root@opnsense:/var/etc # less openvpn/client1.confdev ovpnc1verb 3dev-type tuntun-ipv6dev-node /dev/tun1writepid /var/run/openvpn_client1.pid#user nobody#group nobodyscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udpcipher AES-256-CBCauth SHA1up /usr/local/sbin/ovpn-linkupdown /usr/local/sbin/ovpn-linkdownlocal 192.168.178.2engine rdrandtls-clientclientlport 0management /var/etc/openvpn/client1.sock unixremote s1.4nv.de 1194ca /var/etc/openvpn/client1.ca cert /var/etc/openvpn/client1.cert key /var/etc/openvpn/client1.key tls-auth /var/etc/openvpn/client1.tls-auth 1comp-lzo adaptivepasstosresolv-retry infinitereneg-sec 0#fragment 1428 mssfix 1428
verb 3#verb 6proto udpport 1194dev vpn-s1dev-type tun# fragment 1428 # does not work with android# mssfixmssfix 1428keepalive 10 60passtosfast-io#compress lz4comp-lzo adaptive# testreneg-sec 7200tls-serverkey /etc/openvpn/........cert /etc/openvpn/........ca /etc/openvpn/........dh /etc/openvpn/........remote-cert-eku "TLS Web Client Authentication"cipher AES-256-CBCtls-auth /etc/openvpn/........ 0float # Allow remote peer to change its IP address and/or port number, such as due to DHCPtopology subnetserver 192.168.38.0 255.255.255.0client-config-dir /etc/openvpn/......../clientsroute 192.168.30.0 255.255.255.0route 192.168.31.0 255.255.255.0route 192.168.178.0 255.255.255.0client-to-clientpush "route 192.168.30.0 255.255.255.0"push "route 192.168.31.0 255.255.255.0"push "dhcp-option DNS 192.168.31.1"management localhost 7505