Ubuntu Server, Debian, Raspberry Pi and Orange Pi · amd64, arm64 and armhf · v3.0.2-5
Turn a computer that stays on at home —a VPS, an Ubuntu Server, a Raspberry Pi or an Orange Pi— into your VPN server. No screen needed: you install and manage it from the terminal, over SSH too, with the mivpn command.
The first line adds the key we sign our packages with, the second adds the repository, and the last two install MiVPN Server. You only do this once: from then on, updates arrive with the rest of the system's.
curl -fsSL https://mivpn.net/apt/mivpn.gpg | sudo tee /usr/share/keyrings/mivpn.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/mivpn.gpg] https://mivpn.net/apt stable main" | sudo tee /etc/apt/sources.list.d/mivpn.list
sudo apt update
sudo apt install mivpn-server
Download the package for your architecture:
amd64Intel/AMD PCs, servers and VPS arm64Raspberry Pi and Orange Pi with a 64-bit system armhfRaspberry Pi with a 32-bit systemNot sure of your architecture? Run dpkg --print-architecture
And install it from the folder you downloaded it to:
sudo apt install ./mivpn-server_*.deb
Type your mivpn.net account email; it will ask for your password. The password is only used to sign in this once: it isn't stored on the computer.
sudo mivpn setup -e you@example.com
Starts the VPN server and the agent that keeps it in touch with mivpn.net, and adds both to the system startup: after a reboot or a power cut, the server comes back by itself.
sudo mivpn enable
mivpn status shows the same as the desktop app. This is what a working server looks like:
$ sudo mivpn status
MiVPN Server raspberrypi (aarch64)
Cuenta tu@correo.com · servidor "Casa"
Servicios tunel activo · upnp activo · notify activo · arranque con el sistema: si
Servidor en marcha
mivpn.net conectado (estado y ordenes)
Red Ethernet 1000 Mbps
Puerto UDP 51820 · abierto en el router
IP publica 203.0.113.25 · local 192.168.1.40
Clientes 1 de 2 conectados
movil conectado 10.8.0.2 ahora
portatil desconectado 10.8.0.3 hace 2 h
Everything is done with the mivpn command. Those that touch the server need sudo.
sudo mivpn setup -e …Links the computer to your account and gets the server ready.
When: the first time, or to move here a server that was running on another computer.
sudo mivpn enableStarts the server and makes it start by itself every time the computer boots.
When: right after setup.
sudo mivpn disableThe server no longer starts when the computer boots. If it's running, it keeps going until you stop it.
When: if you'd rather decide when to turn it on.
sudo mivpn statusHow everything is: server, link with mivpn.net, network, port, IP and clients.
When: whenever you want to know whether the server is working.
sudo mivpn logs -fThe server log, live. Without -f, the last lines.
When: if something isn't working and you want to see what's going on.
sudo mivpn stopStops the server completely: the VPN server, the agent and the relay.
When: if you don't want anyone to connect for a while.
sudo mivpn startStarts a stopped server again.
When: after stop.
sudo mivpn restartStops and starts the server again.
When: if you've changed something in the network or the router.
sudo mivpn unlinkUnlinks the computer from your account and leaves it clean: stops the server, releases the router and relay ports, and deletes credentials and clients. It asks for your password.
When: when this computer stops being your server, before uninstalling or selling it.
mivpn --versionThe installed MiVPN Server version.
mivpn status -hHelp for any command: replace status with the one you want.
-e, --emailYour mivpn.net account email.
--password-stdinReads the password from standard input, for scripts.
--replaceMoves the server here from another computer without asking.
-y, --yesDoesn't ask for confirmation.
--port 51820Server UDP port. 51820 if you don't give one.
--no-relayDoesn't check the network or turn on the relay.
To install on several computers or from a script (Ansible, cloud-init…), pass the password through standard input and skip the confirmations:
printf '%s\n' "$MIVPN_PASSWORD" | sudo mivpn setup -e you@example.com --password-stdin -y
sudo mivpn enable
Install MiVPN Server on the new computer and link it with --replace. The old computer stops serving by itself as soon as mivpn.net tells it. Your clients will need to download their configuration again; the MiVPN app does it automatically.
sudo mivpn setup -e you@example.com --replace
sudo mivpn enable
New versions arrive through the repository, like the rest of the system. When you update, the server restarts by itself with the new version.
sudo apt update && sudo apt upgrade
First unlink the computer from your account; then uninstall the package.
sudo mivpn unlink
sudo apt remove mivpn-server
Uninstalling stops everything and deletes the credentials, the clients and the WireGuard server MiVPN created. If you skip unlink, the computer will still appear in your account until you move the server to another one.
The server's keys and status can only be read by the administrator. Use sudo mivpn status.
Your router doesn't open ports automatically. Turn on UPnP in its settings and run sudo mivpn restart. If your connection doesn't accept incoming traffic (CGNAT), you need a plan with relay: the server will go out through the MiVPN relay without touching the router.
The agent can't reach mivpn.net. Check that the computer has Internet access and see what's happening with sudo mivpn logs -f.
Your MiVPN server is already running on another computer. Move it here with sudo mivpn setup -e … --replace, or first unlink the other one with sudo mivpn unlink.
Changing computers changes the server's keys: each client has to download its configuration again from mivpn.net or the MiVPN app.
No: a computer can only be a server once. mivpn-server and mivpn-server-desktop exclude each other; apt removes one if you install the other.