From a6537f7549f70f16bb2efd5c0683e0e94a236f0c Mon Sep 17 00:00:00 2001 From: Antonio Quartulli Date: Fri, 24 Jul 2026 07:55:23 +0200 Subject: [PATCH] options: make 'tun' the default for '--dev' With this change, OpenVPN can be launched without specifying any --dev option and it will start a `tun` (L3) tunnel with the interface named `tunX`. As before, this behaviour can be changed using --dev or --dev-type. Existing configs won't see any behavioural change as they all had to contain at least one --dev directive. Change-Id: I0ca7b5b7ec1a01acaad222c99db137c94c88555a Signed-off-by: Antonio Quartulli Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1537 Message-Id: <20260724055529.1376-1-gert@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg37825.html Signed-off-by: Gert Doering --- doc/man-sections/examples.rst | 4 ++++ doc/man-sections/vpn-network-options.rst | 4 ++++ sample/sample-config-files/client.conf | 2 ++ sample/sample-config-files/server.conf | 2 ++ src/openvpn/options.c | 4 +++- 5 files changed, 15 insertions(+), 1 deletion(-) diff --git a/doc/man-sections/examples.rst b/doc/man-sections/examples.rst index 80ef2df0c..416e576a8 100644 --- a/doc/man-sections/examples.rst +++ b/doc/man-sections/examples.rst @@ -63,6 +63,10 @@ you will get a weird feedback loop. Example 1: A simple tunnel without security (not recommended) ------------------------------------------------------------- +Since :code:`tun` is the default device type, ``--dev`` is optional; when it +is omitted OpenVPN creates a dynamically-named ``tunX`` device. The examples +below still name the device (``--dev tun1``) explicitly for clarity. + On bob:: openvpn --remote alice.example.com --dev tun1 \ diff --git a/doc/man-sections/vpn-network-options.rst b/doc/man-sections/vpn-network-options.rst index 33ebedb5e..960c6addf 100644 --- a/doc/man-sections/vpn-network-options.rst +++ b/doc/man-sections/vpn-network-options.rst @@ -50,6 +50,10 @@ routing. :code:`null` or an arbitrary name string (:code:`X` can be omitted for a dynamic device.) + If neither ``--dev`` nor ``--dev-type`` is specified, OpenVPN defaults to + :code:`tun`, i.e. it creates a dynamically-named :code:`tunX` device and + runs a layer-3 tunnel. + See examples section below for an example on setting up a TUN device. You must use either tun devices on both ends of the connection or tap diff --git a/sample/sample-config-files/client.conf b/sample/sample-config-files/client.conf index 53b8027db..1806b249a 100644 --- a/sample/sample-config-files/client.conf +++ b/sample/sample-config-files/client.conf @@ -20,6 +20,8 @@ client # On most systems, the VPN will not function # unless you partially or fully disable # the firewall for the TUN/TAP interface. +# "tun" is the default device type, so the +# "dev tun" line below is optional. ;dev tap dev tun diff --git a/sample/sample-config-files/server.conf b/sample/sample-config-files/server.conf index 8943c34e9..924fb9600 100644 --- a/sample/sample-config-files/server.conf +++ b/sample/sample-config-files/server.conf @@ -49,6 +49,8 @@ proto udp # On most systems, the VPN will not function # unless you partially or fully disable/open # the firewall for the TUN/TAP interface. +# "tun" is the default device type, so the +# "dev tun" line below is optional. ;dev tap dev tun diff --git a/src/openvpn/options.c b/src/openvpn/options.c index d4675cab4..d0f447cf3 100644 --- a/src/openvpn/options.c +++ b/src/openvpn/options.c @@ -189,7 +189,8 @@ static const char usage_message[] = " or --socks-proxy" " is used).\n" "--nobind : Do not bind to local address and port.\n" - "--dev tunX|tapX : tun/tap device (X can be omitted for dynamic device.\n" + "--dev tunX|tapX : tun/tap device (X can be omitted for dynamic device).\n" + " Defaults to \"tun\" if neither --dev nor --dev-type is given.\n" "--dev-type dt : Which device type are we using? (dt = tun or tap) Use\n" " this option only if the tun/tap device used with --dev\n" " does not begin with \"tun\" or \"tap\".\n" @@ -803,6 +804,7 @@ init_options(struct options *o) gc_init(&o->dns_options.gc); o->mode = MODE_POINT_TO_POINT; + o->dev = "tun"; o->topology = TOP_UNDEF; o->ce.proto = PROTO_UDP; o->ce.af = AF_UNSPEC; -- 2.47.3