Blame
| 340650 | Samuli Seppänen | 2025-02-24 12:45:33 | 1 | # Introduction |
| 2 | ||||
| 3 | The OpenVPN's Windows TAP-drivers consists of four files for each platform (32/64-bit): |
|||
| 4 | ||||
| 5 | * *\<something\>.cat:* contains cryptographic signature for the actual drivers |
|||
| 6 | * *\<something\>.sys:* contains the actual driver |
|||
| 7 | * *\<something\>.inf:* contains driver metadata |
|||
| 8 | ||||
| 9 | If you need to run OpenVPN on Windows Vista/7 64-bit you have to use signed TAP drivers. Unless you sign them yourself, you need to extract drivers from an existing OpenVPN installer. See below for instructions. |
|||
| 10 | ||||
| 11 | OpenVPN installers come bundled with a command-line tool called *\<tap-windows-install-dir\>\\bin\\devcon.exe* for managing the TAP-driver. Two wrapper scripts, *addtap.bat* and *deltapall.bat* are also available in the same directory. For details on *devcon.exe* usage look at [Devcon.exe documentation](http://support.microsoft.com/kb/311272). |
|||
| 12 | ||||
| 13 | **NOTES:** |
|||
| 14 | ||||
| 15 | * In OpenVPN 2.3_alpha1 and earlier *devcon.exe* was called *tapinstall.exe*. |
|||
| 16 | * OpenVPN 2.3_rc2 installer does not install TAP utilities by default. This bug is fixed in later releases. |
|||
| 17 | ||||
| 18 | # Manual configuration of the TAP-Windows adapter |
|||
| 19 | ||||
| 20 | On XP Go to *Start -> Control Panel -> Network Connections*. |
|||
| 21 | ||||
| 22 | You should see a "TAP-Windows Adapter" with a name like "Local Area Connection 3". Right click and rename this to something shorter and without embedded spaces such as "my-tap". |
|||
| 23 | ||||
| 24 | Now right click again and select properties. |
|||
| 25 | ||||
| 26 | Select Internet Protocol (TCP/IP) from the list and click on "Properties". |
|||
| 27 | ||||
| 28 | Set the IP address and subnet mask of your new TAP device. For the example below we will use an IP of 10.3.0.1 and a subnet mask of 255.255.255.0. Other fields can be left as they are. |
|||
| 29 | ||||
| 30 | Note also that the command line tool "netsh" can do many of these same functions. |
|||
| 31 | ||||
| 32 | For example, the following command will set the IP and subnet for my-tap: |
|||
| 33 | ||||
| 34 | ``` |
|||
| 35 | $ netsh interface ip set address my-tap static 10.3.0.1 255.255.255.0 |
|||
| 36 | ``` |
|||
| 37 | ||||
| 38 | This setting is persistent across reboots. |
|||
| 39 | ||||
| 40 | # Installing and uninstalling TAP-drivers |
|||
| 41 | ||||
| 42 | Occasionally you may need play with different TAP-driver versions. In this case you can use *devcon.exe* from the Windows command-prompt. Below are some common commands you can run from an administrator Powershell or cmd.exe console: |
|||
| 43 | ||||
| 44 | List available TAP-Windows adapters: |
|||
| 45 | ||||
| 46 | ``` |
|||
| 47 | $ openvpn --show-adapters |
|||
| 48 | Available TAP-Windows devices: |
|||
| 49 | [1] 'my-tap' |
|||
| 50 | ``` |
|||
| 51 | ||||
| 52 | List network interfaces (incl. TAP-Windows adapters): |
|||
| 53 | ||||
| 54 | ``` |
|||
| 55 | $ ipconfig |
|||
| 56 | ``` |
|||
| 57 | ||||
| 58 | View information about an installed driver: |
|||
| 59 | ||||
| 60 | ``` |
|||
| 61 | > tapinstall.exe hwids <id> |
|||
| 62 | ROOT\NET\0000 |
|||
| 63 | Name: TAP-Windows Adapter V9 |
|||
| 64 | Hardware IDs: |
|||
| 65 | tap0901 |
|||
| 66 | 1 matching device(s) found. |
|||
| 67 | ``` |
|||
| 68 | ||||
| 69 | Uninstall a TAP-driver: |
|||
| 70 | ||||
| 71 | ``` |
|||
| 72 | > tapinstall.exe remove <id> |
|||
| 73 | ROOT\NET\0000 |
|||
| 74 | 1 device(s) were removed |
|||
| 75 | ``` |
|||
| 76 | ||||
| 77 | To verify TAP-driver removal: |
|||
| 78 | ||||
| 79 | ``` |
|||
| 80 | > tapinstall.exe hwids <id> |
|||
| 81 | No matching devices found. |
|||
| 82 | ``` |
|||
| 83 | ||||
| 84 | Install a new TAP-driver: |
|||
| 85 | ||||
| 86 | ``` |
|||
| 87 | > tapinstall.exe install <something.inf> <id> |
|||
| 88 | Device node created. Install is complete when drivers are installed... |
|||
| 89 | Updating drivers for <id> from C:\Program Files\TAP-Windows\driver\OemVista.inf. |
|||
| 90 | Drivers installed successfully. |
|||
| 91 | ``` |
|||
| 92 | ||||
| 93 | Update a TAP-driver: |
|||
| 94 | ||||
| 95 | ``` |
|||
| 96 | > tapinstall.exe update <something.inf> <id> |
|||
| 97 | Updating drivers for <id> from C:\Program Files\TAP-Windows\driver\OemVista.inf. |
|||
| 98 | Drivers installed successfully. |
|||
| 99 | ``` |
|||
| 100 | ||||
| 101 | Notes: |
|||
| 102 | ||||
| 103 | * *<id>* refers to the driver identifier which is *tap0901* for OpenVPN 2.2+, but may be different in older/newer OpenVPN versions. |
|||
| 104 | * *<something.inf>* is typically *OemWin2k.inf* (old tap-drivers) or *OemVista.inf* (newer tap-drivers). You need to specify the full path to this file, e.g.*C:\Program Files\TAP-Windows\driver\!OemVista.inf*. |
|||
| 105 | ||||
| 106 | By installing multiple times, you will create additional TAP-Windows adapter instances, which can be used for multiple concurrent VPN tunnels. It is also possible to install using *Control Panel -> Add New Hardware*, and it is possible to uninstall using *Control Panel -> System -> Hardware -> Device Manager*. |
|||
| 107 | ||||
| 108 | # Extracting TAP-drivers from OpenVPN installers |
|||
| 109 | ||||
| 110 | Extracting TAP-drivers from an OpenVPN installer is relatively easy: you can use [http://www.7-zip.org/ 7-zip] to open the installer executable. There are both 32-bit and 64-bit versions, but the latter are larger in size. |
|||
| 111 | ||||
| 112 | # Windows TAP device naming |
|||
| 113 | ||||
| 114 | Basically what happens when you install the TAP-Windows driver is that you get a new network adapter that shows up in your network control panel. You right click on the TAP adapter and set the TCP/IP properties, i.e. IP address and netmask. Then you rename the TAP adapter icon to something like "my-tap" and reference it using the --dev-node option in OpenVPN. |
|||
| 115 | ||||
| 116 | Windows also has command line utilities to accomplish these same kinds of tasks such as "devcon", "netsh", and "ipconfig". |
|||
| 117 | ||||
| 118 | # Renaming the TAP-driver |
|||
| 119 | ||||
| 120 | Look at [this page](/Pages/TapRenameScript) for a script that can be used to rename TAP-drivers. |
|||
| 121 | ||||
| 122 | # Debugging installation problems |
|||
| 123 | ||||
| 124 | People occasionally report tap-windows installation issues, assuming they are all caused by a single bug, because *devcon.exe* gives the same error message/code. This is unfortunately not the case, and the reason for a install failure could be: |
|||
| 125 | ||||
| 126 | * Lack of privileges for installing the driver(?) |
|||
| 127 | * Broken driver |
|||
| 128 | * Invalid driver signature |
|||
| 129 | * Expired driver signature |
|||
| 130 | * Conflicting drivers: pretty much every OpenVPN-based VPN service has it's own Windows client installer, which install some version of the tap-windows driver. If the installers do a bad job, they could end up installing tap-windows drivers that conflict with the official OpenVPN tap-windows drivers. |
|||
| 131 | * Something else |
|||
| 132 | ||||
| 133 | An exhaustive PPTX presentation of Windows driver installation can be downloaded from [http://download.microsoft.com/download/a/f/d/afdfd50d-6eb9-425e-84e1-b4085a80e34e/dvr-t396_wh07.pptx here]. The basic process of driver installation is this: |
|||
| 134 | ||||
| 135 | 1. The driver is imported in the driver store |
|||
| 136 | 1. The driver is installed to driver folder |
|||
| 137 | 1. The driver is loaded |
|||
| 138 | ||||
| 139 | The *setupapi.dev.log* (see below) should tell you at which phase the driver installation failed. The presentation linked to above also shows common debugging steps that should prove useful. |
|||
| 140 | ||||
| 141 | In case you have tap-windows installation issues, you should try the following: |
|||
| 142 | ||||
| 143 | 1. Back up all OpenVPN configuration files, both for official and for unofficial OpenVPN Windows installers |
|||
| 144 | 1. Uninstall the [http://openvpn.net/index.php/download/community-downloads.html official OpenVPN Windows client] using it's own uninstaller |
|||
| 145 | 1. Uninstall any unofficial OpenVPN Windows clients using their own uninstallers or *Add/Remove programs* |
|||
| 146 | * Note that many of these are not called OpenVPN at all |
|||
| 147 | 1. [Remove all installed tap-windows drivers](http://www.pcworld.com/article/246041/how_to_uninstall_drivers_in_windows.html) |
|||
| 148 | * Note that many of these are not called tap-windows at all |
|||
| 149 | 1. [Remove tap-windows drivers from the driver store](http://technet.microsoft.com/en-us/library/cc730875.aspx) |
|||
| 150 | * *Remove-Tapwindows.ps1* script in [tap-windows-scripts](https://github.com/mattock/tap-windows-scripts) repository can delete all standard tap-windows drivers from the driverstore |
|||
| 151 | 1. Reboot |
|||
| 152 | 1. Try installing OpenVPN using the official installer |
|||
| 153 | ||||
| 154 | If you're still having issues installing the tap-windows driver, you should try installing it on another computer. If installation to another computer works, it's highly likely the problem is in your system, not in the OpenVPN/tap-windows installer itself. |
|||
| 155 | ||||
| 156 | You can further debug tap-windows installation issues by looking at the common log file for all Windows driver installations, which on Windows 7 is normally located in *C:\\Windows\\inf\\setupapi.dev.log*. If you're filing a bug report, you should attach the logs for the tap-windows installation part to the bug report. |
|||
| 157 | ||||
| 158 | Sometimes tap-windows install failures are related to registry corruption. For details, look at these forum postings: |
|||
| 159 | ||||
| 160 | * http://www.osronline.com/showthread.cfm?link=181873 |
|||
| 161 | * ~~https://forums.openvpn.net/post35811.html#p35811~~ |
