MiVPN MiVPN.
Back to Downloads

MiVPN Server for headless Linux

Ubuntu Server, Debian, Raspberry Pi and Orange Pi · amd64, arm64 and armhf · v3.0.2-5

Turn a computer that stays on at home —a VPS, an Ubuntu Server, a Raspberry Pi or an Orange Pi— into your VPN server. No screen needed: you install and manage it from the terminal, over SSH too, with the mivpn command.

Before you start

SystemUbuntu 22.04 or later, Debian 12 or later, Raspberry Pi OS 12 (Bookworm), or Ubuntu/Debian on Orange Pi.
Architectureamd64 (Intel/AMD PCs and servers), arm64 (64-bit Raspberry Pi and Orange Pi) or armhf (32-bit Raspberry Pi).
AccessA terminal, on the computer itself or over SSH, with a user that can use sudo.
AccountYour mivpn.net account with a MiVPN server.
ConnectionA router with UPnP, or a plan with relay if your connection doesn't accept incoming traffic (CGNAT, shared fibre, mobile network).
Does the computer have a desktop? The app with a window will be easier. MiVPN Server for Linux desktop

1 Install

From the MiVPN repository (recommended)

The first line adds the key we sign our packages with, the second adds the repository, and the last two install MiVPN Server. You only do this once: from then on, updates arrive with the rest of the system's.

curl -fsSL https://mivpn.net/apt/mivpn.gpg | sudo tee /usr/share/keyrings/mivpn.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/mivpn.gpg] https://mivpn.net/apt stable main" | sudo tee /etc/apt/sources.list.d/mivpn.list
sudo apt update
sudo apt install mivpn-server

Or with the .deb package

Download the package for your architecture:

amd64Intel/AMD PCs, servers and VPS arm64Raspberry Pi and Orange Pi with a 64-bit system armhfRaspberry Pi with a 32-bit system

Not sure of your architecture? Run dpkg --print-architecture

And install it from the folder you downloaded it to:

sudo apt install ./mivpn-server_*.deb
Installed this way you won't get automatic updates: you'll have to download and install each new version.

2 Link it to your account

Type your mivpn.net account email; it will ask for your password. The password is only used to sign in this once: it isn't stored on the computer.

sudo mivpn setup -e you@example.com

What mivpn setup does

  1. Registers this computer as your account's server.
  2. Creates the WireGuard server if the computer doesn't have one yet, with its network and traffic forwarding ready.
  3. Checks whether your connection accepts incoming traffic: if it does, it opens the port on the router; if not, it turns on the MiVPN relay.
  4. Opens the port in the computer's own firewall.
  5. Sets up the clients you already have in your account.
If your server is already running on another computer, setup tells you and asks whether to move it to this one.

3 Start it

Starts the VPN server and the agent that keeps it in touch with mivpn.net, and adds both to the system startup: after a reboot or a power cut, the server comes back by itself.

sudo mivpn enable

4 Check that it works

mivpn status shows the same as the desktop app. This is what a working server looks like:

$ sudo mivpn status
MiVPN Server  raspberrypi (aarch64)
  Cuenta         tu@correo.com  ·  servidor "Casa"
  Servicios      tunel activo  ·  upnp activo  ·  notify activo  ·  arranque con el sistema: si
  Servidor       en marcha
  mivpn.net      conectado (estado y ordenes)
  Red            Ethernet 1000 Mbps
  Puerto         UDP 51820  ·  abierto en el router
  IP publica     203.0.113.25  ·  local 192.168.1.40
  Clientes       1 de 2 conectados
      movil      conectado      10.8.0.2        ahora
      portatil   desconectado   10.8.0.3        hace 2 h
  • Servidor“en marcha” (running) when the VPN server and the agent are working.
  • mivpn.net“conectado” (connected): the mivpn.net dashboard and the app can see your server and request configurations from it.
  • Puertowhere your clients come in: “abierto en el router” (open on the router) for a direct connection, or the MiVPN relay port.
  • Clientesthe devices you've created, whether they're connected and when they last connected.
For now, the mivpn command shows its messages in Spanish.

Commands

Everything is done with the mivpn command. Those that touch the server need sudo.

Getting started
sudo mivpn setup -e …

Links the computer to your account and gets the server ready.

When: the first time, or to move here a server that was running on another computer.

sudo mivpn enable

Starts the server and makes it start by itself every time the computer boots.

When: right after setup.

sudo mivpn disable

The server no longer starts when the computer boots. If it's running, it keeps going until you stop it.

When: if you'd rather decide when to turn it on.

Day to day
sudo mivpn status

How everything is: server, link with mivpn.net, network, port, IP and clients.

When: whenever you want to know whether the server is working.

sudo mivpn logs -f

The server log, live. Without -f, the last lines.

When: if something isn't working and you want to see what's going on.

sudo mivpn stop

Stops the server completely: the VPN server, the agent and the relay.

When: if you don't want anyone to connect for a while.

sudo mivpn start

Starts a stopped server again.

When: after stop.

sudo mivpn restart

Stops and starts the server again.

When: if you've changed something in the network or the router.

Leaving the computer
sudo mivpn unlink

Unlinks the computer from your account and leaves it clean: stops the server, releases the router and relay ports, and deletes credentials and clients. It asks for your password.

When: when this computer stops being your server, before uninstalling or selling it.

Information
mivpn --version

The installed MiVPN Server version.

mivpn status -h

Help for any command: replace status with the one you want.

mivpn setup options

-e, --email

Your mivpn.net account email.

--password-stdin

Reads the password from standard input, for scripts.

--replace

Moves the server here from another computer without asking.

-y, --yes

Doesn't ask for confirmation.

--port 51820

Server UDP port. 51820 if you don't give one.

--no-relay

Doesn't check the network or turn on the relay.

Unattended install

To install on several computers or from a script (Ansible, cloud-init…), pass the password through standard input and skip the confirmations:

printf '%s\n' "$MIVPN_PASSWORD" | sudo mivpn setup -e you@example.com --password-stdin -y
sudo mivpn enable
Don't put the password in the command itself with -p: it would stay in the history and any user on the computer could see it.

Moving the server to another computer

Install MiVPN Server on the new computer and link it with --replace. The old computer stops serving by itself as soon as mivpn.net tells it. Your clients will need to download their configuration again; the MiVPN app does it automatically.

sudo mivpn setup -e you@example.com --replace
sudo mivpn enable

Update

New versions arrive through the repository, like the rest of the system. When you update, the server restarts by itself with the new version.

sudo apt update && sudo apt upgrade

Uninstall

First unlink the computer from your account; then uninstall the package.

sudo mivpn unlink
sudo apt remove mivpn-server

Uninstalling stops everything and deletes the credentials, the clients and the WireGuard server MiVPN created. If you skip unlink, the computer will still appear in your account until you move the server to another one.

Troubleshooting

status says “Hace falta root para leer el estado” (root needed)

The server's keys and status can only be read by the administrator. Use sudo mivpn status.

Port: “sin UPnP en el router” (no UPnP)

Your router doesn't open ports automatically. Turn on UPnP in its settings and run sudo mivpn restart. If your connection doesn't accept incoming traffic (CGNAT), you need a plan with relay: the server will go out through the MiVPN relay without touching the router.

mivpn.net: “sin conexión” (not connected)

The agent can't reach mivpn.net. Check that the computer has Internet access and see what's happening with sudo mivpn logs -f.

setup says another computer is using the server

Your MiVPN server is already running on another computer. Move it here with sudo mivpn setup -e … --replace, or first unlink the other one with sudo mivpn unlink.

After changing computers, my clients can't connect

Changing computers changes the server's keys: each client has to download its configuration again from mivpn.net or the MiVPN app.

Can I install it alongside the desktop app?

No: a computer can only be a server once. mivpn-server and mivpn-server-desktop exclude each other; apt removes one if you install the other.

Still not working? Write to us from the support chat and paste what sudo mivpn status shows.