1 | ## OpenVPN 2.4 UDP server config file |
---|
2 | |
---|
3 | multihome |
---|
4 | |
---|
5 | cd /etc/openvpn/chroot |
---|
6 | |
---|
7 | ## UDP server specific options |
---|
8 | proto udp4 |
---|
9 | dev tun0 |
---|
10 | replay-window 80 20 |
---|
11 | fast-io |
---|
12 | link-mtu 1420 |
---|
13 | status /var/log/openvpn/status.udp.server.txt 10 |
---|
14 | log-append /var/log/openvpn/udp.server.log |
---|
15 | replay-persist /var/log/openvpn/replay-persist.udp.server.txt |
---|
16 | ## END UDP server specific options |
---|
17 | |
---|
18 | ## TCP server specific options |
---|
19 | # proto tcp4 |
---|
20 | # dev tun1 |
---|
21 | # link-mtu 1420 |
---|
22 | # tcp-nodelay |
---|
23 | # tcp-queue-limit 64 |
---|
24 | # status /var/log/openvpn/status.tcp.server.txt 10 |
---|
25 | # log-append /var/log/openvpn/tcp.server.log |
---|
26 | # replay-persist /var/log/openvpn/replay-persist.tcp.server.txt |
---|
27 | ## END TCP server specific options |
---|
28 | |
---|
29 | lport 443 |
---|
30 | server 172.16.16.0 255.255.255.0 nopool |
---|
31 | ifconfig-pool 172.16.16.0 172.16.16.254 255.255.255.0 |
---|
32 | |
---|
33 | topology subnet |
---|
34 | status-version 1 |
---|
35 | tls-timeout 2 |
---|
36 | reneg-sec 3600 |
---|
37 | |
---|
38 | ca /etc/openvpn/server/keys/ca.crt |
---|
39 | cert /etc/openvpn/server/keys/server.crt |
---|
40 | key /etc/openvpn/server/keys/server.key |
---|
41 | dh /etc/openvpn/server/keys/dh.pem |
---|
42 | crl-verify crl.pem |
---|
43 | tls-auth /etc/openvpn/server/keys/ta.key 0 |
---|
44 | |
---|
45 | nice 5 |
---|
46 | max-clients 1024 |
---|
47 | |
---|
48 | user openvpn |
---|
49 | group openvpn |
---|
50 | |
---|
51 | cipher AES-256-GCM |
---|
52 | auth SHA256 |
---|
53 | tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256:TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 |
---|
54 | tls-version-min 1.2 |
---|
55 | ;opt-verify |
---|
56 | |
---|
57 | script-security 2 |
---|
58 | learn-address scripts/learn-address |
---|
59 | ccd-exclusive |
---|
60 | client-config-dir ccd |
---|
61 | tmp-dir tmp |
---|
62 | |
---|
63 | mute-replay-warnings |
---|
64 | verb 4 |
---|
65 | |
---|
66 | keepalive 10 40 |
---|
67 | persist-key |
---|
68 | persist-tun |
---|
69 | persist-local-ip |
---|
70 | |
---|
71 | comp-lzo adaptive |
---|
72 | push "comp-lzo adaptive" |
---|
73 | |
---|
74 | chroot /etc/openvpn/chroot |
---|