/20220315.txt"&gt;CVE-202200778&lt;/a&gt; report. In short, any remote attacker can cause an infinite loop in OpenSSL by attempting to establish a TLS connection with a specially crafted malformed certificate, and cause a denial of service.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Fcve-2022-0778&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>openvpn</category>
      <category>security</category>
      <category>ssl</category>
      <pubDate>Wed, 16 Mar 2022 20:22:41 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/cve-2022-0778</guid>
      <dc:date>2022-03-16T20:22:41Z</dc:date>
    </item>
    <item>
      <title>Take a third option: site to site OpenVPN</title>
      <link>https://blog.vyos.io/take-a-third-option-site-to-site-openvpn</link>
      <description>&lt;div class="posthaven-post-body"&gt; 
 &lt;p&gt;I've written a long series of post about setting up IPsec VPNs between NATed machines. As you've already seen, with some creative configuration it's possible, but is it always worth the sacrifice? Sometimes performance requirements, or lack of support for anything else on the other side make it necessary, but if the other side is also a VyOS, or another open source system, there's an alternative.&lt;/p&gt; 
 &lt;p&gt;While OpenVPN is usually associated with road warrior VPN setups, it is not limited to it. It does have a site to site option and it's very quick and easy to setup. For some strange reason, that option is neglected by just about everyone who otherwise supports OpenVPN: in OpenWRT it's possible to setup through custom config options, while in Mikrotik RouterOS it's not possible to setup at all. In VyOS we have an explicit option for it. OPNsense also supports site to site OpenVPN out of the box (I thought it doesn't, but the authors corrected me).&lt;br&gt;&lt;/p&gt; 
 &lt;p&gt;The advantages are that it takes very few commands to get a tunnel to work, and that it will work in any network where you can forward a single port, even is both sides are behind double NAT. The downside is performance: squeezing even 100mbit/s of encrypted traffic out of it can be impossible, typical iperf figures are 10-20 mbit/s. For many use cases that performance is more than enough, though if you plan to use the tunnel for storage replication or another high-traffic job, that option is definitely not for you and you'll have to resort to IPsec.&lt;/p&gt; 
 &lt;p&gt;&lt;a&gt;&lt;/a&gt;&lt;br&gt; &lt;/p&gt; 
 &lt;h2&gt;Setting up site to site OpenVPN&lt;/h2&gt; 
 &lt;h3&gt;Generating a key&lt;/h3&gt; 
 &lt;p&gt;OpenVPN in site to site mode supports either static pre-shared keys or x.509. For a quick tunnel setup between your own routers, the format option is a lot easier and arguably not less secure. Unlike most IPsec implementations, OpenVPN stores pre-shared keys in files, and uses keys of considerable length (default is 2038. It takes just one command to generate a suitable key:&lt;/p&gt; 
 &lt;pre&gt;run generate openvpn key /config/auth/mysite.key
&lt;/pre&gt; 
 &lt;p&gt;Then you can copy the file to the remote side via SCP or something else. That command is a wrapper for "openvpn --genkey --secret" in case you want to generate a key outside VyOS. It's a good idea to store the keys in /config/auth directory that was specifically meant for authentication data, since /config will be migrated to the new image when you upgrade your system — if you put them in /etc, they will be inaccessible from the upgraded image.&lt;/p&gt; 
 &lt;h3&gt;Setting up the tunnel&lt;/h3&gt; 
 &lt;p&gt;It's quite straightforward. &lt;br&gt;&lt;/p&gt; 
 &lt;p&gt;Local (listening) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 mode site-to-site&lt;br&gt;
set interfaces openvpn vtun10 description 'My remote site'&lt;br&gt;
set interfaces openvpn vtun10 local-host 203.0.113.50 # Listen address&lt;br&gt;
set interfaces openvpn vtun10 local-address 192.168.34.1 # Tunnel address&lt;br&gt;
set interfaces openvpn vtun10 local-port 8000 # Port to listen on&lt;br&gt;
set interfaces openvpn vtun10 protocol udp # Can be TCP but TCP is slower&lt;br&gt;
set interfaces openvpn vtun10 remote-address 192.168.34.2 # Tunnel peer address&lt;br&gt;
set interfaces openvpn vtun10 shared-secret-key-file /config/auth/mysite.key # The file you generated
&lt;/pre&gt; 
 &lt;p&gt;Remote (connecting) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 mode site-to-site&lt;br&gt;
set interfaces openvpn vtun10 remote-host 203.0.113.50 # Remote router external address&lt;br&gt;
set interfaces openvpn vtun10 local-address 192.168.34.2 # Tunnel address, don't forget to local/remote addresses for the remote side!&lt;br&gt;
set interfaces openvpn vtun10 remote-port 8000 # Port to connect on&lt;br&gt;
set interfaces openvpn vtun10 protocol udp # Can be TCP but TCP is slower&lt;br&gt;
set interfaces openvpn vtun10 remote-address 192.168.34.1&lt;br&gt;
set interfaces openvpn vtun10 shared-secret-key-file /config/auth/mysite.key
&lt;/pre&gt; 
 &lt;p&gt;As you can see, with less than 10 commands on each side, you can get a tunnel working.&lt;/p&gt; 
 &lt;h3&gt;What about x.509?&lt;/h3&gt; 
 &lt;p&gt;It is doable, though I'm not sure if it's really worth the trouble for site to site tunnels.&lt;/p&gt; 
 &lt;p&gt;This is how it's done. Local (listening) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 tls role passive&lt;br&gt;
set interfaces openvpn vtun10 tls dh-file /config/auth/dh2048.pem&lt;br&gt;
set interfaces openvpn vtun10 tls ca-cert-file /config/auth/ca.crt&lt;br&gt;
set interfaces openvpn vtun10 tls cert-file /config/auth/local.crt&lt;br&gt;
set interfaces openvpn vtun10 tls key-file /config/auth/local.key
&lt;/pre&gt; 
 &lt;p&gt;Remote (connecting) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 tls role active&lt;br&gt;
set interfaces openvpn vtun10 tls ca-cert-file /config/auth/ca.crt&lt;br&gt;
set interfaces openvpn vtun10 tls cert-file /config/auth/remote.crt&lt;br&gt;
set interfaces openvpn vtun10 tls key-file /config/auth/remote.key
&lt;/pre&gt; 
 &lt;h3&gt;Routing&lt;/h3&gt; 
 &lt;p&gt;Since OpenVPN tunnels look like normal network interfaces, you can setup routing right away as if they were physical links. You can also use push-route commands through custom options (as in, openvpn-option "push ..."). Note that OpenVPN in site to site mode doesn't install any routes by default so you need to take care of it yourself.&lt;br&gt;&lt;/p&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="posthaven-post-body"&gt; 
 &lt;p&gt;I've written a long series of post about setting up IPsec VPNs between NATed machines. As you've already seen, with some creative configuration it's possible, but is it always worth the sacrifice? Sometimes performance requirements, or lack of support for anything else on the other side make it necessary, but if the other side is also a VyOS, or another open source system, there's an alternative.&lt;/p&gt; 
 &lt;p&gt;While OpenVPN is usually associated with road warrior VPN setups, it is not limited to it. It does have a site to site option and it's very quick and easy to setup. For some strange reason, that option is neglected by just about everyone who otherwise supports OpenVPN: in OpenWRT it's possible to setup through custom config options, while in Mikrotik RouterOS it's not possible to setup at all. In VyOS we have an explicit option for it. OPNsense also supports site to site OpenVPN out of the box (I thought it doesn't, but the authors corrected me).&lt;br&gt;&lt;/p&gt; 
 &lt;p&gt;The advantages are that it takes very few commands to get a tunnel to work, and that it will work in any network where you can forward a single port, even is both sides are behind double NAT. The downside is performance: squeezing even 100mbit/s of encrypted traffic out of it can be impossible, typical iperf figures are 10-20 mbit/s. For many use cases that performance is more than enough, though if you plan to use the tunnel for storage replication or another high-traffic job, that option is definitely not for you and you'll have to resort to IPsec.&lt;/p&gt; 
 &lt;p&gt;&lt;a&gt;&lt;/a&gt;&lt;br&gt; &lt;/p&gt; 
 &lt;h2&gt;Setting up site to site OpenVPN&lt;/h2&gt; 
 &lt;h3&gt;Generating a key&lt;/h3&gt; 
 &lt;p&gt;OpenVPN in site to site mode supports either static pre-shared keys or x.509. For a quick tunnel setup between your own routers, the format option is a lot easier and arguably not less secure. Unlike most IPsec implementations, OpenVPN stores pre-shared keys in files, and uses keys of considerable length (default is 2038. It takes just one command to generate a suitable key:&lt;/p&gt; 
 &lt;pre&gt;run generate openvpn key /config/auth/mysite.key
&lt;/pre&gt; 
 &lt;p&gt;Then you can copy the file to the remote side via SCP or something else. That command is a wrapper for "openvpn --genkey --secret" in case you want to generate a key outside VyOS. It's a good idea to store the keys in /config/auth directory that was specifically meant for authentication data, since /config will be migrated to the new image when you upgrade your system — if you put them in /etc, they will be inaccessible from the upgraded image.&lt;/p&gt; 
 &lt;h3&gt;Setting up the tunnel&lt;/h3&gt; 
 &lt;p&gt;It's quite straightforward. &lt;br&gt;&lt;/p&gt; 
 &lt;p&gt;Local (listening) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 mode site-to-site&lt;br&gt;
set interfaces openvpn vtun10 description 'My remote site'&lt;br&gt;
set interfaces openvpn vtun10 local-host 203.0.113.50 # Listen address&lt;br&gt;
set interfaces openvpn vtun10 local-address 192.168.34.1 # Tunnel address&lt;br&gt;
set interfaces openvpn vtun10 local-port 8000 # Port to listen on&lt;br&gt;
set interfaces openvpn vtun10 protocol udp # Can be TCP but TCP is slower&lt;br&gt;
set interfaces openvpn vtun10 remote-address 192.168.34.2 # Tunnel peer address&lt;br&gt;
set interfaces openvpn vtun10 shared-secret-key-file /config/auth/mysite.key # The file you generated
&lt;/pre&gt; 
 &lt;p&gt;Remote (connecting) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 mode site-to-site&lt;br&gt;
set interfaces openvpn vtun10 remote-host 203.0.113.50 # Remote router external address&lt;br&gt;
set interfaces openvpn vtun10 local-address 192.168.34.2 # Tunnel address, don't forget to local/remote addresses for the remote side!&lt;br&gt;
set interfaces openvpn vtun10 remote-port 8000 # Port to connect on&lt;br&gt;
set interfaces openvpn vtun10 protocol udp # Can be TCP but TCP is slower&lt;br&gt;
set interfaces openvpn vtun10 remote-address 192.168.34.1&lt;br&gt;
set interfaces openvpn vtun10 shared-secret-key-file /config/auth/mysite.key
&lt;/pre&gt; 
 &lt;p&gt;As you can see, with less than 10 commands on each side, you can get a tunnel working.&lt;/p&gt; 
 &lt;h3&gt;What about x.509?&lt;/h3&gt; 
 &lt;p&gt;It is doable, though I'm not sure if it's really worth the trouble for site to site tunnels.&lt;/p&gt; 
 &lt;p&gt;This is how it's done. Local (listening) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 tls role passive&lt;br&gt;
set interfaces openvpn vtun10 tls dh-file /config/auth/dh2048.pem&lt;br&gt;
set interfaces openvpn vtun10 tls ca-cert-file /config/auth/ca.crt&lt;br&gt;
set interfaces openvpn vtun10 tls cert-file /config/auth/local.crt&lt;br&gt;
set interfaces openvpn vtun10 tls key-file /config/auth/local.key
&lt;/pre&gt; 
 &lt;p&gt;Remote (connecting) side:&lt;/p&gt; 
 &lt;pre&gt;set interfaces openvpn vtun10 tls role active&lt;br&gt;
set interfaces openvpn vtun10 tls ca-cert-file /config/auth/ca.crt&lt;br&gt;
set interfaces openvpn vtun10 tls cert-file /config/auth/remote.crt&lt;br&gt;
set interfaces openvpn vtun10 tls key-file /config/auth/remote.key
&lt;/pre&gt; 
 &lt;h3&gt;Routing&lt;/h3&gt; 
 &lt;p&gt;Since OpenVPN tunnels look like normal network interfaces, you can setup routing right away as if they were physical links. You can also use push-route commands through custom options (as in, openvpn-option "push ..."). Note that OpenVPN in site to site mode doesn't install any routes by default so you need to take care of it yourself.&lt;br&gt;&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Ftake-a-third-option-site-to-site-openvpn&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>openvpn</category>
      <category>tutorial</category>
      <category>Uncategorized</category>
      <category>vpn</category>
      <pubDate>Fri, 30 Mar 2018 10:38:22 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/take-a-third-option-site-to-site-openvpn</guid>
      <dc:date>2018-03-30T10:38:22Z</dc:date>
    </item>
    <item>
      <title>Keeping OpenVPN config and certs/keys in one file</title>
      <link>https://blog.vyos.io/index.php/2014/06/20/keeping-openvpn-config-and-certskeys-in-one-file</link>
      <description>&lt;p&gt;OpenVPN client setup requires multiple files apart from the config: CA, client certificate, and client key, in case of certificate authentication. With login/password authentication it’s not just one file either, you still need a CA.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenVPN client setup requires multiple files apart from the config: CA, client certificate, and client key, in case of certificate authentication. With login/password authentication it’s not just one file either, you still need a CA.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=4129050&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.vyos.io%2Findex.php%2F2014%2F06%2F20%2Fkeeping-openvpn-config-and-certskeys-in-one-file&amp;amp;bu=https%253A%252F%252Fblog.vyos.io&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>openvpn</category>
      <category>Uncategorized</category>
      <pubDate>Fri, 20 Jun 2014 04:27:00 GMT</pubDate>
      <author>daniil@sentrium.io (Daniil Baturin)</author>
      <guid>https://blog.vyos.io/index.php/2014/06/20/keeping-openvpn-config-and-certskeys-in-one-file</guid>
      <dc:date>2014-06-20T04:27:00Z</dc:date>
    </item>
  </channel>
</rss>
