186 lines
		
	
	
		
			7.4 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			186 lines
		
	
	
		
			7.4 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
###############################################################################
 | 
						|
# OpenVPN 2.0 Sample Configuration File
 | 
						|
# 
 | 
						|
# !!! AUTO-GENERATED  !!!
 | 
						|
# 
 | 
						|
# !!! YOU HAVE TO REVIEW IT BEFORE USE AND MODIFY IT AS NECESSARY !!!
 | 
						|
# 
 | 
						|
# This configuration file is auto-generated. You might use this config file
 | 
						|
# However, before you try it, you should review the descriptions of the file
 | 
						|
# to determine the necessity to modify to suitable for your real environment.
 | 
						|
# If necessary, you have to modify a little adequately on the file.
 | 
						|
# For example, the IP address or the hostname as a destination VPN Server
 | 
						|
# should be confirmed.
 | 
						|
# 
 | 
						|
# Note that to use OpenVPN 2.0, you have to put the certification file of
 | 
						|
# the destination VPN Server on the OpenVPN Client computer when you use this
 | 
						|
# config file. Please refer the below descriptions carefully.
 | 
						|
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# Specify the type of the layer of the VPN connection.
 | 
						|
# 
 | 
						|
# To connect to the VPN Server as a "Remote-Access VPN Client PC",
 | 
						|
#  specify 'dev tun'. (Layer-3 IP Routing Mode)
 | 
						|
#
 | 
						|
# To connect to the VPN Server as a bridging equipment of "Site-to-Site VPN",
 | 
						|
#  specify 'dev tap'. (Layer-2 Ethernet Bridgine Mode)
 | 
						|
 | 
						|
dev tun
 | 
						|
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# Specify the underlying protocol beyond the Internet.
 | 
						|
# Note that this setting must be correspond with the listening setting on
 | 
						|
# the VPN Server.
 | 
						|
# 
 | 
						|
# Specify either 'proto udp' or 'proto udp'.
 | 
						|
 | 
						|
proto udp
 | 
						|
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# The destination hostname / IP address, and port number of
 | 
						|
# the target VPN Server.
 | 
						|
# 
 | 
						|
# You have to specify as 'remote <HOSTNAME> <PORT>'. You can also
 | 
						|
# specify the IP address instead of the hostname.
 | 
						|
# 
 | 
						|
# Note that the auto-generated below hostname are a "auto-detected
 | 
						|
# IP address" of the VPN Server. You have to confirm the correctness
 | 
						|
# beforehand.
 | 
						|
# 
 | 
						|
# When you want to connect to the VPN Server by using TCP protocol,
 | 
						|
# the port number of the destination TCP port should be same as one of
 | 
						|
# the available TCP listeners on the VPN Server.
 | 
						|
# 
 | 
						|
# When you use UDP protocol, the port number must same as the configuration
 | 
						|
# setting of "OpenVPN Server Compatible Function" on the VPN Server.
 | 
						|
 | 
						|
# Note: The below hostname is came from the Dynamic DNS Client function
 | 
						|
#       which is running on the VPN Server. If you don't want to use
 | 
						|
#       the Dynamic DNS hostname, replace it to either IP address or
 | 
						|
#       other domain's hostname.
 | 
						|
 | 
						|
remote us-or.trust.zone 443
 | 
						|
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# The HTTP/HTTPS proxy setting.
 | 
						|
# 
 | 
						|
# Only if you have to use the Internet via a proxy, uncomment the below
 | 
						|
# two lines and specify the proxy address and the port number.
 | 
						|
# In the case of using proxy-authentication, refer the OpenVPN manual.
 | 
						|
 | 
						|
;http-proxy-retry
 | 
						|
;http-proxy [proxy server] [proxy port]
 | 
						|
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# The encryption and authentication algorithm.
 | 
						|
# 
 | 
						|
# Default setting is good. Modify it as you prefer.
 | 
						|
# When you specify an unsupported algorithm, the error will occur.
 | 
						|
# 
 | 
						|
# The supported algorithms are as follows:
 | 
						|
#  cipher: AES-128-CBC AES-192-CBC AES-256-CBC BF-CBC
 | 
						|
#          CAST-CBC CAST5-CBC DES-CBC DES-EDE-CBC DES-EDE3-CBC DESX-CBC
 | 
						|
#          RC2-40-CBC RC2-64-CBC RC2-CBC
 | 
						|
#  auth:   SHA SHA1 MD5 MD4 RMD160 SHA256 SHA384 SHA512
 | 
						|
 | 
						|
cipher AES-256-CBC
 | 
						|
auth SHA512
 | 
						|
#auth-nocache
 | 
						|
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# Other parameters necessary to connect to the VPN Server.
 | 
						|
# 
 | 
						|
# It is not recommended to modify it unless you have a particular need.
 | 
						|
 | 
						|
resolv-retry infinite
 | 
						|
nobind
 | 
						|
persist-key
 | 
						|
client
 | 
						|
verb 3
 | 
						|
auth-user-pass /config/openvpn-credentials.txt
 | 
						|
 | 
						|
verify-x509-name *.trust.zone name
 | 
						|
 | 
						|
ping 3
 | 
						|
ping-restart 10
 | 
						|
 | 
						|
#remote-cert-tls server
 | 
						|
#remote-cert-ku f6
 | 
						|
 | 
						|
dhcp-option DNS 109.236.87.2
 | 
						|
dhcp-option DNS 144.217.75.55
 | 
						|
 | 
						|
#uncomment next line if you want your OpenVPN client to ignore DNS settings pushed from VPN server
 | 
						|
#pull-filter ignore "dhcp-option DNS "
 | 
						|
 | 
						|
setenv CLIENT_CERT 0
 | 
						|
 | 
						|
###############################################################################
 | 
						|
# The certificate file of the destination VPN Server.
 | 
						|
# 
 | 
						|
# The CA certificate file is embedded in the inline format.
 | 
						|
# You can replace this CA contents if necessary.
 | 
						|
# Please note that if the server certificate is not a self-signed, you have to
 | 
						|
# specify the signer's root certificate (CA) here.
 | 
						|
 | 
						|
<ca>
 | 
						|
-----BEGIN CERTIFICATE-----
 | 
						|
MIIElDCCA3ygAwIBAgIQAf2j627KdciIQ4tyS8+8kTANBgkqhkiG9w0BAQsFADBh
 | 
						|
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
 | 
						|
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
 | 
						|
QTAeFw0xMzAzMDgxMjAwMDBaFw0yMzAzMDgxMjAwMDBaME0xCzAJBgNVBAYTAlVT
 | 
						|
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxJzAlBgNVBAMTHkRpZ2lDZXJ0IFNIQTIg
 | 
						|
U2VjdXJlIFNlcnZlciBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
 | 
						|
ANyuWJBNwcQwFZA1W248ghX1LFy949v/cUP6ZCWA1O4Yok3wZtAKc24RmDYXZK83
 | 
						|
nf36QYSvx6+M/hpzTc8zl5CilodTgyu5pnVILR1WN3vaMTIa16yrBvSqXUu3R0bd
 | 
						|
KpPDkC55gIDvEwRqFDu1m5K+wgdlTvza/P96rtxcflUxDOg5B6TXvi/TC2rSsd9f
 | 
						|
/ld0Uzs1gN2ujkSYs58O09rg1/RrKatEp0tYhG2SS4HD2nOLEpdIkARFdRrdNzGX
 | 
						|
kujNVA075ME/OV4uuPNcfhCOhkEAjUVmR7ChZc6gqikJTvOX6+guqw9ypzAO+sf0
 | 
						|
/RR3w6RbKFfCs/mC/bdFWJsCAwEAAaOCAVowggFWMBIGA1UdEwEB/wQIMAYBAf8C
 | 
						|
AQAwDgYDVR0PAQH/BAQDAgGGMDQGCCsGAQUFBwEBBCgwJjAkBggrBgEFBQcwAYYY
 | 
						|
aHR0cDovL29jc3AuZGlnaWNlcnQuY29tMHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6
 | 
						|
Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RDQS5jcmwwN6A1
 | 
						|
oDOGMWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RD
 | 
						|
QS5jcmwwPQYDVR0gBDYwNDAyBgRVHSAAMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8v
 | 
						|
d3d3LmRpZ2ljZXJ0LmNvbS9DUFMwHQYDVR0OBBYEFA+AYRyCMWHVLyjnjUY4tCzh
 | 
						|
xtniMB8GA1UdIwQYMBaAFAPeUDVW0Uy7ZvCj4hsbw5eyPdFVMA0GCSqGSIb3DQEB
 | 
						|
CwUAA4IBAQAjPt9L0jFCpbZ+QlwaRMxp0Wi0XUvgBCFsS+JtzLHgl4+mUwnNqipl
 | 
						|
5TlPHoOlblyYoiQm5vuh7ZPHLgLGTUq/sELfeNqzqPlt/yGFUzZgTHbO7Djc1lGA
 | 
						|
8MXW5dRNJ2Srm8c+cftIl7gzbckTB+6WohsYFfZcTEDts8Ls/3HB40f/1LkAtDdC
 | 
						|
2iDJ6m6K7hQGrn2iWZiIqBtvLfTyyRRfJs8sjX7tN8Cp1Tm5gr8ZDOo0rwAhaPit
 | 
						|
c+LJMto4JQtV05od8GiG7S5BNO98pVAdvzr508EIDObtHopYJeS4d60tbvVS3bR0
 | 
						|
j6tJLp07kzQoH3jOlOrHvdPJbRzeXDLz
 | 
						|
-----END CERTIFICATE-----
 | 
						|
 | 
						|
-----BEGIN CERTIFICATE-----
 | 
						|
MIIDrzCCApegAwIBAgIQCDvgVpBCRrGhdWrJWZHHSjANBgkqhkiG9w0BAQUFADBh
 | 
						|
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
 | 
						|
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
 | 
						|
QTAeFw0wNjExMTAwMDAwMDBaFw0zMTExMTAwMDAwMDBaMGExCzAJBgNVBAYTAlVT
 | 
						|
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
 | 
						|
b20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IENBMIIBIjANBgkqhkiG
 | 
						|
9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4jvhEXLeqKTTo1eqUKKPC3eQyaKl7hLOllsB
 | 
						|
CSDMAZOnTjC3U/dDxGkAV53ijSLdhwZAAIEJzs4bg7/fzTtxRuLWZscFs3YnFo97
 | 
						|
nh6Vfe63SKMI2tavegw5BmV/Sl0fvBf4q77uKNd0f3p4mVmFaG5cIzJLv07A6Fpt
 | 
						|
43C/dxC//AH2hdmoRBBYMql1GNXRor5H4idq9Joz+EkIYIvUX7Q6hL+hqkpMfT7P
 | 
						|
T19sdl6gSzeRntwi5m3OFBqOasv+zbMUZBfHWymeMr/y7vrTC0LUq7dBMtoM1O/4
 | 
						|
gdW7jVg/tRvoSSiicNoxBN33shbyTApOB6jtSj1etX+jkMOvJwIDAQABo2MwYTAO
 | 
						|
BgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUA95QNVbR
 | 
						|
TLtm8KPiGxvDl7I90VUwHwYDVR0jBBgwFoAUA95QNVbRTLtm8KPiGxvDl7I90VUw
 | 
						|
DQYJKoZIhvcNAQEFBQADggEBAMucN6pIExIK+t1EnE9SsPTfrgT1eXkIoyQY/Esr
 | 
						|
hMAtudXH/vTBH1jLuG2cenTnmCmrEbXjcKChzUyImZOMkXDiqw8cvpOp/2PV5Adg
 | 
						|
06O/nVsJ8dWO41P0jmP6P6fbtGbfYmbW0W5BjfIttep3Sp+dWOIrWcBAI+0tKIJF
 | 
						|
PnlUkiaY4IBIqDfv8NZ5YBberOgOzW6sRBc4L0na4UU+Krk2U886UAb3LujEV0ls
 | 
						|
YSEY1QSteDwsOoBrp+uvFRTp2InBuThs4pFsiv9kuXclVzDAGySj4dzp30d8tbQk
 | 
						|
CAUw7C29C79Fv1C5qfPrmAESrciIxpg0X40KPMbp1ZWVbd4=
 | 
						|
-----END CERTIFICATE-----
 | 
						|
</ca>
 | 
						|
 | 
						|
 |