Office_Networks/WF/openvpn/wf/client-configs/axel.conf
2018-05-08 03:01:03 +02:00

271 lines
12 KiB
Plaintext

##############################################
# Sample client-side OpenVPN 2.0 config file #
# for connecting to multi-client server. #
# #
# This configuration can be used by multiple #
# clients, however each client should have #
# its own cert and key files. #
# #
# On Windows, you might want to rename this #
# file so it has a .ovpn extension #
##############################################
# Specify that we are a client and that we
# will be pulling certain config file directives
# from the server.
client
# Use the same setting as you are using on
# the server.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
;dev tap
dev tun
# Are we connecting to a TCP or
# UDP server? Use the same setting as
# on the server
proto udp
# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
remote wf.oopen.de 1194
topology subnet
# Keep trying indefinitely to resolve the
# host name of the OpenVPN server. Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite
# Most clients don't need to bind to
# a specific local port number.
nobind
# Try to preserve some state across restarts.
persist-key
persist-tun
# Server CA
<ca>
-----BEGIN CERTIFICATE-----
MIIGxjCCBK6gAwIBAgIJANhMyyi1cVS7MA0GCSqGSIb3DQEBCwUAMIGcMQswCQYD
VQQGEwJERTEPMA0GA1UECBMGQmVybGluMQ8wDQYDVQQHEwZCZXJsaW4xDzANBgNV
BAoTBm8ub3BlbjEZMBcGA1UECxMQTmV0d29yayBTZXJ2aWNlczEPMA0GA1UEAxMG
VlBOLVdGMQ8wDQYDVQQpEwZWUE4gV0YxHTAbBgkqhkiG9w0BCQEWDmFyZ3VzQG9v
cGVuLmRlMCAXDTE4MDUwNDE4MjA0MloYDzIwNTAwNTA0MTgyMDQyWjCBnDELMAkG
A1UEBhMCREUxDzANBgNVBAgTBkJlcmxpbjEPMA0GA1UEBxMGQmVybGluMQ8wDQYD
VQQKEwZvLm9wZW4xGTAXBgNVBAsTEE5ldHdvcmsgU2VydmljZXMxDzANBgNVBAMT
BlZQTi1XRjEPMA0GA1UEKRMGVlBOIFdGMR0wGwYJKoZIhvcNAQkBFg5hcmd1c0Bv
b3Blbi5kZTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAK+cDn8x2oBG
oH7SDD3d9p+rRE4uzVDp/7YxuvvCXazhPUVc0BGE8hj6jCwB+tbbNlhbm/uwxAX6
96kz2AmoGzEZQy/Icb+UKNkKni15PUEaCcFWkgb9mMb/6XBP4JLUdnxxUn5rYB8A
m4jpKzMz6tBRlNmLbDVbcHriLuJJ3mgFBN/QYV9zurKzMRLv6Y8MVzLXY6MPYaFs
Lw398Iz/lIVLq40FxZ7oktvT3RFQUFjiTqBvdmQw91MYxJHGYZH6XB+tPhGw+9D7
w2ejAvv3MQU246oaEyyH3Pgh8GajSdKmiTH5YHRkp6LVnh7IGEZ1G7dbq8d5KlZP
zBP+Xdsf0gkjl3HI5cu4RJHWFg3dpNJxatxXc8owhaLa3wiVwSXobNsQBUNI5CeE
OItnetBLZzAmDlS5WoOAj5KMApun4xQQJXaazTaM5LhUN1TmXL6dq6rHSZrnrciV
aM0M6F96h0OFYq0RxsztXHiWFxJgbuNQSx1pzqsaFe4MtEEpMlI4SRQjtJPbje80
HCELo3Qfuxm6vLSGH1jXozhDt3/3jB96yBT+wemN3wxiiR/fWfmwH0k3VEFxbsBR
sMcgA3xopoyHU3cUQqWkFaKT0gBa0t2sZqpsaRgaR4YzKVuHu7Wezb3VRAt9VH35
E97yq3vv0J2OFN4trPMZ6TdRcRppe79bAgMBAAGjggEFMIIBATAdBgNVHQ4EFgQU
Tz6IFOGhISjj5ltza9wPl9lg9fEwgdEGA1UdIwSByTCBxoAUTz6IFOGhISjj5ltz
a9wPl9lg9fGhgaKkgZ8wgZwxCzAJBgNVBAYTAkRFMQ8wDQYDVQQIEwZCZXJsaW4x
DzANBgNVBAcTBkJlcmxpbjEPMA0GA1UEChMGby5vcGVuMRkwFwYDVQQLExBOZXR3
b3JrIFNlcnZpY2VzMQ8wDQYDVQQDEwZWUE4tV0YxDzANBgNVBCkTBlZQTiBXRjEd
MBsGCSqGSIb3DQEJARYOYXJndXNAb29wZW4uZGWCCQDYTMsotXFUuzAMBgNVHRME
BTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQApiMctoi++fFyKUOzdI5p+mJLxldQD
Jx6V6aY3wZRtKerXFuH+rAZDcBg5pCc+IwVYhR0ilJGvSFrN3nsipSRYkev3W8F7
8NBD0I0A02WmwOZA9GM5LAwc3w7dkGKLTIFM/qfwti4Y6o0Sb10r8QKhggiNBO53
Z10StshS5ciUtw0oH7oTRbsXhLOwwikkBxQgeCU5IJUtC2Xp8uG6Mrkqva/l+PIe
I83YPlE6NGiok2N9Cg7wx7Y65hg6F8lLePIh81pPLVujr91B1Y9Oc/iKwDZ+f0ep
uWnLSZJYbCrv4/QqPi4Km7CqJlPy4Wj861U2SmNkzJC721d2UDVBcFoGw3zIszYl
zGdXF71fcLqThlU/EwNgSOa/hQd6mcCZVBh0qlQHp1nefCUM4O5Qd7swSTV3Bdbx
wkkH/lWRPURL0qMevF5KNYT+dUV7Tplf11cW8D3cIe8+mr7p7FnFjKlbQ+YQQZ+O
d1zX06ADQPLsOat4FNwAkxBLSQ0anK9iu0xZUNy3RMRsLIX/gtl6qvxnWvuy2OJs
3bjs7hauPZLwycL5uaFoKt8twwomLPj4tE0AsWwxIGK7vQajJl755QNEgHfUd8Ng
U9tR185HsyrrKii3tuxGRwJGeN5IQkp/04CL2jVYYzkqe7tsr4SPE++hj/vK4zrw
E+i0hdVFGZBFNQ==
-----END CERTIFICATE-----
</ca>
# Client Certificate
<cert>
-----BEGIN CERTIFICATE-----
MIIHIDCCBQigAwIBAgIBAjANBgkqhkiG9w0BAQsFADCBnDELMAkGA1UEBhMCREUx
DzANBgNVBAgTBkJlcmxpbjEPMA0GA1UEBxMGQmVybGluMQ8wDQYDVQQKEwZvLm9w
ZW4xGTAXBgNVBAsTEE5ldHdvcmsgU2VydmljZXMxDzANBgNVBAMTBlZQTi1XRjEP
MA0GA1UEKRMGVlBOIFdGMR0wGwYJKoZIhvcNAQkBFg5hcmd1c0Bvb3Blbi5kZTAe
Fw0xODA1MDUwOTMwNDZaFw0zODA1MDUwOTMwNDZaMIGhMQswCQYDVQQGEwJERTEP
MA0GA1UECBMGQmVybGluMQ8wDQYDVQQHEwZCZXJsaW4xDzANBgNVBAoTBm8ub3Bl
bjEZMBcGA1UECxMQTmV0d29yayBTZXJ2aWNlczEUMBIGA1UEAxMLVlBOLVdGLWF4
ZWwxDzANBgNVBCkTBlZQTiBXRjEdMBsGCSqGSIb3DQEJARYOYXJndXNAb29wZW4u
ZGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDA0eJw8/wfxlpVJeWU
4cY+FVfSuZ8ufh4aY/KWzaRLfxv3kPa/y84Eb2hQUmo3sqSz/TyIx/Cb/kxdri2a
PJY3Aa87rK1EUZMg7tSFmSLRxW16g9DmKeXJbLFzkFhAIX7xvHoIlMdHlrOC3BOx
6OWHTowhLH83XCoK6h2gF7s7++cKEhzuAfPeSkf9ufl37oeEydUz7rlX1xKwTb/6
FvGCGC2yyJZ//ggglmXZd5LnD1/8ojq2rlnWE7y/0aNaFHTt9ONrp8kOa7XHX9i2
717pDmhKfS7iGhO5+eDcs0MZCUJNCeBF0Y82QF3wa8ksJhcXxlsl+qgwH2JX6Q8J
ql+AjnaMwemPWWJHNbMLbcE7VBkjtxFjdO3uqr+guVExY2TpBrEQZRTbQcxSEdm7
rt51cIAT9WzsLS3VtbEL3S9rEsAcLJyS5amIGdWQ8pAI2qC8lUB/EMuJrAPxgJjK
3xB6cqhUgDO69uUj9G3WEXVh3YcO9OHkKrdue2r6czqXIwV4n1MFfl3OlSf26jcZ
stbtg57AhbgWerNXCfSUi4BUmAbRLM0vK8O/iLWizcbztARLvQhqeATYixaEW6U3
DC47HgsUYzVFZyqiJh84QVPog0gMYKAl1n46nmh2ncrwJ0RFbZ+t+xkuvIsrY3Z4
Y9eLCix2uEiM64epHYKvc4AlzwIDAQABo4IBZDCCAWAwCQYDVR0TBAIwADAtBglg
hkgBhvhCAQ0EIBYeRWFzeS1SU0EgR2VuZXJhdGVkIENlcnRpZmljYXRlMB0GA1Ud
DgQWBBTOxbPc2G+P6gmZuUFktyLVvPmmmDCB0QYDVR0jBIHJMIHGgBRPPogU4aEh
KOPmW3Nr3A+X2WD18aGBoqSBnzCBnDELMAkGA1UEBhMCREUxDzANBgNVBAgTBkJl
cmxpbjEPMA0GA1UEBxMGQmVybGluMQ8wDQYDVQQKEwZvLm9wZW4xGTAXBgNVBAsT
EE5ldHdvcmsgU2VydmljZXMxDzANBgNVBAMTBlZQTi1XRjEPMA0GA1UEKRMGVlBO
IFdGMR0wGwYJKoZIhvcNAQkBFg5hcmd1c0Bvb3Blbi5kZYIJANhMyyi1cVS7MBMG
A1UdJQQMMAoGCCsGAQUFBwMCMAsGA1UdDwQEAwIHgDAPBgNVHREECDAGggRheGVs
MA0GCSqGSIb3DQEBCwUAA4ICAQBdYgR+uA1hT/tWVz9NqfhvaKWrkhyyBDJfpAIu
Oh3YWSgvjBucM6PDF6hfUt8M0ipSbAhHXxLKUJ7LTbJISmcmn6B5OUG+oS7xUYKB
kL00VJufelZZdOZ0sOnPWlKF39tmdhQDrgr9PG0q5fR2tSwyaRHXlAtABS/avQEE
05060ZO8JgXxF5m521KTELba0CFTe+SGEv1nv4d9z811gC106Z7Idt8jPDfLwJBB
6vc4I9ZfVFWyJzFO01QsUal/FzDHIRk3HR1186Rzy3nRvrRvEtrwvlHG2y9OtEZs
WrXFDcdEAO7MlnmpRe7N3GlxYcClRgUk6YWGzk0+OqW7fO8uClqfsh84S7Bn9Y94
bnGGQ56ncYVu4hm0XBhjSWsK2lQpTRgFgPkIh+bEagGww3rS7s+TuUO8Lwsfi2Hl
ZAjERVxbUr4fUVantBXEiGrP0Dr6NAPou4rlSbtgHbf949O/DHwoFSbe+FsqnIg1
gKZbolWtv2lW+Ol+qEwKmURI1ZCKQT/RysHEGMaW4fByzCw1jmN4GwD2HWuh28/1
tuWUJ+kCvTUqAYGFegEqiCMVTj1bmjH+EGof0SkMRnLtJXNhLIwpiFV+ROlv2TNK
R0ihbhePvRLfR9rWOkp+1UN+xgFeKbxEFJ8MOPqGD0FdWukngxJ/dS/oBtYq+V0K
bP4Pyw==
-----END CERTIFICATE-----
</cert>
# Client Key
<key>
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIJpDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIYiFMMREJCT0CAggA
MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECLm6bnbYcf1gBIIJUMrfL2VOB/rd
fSk74V0FZkJVsFhVEGZJ0jWM8n75cUO+yOB1wcXv9RczeEtW2e8ZU4LEb4aJZ7T3
RoGG2UxTsrkrN1Tw2sotuNIea2hT1+sTPbc74GJmZjf2BD2BIxpAS6VLkKGLoN11
c+1euUsLcs8Y1Y6T0Ig0aah9tUjp3qeA0pPMvmtWg2BjnmG6oU5FJnxOpuX/ItJi
vm38fMzApjh6vW6vxhD0sPdhanWdKilE+SPpe6sPCfHanVzVmP42NwMofoDrE5bP
CxMTJa2Pi6dA7qt+9HfeDfzOHsfCvlGAnwzumwKQx4O2BO+JQjC1V9WUEvo0zoHR
/+aHWZIF33pJmZJw0kIbC/WdG/SevK22BtcGy/+So1WRywkmtckP5oPcQ/ej+p0V
2bkgRGCfyehuoiBv8W7lCqvJDbdmSLBLrbSWhLHPfxfhW9Yqau3J2oUgQXel3G8F
9pECEQHVm3T54anPqEol96dYhP9inz2/BwFQqGaGrobJ+TOsh1DRAQpM8QMElWaZ
xjX5qcFk6O6Uf61uTOwcQnfxZD6vOhqHSmFJ4AQy6M2SBXM65Q1S3ZnRpWKJxXBg
jspgK2iWDwtoXHGFWpazBaIMd/PRmYmibOAZbCSfRvgfkTXE3+HeZwk7ZCwKBATY
u7oHxdcEaccuLiq0HXutTOjyKUk8ui33FkwI6i2v6bcsSDbj0RiGjPQmdxxZG2bO
yL1JKHMpj5sIS0ZjfSmoOK4u3bEd5TvShPplIVqf79SRUJEEOlqNxXTjkAdG2OXQ
GuNscbIMrvJ7zVyQgWjzfMS0PdSHpeHAqgVLxcjkDTFEHIssmzUSCq9sHVKAQX4h
IDyNJPHWwRnH4pfUGaS62zK2WCFM6GSolPtS5ZwJxgg7TRbKF7Z+ThW7n0MwHhZy
zJXKUL5fJurZYnLRgDzlVR3NsKkYg+Wwxy4k8NDGuYsx7zlQOfjoYe506ObxY9ih
YkQUX/s9AY2VZGWPypis+hZkJCVn7F9NMKOXVjDs4zMGWyhzRVoIwU0p10JqqRPI
k2V/UTYMkWseo1blIitT4ZEZQHVG+ciQsHQA/MBCBELQCl/NKGHjC0I9LRcFp5Sd
x6nTLCRb1i6Xqd1NRN/uF3BgJWJoPu+fBhRPF4ZI1YF+POaegKf80y3vbIMpaBUp
Ok/kS5L22NQvd0moHDKKbIu9H0q3WKokkipmi4cQZWslLO1ZGH3eoN+hyX1qHQOk
kr/bSRfYLdjFumXmw1t7HIu9I8sFnpyoJwVlC3I6zBYPysS3XRzQM4+sLcHR2Stw
9/ucvoLPuYI8Pyyk1WhFMLZtAjsDdRrlNgd3DcBbuR0ldCdMb7DQwj2LJDhaX0md
0E9xpwy415GQDYFkKAuOL5s1oTPbYBVqugErdfZMYU74BDrcxi6Bo2DfnmTF8/SR
0fhhihy5PboH+vsWT1CD4rHaxEFi0JnUQoMgFjUrdcfykz4Y7EPOAKOQ2I6XRhfF
fJfMi4c3iVa1NOd/4Kw6sh+/l1/XZxbdEwNd5CQ9Xa5WDQDglOqkf4Owkg9dYnTS
sfIX9NkQ9yV3n32UqYCDCIIlYnXfHo+cuFMqTwcVOi+acfag39aVSer5M7RUoeVu
JRcS+yOCRkIvm/SRt1XFVB4S1ZEseiSwjwdIvTtXr8bRzIpd3WF+q95qGYZLwISR
zc6WspL6d5Ll48yRntjV7lIgFt1bZB/Vj/U2c/+S5pIIXSPZyIuN8RYiL4IhZmxa
deMIB8Sx5ZriTn52vEUSje1dlolBr5xL+ifpG8IRSwa4GaRctBVrSNguTfx0ZKyQ
Ku+jdBiGFs1TcAec2Zlj2IGL+LkLuCF/ZaHQwkp7egG6tSXmpK6dk1VoUGb4HUXi
lwSJsW1kNj8nVvEvh8m1H7+UyI6y/jFUeuyisM5KV3UFOQNidKsmRBKaC2JlI3Zu
iKJ/jW2O2SwRMm44U2DgNjB05Jr22V/plKhUYFxhVB/1aBeoIywtij0BVY85/KZz
5Q2I3U33nyu5ewTfrT5essBcgKYJne+7s61yaGQeHjJCEbKNKtRtLkQ5vgdleWgg
LM29Oxr+3jjyB+dcIVe9EtYHZ/lF6ywuEeLH3RAdbmhPigt6rM0+MOnsIQOvjN9O
2DpGRvaBeA7acFPzmMJoKk3tQDh7tpJY4cgot9AvBt0US0XUvYSQf2In2S3ifSWU
9uz8otdB2rDf+OFU6L4xg5dTD8nqTHt9z7oUEeJWFz2C4qkZ4+10Czb3QRxj0OlB
isIkMh8k7kYQ4rtrZCbvkVjAJwnUQFI5zFBlo/8GfroOVFdFlx8kG3t0WAXJ9aX3
YnqUoMywxSAz8iBfN/sjv7rkgobozPlqEhGwEJ8hKBAf1HCwVegi5tmlXfXmLbSt
BWhKrJG98NwRApnWzFFvui4qiAGeXAsKx2/3w0An3sUwLJjUcfZNGsn/0wt56Hid
RP5Od59n1+UHWe1eMBhw6lZdvaVHostAj51kdGsuacr3tJN/g5Cko49NyJNI0k+U
/0+Lgxs8rUHHYe4SXeGR4Ri2YgVEJR3dqOPaiIiK4vg3wop8VLN4W+4PLqNFKDd6
RGn3yyS9CkR4Jqu3B5ezLCjwvTV+pcZ9UqlOUOK2O/diE5ro+2sj3zuw5rUUolwx
OQ9ex3m7JrqGadARhtc5ALPY4OmkbddIDL0ewc1PysMB5vATWMH149bmtKJSx5u9
tWnxzpFGpQu2YMyFMkNexbWHLMtZff7mXlwUk5NMgvnHQ+EdCaqj22zhQoRgL+us
SdL20wEBm+eEPgiWMSk1nmrgen1kU3gKRQzw7miqsSPnW+PSfJvxnbib2uuclHZS
8Sz56xwPksT2gNQvA6ir6ndeOAYJpMW3bQrQr8GLfiNDcUJ9cCNWJtfqZcBTxvvf
iHpLlNGBzwk5XDJuCJE1o6pkmF5fQMjBzpntre4df2kIbxuC8Fyu1TLnT9bgLywe
H8azR+2ZYDzSXtPYN+dOgNfH7AoCzLHczvMGLeCttzeUgvMPAesJK6BthIuJpxNV
01oaEQSrU49tiRgC89tgZs267MrIPnkUTlJoz/PW/wZ9f0RqnAfCMZLb7nj+p083
5v+d5g33xex9CZ2XUb051wdir7pamEUV0fpnCBAjRtjjb7PWMuOZjop7L23eMgbp
9obNF+BPYXYzLgSAioucrODoPEV2gYSi
-----END ENCRYPTED PRIVATE KEY-----
</key>
# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server". This is an
# important precaution to protect against
# a potential attack discussed here:
# http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server". The build-key-server
# script in the easy-rsa folder will do this.
#
# Note!
# The option "ns-cert-type" has been deprecated since
# version 2.4 and will be removed from later distributions.
#
# Use the modern equivalent "remote-cert-tls"
#
;ns-cert-type server
remote-cert-tls server
# If a tls-auth key is used on the server
# then every client must also have the key.
#
# Don't forget to set the 'key-direction' Parameter if using
# Inline Key. Usualy , sever has key direction '0', while client
# has ke direction '1'.
#
key-direction 1
<tls-auth>
-----BEGIN OpenVPN Static key V1-----
055e6b31c205ec1ace25b0ef1f0b3e80
e74c454b9136ba2a73e77af7d1a69e27
961a2792f86003c7e5477606511ab117
86a4c648a987b4aed406d30bcf5c32b4
da5405b247161f9f1cafcb82df78f63e
e2151005472f97c913ab994c2b2fc3b0
2c8e2b7d9b466a1f092f375f2a08f561
b8e0c6bd019a5e9b9bc821715287f279
ca56cdd6fcbb3fde55d44da9be2ec86a
b81e52bc44f7c92174795dc12f95a6c1
beeca15154a9c72872c3f205ccf601ea
c610bd2aa828e052febb747c02cfdf4a
959e9a86a01863bebb30ed8f79d13dae
f58e8dde86d46026a27de24e6db51348
1d395e5736eab696c653d1f68a972dc1
e47de0993b8b5d57ecab103e70c4874a
-----END OpenVPN Static key V1-----
</tls-auth>
# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
;cipher BF-CBC # Blowfish (default)
;cipher AES-128-CBC # AES
;cipher DES-EDE3-CBC # Triple-DES
cipher AES-256-CBC
# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
;comp-lzo
# Verbosity level.
# 0 -- quiet except for fatal errors.
# 1 -- mostly quiet, but display non-fatal network errors.
# 3 -- medium output, good for normal operation.
# 9 -- verbose, good for troubleshooting
verb 1
# Setting 'pull' on the client takes care to get the 'push' durectives
# from the server
pull