Then you need to look in the logs of the server to see what the problem is.
Goto the WUI menu Logs - System Logs and select OpneVPN in the dropdown box labelled Section:
Then press the Update button.
Somewhere in the logs it will say why it is not starting.
The best approach is to press the Start OpenVPN Server button and then immediately go to the System Logs and the most recent logs will be at the top if you have the Log Settings checked for
“Sort in reverse chronological order”
WARNING: --topology net30 support for server configs with IPv4 pools will be removed in a future release. Please migrate to --topology subnet as soon as possible.
May 23 22:49:58 ho openvpnserver[4655]: DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
openvpnctrl -s
runs without errors but the GUI still says “paused”
OpenVPN 2.5.8 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Feb 22 2023
library versions: OpenSSL 1.1.1t 7 Feb 2023, LZO 2.09
MANAGEMENT: unix domain socket listening on /var/run/openvpn.sock
NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Diffie-Hellman initialized with 4096 bit key
CRL: loaded 1 CRLs from file /var/ipfire/ovpn/crls/cacrl.pem
Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
TUN/TAP device tun1 opened
/sbin/ip link set dev tun1 up mtu 1400
/sbin/ip link set dev tun1 up
Could not determine IPv4/IPv6 protocol. Using AF_INET
This just means that you have enabled one or more of the zones - red, blue or orange - on the OpenVPN page. If you stop the openvpn server and unselect all of the zones and save then the first page will no longer show OpenVPN.
If you select one zone, say red, and press save then the openvpn server will still be stopped but on the first page it will show as online. Maybe the term enabled would be better there.