2025-02-11 08:12:19Samuli Seppänen:
Fixes to Getting started with OpenVPN
Pages/GettingStartedWithOVPN.md ..
@@ 185,7 185,8 @@
### Even stricter certificate checks
-
It is also possible through a plug-in or the `--tls-verify` script hook to add additional checks on certificates. This can also protect you somewhat better if you lose control over your CA private key, if you check the client certificate's fingerprint/digest against a local database you have collected.```
+
It is also possible through a plug-in or the `--tls-verify` script hook to add additional checks on certificates. This can also protect you somewhat better if you lose control over your CA private key, if you check the client certificate's fingerprint/digest against a local database you have collected.
+
```
push "ifconfig 10.8.0.2 255.255.255.0"
```
@@ 210,7 211,8 @@
After setting up the network layer, test the configuration by connecting a client to the server and checking if it can reach the internet and other network resources as expected. Use tools like `ping` and `traceroute` to verify connectivity and correct routing.
-
Remember, each network is unique, so adjustments to these configurations might be necessary to fit your specific requirements. Always ensure your configurations are secure and tested thoroughly in a controlled environment before deploying in a production scenario.```
+
Remember, each network is unique, so adjustments to these configurations might be necessary to fit your specific requirements. Always ensure your configurations are secure and tested thoroughly in a controlled environment before deploying in a production scenario.
+
```
topology subnet
server 10.8.0.0 255.255.255.0
```
@@ 258,7 260,9 @@
Client configuration alternative:
```
redirect-gateway def1
-
```### What about IPv6?
+
```
+
+
### What about IPv6?
OpenVPN v2.3 and later supports IPv6. To set up IPv6 in the tunnel is pretty much the same as for the IPv4 examples we already have covered. You need to use the `--server-ipv6` and `--route-ipv6` options to configure IPv6.
For example, adding this will configure the IPv6 addresses for server and clients: