$wgDBname<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.cablefree.net/support/radio/software/index.php?action=history&amp;feed=atom&amp;title=Manual%3AInterface%2FOVPN</id>
	<title>Manual:Interface/OVPN - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.cablefree.net/support/radio/software/index.php?action=history&amp;feed=atom&amp;title=Manual%3AInterface%2FOVPN"/>
	<link rel="alternate" type="text/html" href="https://www.cablefree.net/support/radio/software/index.php?title=Manual:Interface/OVPN&amp;action=history"/>
	<updated>2026-06-13T12:40:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.37.3</generator>
	<entry>
		<id>https://www.cablefree.net/support/radio/software/index.php?title=Manual:Interface/OVPN&amp;diff=1276&amp;oldid=prev</id>
		<title>Administrator: /* Properties */</title>
		<link rel="alternate" type="text/html" href="https://www.cablefree.net/support/radio/software/index.php?title=Manual:Interface/OVPN&amp;diff=1276&amp;oldid=prev"/>
		<updated>2018-04-04T18:53:56Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Properties&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:53, 4 April 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l45&quot;&gt;Line 45:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 45:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|type=string {{!}} none&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|type=string {{!}} none&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|default=none&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|default=none&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|desc=Name of the client certificate imported into &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/del&gt;certificate list&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]]&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|desc=Name of the client certificate imported into certificate list.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;}}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;}}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
	<entry>
		<id>https://www.cablefree.net/support/radio/software/index.php?title=Manual:Interface/OVPN&amp;diff=1274&amp;oldid=prev</id>
		<title>Administrator: Created page with &quot;{{Versions|v5+}}   ==Summary==  &lt;p id=&quot;shbox&quot;&gt;&lt;b&gt;Standards:&lt;/b&gt; &lt;code&gt;&lt;/code&gt;&lt;br /&gt; &lt;b&gt;Package:&lt;/b&gt; &lt;code&gt;ppp&lt;/code&gt; &lt;/p&gt;   Currently unsupported OVPN feature: * UDP mode * LZ...&quot;</title>
		<link rel="alternate" type="text/html" href="https://www.cablefree.net/support/radio/software/index.php?title=Manual:Interface/OVPN&amp;diff=1274&amp;oldid=prev"/>
		<updated>2018-04-04T18:49:11Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Versions|v5+}}   ==Summary==  &amp;lt;p id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Standards:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;br /&amp;gt; &amp;lt;b&amp;gt;Package:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;ppp&amp;lt;/code&amp;gt; &amp;lt;/p&amp;gt;   Currently unsupported OVPN feature: * UDP mode * LZ...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Versions|v5+}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Summary==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Standards:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Package:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;ppp&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Currently unsupported OVPN feature:&lt;br /&gt;
* UDP mode&lt;br /&gt;
* LZO compression&lt;br /&gt;
* TLS authentication&lt;br /&gt;
* authentication without username/password&lt;br /&gt;
&lt;br /&gt;
==OVPN Client==&lt;br /&gt;
&amp;lt;p id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Sub-menu:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;/interface ovpn-client&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Properties===&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-h&lt;br /&gt;
|prop=Property&lt;br /&gt;
|desc=Description&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=add-default-route&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|default=no&lt;br /&gt;
|desc=Whether to add OVPN remote address as a default route.&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=auth&lt;br /&gt;
|type=md5 {{!}} sha1&lt;br /&gt;
|default=sha1&lt;br /&gt;
|desc=Allowed authentication methods.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=certificate&lt;br /&gt;
|type=string {{!}} none&lt;br /&gt;
|default=none&lt;br /&gt;
|desc=Name of the client certificate imported into [[certificate list]].&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=cipher&lt;br /&gt;
|type=aes128 {{!}} aes192 {{!}} aes256 {{!}} blowfish128&lt;br /&gt;
|default=blowfish128&lt;br /&gt;
|desc=Allowed ciphers.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=comment&lt;br /&gt;
|type=string&lt;br /&gt;
|default=&lt;br /&gt;
|desc=Descriptive name of an item&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=connect-to&lt;br /&gt;
|type=IP&lt;br /&gt;
|default=&lt;br /&gt;
|desc=Remote address of the OVPN server.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=disabled&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|default=yes&lt;br /&gt;
|desc=Whether interface is disabled or not. By default it is disabled.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=mac-address&lt;br /&gt;
|type=MAC&lt;br /&gt;
|default=&lt;br /&gt;
|desc=Mac address of OVPN interface. Will be auto generated if not specified.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=max-mtu&lt;br /&gt;
|type=integer&lt;br /&gt;
|default=1500&lt;br /&gt;
|desc=Maximum Transmission Unit. Max packet size that OVPN interface will be able to send without packet fragmentation.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=mode&lt;br /&gt;
|type=ip {{!}} ethernet&lt;br /&gt;
|default=ip&lt;br /&gt;
|desc=Layer3 or layer2 tunnel mode (alternatively tun, tap)&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=name&lt;br /&gt;
|type=string&lt;br /&gt;
|default=&lt;br /&gt;
|desc=Descriptive name of the interface.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=password&lt;br /&gt;
|type=string&lt;br /&gt;
|default=&amp;quot;&amp;quot;&lt;br /&gt;
|desc=Password used for authentication.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=port&lt;br /&gt;
|type=integer&lt;br /&gt;
|default=1194&lt;br /&gt;
|desc=Port to connect to.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=profile&lt;br /&gt;
|type=name&lt;br /&gt;
|default=default&lt;br /&gt;
|desc=Used [[Manual:PPP_AAA#User_Profiles | PPP profile]].&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-end&lt;br /&gt;
|arg=user&lt;br /&gt;
|type=string&lt;br /&gt;
|default=&lt;br /&gt;
|desc=User name used for authentication.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
===Quick example===&lt;br /&gt;
&lt;br /&gt;
This example demonstrates how to set up OVPN client with username &amp;quot;test&amp;quot;, password &amp;quot;123&amp;quot; and server 10.1.101.1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[admin@bumba] /interface ovpn-client&amp;gt; add connect-to=10.1.101.1 user=test password=123 disabled=no &lt;br /&gt;
[admin@bumba] /interface ovpn-client&amp;gt; print &lt;br /&gt;
Flags: X - disabled, R - running &lt;br /&gt;
 0    name=&amp;quot;ovpn-out1&amp;quot; mac-address=FE:7B:9C:F9:59:D0 max-mtu=1500 connect-to=10.1.101.1 &lt;br /&gt;
      port=1194 mode=ip user=&amp;quot;test&amp;quot; password=&amp;quot;123&amp;quot; profile=default certificate=none auth=sha1 &lt;br /&gt;
      cipher=blowfish128 add-default-route=no &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OVPN Server==&lt;br /&gt;
&amp;lt;p  id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Sub-menu:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;/interface ovpn-server&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This sub-menu shows interfaces for each connected OVPN clients. &lt;br /&gt;
&lt;br /&gt;
An interface is created for each tunnel established to the given server. There are two types of interfaces in OVPN server&amp;#039;s configuration &lt;br /&gt;
&amp;lt;ul class=&amp;quot;bullets&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; Static interfaces are added administratively if there is a need to reference the particular interface name (in firewall rules or elsewhere) created for the particular user. &lt;br /&gt;
&amp;lt;li&amp;gt;Dynamic interfaces are added to this list automatically whenever a user is connected and its username does not match any existing static entry (or in case the entry is active already, as there can not be two separate tunnel interfaces referenced by the same name). &lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
Dynamic interfaces appear when a user connects and disappear once the user disconnects, so it is impossible to reference the tunnel created for that use in router configuration (for example, in firewall), so if you need a persistent rule for that user, create a static entry for him/her. Otherwise it is safe to use dynamic configuration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Note | in both cases PPP users must be configured properly - static entries do not replace PPP configuration.}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Server configuration===&lt;br /&gt;
&amp;lt;p  id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Sub-menu:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;/interface ovpn-server server&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Properties:&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-h&lt;br /&gt;
|prop=Property&lt;br /&gt;
|desc=Description&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=auth&lt;br /&gt;
|type=sha1 {{!}} md5&lt;br /&gt;
|default=sha1,md5&lt;br /&gt;
|desc=Authentication methods that server will accept.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=certificate&lt;br /&gt;
|type=name {{!}} none&lt;br /&gt;
|default=none&lt;br /&gt;
|desc=Name of the certificate that OVPN server will use.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=cipher&lt;br /&gt;
|type=aes128 {{!}} aes192 {{!}} aes256 {{!}} blowfish128&lt;br /&gt;
|default=aes128,blowfish128&lt;br /&gt;
|desc=Allowed ciphers.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=default-profile&lt;br /&gt;
|type=name&lt;br /&gt;
|default=default&lt;br /&gt;
|desc=Default profile to use.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=enabled&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|default=no&lt;br /&gt;
|desc= Defines whether OVPN server is enabled or not.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=keepalive-timeout&lt;br /&gt;
|type=integer {{!}} disabled&lt;br /&gt;
|default=60&lt;br /&gt;
|desc=Defines the time period (in seconds) after which the router is starting to send keepalive packets every second. If no traffic and no keepalive responses has came for that period of time (i.e. 2 * keepalive-timeout), not responding client is proclaimed disconnected&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=mac-address&lt;br /&gt;
|type=MAC&lt;br /&gt;
|default=&lt;br /&gt;
|desc=Auto Generated MAC address of the server.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=max-mtu&lt;br /&gt;
|type=integer&lt;br /&gt;
|default=1500&lt;br /&gt;
|desc=Maximum Transmission Unit. Max packet size that OVPN interface will be able to send without packet fragmentation.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=mode&lt;br /&gt;
|type=ip {{!}} ethernet&lt;br /&gt;
|default=ip&lt;br /&gt;
|desc=Layer3 or layer2 tunnel mode (alternatively tun, tap)&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=netmask&lt;br /&gt;
|type=integer&lt;br /&gt;
|default=24&lt;br /&gt;
|desc=Subnet mask to be applied to client.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=port&lt;br /&gt;
|type=integer&lt;br /&gt;
|default=1194&lt;br /&gt;
|desc=Port to run server on.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-end&lt;br /&gt;
|arg=require-client-certificate&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|default=no&lt;br /&gt;
|desc=If set to yes, then server checks whether client&amp;#039;s certificate belongs to the same certificate chain.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[admin@bumba] /interface ovpn-server server set enabled=yes &lt;br /&gt;
[admin@bumba] /interface ovpn-server server set certificate=server &lt;br /&gt;
[admin@bumba] /interface ovpn-server server print &lt;br /&gt;
                     enabled: yes&lt;br /&gt;
                        port: 1194&lt;br /&gt;
                        mode: ip&lt;br /&gt;
                     netmask: 24&lt;br /&gt;
                 mac-address: FE:A5:57:72:9D:EC&lt;br /&gt;
                     max-mtu: 1500&lt;br /&gt;
           keepalive-timeout: 60&lt;br /&gt;
             default-profile: default&lt;br /&gt;
                 certificate: server&lt;br /&gt;
  require-client-certificate: no&lt;br /&gt;
                        auth: sha1,md5&lt;br /&gt;
                      cipher: blowfish128,aes128&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Warning | &lt;br /&gt;
It is very important that the date on the router is within the range of the installed certificate&amp;#039;s date of expiration.  To overcome any certificate verification problems, enable &amp;lt;b&amp;gt;NTP&amp;lt;/b&amp;gt; date synchronization on both server and client.}}&lt;br /&gt;
&lt;br /&gt;
==Monitoring==&lt;br /&gt;
Monitor command can be used to monitor the status of the tunnel on both client and server.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[admin@dzeltenais_burkaans] /interface ovpn-server monitor 0&lt;br /&gt;
     status: &amp;quot;connected&amp;quot;&lt;br /&gt;
     uptime: 17m47s&lt;br /&gt;
  idle-time: 17m47s&lt;br /&gt;
       user: &amp;quot;test&amp;quot;&lt;br /&gt;
  caller-id: &amp;quot;10.1.101.18:43886&amp;quot;&lt;br /&gt;
        mtu: 1500&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Read-only properties&amp;lt;/b&amp;gt;&lt;br /&gt;
{{Mr-arg-table-h&lt;br /&gt;
|prop=Property&lt;br /&gt;
|desc=Description&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=status&lt;br /&gt;
|type=&lt;br /&gt;
|desc=Current status. Value other than &amp;quot;connected&amp;quot; indicates that there are some problems establishing tunnel.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=uptime&lt;br /&gt;
|type=time&lt;br /&gt;
|desc=Elapsed time since tunnel was established.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=idle-time&lt;br /&gt;
|type=time&lt;br /&gt;
|desc=Elapsed time since last activity on the tunnel.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=user&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=Username used to establish the tunnel.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=mtu&lt;br /&gt;
|type=integer&lt;br /&gt;
|desc=Negotiated and used MTU&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table-end&lt;br /&gt;
|arg=caller-id&lt;br /&gt;
|type=IP:ID&lt;br /&gt;
|desc=Source IP and Port of client.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Application Examples==&lt;br /&gt;
&lt;br /&gt;
====Setup Overview====&lt;br /&gt;
&lt;br /&gt;
[[file:ipsec-road-warrior.png]]&lt;br /&gt;
&lt;br /&gt;
Assume that Office public IP address is 2.2.2.2 and we want two remote OVPN clients to have access to 10.5.8.20 and 192.168.55.0/24 networks behind office gateway.&lt;br /&gt;
&lt;br /&gt;
====Creating Certificates====&lt;br /&gt;
All certificates can be created on RadioOS server using certificate manager. [[M:Create_Certificates#Generate_certificates_on_RadioOS | See example &amp;gt;&amp;gt;]].&lt;br /&gt;
&lt;br /&gt;
For simplest setup you need only ovpn server certificate.&lt;br /&gt;
&lt;br /&gt;
====Server Config====&lt;br /&gt;
&lt;br /&gt;
First step is to create ip pool from which client addresses will be assigned and some users&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/ip pool add name=ovpn-pool range=192.168.77.2-192.168.77.254&lt;br /&gt;
&lt;br /&gt;
/ppp profile add name=ovpn local-address=192.168.77.1 remote-address=ovpn-pool&lt;br /&gt;
/ppp secret&lt;br /&gt;
  add name=client1 password=123 profile=ovpn&lt;br /&gt;
  add name=client2 password=234 profile=ovpn&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Assume that server certificate is already created and named &amp;quot;server&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface ovpn-server server set enabled=yes certificate=server&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Client Config====&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;RadioOS client&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
Since RadioOS does not support route-push you need to add manually which networks you want to access over the tunnel.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/interface ovpn-client&lt;br /&gt;
  add name=ovpn-client1 connect-to=2.2.2.2 user=client1 password=123 disabled=no&lt;br /&gt;
/ip route &lt;br /&gt;
  add dst-address=10.5.8.20 gateway=ovpn-client1&lt;br /&gt;
  add dst-address=192.168.55.0/24 gateway=ovpn-client1&lt;br /&gt;
/ip firewall nat add chain=srcnat action=masquerade out-interface=ovpn-client1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Linux Client config&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dev tun&lt;br /&gt;
proto tcp-client&lt;br /&gt;
&lt;br /&gt;
remote 2.2.2.2 1194&lt;br /&gt;
&lt;br /&gt;
tls-client&lt;br /&gt;
&lt;br /&gt;
user nobody&lt;br /&gt;
group nogroup&lt;br /&gt;
&lt;br /&gt;
#comp-lzo # Do not use compression.&lt;br /&gt;
&lt;br /&gt;
# More reliable detection when a system loses its connection.&lt;br /&gt;
ping 15&lt;br /&gt;
ping-restart 45&lt;br /&gt;
ping-timer-rem&lt;br /&gt;
persist-tun&lt;br /&gt;
persist-key&lt;br /&gt;
&lt;br /&gt;
mute-replay-warnings&lt;br /&gt;
&lt;br /&gt;
verb 3&lt;br /&gt;
&lt;br /&gt;
cipher BF-CBC&lt;br /&gt;
auth SHA1&lt;br /&gt;
pull&lt;br /&gt;
&lt;br /&gt;
auth-user-pass auth.cfg &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The file auth.cfg holds your username/password combination. On the first line must be the username and on the second line your password.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
client2&lt;br /&gt;
234&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Cont}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Manual|O]]&lt;br /&gt;
[[Category:VPN|O]]&lt;br /&gt;
[[Category:Interface|O]]&lt;/div&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
</feed>