make it work (UDP/1194) with a Real-Ewon! (lower security levels)

This commit is contained in:
Joerg Lehmann 2022-10-28 18:55:50 +02:00
parent 0457852f6f
commit 2afa3e3657
2 changed files with 12 additions and 1 deletions

View File

@ -40,6 +40,14 @@ Noch ein paar Zusatzpakete:
# yum install tcpdump -y # yum install tcpdump -y
# yum install python3-bcrypt -y # yum install python3-bcrypt -y
# yum install tar -y # yum install tar -y
Firewalld disablen (WICHTIG!!!)
# systemctl disable --now firewalld
Tiefere Sicherheitsstufe, siehe https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening
# update-crypto-policies --set LEGACY
``` ```
Wegen Entropy: Wegen Entropy:

View File

@ -9,7 +9,10 @@ script-security 3
writepid /var/run/openvpn-server/myopenvpn.pid writepid /var/run/openvpn-server/myopenvpn.pid
; ciphers ; ciphers
tls-cipher "DEFAULT" tls-cipher "DEFAULT:@SECLEVEL=0"
tls-version-min 1.0
providers legacy default
data-ciphers AES-256-GCM:AES-128-GCM:AES-256-CBC:BF-CBC
; tunnel configuration ; tunnel configuration
dev tap0 dev tap0