Update openvpn config
This commit is contained in:
1 parent
b213d07da6
commit
3af17b7a66
3 files changed
+30
-30
No files matched your search
@@ -11,14 +11,13 @@ proto udp
|
||||
# We're using the layer 3 tunnel device
|
||||
dev tun
|
||||
|
||||
# Specify multiple remotes for dualstack connectivity
|
||||
remote 2003:d7:b70f:e387::5 1194
|
||||
remote 172.16.20.5 1194
|
||||
# Specify vpn server
|
||||
remote vpn-test.inform.hs-hannover.de 1194
|
||||
|
||||
# Certificates
|
||||
ca /etc/openvpn/vpnclient/ca.crt
|
||||
cert /etc/openvpn/vpnclient/vpnclient0.crt
|
||||
key /etc/openvpn/vpnclient/vpnclient0.key
|
||||
cert /etc/openvpn/vpnclient/jan-philipp.timme@hs-hannover.de.crt
|
||||
key /etc/openvpn/vpnclient/jan-philipp.timme@hs-hannover.de.key
|
||||
|
||||
# Make sure the server presents a certificate with "server role"
|
||||
remote-cert-tls server
|
||||
|
||||
@@ -8,8 +8,8 @@ dev tun
|
||||
|
||||
# Certificates
|
||||
ca /etc/openvpn/vpnserver/ca.crt
|
||||
cert /etc/openvpn/vpnserver/vpnserver.crt
|
||||
key /etc/openvpn/vpnserver/vpnserver.key
|
||||
cert /etc/openvpn/vpnserver/aither.inform.hs-hannover.de.crt
|
||||
key /etc/openvpn/vpnserver/aither.inform.hs-hannover.de.key
|
||||
dh /etc/openvpn/vpnserver/dh.pem
|
||||
|
||||
# Make sure the client presents a certificate with "client role"
|
||||
@@ -20,22 +20,27 @@ remote-cert-tls client
|
||||
|
||||
# net30 is point-to-point, compatible with windows
|
||||
# TODO: Topology subnet is supposed to work with windows just fine. CHECK THIS
|
||||
topology net30
|
||||
# Subnet topology is supposed to be working with windows clients just fine.
|
||||
topology subnet
|
||||
|
||||
# Use this IPv4 range for clients (/16, so we can cope with all possible clients)
|
||||
server 10.183.0.0 255.255.0.0
|
||||
server 10.2.0.0 255.255.0.0
|
||||
|
||||
# Use this IPv6 network for clients
|
||||
server-ipv6 2001:638:614:1750::/64
|
||||
|
||||
# Do we need persistence here?
|
||||
ifconfig-pool-persist /etc/openvpn/vpnserver/ipp.txt
|
||||
# No, not yet.
|
||||
#ifconfig-pool-persist /etc/openvpn/vpnserver/ipp.txt
|
||||
|
||||
# Make sure the client can still reach the OpenVPN server via its default gateway
|
||||
push "route remote_host 255.255.255.255 net_gateway"
|
||||
|
||||
# Push routes for local networks
|
||||
push "route 172.16.20.0 255.255.255.0 vpn_gateway"
|
||||
# Push routes for local IPv4 networks
|
||||
push "route 141.71.30.0 255.255.254.0 vpn_gateway"
|
||||
push "route 192.168.99.0 255.255.255.0 vpn_gateway"
|
||||
push "route 10.3.1.0 255.255.255.0 vpn_gateway"
|
||||
push "route 10.0.0.0 255.255.255.0 vpn_gateway"
|
||||
|
||||
# Push the whole /56 block for IPv6
|
||||
push "route-ipv6 2003:638:614:1700::/56"
|
||||
@@ -55,5 +60,5 @@ group nogroup
|
||||
verb 3
|
||||
mute 5
|
||||
|
||||
# Have a status log
|
||||
status /etc/openvpn/vpnserver/status.log
|
||||
# Have a status log if needed.
|
||||
# status /etc/openvpn/vpnserver/status.log
|
||||
Reference in new issue
Block a user