|
@@ -0,0 +1,35 @@
|
|
1
|
+# Serveur TCP/443
|
|
2
|
+mode server
|
|
3
|
+proto tcp-server
|
|
4
|
+port 8080
|
|
5
|
+dev tun
|
|
6
|
+
|
|
7
|
+# Cles et certificats
|
|
8
|
+ca /etc/openvpn/vpn_internet/ca.crt
|
|
9
|
+cert /etc/openvpn/vpn_internet/server.crt
|
|
10
|
+key /etc/openvpn/vpn_internet/server.key
|
|
11
|
+dh /etc/openvpn/vpn_internet/dh1024.pem
|
|
12
|
+tls-auth /etc/openvpn/vpn_internet/ta.key 1
|
|
13
|
+
|
|
14
|
+key-direction 0
|
|
15
|
+cipher AES-256-CBC
|
|
16
|
+crl-verify /etc/openvpn/vpn_internet/easy-rsa/keys/crl.pem
|
|
17
|
+client-config-dir /etc/openvpn/vpn_internet/clientsconf
|
|
18
|
+
|
|
19
|
+# Reseau
|
|
20
|
+server 10.8.0.0 255.255.255.0
|
|
21
|
+push "redirect-gateway def1 bypass-dhcp"
|
|
22
|
+keepalive 10 120
|
|
23
|
+
|
|
24
|
+# Securite
|
|
25
|
+user www-data
|
|
26
|
+group ovpn-manager
|
|
27
|
+persist-key
|
|
28
|
+persist-tun
|
|
29
|
+comp-lzo
|
|
30
|
+
|
|
31
|
+# Log
|
|
32
|
+verb 1
|
|
33
|
+mute 20
|
|
34
|
+status /var/vpn.example.com/status-vpn_internet
|
|
35
|
+log-append /var/log/openvpn-vpn_internet.log
|