tests: use generated networks and lint hard-coded addresses

Convert every test to REQ-GEN-TEST-010. Addresses configured on an
interface come from random-vpnnet.sh: templates use @VPNNET_BASE@ and
friends, keeping the original netmask and route formats; the vhost
tests allocate a distinct network per vhost with alloc_vpnnet4; the
firewall tests take the address of the blocked host from one; and the
RADIUS users file becomes a template materialized per test with
update_raddb(), so the tests no longer pin VPNNET to fixed ranges.
Addresses that are only data (routes, no-routes, iroutes, DNS servers,
Framed-Route, the pools of tests without a TUN device) move to
documentation ranges, keeping distinct networks distinct, and the
assertions follow; multiple-routes pushes 256 distinct routes, taken
from 198.18.0.0/15.

Add tests/check-test-addresses.py, run by the test-addresses-check job
in the preliminaries CI stage, which rejects any literal address outside
the ranges REQ-GEN-TEST-010 allows.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
This commit is contained in:
Nikos Mavrogiannopoulos
2026-09-29 21:48:14 +02:00
parent 1e06cd36e0
commit 2d240e02d3
170 changed files with 856 additions and 646 deletions
+8
View File
@@ -32,6 +32,14 @@ config-scope-check:
- tags
- schedules
test-addresses-check:
stage: preliminaries
script:
- python3 tests/check-test-addresses.py
except:
- tags
- schedules
Signoff:
stage: preliminaries
script:
+2 -1
View File
@@ -208,7 +208,8 @@ DISABLE_ASAN_BROKEN_TESTS=1 # Skip ldpreload-based tests (incompatible with ASA
more (`@NAME@`, `@NAME_BASE@`, `@NAME_ADDR@`). Tests using `ns.sh` source `random-net.sh`
(and `random-net2.sh`) instead. Addresses configured on an interface MUST come from
these; routes, DNS and other data-only addresses MUST use documentation ranges
(192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24, 2001:db8::/32) (**REQ-GEN-TEST-010**)
(192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24, 2001:db8::/32). Enforced by
`tests/check-test-addresses.py` (**REQ-GEN-TEST-010**)
- `tests/certs/` — Test certificates and keys
- `tests/common.sh` — Shared utilities (requires the `openconnect` client)
- `tests/*.c` — Unit tests for specific components
+18 -11
View File
@@ -10,6 +10,7 @@ sources:
- tests/random-vpnnet.sh
- tests/random-net.sh
- tests/random-net2.sh
- tests/check-test-addresses.py
- .gitlab-ci.yml
- meson_options.txt
---
@@ -219,9 +220,10 @@ a literal absolute path, username, or port baked in by the test author.
The same applies to a per-user or per-group configuration directory
(`config-per-user`, `config-per-group`): its files MUST live under
`tests/data/<dir>/` and be materialized with `update_config_dir <dir>`,
which applies the same substitution to every file and sets `CONFIG_DIR`
(referenced from the server config as `@CONFIG_DIR@`). A test using
FreeRADIUS MUST call `update_raddb` before starting `radiusd`: it copies
which applies the same substitution to every file and sets
`CONFIG_PER_USER_DIR` (referenced from the server config as
`@CONFIG_PER_USER_DIR@`). A test using FreeRADIUS MUST call `update_raddb`
before starting `radiusd`: it copies
`$RADDB_DIR` into a private directory, applies the same substitution to its
`users` file, removes group and world write permission (which FreeRADIUS
requires), and points `RADDB_DIR` at the copy, which the test removes on
@@ -328,17 +330,22 @@ netmasks and prefix lengths; IPv6 link-local addresses (`fe80::/10`),
which are scoped to one interface and cannot collide; C unit tests
(`tests/*.c`), and shell tests whose addresses are only input data to the
script under test (`tests/test-fw-normalize-route`,
`tests/test-fw-script`); and tests that existed when this requirement was
introduced, which are to be converted separately.
`tests/test-fw-script`).
**Strength:** MUST / MUST NOT
**Status:** DERIVED
**Source:** `tests/random-vpnnet.sh`, `tests/random-net.sh`;
`tests/test-ipv4-p2p` as the reference
**Source:** `tests/random-vpnnet.sh`, `tests/random-net.sh`,
`tests/check-test-addresses.py`; `tests/test-ipv4-p2p` as the reference
consumer; maintainer decision recorded with this requirement.
**Acceptance:** code-review — grep the test, its `tests/data/` template
and its per-user/per-group templates for IPv4 and IPv6 literals: every
match MUST be in a documentation range and data only (class (b)), or out
of scope; a class (a) value in a documentation range is a finding. local — run
**Acceptance:** CI — `tests/check-test-addresses.py`, run by the
`test-addresses-check` job in the `preliminaries` stage of
`.gitlab-ci.yml`, scans every file under `tests/` except C sources,
certificates and the out-of-scope files above, reports each literal outside
the allowed ranges as `file:line: literal`, and passes. local, negative —
add an untracked file under `tests/` containing `VPNNET=192.168.7.0/24` and
confirm the check prints `tests/<file>:<line>: 192.168.7.0` and exits 1.
code-review — for each literal the check accepts
because it is in a documentation range, confirm it is data only (class
(b)); a class (a) value in a documentation range is a finding. local — run
a converted test twice and confirm from its printed banner that different
networks were used and both runs pass.
**Links:** REQ-GEN-TEST-008, REQ-GEN-TEST-011
+1 -1
View File
@@ -21,11 +21,11 @@
SERV="${SERV:-../src/ocserv}"
srcdir=${srcdir:-.}
builddir=${builddir:-.}
VPNNET=172.23.115.0/24
TMPFILE=ios.$$.tmp
VERBOSE=1
. `dirname $0`/common.sh
. `dirname $0`/random-vpnnet.sh
eval "${GETPORT}"
+1
View File
@@ -28,6 +28,7 @@ PIDFILE=ocserv-pid.$$.tmp
BANNER="Welcome%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%All"
. `dirname $0`/common.sh
. `dirname $0`/random-vpnnet.sh
eval "${GETPORT}"
+146
View File
@@ -0,0 +1,146 @@
#!/usr/bin/env python3
"""
Check that tests do not hard-code IP addresses or networks
(REQ-GEN-TEST-010).
A test must take any network or address configured on an interface from
tests/random-vpnnet.sh (via @VPNNET@-style placeholders or variables), and
must use documentation ranges for addresses that are only data (routes,
DNS servers, pools of tests that create no TUN device). This script scans
the tracked files under tests/ and reports every IPv4/IPv6 literal outside
the allowed ranges below.
Exit code: 0 on success, 1 if any errors are found.
"""
import ipaddress
import re
import subprocess
import sys
from pathlib import Path
ALLOWED_NETWORKS = [
ipaddress.ip_network(n)
for n in (
# documentation ranges (RFC 5737, RFC 3849)
"192.0.2.0/24",
"198.51.100.0/24",
"203.0.113.0/24",
"2001:db8::/32",
# benchmarking range (RFC 2544), for prefixes shorter than /24
"198.18.0.0/15",
# loopback, used by socket_wrapper and local listeners
"127.0.0.0/8",
"::1/128",
# socket_wrapper's IPv6 interface addresses (FD00::5357:5FXX)
"fd00::5357:5f00/120",
# link-local IPv6 is scoped to the interface and cannot collide
"fe80::/10",
# 2000::/3, sent by ocserv itself as the IPv6 default route of
# Apple clients (src/worker-vpn.c)
"2000::/128",
)
]
# Files whose addresses are input data to the script under test rather
# than networks configured by the test (REQ-GEN-TEST-010, out of scope).
EXEMPT = {
"tests/test-fw-normalize-route",
"tests/test-fw-script",
}
SKIP_SUFFIXES = {
".c", ".h", ".py", ".md", ".txt", ".supp", ".pem", ".der", ".crl",
".key", ".p12", ".csr", ".tmpl", ".json",
}
SKIP_NAMES = {"meson.build"}
IPV4_RE = re.compile(r"(?<![\w.])(\d{1,3}(?:\.\d{1,3}){3})(?![\w.])")
IPV6_RE = re.compile(r"(?<![\w:])([0-9A-Fa-f]{0,4}(?::[0-9A-Fa-f]{0,4}){2,7})(?![\w:])")
def is_netmask(addr):
"""True for contiguous IPv4 netmasks such as 255.255.255.0."""
if addr.version != 4:
return False
value = int(addr)
inverted = ~value & 0xFFFFFFFF
return inverted & (inverted + 1) == 0
def offending(literal):
try:
addr = ipaddress.ip_address(literal)
except ValueError:
return False
if addr.is_unspecified or is_netmask(addr):
return False
return not any(addr in net for net in ALLOWED_NETWORKS
if net.version == addr.version)
def candidate_files(root):
try:
out = subprocess.run(["git", "ls-files", "--cached", "--others",
"--exclude-standard", "tests"], cwd=root,
capture_output=True, text=True,
check=True).stdout
return out.splitlines()
except (OSError, subprocess.CalledProcessError):
# no git, or git refusing the checkout (e.g., dubious ownership in CI)
return [str(p.relative_to(root)) for p in (root / "tests").rglob("*")
if p.is_file()]
def scanned_files(root):
for name in candidate_files(root):
path = Path(name)
if path.suffix in SKIP_SUFFIXES or path.name in SKIP_NAMES:
continue
if path.parts[:2] == ("tests", "certs"):
continue
if name in EXEMPT:
continue
yield name
def check_file(root, name):
errors = []
try:
text = (root / name).read_text()
except UnicodeDecodeError:
return errors
for lineno, line in enumerate(text.splitlines(), 1):
stripped = line.lstrip()
if stripped.startswith("#") or stripped.startswith(";"):
continue
if re.search(r"oid\s*=", line, re.IGNORECASE):
continue
# addresses inside regular expressions, e.g. grep "1\.2\.3\.4"
line = line.replace("\\.", ".")
for regex in (IPV4_RE, IPV6_RE):
for m in regex.finditer(line):
if offending(m.group(1)):
errors.append(f"{name}:{lineno}: {m.group(1)}")
return errors
def main():
root = Path(__file__).resolve().parent.parent
failures = []
for name in scanned_files(root):
failures.extend(check_file(root, name))
if failures:
print("Hard-coded addresses in tests (REQ-GEN-TEST-010): use "
"random-vpnnet.sh placeholders for networks configured on an "
"interface, or documentation ranges (192.0.2.0/24, "
"198.51.100.0/24, 203.0.113.0/24, 2001:db8::/32) for data.")
for f in failures:
print(f" {f}")
return 1
return 0
if __name__ == "__main__":
sys.exit(main())
+4 -4
View File
@@ -115,7 +115,7 @@ _subst_placeholders() {
-e 's|@MATCH_CIPHERS@|'${MATCH_CIPHERS}'|g' \
-e 's|@OCCTL_SOCKET@|'${OCCTL_SOCKET}'|g' \
-e 's|@LISTEN_NS@|'${LISTEN_NS}'|g' \
-e 's|@CONFIG_DIR@|'${CONFIG_DIR}'|g' \
-e 's|@CONFIG_PER_USER_DIR@|'${CONFIG_PER_USER_DIR}'|g' \
-e 's|@RADIUSCLIENT_DIR@|'${RADIUSCLIENT_DIR}'|g' "$1"
}
@@ -128,8 +128,8 @@ update_config() {
}
# update_config_dir DIR: materializes the per-user or per-group config
# directory tests/data/DIR into $CONFIG_DIR; call it before update_config
# so that @CONFIG_DIR@ in the server config resolves.
# directory tests/data/DIR into $CONFIG_PER_USER_DIR; call it before
# update_config so that @CONFIG_PER_USER_DIR@ in the server config resolves.
update_config_dir() {
dir=$1
rm -rf "$dir.$$.tmp"
@@ -137,7 +137,7 @@ update_config_dir() {
for f in "$dir.$$.tmp"/*; do
_subst_placeholders "$f"
done
CONFIG_DIR="$(pwd)/$dir.$$.tmp"
CONFIG_PER_USER_DIR="$(pwd)/$dir.$$.tmp"
}
# update_raddb: gives this test a private copy of the FreeRADIUS directory
+9 -8
View File
@@ -20,22 +20,23 @@ verify_env_set "USER_AGENT"
verify_env_set "DEVICE_PLATFORM"
verify_env_set "DEVICE_TYPE"
# VPNNET_BASE is exported by the test (test-pass-script) to ocserv
case "$REASON" in
connect)
verify_env_set "DEVICE"
test "${OCSERV_DNS}" = "192.168.1.1 192.168.5.1 " && \
test "${OCSERV_DNS4}" = "192.168.1.1 192.168.5.1 " && \
test "${OCSERV_ROUTES}" = "192.168.1.0/255.255.255.0 192.168.5.0/255.255.255.0 " && \
test "${OCSERV_ROUTES4}" = "192.168.1.0/255.255.255.0 192.168.5.0/255.255.255.0 " && \
test "${OCSERV_DNS}" = "${VPNNET_BASE}.1 203.0.113.1 " && \
test "${OCSERV_DNS4}" = "${VPNNET_BASE}.1 203.0.113.1 " && \
test "${OCSERV_ROUTES}" = "${VPNNET_BASE}.0/255.255.255.0 203.0.113.0/255.255.255.0 " && \
test "${OCSERV_ROUTES4}" = "${VPNNET_BASE}.0/255.255.255.0 203.0.113.0/255.255.255.0 " && \
echo "${IP_REMOTE}" > ${builddir}/connect.ok
;;
disconnect)
if ! test -z "$DEVICE";then
test "${OCSERV_DNS}" = "192.168.1.1 192.168.5.1 " && \
test "${OCSERV_DNS4}" = "192.168.1.1 192.168.5.1 " && \
test "${OCSERV_ROUTES}" = "192.168.1.0/255.255.255.0 192.168.5.0/255.255.255.0 " && \
test "${OCSERV_ROUTES4}" = "192.168.1.0/255.255.255.0 192.168.5.0/255.255.255.0 " && \
test "${OCSERV_DNS}" = "${VPNNET_BASE}.1 203.0.113.1 " && \
test "${OCSERV_DNS4}" = "${VPNNET_BASE}.1 203.0.113.1 " && \
test "${OCSERV_ROUTES}" = "${VPNNET_BASE}.0/255.255.255.0 203.0.113.0/255.255.255.0 " && \
test "${OCSERV_ROUTES4}" = "${VPNNET_BASE}.0/255.255.255.0 203.0.113.0/255.255.255.0 " && \
echo "${IP_REMOTE}" > ${builddir}/disconnect.ok
fi
;;
+1 -1
View File
@@ -148,7 +148,7 @@ ipv4-network = @VPNNET@
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
ipv6-network = fd69:7016:8d15:b5a5::/64
ipv6-network = @VPNNET6@
#ipv6-mask =
#ipv6-dns =
+1 -1
View File
@@ -41,7 +41,7 @@ device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ipv6-network = @VPNNET6@
+1 -1
View File
@@ -141,7 +141,7 @@ ipv4-network = @VPNNET@
ipv6-network = @VPNNET6@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -141,7 +141,7 @@ ipv4-network = @VPNNET@
ipv6-network = @VPNNET6@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -137,7 +137,7 @@ ipv4-network = @VPNNET@
ipv6-network = @VPNNET6@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -22,5 +22,5 @@ run-as-group = @GROUP@
device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ping-leases = false
+4 -4
View File
@@ -143,7 +143,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -159,7 +159,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
@@ -193,7 +193,7 @@ ca-cert = @SRCDIR@/certs/ca.pem
server-cert = @SRCDIR@/certs/server-cert-secp521r1.pem
server-key = @SRCDIR@/certs/server-key-secp521r1.pem
ipv4-network = 192.168.2.0
ipv4-network = @VPNNET2_BASE@.0
ipv4-netmask = 255.255.255.0
cert-user-oid = 0.9.2342.19200300.100.1.1
@@ -206,4 +206,4 @@ ca-cert = @SRCDIR@/certs/ca.pem
server-cert = @SRCDIR@/certs/server-cert-secp521r1.pem
server-key = @SRCDIR@/certs/server-key-secp521r1.pem
ipv4-network = 192.168.3.0/24
ipv4-network = @VPNNET3@
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -1 +1 @@
no-route = 192.168.98.0/24
no-route = 198.51.100.0/24
+2 -2
View File
@@ -1,2 +1,2 @@
route = 1.1.1.0/24
ipv4-dns = 1.1.1.1
route = 203.0.113.0/24
ipv4-dns = 203.0.113.1
+2 -2
View File
@@ -1,2 +1,2 @@
route = 1.1.1.0/24
ipv4-dns = 1.1.1.1
route = 203.0.113.0/24
ipv4-dns = 203.0.113.1
+2 -2
View File
@@ -141,7 +141,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -157,7 +157,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+2 -2
View File
@@ -147,7 +147,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -163,7 +163,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1 -1
View File
@@ -160,4 +160,4 @@ ping-leases = false
# should be set for them.
#always-require-cert = false
route = fd63:5c2c:462c:26c2:5ca:d418::/96
route = 2001:db8:d418::/96
+2 -2
View File
@@ -241,9 +241,9 @@ ping-leases = false
#
# To set the server as the default gateway for the client just
# comment out all routes from the server.
route = 10.209.209.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = fc13:71:ea31:4b4e::/64
route = 2001:db8:4b4e::/64
# Configuration files that will be applied per user connection or
# per group. Each file name on these directories must match the username
+259 -259
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.5.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.5.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,260 +154,260 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
no-route = 192.168.98.0/255.255.255.0
route = 10.10.0.0/24
route = 10.10.1.0/24
route = 10.10.2.0/24
route = 10.10.3.0/24
route = 10.10.4.0/24
route = 10.10.5.0/24
route = 10.10.6.0/24
route = 10.10.7.0/24
route = 10.10.8.0/24
route = 10.10.9.0/24
route = 10.10.10.0/24
route = 10.10.11.0/24
route = 10.10.12.0/24
route = 10.10.13.0/24
route = 10.10.14.0/24
route = 10.10.15.0/24
route = 10.10.16.0/24
route = 10.10.17.0/24
route = 10.10.18.0/24
route = 10.10.19.0/24
route = 10.10.20.0/24
route = 10.10.21.0/24
route = 10.10.22.0/24
route = 10.10.23.0/24
route = 10.10.24.0/24
route = 10.10.25.0/24
route = 10.10.26.0/24
route = 10.10.27.0/24
route = 10.10.28.0/24
route = 10.10.29.0/24
route = 10.10.30.0/24
route = 10.10.31.0/24
route = 10.10.32.0/24
route = 10.10.33.0/24
route = 10.10.34.0/24
route = 10.10.35.0/24
route = 10.10.36.0/24
route = 10.10.37.0/24
route = 10.10.38.0/24
route = 10.10.39.0/24
route = 10.10.40.0/24
route = 10.10.41.0/24
route = 10.10.42.0/24
route = 10.10.43.0/24
route = 10.10.44.0/24
route = 10.10.45.0/24
route = 10.10.46.0/24
route = 10.10.47.0/24
route = 10.10.48.0/24
route = 10.10.49.0/24
route = 10.10.50.0/24
route = 10.10.51.0/24
route = 10.10.52.0/24
route = 10.10.53.0/24
route = 10.10.54.0/24
route = 10.10.55.0/24
route = 10.10.56.0/24
route = 10.10.57.0/24
route = 10.10.58.0/24
route = 10.10.59.0/24
route = 10.10.60.0/24
route = 10.10.61.0/24
route = 10.10.62.0/24
route = 10.10.63.0/24
route = 10.10.64.0/24
route = 10.10.65.0/24
route = 10.10.66.0/24
route = 10.10.67.0/24
route = 10.10.68.0/24
route = 10.10.69.0/24
route = 10.10.70.0/24
route = 10.10.71.0/24
route = 10.10.72.0/24
route = 10.10.73.0/24
route = 10.10.74.0/24
route = 10.10.75.0/24
route = 10.10.76.0/24
route = 10.10.77.0/24
route = 10.10.78.0/24
route = 10.10.79.0/24
route = 10.10.80.0/24
route = 10.10.81.0/24
route = 10.10.82.0/24
route = 10.10.83.0/24
route = 10.10.84.0/24
route = 10.10.85.0/24
route = 10.10.86.0/24
route = 10.10.87.0/24
route = 10.10.88.0/24
route = 10.10.89.0/24
route = 10.10.90.0/24
route = 10.10.91.0/24
route = 10.10.92.0/24
route = 10.10.93.0/24
route = 10.10.94.0/24
route = 10.10.95.0/24
route = 10.10.96.0/24
route = 10.10.97.0/24
route = 10.10.98.0/24
route = 10.10.99.0/24
route = 10.10.100.0/24
route = 10.10.101.0/24
route = 10.10.102.0/24
route = 10.10.103.0/24
route = 10.10.104.0/24
route = 10.10.105.0/24
route = 10.10.106.0/24
route = 10.10.107.0/24
route = 10.10.108.0/24
route = 10.10.109.0/24
route = 10.10.110.0/24
route = 10.10.111.0/24
route = 10.10.112.0/24
route = 10.10.113.0/24
route = 10.10.114.0/24
route = 10.10.115.0/24
route = 10.10.116.0/24
route = 10.10.117.0/24
route = 10.10.118.0/24
route = 10.10.119.0/24
route = 10.10.120.0/24
route = 10.10.121.0/24
route = 10.10.122.0/24
route = 10.10.123.0/24
route = 10.10.124.0/24
route = 10.10.125.0/24
route = 10.10.126.0/24
route = 10.10.127.0/24
route = 10.10.128.0/24
route = 10.10.129.0/24
route = 10.10.130.0/24
route = 10.10.131.0/24
route = 10.10.132.0/24
route = 10.10.133.0/24
route = 10.10.134.0/24
route = 10.10.135.0/24
route = 10.10.136.0/24
route = 10.10.137.0/24
route = 10.10.138.0/24
route = 10.10.139.0/24
route = 10.10.140.0/24
route = 10.10.141.0/24
route = 10.10.142.0/24
route = 10.10.143.0/24
route = 10.10.144.0/24
route = 10.10.145.0/24
route = 10.10.146.0/24
route = 10.10.147.0/24
route = 10.10.148.0/24
route = 10.10.149.0/24
route = 10.10.150.0/24
route = 10.10.151.0/24
route = 10.10.152.0/24
route = 10.10.153.0/24
route = 10.10.154.0/24
route = 10.10.155.0/24
route = 10.10.156.0/24
route = 10.10.157.0/24
route = 10.10.158.0/24
route = 10.10.159.0/24
route = 10.10.160.0/24
route = 10.10.161.0/24
route = 10.10.162.0/24
route = 10.10.163.0/24
route = 10.10.164.0/24
route = 10.10.165.0/24
route = 10.10.166.0/24
route = 10.10.167.0/24
route = 10.10.168.0/24
route = 10.10.169.0/24
route = 10.10.170.0/24
route = 10.10.171.0/24
route = 10.10.172.0/24
route = 10.10.173.0/24
route = 10.10.174.0/24
route = 10.10.175.0/24
route = 10.10.176.0/24
route = 10.10.177.0/24
route = 10.10.178.0/24
route = 10.10.179.0/24
route = 10.10.180.0/24
route = 10.10.181.0/24
route = 10.10.182.0/24
route = 10.10.183.0/24
route = 10.10.184.0/24
route = 10.10.185.0/24
route = 10.10.186.0/24
route = 10.10.187.0/24
route = 10.10.188.0/24
route = 10.10.189.0/24
route = 10.10.190.0/24
route = 10.10.191.0/24
route = 10.10.192.0/24
route = 10.10.193.0/24
route = 10.10.194.0/24
route = 10.10.195.0/24
route = 10.10.196.0/24
route = 10.10.197.0/24
route = 10.10.198.0/24
route = 10.10.199.0/24
route = 10.10.200.0/24
route = 10.10.201.0/24
route = 10.10.202.0/24
route = 10.10.203.0/24
route = 10.10.204.0/24
route = 10.10.205.0/24
route = 10.10.206.0/24
route = 10.10.207.0/24
route = 10.10.208.0/24
route = 10.10.209.0/24
route = 10.10.210.0/24
route = 10.10.211.0/24
route = 10.10.212.0/24
route = 10.10.213.0/24
route = 10.10.214.0/24
route = 10.10.215.0/24
route = 10.10.216.0/24
route = 10.10.217.0/24
route = 10.10.218.0/24
route = 10.10.219.0/24
route = 10.10.220.0/24
route = 10.10.221.0/24
route = 10.10.222.0/24
route = 10.10.223.0/24
route = 10.10.224.0/24
route = 10.10.225.0/24
route = 10.10.226.0/24
route = 10.10.227.0/24
route = 10.10.228.0/24
route = 10.10.229.0/24
route = 10.10.230.0/24
route = 10.10.231.0/24
route = 10.10.232.0/24
route = 10.10.233.0/24
route = 10.10.234.0/24
route = 10.10.235.0/24
route = 10.10.236.0/24
route = 10.10.237.0/24
route = 10.10.238.0/24
route = 10.10.239.0/24
route = 10.10.240.0/24
route = 10.10.241.0/24
route = 10.10.242.0/24
route = 10.10.243.0/24
route = 10.10.244.0/24
route = 10.10.245.0/24
route = 10.10.246.0/24
route = 10.10.247.0/24
route = 10.10.248.0/24
route = 10.10.249.0/24
route = 10.10.250.0/24
route = 10.10.251.0/24
route = 10.10.252.0/24
route = 10.10.253.0/24
route = 10.10.254.0/24
route = 10.10.255.0/24
no-route = 198.51.100.0/255.255.255.0
route = 198.18.0.0/24
route = 198.18.1.0/24
route = 198.18.2.0/24
route = 198.18.3.0/24
route = 198.18.4.0/24
route = 198.18.5.0/24
route = 198.18.6.0/24
route = 198.18.7.0/24
route = 198.18.8.0/24
route = 198.18.9.0/24
route = 198.18.10.0/24
route = 198.18.11.0/24
route = 198.18.12.0/24
route = 198.18.13.0/24
route = 198.18.14.0/24
route = 198.18.15.0/24
route = 198.18.16.0/24
route = 198.18.17.0/24
route = 198.18.18.0/24
route = 198.18.19.0/24
route = 198.18.20.0/24
route = 198.18.21.0/24
route = 198.18.22.0/24
route = 198.18.23.0/24
route = 198.18.24.0/24
route = 198.18.25.0/24
route = 198.18.26.0/24
route = 198.18.27.0/24
route = 198.18.28.0/24
route = 198.18.29.0/24
route = 198.18.30.0/24
route = 198.18.31.0/24
route = 198.18.32.0/24
route = 198.18.33.0/24
route = 198.18.34.0/24
route = 198.18.35.0/24
route = 198.18.36.0/24
route = 198.18.37.0/24
route = 198.18.38.0/24
route = 198.18.39.0/24
route = 198.18.40.0/24
route = 198.18.41.0/24
route = 198.18.42.0/24
route = 198.18.43.0/24
route = 198.18.44.0/24
route = 198.18.45.0/24
route = 198.18.46.0/24
route = 198.18.47.0/24
route = 198.18.48.0/24
route = 198.18.49.0/24
route = 198.18.50.0/24
route = 198.18.51.0/24
route = 198.18.52.0/24
route = 198.18.53.0/24
route = 198.18.54.0/24
route = 198.18.55.0/24
route = 198.18.56.0/24
route = 198.18.57.0/24
route = 198.18.58.0/24
route = 198.18.59.0/24
route = 198.18.60.0/24
route = 198.18.61.0/24
route = 198.18.62.0/24
route = 198.18.63.0/24
route = 198.18.64.0/24
route = 198.18.65.0/24
route = 198.18.66.0/24
route = 198.18.67.0/24
route = 198.18.68.0/24
route = 198.18.69.0/24
route = 198.18.70.0/24
route = 198.18.71.0/24
route = 198.18.72.0/24
route = 198.18.73.0/24
route = 198.18.74.0/24
route = 198.18.75.0/24
route = 198.18.76.0/24
route = 198.18.77.0/24
route = 198.18.78.0/24
route = 198.18.79.0/24
route = 198.18.80.0/24
route = 198.18.81.0/24
route = 198.18.82.0/24
route = 198.18.83.0/24
route = 198.18.84.0/24
route = 198.18.85.0/24
route = 198.18.86.0/24
route = 198.18.87.0/24
route = 198.18.88.0/24
route = 198.18.89.0/24
route = 198.18.90.0/24
route = 198.18.91.0/24
route = 198.18.92.0/24
route = 198.18.93.0/24
route = 198.18.94.0/24
route = 198.18.95.0/24
route = 198.18.96.0/24
route = 198.18.97.0/24
route = 198.18.98.0/24
route = 198.18.99.0/24
route = 198.18.100.0/24
route = 198.18.101.0/24
route = 198.18.102.0/24
route = 198.18.103.0/24
route = 198.18.104.0/24
route = 198.18.105.0/24
route = 198.18.106.0/24
route = 198.18.107.0/24
route = 198.18.108.0/24
route = 198.18.109.0/24
route = 198.18.110.0/24
route = 198.18.111.0/24
route = 198.18.112.0/24
route = 198.18.113.0/24
route = 198.18.114.0/24
route = 198.18.115.0/24
route = 198.18.116.0/24
route = 198.18.117.0/24
route = 198.18.118.0/24
route = 198.18.119.0/24
route = 198.18.120.0/24
route = 198.18.121.0/24
route = 198.18.122.0/24
route = 198.18.123.0/24
route = 198.18.124.0/24
route = 198.18.125.0/24
route = 198.18.126.0/24
route = 198.18.127.0/24
route = 198.18.128.0/24
route = 198.18.129.0/24
route = 198.18.130.0/24
route = 198.18.131.0/24
route = 198.18.132.0/24
route = 198.18.133.0/24
route = 198.18.134.0/24
route = 198.18.135.0/24
route = 198.18.136.0/24
route = 198.18.137.0/24
route = 198.18.138.0/24
route = 198.18.139.0/24
route = 198.18.140.0/24
route = 198.18.141.0/24
route = 198.18.142.0/24
route = 198.18.143.0/24
route = 198.18.144.0/24
route = 198.18.145.0/24
route = 198.18.146.0/24
route = 198.18.147.0/24
route = 198.18.148.0/24
route = 198.18.149.0/24
route = 198.18.150.0/24
route = 198.18.151.0/24
route = 198.18.152.0/24
route = 198.18.153.0/24
route = 198.18.154.0/24
route = 198.18.155.0/24
route = 198.18.156.0/24
route = 198.18.157.0/24
route = 198.18.158.0/24
route = 198.18.159.0/24
route = 198.18.160.0/24
route = 198.18.161.0/24
route = 198.18.162.0/24
route = 198.18.163.0/24
route = 198.18.164.0/24
route = 198.18.165.0/24
route = 198.18.166.0/24
route = 198.18.167.0/24
route = 198.18.168.0/24
route = 198.18.169.0/24
route = 198.18.170.0/24
route = 198.18.171.0/24
route = 198.18.172.0/24
route = 198.18.173.0/24
route = 198.18.174.0/24
route = 198.18.175.0/24
route = 198.18.176.0/24
route = 198.18.177.0/24
route = 198.18.178.0/24
route = 198.18.179.0/24
route = 198.18.180.0/24
route = 198.18.181.0/24
route = 198.18.182.0/24
route = 198.18.183.0/24
route = 198.18.184.0/24
route = 198.18.185.0/24
route = 198.18.186.0/24
route = 198.18.187.0/24
route = 198.18.188.0/24
route = 198.18.189.0/24
route = 198.18.190.0/24
route = 198.18.191.0/24
route = 198.18.192.0/24
route = 198.18.193.0/24
route = 198.18.194.0/24
route = 198.18.195.0/24
route = 198.18.196.0/24
route = 198.18.197.0/24
route = 198.18.198.0/24
route = 198.18.199.0/24
route = 198.18.200.0/24
route = 198.18.201.0/24
route = 198.18.202.0/24
route = 198.18.203.0/24
route = 198.18.204.0/24
route = 198.18.205.0/24
route = 198.18.206.0/24
route = 198.18.207.0/24
route = 198.18.208.0/24
route = 198.18.209.0/24
route = 198.18.210.0/24
route = 198.18.211.0/24
route = 198.18.212.0/24
route = 198.18.213.0/24
route = 198.18.214.0/24
route = 198.18.215.0/24
route = 198.18.216.0/24
route = 198.18.217.0/24
route = 198.18.218.0/24
route = 198.18.219.0/24
route = 198.18.220.0/24
route = 198.18.221.0/24
route = 198.18.222.0/24
route = 198.18.223.0/24
route = 198.18.224.0/24
route = 198.18.225.0/24
route = 198.18.226.0/24
route = 198.18.227.0/24
route = 198.18.228.0/24
route = 198.18.229.0/24
route = 198.18.230.0/24
route = 198.18.231.0/24
route = 198.18.232.0/24
route = 198.18.233.0/24
route = 198.18.234.0/24
route = 198.18.235.0/24
route = 198.18.236.0/24
route = 198.18.237.0/24
route = 198.18.238.0/24
route = 198.18.239.0/24
route = 198.18.240.0/24
route = 198.18.241.0/24
route = 198.18.242.0/24
route = 198.18.243.0/24
route = 198.18.244.0/24
route = 198.18.245.0/24
route = 198.18.246.0/24
route = 198.18.247.0/24
route = 198.18.248.0/24
route = 198.18.249.0/24
route = 198.18.250.0/24
route = 198.18.251.0/24
route = 198.18.252.0/24
route = 198.18.253.0/24
route = 198.18.254.0/24
route = 198.18.255.0/24
+3 -3
View File
@@ -147,10 +147,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -166,7 +166,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
no-route = 192.168.98.0/255.255.255.0
no-route = 198.51.100.0/255.255.255.0
route = default
#
+2 -2
View File
@@ -147,10 +147,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+3 -3
View File
@@ -133,10 +133,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -152,7 +152,7 @@ ping-leases = true
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+35 -35
View File
@@ -6,8 +6,8 @@
test Cleartext-Password := "test"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-IP-Address = 192.168.7.2,
Framed-Route = 203.0.113.0/24,
Framed-IP-Address = @VPNNET_BASE@.2,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -15,9 +15,9 @@ test Cleartext-Password := "test"
test2 Cleartext-Password := "test2"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.191,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.191,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -25,9 +25,9 @@ test2 Cleartext-Password := "test2"
test3 Cleartext-Password := "test3"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.192,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -35,9 +35,9 @@ test3 Cleartext-Password := "test3"
test4 Cleartext-Password := "test4"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.192,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -45,9 +45,9 @@ test4 Cleartext-Password := "test4"
test5 Cleartext-Password := "test5"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.192,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -55,9 +55,9 @@ test5 Cleartext-Password := "test5"
test6 Cleartext-Password := "test6"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.192,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -65,9 +65,9 @@ test6 Cleartext-Password := "test6"
test7 Cleartext-Password := "test7"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.192,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -75,9 +75,9 @@ test7 Cleartext-Password := "test7"
test8 Cleartext-Password := "test8"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.0/24,
Framed-Route = 192.168.1.0/8,
Framed-IP-Address = 192.168.1.192,
Framed-Route = 203.0.113.0/24,
Framed-Route = 198.18.1.0/15,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -85,7 +85,7 @@ test8 Cleartext-Password := "test8"
test-arb Cleartext-Password := "test-arb"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-Route = 192.168.100.5/24,
Framed-Route = 203.0.113.5/24,
Framed-IP-Address = 255.255.255.254,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
@@ -94,7 +94,7 @@ test-arb Cleartext-Password := "test-arb"
test-class Cleartext-Password := "test-class"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.93.190,
Framed-IP-Address = @VPNNET_BASE@.190,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Class = "OU=group1;group2",
@@ -104,7 +104,7 @@ test-class Cleartext-Password := "test-class"
test-multi-class Cleartext-Password := "test-multi-class"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.94.192,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Class = "group1",
@@ -117,7 +117,7 @@ test-multi-class Cleartext-Password := "test-multi-class"
test-multi-class-ou Cleartext-Password := "test-multi-class-ou"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.94.192,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Class = "OU=group1;group2",
@@ -127,7 +127,7 @@ test-multi-class-ou Cleartext-Password := "test-multi-class-ou"
test-multi-class-ou-comma Cleartext-Password := "test-multi-class-ou-comma"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.95.192,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Class = "OU=group1,group2",
@@ -137,8 +137,8 @@ test-multi-class-ou-comma Cleartext-Password := "test-multi-class-ou-comma"
testtime Cleartext-Password := "test"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.66.192,
Framed-Route = 192.168.67.0/24,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-Route = 198.51.100.0/24,
Framed-IP-Netmask = 255.255.255.0,
Framed-MTU = 1500,
Session-Timeout = 60,
@@ -149,15 +149,15 @@ testtime Cleartext-Password := "test"
test-ipv6prefix Cleartext-Password := "test"
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.66.194,
Framed-IP-Address = @VPNNET_BASE@.194,
Framed-IP-Netmask = 255.255.255.0,
Framed-IPv6-Prefix = fd00:abcd:ef00::/48,
Framed-IPv6-Prefix = 2001:db8:abcd::/48,
Framed-MTU = 1500
test1-otp Cleartext-Password := "test1-otp-stage%{string:State}", Tmp-Integer-0 := 3
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.55.190,
Framed-IP-Address = @VPNNET_BASE@.190,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -165,7 +165,7 @@ test1-otp Cleartext-Password := "test1-otp-stage%{string:State}", Tmp
test2-otp Cleartext-Password := "test2-otp-stage%{string:State}", Tmp-Integer-0 := 17
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.55.191,
Framed-IP-Address = @VPNNET_BASE@.191,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
@@ -173,7 +173,7 @@ test2-otp Cleartext-Password := "test2-otp-stage%{string:State}", Tmp
test3-otp Cleartext-Password := "test3-otp-stage%{string:State}", Tmp-Integer-0 := 3
Service-Type = Framed-User,
Framed-Protocol = PPP,
Framed-IP-Address = 192.168.55.192,
Framed-IP-Address = @VPNNET_BASE@.192,
Framed-IP-Netmask = 255.255.255.0,
Framed-Routing = Broadcast-Listen,
Framed-MTU = 1500
+2 -2
View File
@@ -246,9 +246,9 @@ ping-leases = false
#
# To set the server as the default gateway for the client just
# comment out all routes from the server.
route = 10.209.209.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = fc13:71:ea31:4b4e::/64
route = 2001:db8:4b4e::/64
# Configuration files that will be applied per user connection or
# per group. Each file name on these directories must match the username
+2 -2
View File
@@ -247,9 +247,9 @@ ping-leases = false
#
# To set the server as the default gateway for the client just
# comment out all routes from the server.
route = 10.209.209.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = fc13:71:ea31:4b4e::/64
route = 2001:db8:4b4e::/64
# Configuration files that will be applied per user connection or
# per group. Each file name on these directories must match the username
+2 -2
View File
@@ -247,9 +247,9 @@ ping-leases = false
#
# To set the server as the default gateway for the client just
# comment out all routes from the server.
route = 10.209.209.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = fc13:71:ea31:4b4e::/64
route = 2001:db8:4b4e::/64
# Configuration files that will be applied per user connection or
# per group. Each file name on these directories must match the username
+2 -2
View File
@@ -267,9 +267,9 @@ ping-leases = false
#
# To set the server as the default gateway for the client just
# comment out all routes from the server.
route = 10.209.209.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = fc13:71:ea31:4b4e::/64
route = 2001:db8:4b4e::/64
# Configuration files that will be applied per user connection or
# per group. Each file name on these directories must match the username
+2 -2
View File
@@ -242,9 +242,9 @@ ping-leases = false
#
# To set the server as the default gateway for the client just
# comment out all routes from the server.
route = 10.209.209.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = fc13:71:ea31:4b4e::/64
route = 2001:db8:4b4e::/64
# Configuration files that will be applied per user connection or
# per group. Each file name on these directories must match the username
+2 -2
View File
@@ -160,7 +160,7 @@ device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ipv6-network = @VPNNET6@
@@ -171,7 +171,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -144,10 +144,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -163,7 +163,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -144,10 +144,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -163,7 +163,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -132,10 +132,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -151,7 +151,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -147,10 +147,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -166,7 +166,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
no-route = 192.168.98.0/255.255.255.0
no-route = 198.51.100.0/255.255.255.0
route = default
#
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -144,10 +144,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -163,7 +163,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -144,10 +144,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -163,7 +163,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -137,10 +137,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -156,7 +156,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -137,10 +137,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -156,7 +156,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -137,10 +137,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -156,7 +156,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+5 -5
View File
@@ -135,13 +135,13 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
ipv6-network = fda9:4efe:7e3b:03ea::/64
ipv6-network = @VPNNET6@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -153,7 +153,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
@@ -173,4 +173,4 @@ route = 192.168.1.0/255.255.255.0
# should be set for them.
cisco-client-compat = true
config-per-user = @SRCDIR@/user-config-explicit/
config-per-user = @CONFIG_PER_USER_DIR@/
@@ -139,10 +139,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -158,7 +158,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -142,10 +142,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -161,7 +161,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -148,10 +148,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -167,7 +167,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -144,10 +144,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -163,7 +163,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -140,10 +140,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -159,7 +159,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -140,10 +140,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -159,7 +159,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -139,10 +139,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -158,7 +158,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -139,10 +139,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -158,7 +158,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1 -1
View File
@@ -141,7 +141,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+6 -11
View File
@@ -114,14 +114,14 @@ auth-timeout = 40
use-utmp = true
# PID file
pid-file = /var/run/ocserv.pid
pid-file = ./ocserv.pid
# The default server directory. Does not require any devices present.
#chroot-dir = /path/to/chroot
# socket file used for IPC, will be appended with .PID
# It must be accessible within the chroot environment (if any)
socket-file = /var/run/ocserv-socket
socket-file = ./ocserv-socket
# The user the worker processes will be run as. It should be
# unique (no other services run as this user).
@@ -135,15 +135,11 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.210.0
ipv4-netmask = 255.255.255.0
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.210.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
ipv4-dns = @VPNADDR@
# Prior to leasing any IP from the pool ping it to verify that
# it is not in use by another (unrelated to this server) host.
@@ -152,8 +148,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.210.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
route = @VPNNET@
#
# The following options are for (experimental) AnyConnect client
@@ -172,6 +167,6 @@ route = 192.168.210.0/255.255.255.0
# should be set for them.
cisco-client-compat = true
config-per-user = @SRCDIR@/user-config-p2p/
config-per-user = @CONFIG_PER_USER_DIR@/
occtl-socket-file = @OCCTL_SOCKET@
use-occtl = true
+4 -4
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,10 +154,10 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
config-per-user = @SRCDIR@/user-config/
config-per-user = @CONFIG_PER_USER_DIR@/
route-add-cmd = "echo %R %{RI} %D > ./test-iroute.tmp"
#route-del-cmd = "ip route delete %R dev %D"
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -162,7 +162,7 @@ device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# Prior to leasing any IP from the pool ping it to verify that
# it is not in use by another (unrelated to this server) host.
+2 -2
View File
@@ -20,7 +20,7 @@ run-as-user = @USERNAME@
run-as-group = @GROUP@
device = vpns
default-domain = example.com
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
ipv4-network = @VPNNET@
ipv6-network = @VPNNET6@
ping-leases = false
@@ -28,7 +28,7 @@ ping-leases = false
[vhost:udp-restricted.example.com]
no-udp = true
auth = plain[passwd=@SRCDIR@/data/test-no-udp.passwd]
config-per-user = @SRCDIR@/user-config/
config-per-user = @CONFIG_PER_USER_DIR@/
ca-cert = @SRCDIR@/certs/ca.pem
server-cert = @SRCDIR@/certs/server-cert.pem
server-key = @SRCDIR@/certs/server-key.pem
+1 -1
View File
@@ -48,7 +48,7 @@ device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ipv6-network = @VPNNET6@
+3 -3
View File
@@ -138,10 +138,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -157,7 +157,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -157,10 +157,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -176,7 +176,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -44,10 +44,10 @@ device = vpns
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ping-leases = false
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
+3 -3
View File
@@ -148,10 +148,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -167,7 +167,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -147,10 +147,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -166,7 +166,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -132,10 +132,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -151,7 +151,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1 -1
View File
@@ -42,7 +42,7 @@ device = vpns
default-domain = example.com
ipv4-network = @VPNNET@
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ipv6-network = @VPNNET6@
+5 -5
View File
@@ -140,11 +140,11 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.168.5.1
ipv4-dns = @VPNNET_BASE@.1
ipv4-dns = 203.0.113.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -160,8 +160,8 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.168.5.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
route = 203.0.113.0/255.255.255.0
#
# The following options are for (experimental) AnyConnect client
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+3 -3
View File
@@ -137,10 +137,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -156,7 +156,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -136,10 +136,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -155,7 +155,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -137,10 +137,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -156,7 +156,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1 -1
View File
@@ -144,7 +144,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+1 -1
View File
@@ -142,7 +142,7 @@ default-domain = example.com
ipv4-network = @VPNNET@
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
+3 -3
View File
@@ -41,12 +41,12 @@ run-as-group = @GROUP@
device = vpns
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ping-leases = false
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
cisco-client-compat = true
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+5 -5
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.5.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.5.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -160,10 +160,10 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.5.0/255.255.255.0
no-route = 192.168.98.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
no-route = 198.51.100.0/255.255.255.0
config-per-user = @SRCDIR@/user-config/
config-per-user = @CONFIG_PER_USER_DIR@/
#route-add-cmd = "echo %R %D > ./test-expose-iroute.tmp"
#route-del-cmd = "ip route delete %R dev %D"
@@ -142,10 +142,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -161,7 +161,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -142,10 +142,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -161,7 +161,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+5 -5
View File
@@ -140,10 +140,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -159,7 +159,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
@@ -193,7 +193,7 @@ ca-cert = @SRCDIR@/certs/ca.pem
server-cert = @SRCDIR@/certs/server-cert-secp521r1.pem
server-key = @SRCDIR@/certs/server-key-secp521r1.pem
ipv4-network = 192.168.2.0
ipv4-network = 198.51.100.0
ipv4-netmask = 255.255.255.0
cert-user-oid = 0.9.2342.19200300.100.1.1
@@ -206,5 +206,5 @@ ca-cert = @SRCDIR@/certs/ca.pem
server-cert = @SRCDIR@/certs/server-cert-secp521r1.pem
server-key = @SRCDIR@/certs/server-key-secp521r1.pem
ipv4-network = 192.168.3.0
ipv4-network = 203.0.113.0
ipv4-netmask = 255.255.255.0
@@ -23,7 +23,7 @@ run-as-user = @USERNAME@
run-as-group = @GROUP@
device = vpns
default-domain = example.com
ipv4-dns = 192.168.1.1
ipv4-dns = 192.0.2.1
ipv4-network = @VPNNET@
ipv6-network = @VPNNET6@
ping-leases = false
+3 -3
View File
@@ -133,10 +133,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = @VPNNET_BASE@.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
ipv4-dns = 192.168.1.1
ipv4-dns = @VPNNET_BASE@.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -152,7 +152,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = @VPNNET_BASE@.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+3 -3
View File
@@ -135,10 +135,10 @@ device = vpns
# The default domain to be advertised
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-network = 192.0.2.0
ipv4-netmask = 255.255.255.0
# Use the keyword local to advertise the local P-t-P address as DNS server
dns = 192.168.1.1
dns = 192.0.2.1
# The NBNS server (if any)
#ipv4-nbns = 192.168.2.3
@@ -154,7 +154,7 @@ ping-leases = false
# Leave empty to assign the default MTU of the device
# mtu =
route = 192.168.1.0/255.255.255.0
route = 192.0.2.0/255.255.255.0
#route = 192.168.5.0/255.255.255.0
#
+1
View File
@@ -0,0 +1 @@
explicit-ipv4 = @VPNNET_BASE@.201
+1
View File
@@ -0,0 +1 @@
explicit-ipv4 = @VPNNET_BASE@.0
+1
View File
@@ -0,0 +1 @@
explicit-ipv6 = @VPNNET6_BASE@5
+1
View File
@@ -0,0 +1 @@
explicit-ipv6 = @VPNNET6_BASE@1
+1
View File
@@ -0,0 +1 @@
ipv4-network = @VPNNET_BASE@.0/31

Some files were not shown because too many files have changed in this diff Show More