Advertisement
Guest User

ocserv config

a guest
Feb 16th, 2020
1,550
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.26 KB | None | 0 0
  1. auth = "plain[/etc/ocserv/ocpasswd]"
  2. enable-auth = "certificate"
  3. #max-clients = 0
  4. #max-same-clients= 0
  5. tcp-port = 8080
  6. #udp-port = 8080
  7. keepalive = 32400
  8. dpd = 90
  9. #switch-to-tcp-timeout = 25
  10. mobile-dpd = 1800
  11. try-mtu-discovery = true
  12. server-cert = /etc/ocserv/full_chain.pem
  13. server-key = /etc/ocserv/private.key
  14. #dh-params = /etc/ocserv/dh.pem
  15. ca-cert =/etc/ocserv/vpn.pem
  16. cert-user-oid = 2.5.4.3
  17. #crl = /etc/ocserv/crl.pem
  18.  
  19. tls-priorities = "NORMAL:%SERVER_PRECEDENCE:%COMPAT:-VERS-SSL3.0"
  20. auth-timeout = 60
  21. #mobile-idle-timeout =
  22. deny-roaming = false
  23. cookie-timeout = 86400000
  24. rekey-time = 86400000
  25. rekey-method = ssl
  26. use-utmp = true
  27. use-occtl= true
  28. user-profile = /etc/ocserv/profile.xml
  29. pid-file = /var/run/ocserv.pid
  30. socket-file = /var/run/ocserv-socket
  31. run-as-user = nobody
  32. run-as-group = nobody
  33. net-priority = 5
  34. device = vpns
  35. default-domain = hk.mydomain.com
  36. ipv4-network = 10.1.0.0/16
  37. persistent-cookies = true
  38. dns = 8.8.8.8
  39. max-ban-score = 0
  40. ping-leases = false
  41. output-buffer = 23000
  42. compression = true
  43. no-compress-limit = 256
  44. predictable-ips = false
  45. #route-add-cmd = "ip route add %R dev %D"
  46. #route-del-cmd = "ip route delete %R dev %D"
  47. cisco-client-compat = true
  48. #custom-header = "X-DTLS-MTU: 1420"
  49. #custom-header = "X-CSTP-MTU: 1280"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement