Сервер

ovpnsrv.conf
port 1194
proto udp
dev tun
ca         ca.crt
cert       ovpnsrv.crt
key        ovpnsrv.key
dh         dh.pem
crl-verify crl.pem
tls-auth   ta.key 0

topology subnet
server 10.250.101.0 255.255.255.0

ifconfig-pool-persist ipp.txt
keepalive 10 120
cipher AES-256-CBC
auth SHA512
persist-key
persist-tun
verb 3
explicit-exit-notify 1

client-config-dir ccd
#ccd-exclusive

client-to-client

user nobody
group nogroup

compress lz4

log    /var/log/openvpn/ovpnsrv.log
status /var/log/openvpn/ovpnsrv_status.log

Клиент

ovpncl.conf
client
dev tun
proto udp
remote адрес_сервера 1194
cipher AES-256-CBC
auth SHA512
float
remote-random
resolv-retry infinite
nobind
persist-key
persist-tun
verify-x509-name имя_в_сертификате_сервера name
compress lz4
verb 3
explicit-exit-notify 3
log /var/log/openvpn/ovpnclient.log
status /var/log/openvpn/ovpnclient_status.log
<ca>
</ca>
<cert>
</cert>
<key>
</key>
key-direction 1
<tls-auth>
</tls-auth>