Technical data
4. Packages
OPENVPN_DEFAULT_SHAPER Default: OPENVPN_DEFAULT_SHAPER=”
Restricts outgoing bandwidth of the tunnel to the specified value of bytes per second.
Possible range is from 100 up to 100000000 bytes. For values up to 1000 bytes per
second reduce MTU of the connection otherwise ping times will increase significantly.
If you want to restrict a tunnel to a certain bandwidth in both directions you have to
configure this option on both OpenVPN end points separately.
In modern OpenVPN versions shaping is not working correctly. Data transfer rates in
tunnels using shaping may be extremely fluctuating or even not work at all. Problems
may occur in completely different ways depending on the hardware used and lead to un-
predictable behavior. Please use shaping with care at the moment. If in doubt deactivate
or at least test shaping extensively.
OPENVPN_EXPERT Default: OPENVPN_EXPERT=’no’
Expert mode enables you to use native Openvpn config files. These have to be stored in
the config directory etc/openvpn. All files found there will be transferred to the router.
Expert mode ignores all config settings thus OPENVPN_N=’0’ has to be set.
Expert mode creates no firewall rules. You will have to place them in base.txt by yourself.
Connection-specific Settings
The following OpenVPN options only are valid for the connection mentioned. Only a few
of them are mandatory while the most can be omitted. All default settings are taken from
OPENVPN_DEFAULT_x. Changing values in OPENVPN_DEFAULT_ applies to all connections that do
not explicitely change defaults.
OPENVPN_x_NAME Default: OPENVPN_x_NAME=”
Defines a name for the OpenVPN connection with up to 16 characters. A config file
with this name and suffix .conf will be created in directory /etc/openvpn. This name
will appear in syslogs as well. Example: if the name ’peter’ is entered in syslog the
connection will appear as ’openvpn-peter’. This helps to identify connections. A name
may contain characters, numbers and the ’-’.
OPENVPN_x_ACTIV Default: OPENVPN_x_ACTIV=’yes’
If you want to deactivate an OpenVPN connection but keep the config file it can be
disabled by specifying ’no’. Config files will be written to rc.cfg but no corresponding
connection will be created.
OPENVPN_x_CHECK_CONFIG Default: OPENVPN_x_CHECK_CONFIG=’yes’
OpenVPN’s extended config file checks are too stringent in rare cases. For example if an
ISDN backup connection uses the same routing entries as a connection over the Internet
extended checks will complain. In this case extended checking should be disabled for the
backup connection. Set OPENVPN_x_CHECK_CONFIG=’no’ to switch off extended checking
for this connection.
OPENVPN_x_CIPHER Default see: OPENVPN_DEFAULT_CIPHER
See OPENVPN_DEFAULT_CIPHER (Page 169). In contradiction to the default setting this
setting only affects the OpenVPN connection mentioned.
173










