本帖最後由 角色 於 2018-9-13 16:22 編輯
如果你看不到MyTV Super,RTHK TV,那么就把所有no-routes都delete掉,就可以。- auth = "plain[passwd=/etc/ocserv/ocpasswd]"
- # listen-host = [IP|HOSTNAME]
- tcp-port = 443
- udp-port = 443
- run-as-user = nobody
- run-as-group = daemon
- socket-file = /var/run/ocserv-socket
- server-cert = /etc/ocserv/ssl/server-cert.pem
- server-key = /etc/ocserv/ssl/server-key.pem
- ca-cert = /etc/ocserv/ssl/ca-cert.pem
- isolate-workers = true
- banner = "Welcome DOUB.IO"
- max-clients = 0
- max-same-clients = 0
- rate-limit-ms = 0
- server-stats-reset-time = 604800
- keepalive = 32400
- dpd = 90
- mobile-dpd = 1800
- switch-to-tcp-timeout = 25
- try-mtu-discovery = false
- tls-priorities = "NORMAL:%SERVER_PRECEDENCE:%COMPAT:-VERS-SSL3.0"
- auth-timeout = 240
- idle-timeout = 86400
- mobile-idle-timeout = 86400
- min-reauth-time = 300
- max-ban-score = 80
- ban-reset-time = 1200
- cookie-timeout = 300
- deny-roaming = false
- rekey-time = 172800
- rekey-method = ssl
- use-occtl = true
- pid-file = /var/run/ocserv.pid
- net-priority = 6
- device = vpns
- predictable-ips = trueipv4-network = 192.168.1.0
- ipv4-netmask = 255.255.255.0
- # An alternative way of specifying the network:
- #ipv4-network = 192.168.1.0/24
- # The IPv6 subnet that leases will be given from.
- #ipv6-network = fda9:4efe:7e3b:03ea::/48
- # Specify the size of the network to provide to clients. It is
- # generally recommended to provide clients with a /64 network in
- # IPv6, but any subnet may be specified. To provide clients only
- # with a single IP use the prefix 128.
- #ipv6-subnet-prefix = 128
- #ipv6-subnet-prefix = 64
- # tunnel-all-dns = true
- dns = 8.8.8.8
- dns = 8.8.4.4
- ping-leases = false
- # Beginning of no-route, the following no-routes will be pushed to the client when connected. If all no-routes are removed, then all the traffic will be directed the remote gateway, i.e., Openconnect server gateway
- #no-route = 1.0.0.0/255.192.0.0
- #no-route = 1.64.0.0/255.224.0.0
- #no-route = 1.112.0.0/255.248.0.0
- #***
- #***
- #***
- #no-route = 223.0.0.0/255.224.0.0
- #no-route = 223.64.0.0/255.192.0.0
- #no-route = 223.128.0.0/255.128.0.0
- # End of no-route
- cisco-client-compat = true
- dtls-legacy = true
- default-domain = example.com
複製代碼 |