Getting Started with OpenVPN AS - Appliance

Updated by @KeithResar on Oct 23, 2015

Technology Profile

Customer Support
Sales Contact
[email protected]


OpenVPN Access Server is a full featured secure network tunneling VPN software solution that integrates OpenVPN server capabilities, enterprise management capabilities, simplified OpenVPN Connect UI, and OpenVPN Client software packages that accommodate Windows, MAC, Linux, Android, and iOS environments. OpenVPN Access Server supports a wide range of configurations, including secure and granular remote access to internal network and/ or private cloud network resources and applications with fine-grained access control.


CenturyLink Cloud Users


  • Access to the CenturyLink Cloud platform as an authorized user.
  • account with password authentication (two factor authentication not yet supported).

Steps to Deploy a New Appliance

  1. Locate the Blueprint in the Blueprint Library.

    • Login to the Control Portal. From the Nav Menu on the left, click Orchestration > Blueprints Library.
    • Search for "OpenVPN AS Appliance" in the keyword search on the right side of the page.
  2. Click the deploy blueprint button.

  3. Set Required parameters.

    • Control User Password - The password associated with your login.
  4. Set Optional Parameters.

    • Password/Confirm Password (This is the root password for the server. Keep this in a secure place).
    • Set DNS to “Manually Specify” and use “” (or any other public DNS server of your choice).
    • Optionally set the server name prefix.
    • The default values are fine for every other option.
  5. Review and Confirm the Blueprint.

  6. Deploy the Blueprint.

    • Once verified, click the deploy blueprint button.
    • You will see the deployment details stating the Blueprint is queued for execution.
  7. Deployment Complete.

    • Once the Blueprint has finished execution you will receive a number of emails.
    • The first will indicate the server has been deployed and the second will come a few minutes later once the appliance has been fully activated.
    • If you do not receive an email like the one shown below you may have had a deployment error - review the Blueprint Build Log to for error messages.

    Email #1: Appliance deploy started
    Email #2: Appliance deploy complete

    • Wait for the second email indicating your appliance is ready for use before attempting to access the resource.
  8. Access Your Appliance.

    • Access your appliance and finalize configuration by opening an ssh connection to your server and loging in as the root user with the password credentials supplied in Step 4 above.
    • Note that on first login you will finalize the configuration.
    • For proper authentication select root as your login user or if leveraging the default openvpn user you'll need to set the credentials for that user with the passwd openvpn command:

    `To initially login to the Admin Web UI, you must use a username and password that successfully authenticates you with the host UNIX system (you can later modify the settings so that RADIUS or LDAP is used for authentication instead).

    You can login to the Admin Web UI as "openvpn" or specify a different user account to use for this purpose.

    Do you wish to login to the Admin UI as "openvpn"?

    Press ENTER for default [yes]: no

    Specify the username for an existing user or for the new user account: root Note: This user already exists.`


The costs listed above in the above steps are for the infrastructure only. After deploying this Blueprint, you may secure entitlements to the technology using the following steps:

  • Email: [email protected]

Additional Resources

Frequently Asked Questions

Where do I obtain my license? Contact [email protected]

Who should I contact for support?

  • For issues related to deploying OpenVPN AS email [email protected]
  • For issues related to cloud infrastructure, please open a ticket using the CenturyLink Cloud Support Process.

Customer Support

Can’t find what you need?
Give us a call.


M – F, 8am to 6pm