Advertisement
Guest User

Untitled

a guest
Feb 22nd, 2019
82
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.84 KB | None | 0 0
  1. sudo yum -y install gnutls-devel libev-devel tcp_wrappers-devel pam-devel lz4-devel libseccomp-devel readline-devel libnl3-devel krb5-devel radcli-devel
  2. sudo yum -y install epel-release
  3. sudo yum repolist enabled
  4. sudo yum info ocserv
  5. sudo yum -y install ocserv
  6. sudo ocpasswd -c /etc/ocserv/ocpasswd test
  7. 123
  8. nano -K /etc/ocserv/ocserv.conf
  9.  
  10. auth = "plain[passwd=/etc/ocserv/ocpasswd]"
  11.  
  12. tcp-port = 8090
  13. udp-port = 8090
  14.  
  15. run-as-user = ocserv
  16. run-as-group = ocserv
  17.  
  18. socket-file = ocserv.sock
  19.  
  20. chroot-dir = /var/lib/ocserv
  21.  
  22. isolate-workers = true
  23.  
  24. max-clients = 5
  25.  
  26. max-same-clients = 1
  27.  
  28. keepalive = 32400
  29.  
  30. dpd = 90
  31.  
  32. mobile-dpd = 1800
  33.  
  34. switch-to-tcp-timeout = 25
  35.  
  36. try-mtu-discovery = true
  37.  
  38. server-cert = /etc/pki/ocserv/public/server.crt
  39. server-key = /etc/pki/ocserv/private/server.key
  40.  
  41. ca-cert = /etc/pki/ocserv/cacerts/ca.crt
  42.  
  43. cert-user-oid = 0.9.2342.19200300.100.1.1
  44.  
  45. tls-priorities = "NORMAL:%SERVER_PRECEDENCE:%COMPAT:-VERS-SSL3.0"
  46.  
  47. auth-timeout = 240
  48.  
  49. min-reauth-time = 300
  50.  
  51. max-ban-score = 50
  52.  
  53. ban-reset-time = 300
  54.  
  55. cookie-timeout = 300
  56.  
  57. deny-roaming = false
  58.  
  59. rekey-time = 172800
  60.  
  61. rekey-method = ssl
  62.  
  63. use-occtl = true
  64.  
  65. pid-file = /var/run/ocserv.pid
  66.  
  67. device = vpns
  68.  
  69. predictable-ips = true
  70.  
  71. default-domain = example.com
  72.  
  73. ipv4-network = 192.168.102.0
  74. ipv4-netmask = 255.255.255.0
  75.  
  76. dns = 8.8.8.8
  77. dns = 8.8.4.4
  78.  
  79. ping-leases = false
  80.  
  81. cisco-client-compat = true
  82.  
  83. dtls-legacy = true
  84.  
  85. user-profile = profile.xml
  86.  
  87. # Routes to be forwarded to the client. If you need the
  88. # client to forward routes to the server, you may use the
  89. # config-per-user/group or even connect and disconnect scripts.
  90. #
  91. # To set the server as the default gateway for the client just
  92. # comment out all routes from the server, or use the special keyword
  93. # 'default'.
  94.  
  95. #route = 10.10.10.0/255.255.255.0
  96. #route = 192.168.0.0/255.255.0.0
  97. #route = fef4:db8:1000:1001::/64
  98.  
  99. journalctl -fu ocserv
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement