186 lines
		
	
	
		
			7.4 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			186 lines
		
	
	
		
			7.4 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
| ###############################################################################
 | |
| # OpenVPN 2.0 Sample Configuration File
 | |
| # 
 | |
| # !!! AUTO-GENERATED  !!!
 | |
| # 
 | |
| # !!! YOU HAVE TO REVIEW IT BEFORE USE AND MODIFY IT AS NECESSARY !!!
 | |
| # 
 | |
| # This configuration file is auto-generated. You might use this config file
 | |
| # However, before you try it, you should review the descriptions of the file
 | |
| # to determine the necessity to modify to suitable for your real environment.
 | |
| # If necessary, you have to modify a little adequately on the file.
 | |
| # For example, the IP address or the hostname as a destination VPN Server
 | |
| # should be confirmed.
 | |
| # 
 | |
| # Note that to use OpenVPN 2.0, you have to put the certification file of
 | |
| # the destination VPN Server on the OpenVPN Client computer when you use this
 | |
| # config file. Please refer the below descriptions carefully.
 | |
| 
 | |
| 
 | |
| ###############################################################################
 | |
| # Specify the type of the layer of the VPN connection.
 | |
| # 
 | |
| # To connect to the VPN Server as a "Remote-Access VPN Client PC",
 | |
| #  specify 'dev tun'. (Layer-3 IP Routing Mode)
 | |
| #
 | |
| # To connect to the VPN Server as a bridging equipment of "Site-to-Site VPN",
 | |
| #  specify 'dev tap'. (Layer-2 Ethernet Bridgine Mode)
 | |
| 
 | |
| dev tun
 | |
| 
 | |
| 
 | |
| ###############################################################################
 | |
| # Specify the underlying protocol beyond the Internet.
 | |
| # Note that this setting must be correspond with the listening setting on
 | |
| # the VPN Server.
 | |
| # 
 | |
| # Specify either 'proto udp' or 'proto udp'.
 | |
| 
 | |
| proto udp
 | |
| 
 | |
| 
 | |
| ###############################################################################
 | |
| # The destination hostname / IP address, and port number of
 | |
| # the target VPN Server.
 | |
| # 
 | |
| # You have to specify as 'remote <HOSTNAME> <PORT>'. You can also
 | |
| # specify the IP address instead of the hostname.
 | |
| # 
 | |
| # Note that the auto-generated below hostname are a "auto-detected
 | |
| # IP address" of the VPN Server. You have to confirm the correctness
 | |
| # beforehand.
 | |
| # 
 | |
| # When you want to connect to the VPN Server by using TCP protocol,
 | |
| # the port number of the destination TCP port should be same as one of
 | |
| # the available TCP listeners on the VPN Server.
 | |
| # 
 | |
| # When you use UDP protocol, the port number must same as the configuration
 | |
| # setting of "OpenVPN Server Compatible Function" on the VPN Server.
 | |
| 
 | |
| # Note: The below hostname is came from the Dynamic DNS Client function
 | |
| #       which is running on the VPN Server. If you don't want to use
 | |
| #       the Dynamic DNS hostname, replace it to either IP address or
 | |
| #       other domain's hostname.
 | |
| 
 | |
| remote sg.trust.zone 443
 | |
| 
 | |
| 
 | |
| ###############################################################################
 | |
| # The HTTP/HTTPS proxy setting.
 | |
| # 
 | |
| # Only if you have to use the Internet via a proxy, uncomment the below
 | |
| # two lines and specify the proxy address and the port number.
 | |
| # In the case of using proxy-authentication, refer the OpenVPN manual.
 | |
| 
 | |
| ;http-proxy-retry
 | |
| ;http-proxy [proxy server] [proxy port]
 | |
| 
 | |
| 
 | |
| ###############################################################################
 | |
| # The encryption and authentication algorithm.
 | |
| # 
 | |
| # Default setting is good. Modify it as you prefer.
 | |
| # When you specify an unsupported algorithm, the error will occur.
 | |
| # 
 | |
| # The supported algorithms are as follows:
 | |
| #  cipher: AES-128-CBC AES-192-CBC AES-256-CBC BF-CBC
 | |
| #          CAST-CBC CAST5-CBC DES-CBC DES-EDE-CBC DES-EDE3-CBC DESX-CBC
 | |
| #          RC2-40-CBC RC2-64-CBC RC2-CBC
 | |
| #  auth:   SHA SHA1 MD5 MD4 RMD160 SHA256 SHA384 SHA512
 | |
| 
 | |
| cipher AES-256-CBC
 | |
| auth SHA512
 | |
| #auth-nocache
 | |
| 
 | |
| 
 | |
| ###############################################################################
 | |
| # Other parameters necessary to connect to the VPN Server.
 | |
| # 
 | |
| # It is not recommended to modify it unless you have a particular need.
 | |
| 
 | |
| resolv-retry infinite
 | |
| nobind
 | |
| persist-key
 | |
| client
 | |
| verb 3
 | |
| auth-user-pass /config/openvpn-credentials.txt
 | |
| 
 | |
| verify-x509-name *.trust.zone name
 | |
| 
 | |
| ping 3
 | |
| ping-restart 10
 | |
| 
 | |
| #remote-cert-tls server
 | |
| #remote-cert-ku f6
 | |
| 
 | |
| dhcp-option DNS 109.236.87.2
 | |
| dhcp-option DNS 144.217.75.55
 | |
| 
 | |
| #uncomment next line if you want your OpenVPN client to ignore DNS settings pushed from VPN server
 | |
| #pull-filter ignore "dhcp-option DNS "
 | |
| 
 | |
| setenv CLIENT_CERT 0
 | |
| 
 | |
| ###############################################################################
 | |
| # The certificate file of the destination VPN Server.
 | |
| # 
 | |
| # The CA certificate file is embedded in the inline format.
 | |
| # You can replace this CA contents if necessary.
 | |
| # Please note that if the server certificate is not a self-signed, you have to
 | |
| # specify the signer's root certificate (CA) here.
 | |
| 
 | |
| <ca>
 | |
| -----BEGIN CERTIFICATE-----
 | |
| MIIElDCCA3ygAwIBAgIQAf2j627KdciIQ4tyS8+8kTANBgkqhkiG9w0BAQsFADBh
 | |
| MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
 | |
| d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
 | |
| QTAeFw0xMzAzMDgxMjAwMDBaFw0yMzAzMDgxMjAwMDBaME0xCzAJBgNVBAYTAlVT
 | |
| MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxJzAlBgNVBAMTHkRpZ2lDZXJ0IFNIQTIg
 | |
| U2VjdXJlIFNlcnZlciBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB
 | |
| ANyuWJBNwcQwFZA1W248ghX1LFy949v/cUP6ZCWA1O4Yok3wZtAKc24RmDYXZK83
 | |
| nf36QYSvx6+M/hpzTc8zl5CilodTgyu5pnVILR1WN3vaMTIa16yrBvSqXUu3R0bd
 | |
| KpPDkC55gIDvEwRqFDu1m5K+wgdlTvza/P96rtxcflUxDOg5B6TXvi/TC2rSsd9f
 | |
| /ld0Uzs1gN2ujkSYs58O09rg1/RrKatEp0tYhG2SS4HD2nOLEpdIkARFdRrdNzGX
 | |
| kujNVA075ME/OV4uuPNcfhCOhkEAjUVmR7ChZc6gqikJTvOX6+guqw9ypzAO+sf0
 | |
| /RR3w6RbKFfCs/mC/bdFWJsCAwEAAaOCAVowggFWMBIGA1UdEwEB/wQIMAYBAf8C
 | |
| AQAwDgYDVR0PAQH/BAQDAgGGMDQGCCsGAQUFBwEBBCgwJjAkBggrBgEFBQcwAYYY
 | |
| aHR0cDovL29jc3AuZGlnaWNlcnQuY29tMHsGA1UdHwR0MHIwN6A1oDOGMWh0dHA6
 | |
| Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RDQS5jcmwwN6A1
 | |
| oDOGMWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEdsb2JhbFJvb3RD
 | |
| QS5jcmwwPQYDVR0gBDYwNDAyBgRVHSAAMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8v
 | |
| d3d3LmRpZ2ljZXJ0LmNvbS9DUFMwHQYDVR0OBBYEFA+AYRyCMWHVLyjnjUY4tCzh
 | |
| xtniMB8GA1UdIwQYMBaAFAPeUDVW0Uy7ZvCj4hsbw5eyPdFVMA0GCSqGSIb3DQEB
 | |
| CwUAA4IBAQAjPt9L0jFCpbZ+QlwaRMxp0Wi0XUvgBCFsS+JtzLHgl4+mUwnNqipl
 | |
| 5TlPHoOlblyYoiQm5vuh7ZPHLgLGTUq/sELfeNqzqPlt/yGFUzZgTHbO7Djc1lGA
 | |
| 8MXW5dRNJ2Srm8c+cftIl7gzbckTB+6WohsYFfZcTEDts8Ls/3HB40f/1LkAtDdC
 | |
| 2iDJ6m6K7hQGrn2iWZiIqBtvLfTyyRRfJs8sjX7tN8Cp1Tm5gr8ZDOo0rwAhaPit
 | |
| c+LJMto4JQtV05od8GiG7S5BNO98pVAdvzr508EIDObtHopYJeS4d60tbvVS3bR0
 | |
| j6tJLp07kzQoH3jOlOrHvdPJbRzeXDLz
 | |
| -----END CERTIFICATE-----
 | |
| 
 | |
| -----BEGIN CERTIFICATE-----
 | |
| MIIDrzCCApegAwIBAgIQCDvgVpBCRrGhdWrJWZHHSjANBgkqhkiG9w0BAQUFADBh
 | |
| MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
 | |
| d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
 | |
| QTAeFw0wNjExMTAwMDAwMDBaFw0zMTExMTAwMDAwMDBaMGExCzAJBgNVBAYTAlVT
 | |
| MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
 | |
| b20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IENBMIIBIjANBgkqhkiG
 | |
| 9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4jvhEXLeqKTTo1eqUKKPC3eQyaKl7hLOllsB
 | |
| CSDMAZOnTjC3U/dDxGkAV53ijSLdhwZAAIEJzs4bg7/fzTtxRuLWZscFs3YnFo97
 | |
| nh6Vfe63SKMI2tavegw5BmV/Sl0fvBf4q77uKNd0f3p4mVmFaG5cIzJLv07A6Fpt
 | |
| 43C/dxC//AH2hdmoRBBYMql1GNXRor5H4idq9Joz+EkIYIvUX7Q6hL+hqkpMfT7P
 | |
| T19sdl6gSzeRntwi5m3OFBqOasv+zbMUZBfHWymeMr/y7vrTC0LUq7dBMtoM1O/4
 | |
| gdW7jVg/tRvoSSiicNoxBN33shbyTApOB6jtSj1etX+jkMOvJwIDAQABo2MwYTAO
 | |
| BgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUA95QNVbR
 | |
| TLtm8KPiGxvDl7I90VUwHwYDVR0jBBgwFoAUA95QNVbRTLtm8KPiGxvDl7I90VUw
 | |
| DQYJKoZIhvcNAQEFBQADggEBAMucN6pIExIK+t1EnE9SsPTfrgT1eXkIoyQY/Esr
 | |
| hMAtudXH/vTBH1jLuG2cenTnmCmrEbXjcKChzUyImZOMkXDiqw8cvpOp/2PV5Adg
 | |
| 06O/nVsJ8dWO41P0jmP6P6fbtGbfYmbW0W5BjfIttep3Sp+dWOIrWcBAI+0tKIJF
 | |
| PnlUkiaY4IBIqDfv8NZ5YBberOgOzW6sRBc4L0na4UU+Krk2U886UAb3LujEV0ls
 | |
| YSEY1QSteDwsOoBrp+uvFRTp2InBuThs4pFsiv9kuXclVzDAGySj4dzp30d8tbQk
 | |
| CAUw7C29C79Fv1C5qfPrmAESrciIxpg0X40KPMbp1ZWVbd4=
 | |
| -----END CERTIFICATE-----
 | |
| </ca>
 | |
| 
 | |
| 
 |