oVPN Frequently Asked Questions

  • What can I do with oVPN.to?
    Browse and use the WWW anonymized, uncensored, encrypted and secured through our openVPN / SSH-SOCKS5 / SSL-SOCKS5 / HTTP / TOR Proxy Servers.
    Servers are inter-connected with tinc-VPN and you can chain and randomize SOCKS5/HTTP between Servers through AES-256-CTR/SHA256 encrypted vLAN.
    You can use our Usenet Access to read news or download binaryfiles with fullspeed through our anonymized network.

  • Which encryption is oVPN.to using?
  • openVPN 2.3.x: AES-256-CBC with HMAC SHA-512
  • openVPN 2.4+ uses AES-256-GCM and allows AES-128/192 too with 'ncp-disable'
  • openVPN CA & Server Keys are 4096 bit strong
  • SSH: AES-256-GCM or you can specify own ciphers
  • SSL Tunnel: ECDHE-AES-256-GCM or CHACHA20
  • Do you help me on problems with setup or configurations?
    Yes! Check our Chat page.

  • Setup and Installation
    You need openVPN software (opensource) to use our Anonymous VPN.
    We have configurations per server with your private keys and certificates included.

  • Windows (oVPN.to Client): 'Download'
    Download, Install and Start our 'oVPN.to Client'.
    Enter your 'User ID' + 'API Key' from Account page.
    Our Client will install latest openVPN 2.4.x.
    Do NOT use the standard openVPN GUI! Use only 'oVPN.to Client' !
  • Windows (Standard openVPN GUI): 'OpenVPN.net ( Community )' latest release on branch 2.4.x.
    Extract Configs ZIP file into '%PROGRAMFILES%\openvpn\config\'

  • Linux: install 'openVPN' (2.3.x/2.4.x) package from your distribution or compile latest openVPN from source.
    Become root and extract the Configs ZIP file into '/etc/openvpn'
    Connect with 'openvpn --config /etc/openvpn/NL5.ovpn.to.ovpn'
    You can find more detailed instructions for linux here.

  • MAC OS X: Tunnelblick (opensource) or Viscosity
    Extract the Configs ZIP file and doubleclick the .ovpn files to import into Tunnelblick!

  • Android: openVPN for Android (from google playstore), Author 'Arne Schwabe'
    Extract the Configs ZIP file into /sdcard/openvpn/ and import!

  • iPhone/iPad iOS: openVPN Connect App
    Import TCP Server configs into iOS openVPN Connect App. UDP Servers will not work due do missing 'fragment' option in iOS!

  • Payment Methods
    We offer different payment methods and you'll get credits to your account after payment.
    You can enable service from your credit balance whenever you need.

  • Is there any connection limit?
    Every oVPN Server allows 1 connection / device with openVPN.
    IPv6 enabled oVPN Servers allow 2nd connection with ipv46 configs or ipv64 configs.
    We have more than 40 oVPN Servers (IPv4 + IPv6) available, so you can connect more than 40 devices with openVPN: each to a different oVPN Server.
    SSH or SOCKS5/HTTP-Proxy have no connection limits!

  • Is there any bandwidth limit?
    We don't limit bandwidth for anyone until we notice real excessive usage, disturbing other clients or server itself.
    If you need lots of traffic please contact support or join Chat!

  • Some IRC networks block access from oVPN.to Servers because of an open proxy is detected?
    This can happen on many IRC networks! Join our IRC into channel #help and tell your IRC Server address to whitelist.
    We'll add the IPs to our input drop list and you can connect to your IRC network!

  • Does oVPN.to create any logfiles or monitor my traffic?
    None of our oVPN Server creates any logs and we will never monitor, collect or record or do anything else with your traffic.
    We have no information about when you connect or disconnect or how much traffic you produce or what you download or upload.
    Only in case of abuse, we are able to monitor traffic from Server to abused/attacked hosts, just to stop/block abuse through our services.

  • Under which jurisdiction is oVPN.to?
    Each oVPN Server is handled with jurisdiction at Server's location/country.
    We will close Servers and notify our customers, if we are forced to create any logs anywhere. Not happened yet.
    Your jurisdiction depends on your location/country.

  • Does oVPN.to use Dedicated or Virtual Servers?
    All our servers are real dedicated roots or selfhosted KVM on our roots to earn maximum core power from CPUs.
    We don't trust VirtualServers for full anonymity, if we don't host them ourselves, because diskdumps or even memorydumps could be made easy...

  • How does oVPN.to keep Servers secure?
    We setup Servers with minimal Debian Linux OS and store all needed software and configfiles on RAM mounts!
    Servers become inaccessible for our clients after system failure, reboot or take down.
    No information left when server goes offline or reboots.
    We have to run our setup process again to get servers back online and usable for you.
    Our cronjob monitors software for needed updates and compiles updates automatically.

  • Can I share my account with my friends?
    We don't want accounts to be shared between different people, but we can't determine sharing of accounts...
    You can use your account on your own devices without restrictions and even from different IPs/uplinks.

  • Does oVPN.to block ports or anything?
    We block some ports from our servers to world.
    Port 25 TCP: Plain SMTP
    Port 42 TCP+UDP: WINS (Microsoft Security Issue)
    Port 135 TCP+UDP, 137 TCP+UDP, 138 TCP+UDP, 139 TCP+UDP, 445 TCP: Microsoft SMB Sharing
    Port 520 UDP: Routing Information Protocol
    Port 1900 UDP: Microsoft UPnP Discovery
    Port 3478 TCP+UDP: STUN standard port
    Port 3544 UDP: Microsoft Teredo IPv6 Tunneling (for your own security!)
    None of these blocked ports should affect you.
    We had to block some IPs/ranges, but for privacy reasons we can't post a list.
    If you are unable to connect to any site or IP/range, ask us about and we will tell you.
    We will block IPs or ranges upon any abusive request or if abused site, owner or provider requests from us to prevent future abuses.

  • Does oVPN.to protect against DNS Leak?
    DNS Leak is a not a VPN providers fault. It is always a problem in your OS! Read dnscrypt for more information.
    Note: We redirect DNS queries from VPN to 8.8.8.8, 8.8.4.4 (google-dns) and 208.67.222.222, 208.67.220.220 (opendns) to 172.16.32.1!
    Set your DNS to 172.16.32.1 while connected to oVPN.
    Other DNScrypt available here: https://dns.d0wn.biz or openNIC Tier2 DNS.

  • Does oVPN.to serve a NTP Timeserver?
    Internal NTP Timeserver IP: 172.16.32.1.
    Some of our ISP block NTP. We redirect following most used NTP addresses to internal NTP!
    pool.ntp.org, 0.debian.pool.ntp.org, time.microsoft.akadns.net, time.windows.com, time.nist.gov, time-nw.nist.gov, time-a.nist.gov, time-b.nist.gov, time-c.nist.gov, time-d.nist.gov
    Not redirected: 0.pool.ntp.org or anything else from ntp.org.

  • Does oVPN.to support IPv6 or Dual-Stack Lite?
    IPv6 with openVPN is working in 3 different ways:
  • you can connect 1st device with openVPN IPv4-only-configs from IPv4 to IPv4 Servers and have access to anonymized IPv4 Internet
  • and you can connect 2nd device with openVPN IPv46-configs from IPv4 to IPv4 Servers and have access to anonymized IPv4 and IPv6 Internet
  • or you can connect 2nd device with openVPN IPv64-configs from IPv6 to IPv6 Servers and have access to anonymized IPv4 and IPv6 Internet
  • You are not directly exposed to IPv6 internet, we deploy private IPv6 fd48:/64 per Server.
    Portforwarding with IPv6 is possible. Own Public IPv6 will arrive soon.

  • Is UDP/TCP port forwarding through openVPN supported?
    Yes, you can forward (open) up to 20 ports same like in your router, allowing torrent or other services to reach your client.
    We will close forwarded ports on DMCA request and send notice into your account...

  • Why do I need email for registration?
    You need valid email to change or request lost password.
    We store your account mail encrypted with itself, so we are unable to reveal it.



  • oVPN.to Help & Support


    Join WebIRC into channel: #help

    IRC Server @ irc.ovpn.to (SSL Port: 6697)



    PGP PUBLIC KEY

    support@ovpn.to

    valid to: Dec 21, 2022

  • Keyfile: 0xE4446C33.asc
    Fingerprint: 766C 1895 8630 F4DA 8BFA 0B03 1DF9 C9FB E444 6C33


    oVPN Domain Name Servers powered by cloudns.net

    Primary DNSIPv4IPv6
    ans1.ovpn.to185.136.96.772a06:fb00:1::1:77
    ans2.ovpn.to185.136.97.772a06:fb00:1::2:77
    ans3.ovpn.to185.136.98.772a06:fb00:1::3:77
    ans4.ovpn.to185.136.99.772a06:fb00:1::4:77

    Secondary DNSIPv4IPv6
    bns1.ovpn.to185.136.96.1112a06:fb00:1::1:111
    bns2.ovpn.to185.136.97.1112a06:fb00:1::2:111
    bns3.ovpn.to185.136.98.1112a06:fb00:1::3:111
    bns4.ovpn.to185.136.99.1112a06:fb00:1::4:111


    oVPN alternate backup domains

  • ovpn.asia
  • ovpn.biz
  • ovpn.bz
  • ovpn.cx
  • ovpn.eu
  • ovpn.info
  • ovpn.nz
  • ovpn.mx
  • ovpn.rip
  • ovpn.so
  • ovpn.vc
  • ovpn.ws

  • oVPN Public SSL Certificates

    https://ovpn.to [Main]

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo RSA Domain Validation Secure Server CA
    notBefore=Mar 18 00:00:00 2019 GMT
    notAfter=Mar 17 23:59:59 2021 GMT
    SHA1 Fingerprint=7B:B8:C3:B6:DD:97:B8:34:5D:50:15:7B:E7:10:B3:8E:7C:52:E8:68
    SHA256 Fingerprint=F3:23:66:C5:06:D5:F0:4C:95:88:F0:17:CB:FA:4B:8E:D9:07:B3:48:14:7A:10:7B:22:D7:38:6C:77:96:B2:B1
    SHA512 Fingerprint=C6:B8:F3:AC:F4:40:23:E8:C8:30:CD:D6:0C:C6:2A:CF:49:2D:FE:63:4A:14:57:79:8F:12:54:33:37:6B:0C:06:DF:31:6D:08:33:8D:7D:78:11:78:AE:83:27:1D:77:0C:98:BB:DE:F6:A6:28:87:A8:04:4F:28:88:C1:24:9E:76
    HPKP pin-sha256: qLOjRk/vnWjkwsIMHURVSGmDBSMzZVO+Jg2ZhzxuBJE=


    https://vcp.ovpn.to [Main]

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Dec 7 00:00:00 2018 GMT
    notAfter=Dec 6 23:59:59 2020 GMT
    SHA1 Fingerprint=DF:94:98:1E:B0:C5:FA:A8:A1:C1:A1:09:5D:16:A8:9E:43:CF:6A:24
    SHA256 Fingerprint=FD:02:90:38:67:1E:58:B6:B6:0F:77:B5:8B:64:BE:DD:50:4F:A4:D1:40:59:87:6E:86:A1:94:3A:4B:B0:BE:ED
    SHA512 Fingerprint=F0:97:E4:D5:AC:61:FD:0B:FD:96:16:27:F3:40:28:DA:A9:9F:84:F6:41:06:9A:9C:EA:A3:16:10:D0:32:C7:0A:3D:EA:10:54:69:B6:78:54:F3:30:B0:12:5C:B5:48:EA:6D:0A:0C:F0:75:CD:ED:A7:6C:2A:72:FB:7B:71:DE:93
    HPKP pin-sha256: oe6PZcrhoX7wqST+PANlTVXEospkClhlVf8/LG1thS4=


    https://vcp.ovpn.to [Backup]

    HPKP pin-sha256: tWPKCZ5Y8zYrtI5M4YUREMryXgTcQ2oEocmT2PAjxfM=


    https://webirc.ovpn.to

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Jun 16 00:00:00 2016 GMT
    notAfter=Jun 16 23:59:59 2019 GMT
    SHA1 Fingerprint=83:64:03:76:63:82:91:2B:06:10:55:60:0D:A1:5F:1F:2C:E4:8D:6B
    SHA256 Fingerprint=D0:3C:86:EA:F2:FA:5E:86:B8:DA:7E:2E:1E:B0:7D:7D:2E:92:F2:71:43:76:B2:90:45:8A:90:5C:26:B1:82:25


    irc://irc.ovpn.to:+6697

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Sep 1 00:00:00 2016 GMT
    notAfter=Sep 1 23:59:59 2019 GMT
    SHA1 Fingerprint=72:FE:FE:45:6E:ED:A8:10:33:E9:BB:0F:09:F4:86:28:90:91:FD:9B
    SHA256 Fingerprint=F5:FF:BE:EA:8E:08:56:BA:55:E5:D1:7D:9E:4D:A7:78:3E:69:79:D5:24:8D:29:41:FF:80:59:9B:13:DB:EB:2F



    smtp/imap/pop3://anomx.ovpn.to

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Dec 6 00:00:00 2016 GMT
    notAfter=Dec 6 23:59:59 2019 GMT
    SHA1 Fingerprint=7D:0F:C6:72:26:E4:B7:B3:4C:0B:A5:11:A5:89:70:32:A6:D6:B2:DB
    SHA256 Fingerprint=5B:00:29:89:CD:16:C4:23:FA:37:E6:B3:BA:FC:A4:C8:E3:CF:D4:7F:3A:A0:D8:37:77:FA:2C:8F:93:E6:AC:D1



    xmpp://jabber.ovpn.to

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Mar 6 00:00:00 2017 GMT
    notAfter=Mar 5 23:59:59 2020 GMT
    SHA1 Fingerprint=78:F0:77:23:02:E3:A6:CE:4F:C7:87:A2:3C:EC:68:91:73:B8:88:29
    SHA256 Fingerprint=ED:CC:17:5F:94:6F:91:CF:33:7F:07:F4:9F:B0:14:17:21:8D:C5:B0:F3:93:66:31:5D:C6:86:CB:1A:FE:99:3D


    nntp://nntp.ovpn.to

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Jun 16 00:00:00 2017 GMT
    notAfter=Jun 15 23:59:59 2020 GMT
    SHA1 Fingerprint=84:A4:9C:8D:F0:48:CF:07:29:5F:CF:33:B6:FC:6C:6C:4B:B1:4C:83
    SHA256 Fingerprint=46:7B:24:20:7D:A5:6B:92:D8:DD:42:DA:D7:E2:51:D6:F9:1A:4A:CC:C8:33:8D:12:15:BE:32:18:30:10:EA:76
    SHA512 Fingerprint=AF:2C:2A:F6:6A:2D:85:1E:DD:AB:F5:03:8E:9E:42:68:0C:8A:70:F9:18:13:CC:AC:A0:F4:1D:A6:9F:25:5B:D6:DC:48:D0:63:54:27:F5:F7:F9:5F:5B:19:60:F6:BB:D6:EA:C6:61:74:08:F8:98:73:E2:C1:8F:A6:A2:35:20:4A


    nnrp://news.ovpn.to

    issuer= /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
    notBefore=Jun 16 00:00:00 2017 GMT
    notAfter=Jun 15 23:59:59 2020 GMT
    SHA1 Fingerprint=86:59:A3:01:68:B6:E3:46:90:C0:18:27:28:CE:B0:FA:E1:A5:E8:78
    SHA256 Fingerprint=14:37:0D:31:2D:A6:78:D3:54:0F:8B:4F:8B:64:24:B4:52:F2:B9:96:EF:57:C8:33:5E:A1:19:40:31:E3:6D:9A
    SHA512 Fingerprint=28:81:13:7F:DC:5A:6B:94:43:8B:8C:6D:8F:32:AB:66:C5:ED:E0:E1:4C:1C:FE:17:BB:7B:27:1E:FF:DC:35:4F:32:8D:34:D6:CF:39:B1:AE:A0:5E:46:7D:73:95:C9:66:D9:AF:1B:60:BA:FE:48:34:E1:86:6D:2B:2E:35:82:7A



    oVPN Root Certificate Authority

    root-ca.ovpn.to.crt *

    * Do NOT add our Root CA into your browser without any good reason!
    Accepting an exception to Certificate on TOR is sufficient!


    issuer= /C=TO/ST=Tonga/O=oVPN.to/OU=Root CA/CN=root-ca.ovpn.to/emailAddress=root@ovpn.to
    notBefore=Apr 14 12:59:05 2016 GMT
    notAfter=Apr 14 12:59:05 2019 GMT
    SHA1 Fingerprint=30:E1:A8:21:56:53:99:2A:B4:B2:CC:83:02:D1:7A:B9:0C:6B:0D:B0
    SHA256 Fingerprint=4D:9C:13:4E:A3:05:CD:1C:B0:C3:20:50:DE:1F:24:D0:EA:EF:6A:84:4A:76:E7:7E:FE:2C:AC:0F:ED:55:4C:5F


  • CA Index.txt: index.txt
  • CA CRL File: crl.pem