port 1194
# Mikrotik пока еще не поддерживает UDP
proto tcp
dev tun
ca ca.crt
cert server.crt
key server.key # This file should be kept secret
dh dh4096.pem
server 10.0.0.0 255.255.255.0
client-config-dir clients
route 192.168.0.0 255.255.255.0
keepalive 10 120
tun-mtu 1500
mssfix 1450
cipher AES-256-CBC # AES
auth sha1
# Компрессия микротиком пока не поддерживается
;comp-lzo
user nobody
group nobody
#Сохраняем туннель при обрыве на время keepalive
persist-key
#Не пересчитываем ключи при обрыве связи
persist-tun
status /var/log/openvpn-status.log
log /var/log/openvpn.log
verb 3
mute 10
# mkdir -p /etc/openvpn/clients
# vi /etc/openvpn/clients/client
# cat /etc/openvpn/clients/client
/etc/openvpn/clients/client
# LAN behind mikrotik
iroute 192.168.0.0 255.255.255.0
# vpn ip for mikrotik
ifconfig-push 10.0.0.2 10.0.0.1
# vi /etc/firewalld/zones/public.xml
# cat /etc/firewalld/zones/public.xml
/etc/firewalld/zones/public.xml
<?xml version="1.0" encoding="utf-8"?>
<zone>
<short>Public</short>
<description>For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
<service name="dhcpv6-client"/>
<service name="ssh"/>
<service name="openvpn"/>
</zone>