Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server.conf
- # Custom user conf file for OpenVPN server
- # Please add needed params only!
- ### Authenticate packets with HMAC using message digest algorithm
- ;auth SHA1 # SHA1 160 bit (default)
- auth SHA256 # SHA256 256 bit
- ;auth SHA512 # SHA512 512 bit
- ### Encrypt packets with cipher algorithm
- ;cipher BF-CBC # Blowfish 128 bit (default)
- cipher AES-128-CBC # AES 128 bit
- ;cipher AES-256-CBC # AES 256 bit
- ;cipher DES-EDE3-CBC # Triple-DES 192 bit
- ;cipher none # No encryption
- ### Enable LZO compression on the VPN link
- comp-lzo
- ### Max clients limit
- max-clients 10
- ### Internally route client-to-client traffic
- ;client-to-client
- ### Allow clients with duplicate "Common Name"
- ;duplicate-cn
- ### Keepalive and timeout
- keepalive 10 60
- ### Process priority level (0..19)
- ;nice 3
- ### Syslog verbose level
- verb 4
- mute 20
- ==============================
- OVPN file
- все что ниже вставить в client.ovpn
- ==============================
- client
- dev tap
- #dev tun
- # Windows needs the TAP-Win32 adapter name
- # from the Network Connections panel
- # if you have more than one. On XP SP2,
- # you may need to disable the firewall
- # for the TAP adapter.
- # dev-node TAP
- # Are we connecting to a TCP or
- # UDP server? Use the same setting as
- # on the server.
- proto tcp
- ;proto udp
- # The hostname/IP and port of the server.
- # You can have multiple remote entries
- # to load balance between the servers.
- remote X.X.X.X 1194
- #;remote my-server-2 1194
- # Choose a random host from the remote
- # list for load-balancing. Otherwise
- # try hosts in the order specified.
- ;remote-random
- # Keep trying indefinitely to resolve the
- # host name of the OpenVPN server. Very useful
- # on machines which are not permanently connected
- # to the internet such as laptops.
- resolv-retry infinite
- # Most clients don't need to bind to
- # a specific local port number.
- nobind
- # Downgrade privileges after initialization (non-Windows only)
- ;user nobody
- ;group nobody
- # Try to preserve some state across restarts.
- persist-key
- persist-tun
- # Wireless networks often produce a lot
- # of duplicate packets. Set this flag
- # to silence duplicate packet warnings.
- ;mute-replay-warnings
- auth SHA256
- remote-cert-tls server
- cipher AES-128-CBC
- comp-lzo
- verb 3
- mute 20
- key-direction 1
- #### сюда (между <ca> и </ca>) вставляешь содержимое файла ca.crt ####
- <ca>
- </ca>
- ##### сюда (между <cert> и </cert>) вставляешь содержимое client.crt ####
- <cert>
- </cert>
- #### сюда (между <key> и </key>) содержимое client.key ####
- <key>
- </key>
- #### сюда (между <tls-auth> и </tls-auth>) ta.key ####
- <tls-auth>
- </tls-auth>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement