############################################################################### # OpenVPN 2.0 Sample Configuration File # for PacketiX VPN / SoftEther VPN Server # # !!! AUTO-GENERATED BY SOFTETHER VPN SERVER MANAGEMENT TOOL !!! # # !!! YOU HAVE TO REVIEW IT BEFORE USE AND MODIFY IT AS NECESSARY !!! # # This configuration file is auto-generated. You might use this config file # in order to connect to the PacketiX VPN / SoftEther VPN Server. # However, before you try it, you should review the descriptions of the file # to determine the necessity to modify to suitable for your real environment. # If necessary, you have to modify a little adequately on the file. # For example, the IP address or the hostname as a destination VPN Server # should be confirmed. # # Note that to use OpenVPN 2.0, you have to put the certification file of # the destination VPN Server on the OpenVPN Client computer when you use this # config file. Please refer the below descriptions carefully. ############################################################################### # Specify the type of the layer of the VPN connection. # # To connect to the VPN Server as a "Remote-Access VPN Client PC", # specify 'dev tun'. (Layer-3 IP Routing Mode) # # To connect to the VPN Server as a bridging equipment of "Site-to-Site VPN", # specify 'dev tap'. (Layer-2 Ethernet Bridgine Mode) dev tun ############################################################################### # Specify the underlying protocol beyond the Internet. # Note that this setting must be correspond with the listening setting on # the VPN Server. # # Specify either 'proto tcp' or 'proto udp'. proto udp ############################################################################### # The destination hostname / IP address, and port number of # the target VPN Server. # # You have to specify as 'remote '. You can also # specify the IP address instead of the hostname. # # Note that the auto-generated below hostname are a "auto-detected # IP address" of the VPN Server. You have to confirm the correctness # beforehand. # # When you want to connect to the VPN Server by using TCP protocol, # the port number of the destination TCP port should be same as one of # the available TCP listeners on the VPN Server. # # When you use UDP protocol, the port number must same as the configuration # setting of "OpenVPN Server Compatible Function" on the VPN Server. # Note: The below hostname is came from the Dynamic DNS Client function # which is running on the VPN Server. If you don't want to use # the Dynamic DNS hostname, replace it to either IP address or # other domain's hostname. remote goribervpn.v4.softether.net 1194 ############################################################################### # The HTTP/HTTPS proxy setting. # # Only if you have to use the Internet via a proxy, uncomment the below # two lines and specify the proxy address and the port number. # In the case of using proxy-authentication, refer the OpenVPN manual. ;http-proxy-retry ;http-proxy [proxy server] [proxy port] ############################################################################### # The encryption and authentication algorithm. # # Default setting is good. Modify it as you prefer. # When you specify an unsupported algorithm, the error will occur. # # The supported algorithms are as follows: # cipher: [NULL-CIPHER] NULL AES-128-CBC AES-192-CBC AES-256-CBC BF-CBC # CAST-CBC CAST5-CBC DES-CBC DES-EDE-CBC DES-EDE3-CBC DESX-CBC # RC2-40-CBC RC2-64-CBC RC2-CBC CAMELLIA-128-CBC CAMELLIA-192-CBC CAMELLIA-256-CBC # auth: SHA SHA1 SHA256 SHA384 SHA512 MD5 MD4 RMD160 cipher AES-128-CBC auth SHA1 ############################################################################### # Other parameters necessary to connect to the VPN Server. # # It is not recommended to modify it unless you have a particular need. resolv-retry infinite nobind persist-key persist-tun client verb 3 ############################################################################### # Authentication with credentials. # # Comment the line out in case you want to use the certificate authentication. auth-user-pass ############################################################################### # The certificate file of the destination VPN Server. # # The CA certificate file is embedded in the inline format. # You can replace this CA contents if necessary. # Please note that if the server certificate is not a self-signed, you have to # specify the signer's root certificate (CA) here. -----BEGIN CERTIFICATE----- MIID7jCCAtagAwIBAgIBADANBgkqhkiG9w0BAQsFADB2MSEwHwYDVQQDDBhnb3Jp YmVydnBuLnNvZnRldGhlci5uZXQxITAfBgNVBAoMGGdvcmliZXJ2cG4uc29mdGV0 aGVyLm5ldDEhMB8GA1UECwwYZ29yaWJlcnZwbi5zb2Z0ZXRoZXIubmV0MQswCQYD VQQGEwJVUzAeFw0yMTA3MjAwNDM2NDVaFw0zNzEyMzEwNDM2NDVaMHYxITAfBgNV BAMMGGdvcmliZXJ2cG4uc29mdGV0aGVyLm5ldDEhMB8GA1UECgwYZ29yaWJlcnZw bi5zb2Z0ZXRoZXIubmV0MSEwHwYDVQQLDBhnb3JpYmVydnBuLnNvZnRldGhlci5u ZXQxCzAJBgNVBAYTAlVTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA zWIKl98VrznjqvONC/zC9NdS7gTvRK5VDr3UpO+XaRZQdryFXYv3cP9Hh5aill01 t93mO8GvWK5F1k7eQigJf8FYvMeH3LG4WTQBtN+df2DY6EZurASBKNinTTVF53Z5 WeU7SqTzh1O5O7Yf5ObbF7vDMz83GrJCzDSD7+dmKOr4RDjwXlWEl6HHTS9Xt5Lj TSJAcqABBfLIuqbnZ2dm//i/Nh/dstSk2UjHDOghEZJVo2mtIaelibFqTIXN5jrp ivz7NDvn7R/LGhyKpmOVCbUd+azZessRQ+8WKK8CAOeEodtOob896ACiAes1/LBf hRULyb5QFPGGslGzoptg5QIDAQABo4GGMIGDMA8GA1UdEwEB/wQFMAMBAf8wCwYD VR0PBAQDAgH2MGMGA1UdJQRcMFoGCCsGAQUFBwMBBggrBgEFBQcDAgYIKwYBBQUH AwMGCCsGAQUFBwMEBggrBgEFBQcDBQYIKwYBBQUHAwYGCCsGAQUFBwMHBggrBgEF BQcDCAYIKwYBBQUHAwkwDQYJKoZIhvcNAQELBQADggEBAGa/tc88CdTv0HntBBk0 22VHkuGNSV9L7iyV6kcyg08IMr+HPaguyHvZ7TebzyxSFVgLpbKsKouhKxZ6eEab RMbBXBI7wYcy+Ep5pcjpVGPNPs7dkDxAltNZpVOQNLc5vBkSHi9tj99A3oTUFI6e qWAeYfZOeuIkFL0Crj47ZY9PP4ksm01ldR1wmNS/RXroHCql4+xdykuSJVxvQWsE daUswVxOxWCvtjfa/B7XzsdeW63vXDnXLMv1iHEUTe112WL2Nvrx7zF2GjScFGb2 1rtKxudyV2LhXSbgYGDfWep6fxRxDK6V38qq+Yvb+RKFEGyPprBbVPLuqB/B7ilK 45U= -----END CERTIFICATE----- ############################################################################### # Client certificate and key. # # A pair of client certificate and private key is required in case you want to # use the certificate authentication. # # To enable it, uncomment the lines below. # Paste your certificate in the block and the key in the one. ; ;-----BEGIN CERTIFICATE----- ; ;-----END CERTIFICATE----- ; ; ;-----BEGIN RSA PRIVATE KEY----- ; ;-----END RSA PRIVATE KEY----- ;