Blame

340650 Samuli Seppänen 2025-02-24 12:45:33 1
# Introduction 
2
3
The OpenVPN's Windows TAP-drivers consists of four files for each platform (32/64-bit):
4
5
* *\<something\>.cat:* contains cryptographic signature for the actual drivers
6
* *\<something\>.sys:* contains the actual driver
7
* *\<something\>.inf:* contains driver metadata
8
9
If you need to run OpenVPN on Windows Vista/7 64-bit you have to use signed TAP drivers. Unless you sign them yourself, you need to extract drivers from an existing OpenVPN installer. See below for instructions.
10
11
OpenVPN installers come bundled with a command-line tool called *\<tap-windows-install-dir\>\\bin\\devcon.exe* for managing the TAP-driver. Two wrapper scripts, *addtap.bat* and *deltapall.bat* are also available in the same directory. For details on *devcon.exe* usage look at [Devcon.exe documentation](http://support.microsoft.com/kb/311272).
12
13
**NOTES:**
14
15
* In OpenVPN 2.3_alpha1 and earlier *devcon.exe* was called *tapinstall.exe*.
16
* OpenVPN 2.3_rc2 installer does not install TAP utilities by default. This bug is fixed in later releases.
17
18
# Manual configuration of the TAP-Windows adapter
19
20
On XP Go to *Start -> Control Panel -> Network Connections*.
21
22
You should see a "TAP-Windows Adapter" with a name like "Local Area Connection 3". Right click and rename this to something shorter and without embedded spaces such as "my-tap".
23
24
Now right click again and select properties.
25
26
Select Internet Protocol (TCP/IP) from the list and click on "Properties".
27
28
Set the IP address and subnet mask of your new TAP device. For the example below we will use an IP of 10.3.0.1 and a subnet mask of 255.255.255.0. Other fields can be left as they are.
29
30
Note also that the command line tool "netsh" can do many of these same functions.
31
32
For example, the following command will set the IP and subnet for my-tap:
33
34
```
35
$ netsh interface ip set address my-tap static 10.3.0.1 255.255.255.0
36
```
37
38
This setting is persistent across reboots.
39
40
# Installing and uninstalling TAP-drivers
41
42
Occasionally you may need play with different TAP-driver versions. In this case you can use *devcon.exe* from the Windows command-prompt. Below are some common commands you can run from an administrator Powershell or cmd.exe console:
43
44
List available TAP-Windows adapters:
45
46
```
47
$ openvpn --show-adapters
48
Available TAP-Windows devices:
49
[1] 'my-tap'
50
```
51
52
List network interfaces (incl. TAP-Windows adapters):
53
54
```
55
$ ipconfig
56
```
57
58
View information about an installed driver:
59
60
```
61
> tapinstall.exe hwids <id>
62
ROOT\NET\0000
63
Name: TAP-Windows Adapter V9
64
Hardware IDs:
65
tap0901
66
1 matching device(s) found.
67
```
68
69
Uninstall a TAP-driver:
70
71
```
72
> tapinstall.exe remove <id>
73
ROOT\NET\0000
74
1 device(s) were removed
75
```
76
77
To verify TAP-driver removal:
78
79
```
80
> tapinstall.exe hwids <id>
81
No matching devices found.
82
```
83
84
Install a new TAP-driver:
85
86
```
87
> tapinstall.exe install <something.inf> <id>
88
Device node created. Install is complete when drivers are installed...
89
Updating drivers for <id> from C:\Program Files\TAP-Windows\driver\OemVista.inf.
90
Drivers installed successfully.
91
```
92
93
Update a TAP-driver:
94
95
```
96
> tapinstall.exe update <something.inf> <id>
97
Updating drivers for <id> from C:\Program Files\TAP-Windows\driver\OemVista.inf.
98
Drivers installed successfully.
99
```
100
101
Notes:
102
103
* *<id>* refers to the driver identifier which is *tap0901* for OpenVPN 2.2+, but may be different in older/newer OpenVPN versions.
104
* *<something.inf>* is typically *OemWin2k.inf* (old tap-drivers) or *OemVista.inf* (newer tap-drivers). You need to specify the full path to this file, e.g.*C:\Program Files\TAP-Windows\driver\!OemVista.inf*.
105
106
By installing multiple times, you will create additional TAP-Windows adapter instances, which can be used for multiple concurrent VPN tunnels. It is also possible to install using *Control Panel -> Add New Hardware*, and it is possible to uninstall using *Control Panel -> System -> Hardware -> Device Manager*.
107
108
# Extracting TAP-drivers from OpenVPN installers
109
110
Extracting TAP-drivers from an OpenVPN installer is relatively easy: you can use [http://www.7-zip.org/ 7-zip] to open the installer executable. There are both 32-bit and 64-bit versions, but the latter are larger in size.
111
112
# Windows TAP device naming
113
114
Basically what happens when you install the TAP-Windows driver is that you get a new network adapter that shows up in your network control panel. You right click on the TAP adapter and set the TCP/IP properties, i.e. IP address and netmask. Then you rename the TAP adapter icon to something like "my-tap" and reference it using the --dev-node option in OpenVPN.
115
116
Windows also has command line utilities to accomplish these same kinds of tasks such as "devcon", "netsh", and "ipconfig".
117
118
# Renaming the TAP-driver
119
120
Look at [this page](/Pages/TapRenameScript) for a script that can be used to rename TAP-drivers.
121
122
# Debugging installation problems
123
124
People occasionally report tap-windows installation issues, assuming they are all caused by a single bug, because *devcon.exe* gives the same error message/code. This is unfortunately not the case, and the reason for a install failure could be:
125
126
* Lack of privileges for installing the driver(?)
127
* Broken driver
128
* Invalid driver signature
129
* Expired driver signature
130
* Conflicting drivers: pretty much every OpenVPN-based VPN service has it's own Windows client installer, which install some version of the tap-windows driver. If the installers do a bad job, they could end up installing tap-windows drivers that conflict with the official OpenVPN tap-windows drivers.
131
* Something else
132
133
An exhaustive PPTX presentation of Windows driver installation can be downloaded from [http://download.microsoft.com/download/a/f/d/afdfd50d-6eb9-425e-84e1-b4085a80e34e/dvr-t396_wh07.pptx here]. The basic process of driver installation is this:
134
135
1. The driver is imported in the driver store
136
1. The driver is installed to driver folder
137
1. The driver is loaded
138
139
The *setupapi.dev.log* (see below) should tell you at which phase the driver installation failed. The presentation linked to above also shows common debugging steps that should prove useful.
140
141
In case you have tap-windows installation issues, you should try the following:
142
143
1. Back up all OpenVPN configuration files, both for official and for unofficial OpenVPN Windows installers
144
1. Uninstall the [http://openvpn.net/index.php/download/community-downloads.html official OpenVPN Windows client] using it's own uninstaller
145
1. Uninstall any unofficial OpenVPN Windows clients using their own uninstallers or *Add/Remove programs*
146
* Note that many of these are not called OpenVPN at all
147
1. [Remove all installed tap-windows drivers](http://www.pcworld.com/article/246041/how_to_uninstall_drivers_in_windows.html)
148
* Note that many of these are not called tap-windows at all
149
1. [Remove tap-windows drivers from the driver store](http://technet.microsoft.com/en-us/library/cc730875.aspx)
150
* *Remove-Tapwindows.ps1* script in [tap-windows-scripts](https://github.com/mattock/tap-windows-scripts) repository can delete all standard tap-windows drivers from the driverstore
151
1. Reboot
152
1. Try installing OpenVPN using the official installer
153
154
If you're still having issues installing the tap-windows driver, you should try installing it on another computer. If installation to another computer works, it's highly likely the problem is in your system, not in the OpenVPN/tap-windows installer itself.
155
156
You can further debug tap-windows installation issues by looking at the common log file for all Windows driver installations, which on Windows 7 is normally located in *C:\\Windows\\inf\\setupapi.dev.log*. If you're filing a bug report, you should attach the logs for the tap-windows installation part to the bug report.
157
158
Sometimes tap-windows install failures are related to registry corruption. For details, look at these forum postings:
159
160
* http://www.osronline.com/showthread.cfm?link=181873
161
* ~~https://forums.openvpn.net/post35811.html#p35811~~