client
|
|
dev tun
|
|
proto udp
|
|
remote reymota.ddns.net 1194
|
|
resolv-retry infinite
|
|
nobind
|
|
user nobody
|
|
group nobody
|
|
persist-key
|
|
persist-tun
|
|
|
|
# Verify server certificate by checking that the
|
|
# certificate has the correct key usage set.
|
|
# This is an important precaution to protect against
|
|
# a potential attack discussed here:
|
|
# http://openvpn.net/howto.html#mitm
|
|
#
|
|
# To use this feature, you will need to generate
|
|
# your server certificates with the keyUsage set to
|
|
# digitalSignature, keyEncipherment
|
|
# and the extendedKeyUsage to
|
|
# serverAuth
|
|
# EasyRSA can do this for you.
|
|
remote-cert-tls server
|
|
|
|
# If a tls-auth key is used on the server
|
|
# then every client must also have the key.
|
|
key-direction 1
|
|
# Select a cryptographic cipher.
|
|
# If the cipher option is used on the server
|
|
# then you must also specify it here.
|
|
# Note that v2.4 client/server will automatically
|
|
# negotiate AES-256-GCM in TLS mode.
|
|
# See also the data-ciphers option in the manpage
|
|
cipher AES-256-GCM
|
|
|
|
# Enable compression on the VPN link.
|
|
# Don't enable this unless it is also
|
|
# enabled in the server config file.
|
|
#comp-lzo
|
|
|
|
# Set log file verbosity.
|
|
verb 3
|
|
|
|
# Silence repeating messages
|
|
;mute 20
|