pivpn/files/etc/openvpn/server_config.txt

40 lines
1.1 KiB
Text
Raw Normal View History

2016-04-19 18:01:55 +00:00
dev tun
proto udp
port 1194
ca /etc/openvpn/easy-rsa/pki/ca.crt
cert /etc/openvpn/easy-rsa/pki/issued/server.crt
key /etc/openvpn/easy-rsa/pki/private/server.key
dh /etc/openvpn/easy-rsa/pki/dh2048.pem
topology subnet
2016-04-19 18:01:55 +00:00
server 10.8.0.0 255.255.255.0
# Set your primary domain name server address for clients
push "dhcp-option DNS 9.9.9.9"
push "dhcp-option DNS 149.112.112.112"
# Prevent DNS leaks on Windows
push "block-outside-dns"
2016-04-19 18:01:55 +00:00
# Override the Client default gateway by using 0.0.0.0/1 and
# 128.0.0.0/1 rather than 0.0.0.0/0. This has the benefit of
# overriding but not wiping out the original default gateway.
push "redirect-gateway def1"
client-to-client
client-config-dir /etc/openvpn/ccd
keepalive 15 120
remote-cert-tls client
tls-version-min 1.2
tls-auth /etc/openvpn/easy-rsa/pki/ta.key 0
2016-04-23 19:08:14 +00:00
cipher AES-256-CBC
auth SHA256
2019-12-10 15:06:28 +00:00
user openvpn
group openvpn
2016-04-19 18:01:55 +00:00
persist-key
persist-tun
crl-verify /etc/openvpn/crl.pem
2016-04-19 18:01:55 +00:00
status /var/log/openvpn-status.log 20
status-version 3
2018-02-15 09:14:03 +00:00
syslog
verb 3
#DuplicateCNs allow access control on a less-granular, per user basis.
#Remove # if you will manage access by user instead of device.
#duplicate-cn
# Generated for use by PiVPN.io