mirror of
https://github.com/shtorm-7/sing-box-extended.git
synced 2026-10-07 22:59:59 +00:00
Add openvpn and openconnect
This commit is contained in:
@@ -19,10 +19,13 @@ An endpoint is a protocol with inbound and outbound behavior.
|
||||
|
||||
### Fields
|
||||
|
||||
| Type | Format |
|
||||
|-------------|---------------------------|
|
||||
| `wireguard` | [WireGuard](./wireguard/) |
|
||||
| `tailscale` | [Tailscale](./tailscale/) |
|
||||
| Type | Format |
|
||||
|------------------|-----------------------------------------|
|
||||
| `wireguard` | [WireGuard](./wireguard/) |
|
||||
| `tailscale` | [Tailscale](./tailscale/) |
|
||||
| `openconnect` | [OpenConnect Client](./openconnect/) |
|
||||
| `openvpn-client` | [OpenVPN Client](./openvpn-client/) |
|
||||
| `openvpn-server` | [OpenVPN Server](./openvpn-server/) |
|
||||
|
||||
#### tag
|
||||
|
||||
|
||||
@@ -19,10 +19,13 @@
|
||||
|
||||
### 字段
|
||||
|
||||
| 类型 | 格式 |
|
||||
|-------------|---------------------------|
|
||||
| `wireguard` | [WireGuard](./wireguard/) |
|
||||
| `tailscale` | [Tailscale](./tailscale/) |
|
||||
| 类型 | 格式 |
|
||||
|------------------|-----------------------------------------|
|
||||
| `wireguard` | [WireGuard](./wireguard/) |
|
||||
| `tailscale` | [Tailscale](./tailscale/) |
|
||||
| `openconnect` | [OpenConnect 客户端](./openconnect/) |
|
||||
| `openvpn-client` | [OpenVPN 客户端](./openvpn-client/) |
|
||||
| `openvpn-server` | [OpenVPN 服务器](./openvpn-server/) |
|
||||
|
||||
#### tag
|
||||
|
||||
|
||||
@@ -0,0 +1,387 @@
|
||||
# OpenConnect Client
|
||||
|
||||
!!! question "Since sing-box 1.14.0"
|
||||
|
||||
==Client only==
|
||||
|
||||
## Structure
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "openconnect",
|
||||
"tag": "oc-client",
|
||||
|
||||
"system": false,
|
||||
"name": "",
|
||||
"server": "vpn.example.com",
|
||||
"flavor": "anyconnect",
|
||||
"username": "",
|
||||
"password": "",
|
||||
"auth_group": "",
|
||||
"token": {
|
||||
"mode": "",
|
||||
"secret": "",
|
||||
"pin": "",
|
||||
"password": "",
|
||||
"device_id": "",
|
||||
"counter": 0
|
||||
},
|
||||
"reported_os": "",
|
||||
"user_agent": "",
|
||||
"csd": {
|
||||
"wrapper_path": ""
|
||||
},
|
||||
"hip": {
|
||||
"wrapper_path": ""
|
||||
},
|
||||
"tncc": {
|
||||
"wrapper_path": "",
|
||||
"device_id": "",
|
||||
"user_agent": "",
|
||||
"machine_identification_enabled": false,
|
||||
"certificates": [
|
||||
{
|
||||
"certificate": [],
|
||||
"certificate_path": ""
|
||||
}
|
||||
]
|
||||
},
|
||||
"no_udp": false,
|
||||
"allow_insecure_crypto": false,
|
||||
"tls": {
|
||||
"certificate_authority": [],
|
||||
"certificate_authority_path": "",
|
||||
"client_certificate": [],
|
||||
"client_certificate_path": "",
|
||||
"client_key": [],
|
||||
"client_key_path": "",
|
||||
"client_key_password": "",
|
||||
"mca_certificate": [],
|
||||
"mca_certificate_path": "",
|
||||
"mca_key": [],
|
||||
"mca_key_path": "",
|
||||
"mca_key_password": ""
|
||||
},
|
||||
"form_entries": [
|
||||
{
|
||||
"form_id": "",
|
||||
"submission_key": "",
|
||||
"name": "",
|
||||
"value": "",
|
||||
"promote": false
|
||||
}
|
||||
],
|
||||
|
||||
... // Dial Fields
|
||||
}
|
||||
```
|
||||
|
||||
!!! note ""
|
||||
|
||||
You can ignore the JSON Array [] tag when the content is only one item.
|
||||
|
||||
## Fields
|
||||
|
||||
### system
|
||||
|
||||
Use a system interface.
|
||||
|
||||
Requires privilege and cannot conflict with existing system interfaces.
|
||||
|
||||
If disabled, sing-box uses the internal network stack.
|
||||
|
||||
### name
|
||||
|
||||
Custom interface name for the system interface.
|
||||
|
||||
An automatically generated `oc` interface name is used by default.
|
||||
|
||||
### server
|
||||
|
||||
==Required==
|
||||
|
||||
OpenConnect VPN server HTTPS URL.
|
||||
|
||||
The `https://` scheme is added if omitted. URL user information, queries, and fragments are not supported.
|
||||
|
||||
### flavor
|
||||
|
||||
OpenConnect protocol flavor, one of `anyconnect`, `gp`, `fortinet`, `f5`, `pulse`, or `nc`.
|
||||
|
||||
`anyconnect` is used by default.
|
||||
|
||||
### username
|
||||
|
||||
Username used to fill matching authentication form fields.
|
||||
|
||||
### password
|
||||
|
||||
Password used to fill matching authentication form fields.
|
||||
|
||||
### auth_group
|
||||
|
||||
Authentication group used to preselect a matching group, realm, domain, or gateway choice when supported by the selected flavor.
|
||||
|
||||
### token
|
||||
|
||||
Software token configuration for automatically answering matching token fields.
|
||||
|
||||
### token.mode
|
||||
|
||||
==Required==
|
||||
|
||||
Software token mode, one of:
|
||||
|
||||
- `totp`: Time-based One-Time Password.
|
||||
- `hotp`: HMAC-based One-Time Password.
|
||||
- `stoken`: RSA SecurID software token.
|
||||
|
||||
### token.secret
|
||||
|
||||
==Required==
|
||||
|
||||
Software token secret.
|
||||
|
||||
For `totp` and `hotp`, this can be a Base32 secret, a `base32:`-prefixed secret, or an `otpauth://` URI of the matching type.
|
||||
|
||||
For `stoken`, this is the encoded RSA SecurID CTF token content.
|
||||
|
||||
### token.pin
|
||||
|
||||
RSA SecurID PIN for `stoken` mode.
|
||||
|
||||
### token.password
|
||||
|
||||
Password for decrypting a password-protected RSA SecurID token in `stoken` mode.
|
||||
|
||||
### token.device_id
|
||||
|
||||
Device ID for decrypting a device-bound RSA SecurID token in `stoken` mode.
|
||||
|
||||
### token.counter
|
||||
|
||||
Initial counter for `hotp` mode.
|
||||
|
||||
If zero, the counter from an `otpauth://` URI is used when present; otherwise the counter starts at zero.
|
||||
|
||||
### reported_os
|
||||
|
||||
Operating system identity reported to the VPN server when supported by the selected flavor.
|
||||
|
||||
For `anyconnect`, `gp`, and `pulse`, the supported values are `linux`, `linux-64`, `win`, `mac-intel`, `android`, and `apple-ios`.
|
||||
|
||||
`anyconnect` uses `linux-64` by default. `gp` and `pulse` select a value based on the system platform by default.
|
||||
|
||||
### user_agent
|
||||
|
||||
User agent reported to the VPN server when supported by the selected flavor.
|
||||
|
||||
The default is flavor-specific.
|
||||
|
||||
### csd
|
||||
|
||||
AnyConnect CSD/host scan compliance options.
|
||||
|
||||
Built-in CSD handling is used by default when requested by the server.
|
||||
|
||||
### csd.wrapper_path
|
||||
|
||||
Path to an external AnyConnect CSD wrapper executable.
|
||||
|
||||
Built-in CSD handling is used if empty.
|
||||
|
||||
### hip
|
||||
|
||||
GlobalProtect HIP check and report options.
|
||||
|
||||
Built-in HIP reporting is used by default when requested by the server.
|
||||
|
||||
### hip.wrapper_path
|
||||
|
||||
Path to an external GlobalProtect HIP report wrapper executable.
|
||||
|
||||
Built-in HIP reporting is used if empty.
|
||||
|
||||
### tncc
|
||||
|
||||
Network Connect TNCC compliance options.
|
||||
|
||||
Built-in TNCC handling is used by default when requested by the server.
|
||||
|
||||
### tncc.wrapper_path
|
||||
|
||||
Path to an external Network Connect TNCC wrapper executable.
|
||||
|
||||
Built-in TNCC handling is used if empty.
|
||||
|
||||
Conflict with `tncc.device_id`, `tncc.user_agent`, `tncc.machine_identification_enabled`, and `tncc.certificates`.
|
||||
|
||||
### tncc.device_id
|
||||
|
||||
Device ID reported by the built-in TNCC handler.
|
||||
|
||||
Conflict with `tncc.wrapper_path`.
|
||||
|
||||
### tncc.user_agent
|
||||
|
||||
User agent used by the built-in TNCC handler.
|
||||
|
||||
`Neoteris HC Http` is used by default.
|
||||
|
||||
Conflict with `tncc.wrapper_path`.
|
||||
|
||||
### tncc.machine_identification_enabled
|
||||
|
||||
Enable built-in TNCC machine identification, including the platform, hostname, and observed MAC addresses.
|
||||
|
||||
Conflict with `tncc.wrapper_path`.
|
||||
|
||||
### tncc.certificates
|
||||
|
||||
Machine certificates used by the built-in TNCC handler to answer certificate requests.
|
||||
|
||||
Requires `tncc.machine_identification_enabled`.
|
||||
|
||||
Conflict with `tncc.wrapper_path`.
|
||||
|
||||
### tncc.certificates.certificate
|
||||
|
||||
TNCC machine certificate content in PEM format.
|
||||
|
||||
Conflict with `tncc.certificates.certificate_path`.
|
||||
|
||||
### tncc.certificates.certificate_path
|
||||
|
||||
TNCC machine certificate path in PEM format.
|
||||
|
||||
Conflict with `tncc.certificates.certificate`.
|
||||
|
||||
### no_udp
|
||||
|
||||
Disable the DTLS or ESP secondary data channel and use the TLS data channel only.
|
||||
|
||||
### allow_insecure_crypto
|
||||
|
||||
Allow deprecated TLS and DTLS versions and cipher suites required by legacy VPN servers.
|
||||
|
||||
Disabled by default. This option does not disable server certificate verification.
|
||||
|
||||
### tls
|
||||
|
||||
OpenConnect TLS configuration.
|
||||
|
||||
### tls.certificate_authority
|
||||
|
||||
Additional trusted CA certificate content in PEM format.
|
||||
|
||||
The certificates are added to the system certificate pool.
|
||||
|
||||
Conflict with `tls.certificate_authority_path`.
|
||||
|
||||
### tls.certificate_authority_path
|
||||
|
||||
Path to additional trusted CA certificates in PEM format.
|
||||
|
||||
The certificates are added to the system certificate pool.
|
||||
|
||||
Conflict with `tls.certificate_authority`.
|
||||
|
||||
### tls.client_certificate
|
||||
|
||||
Client certificate chain content in PEM format.
|
||||
|
||||
Conflict with `tls.client_certificate_path`.
|
||||
|
||||
### tls.client_certificate_path
|
||||
|
||||
Client certificate chain path in PEM format.
|
||||
|
||||
Conflict with `tls.client_certificate`.
|
||||
|
||||
### tls.client_key
|
||||
|
||||
Client private key content in PEM format.
|
||||
|
||||
Conflict with `tls.client_key_path`.
|
||||
|
||||
### tls.client_key_path
|
||||
|
||||
Client private key path in PEM format.
|
||||
|
||||
Conflict with `tls.client_key`.
|
||||
|
||||
The client certificate and key must both be set or both be empty.
|
||||
|
||||
### tls.client_key_password
|
||||
|
||||
Password for the encrypted client private key.
|
||||
|
||||
### tls.mca_certificate
|
||||
|
||||
AnyConnect multiple-certificate authentication (MCA) certificate chain content in PEM format.
|
||||
|
||||
Conflict with `tls.mca_certificate_path`.
|
||||
|
||||
### tls.mca_certificate_path
|
||||
|
||||
AnyConnect multiple-certificate authentication (MCA) certificate chain path in PEM format.
|
||||
|
||||
Conflict with `tls.mca_certificate`.
|
||||
|
||||
### tls.mca_key
|
||||
|
||||
AnyConnect multiple-certificate authentication (MCA) private key content in PEM format.
|
||||
|
||||
Conflict with `tls.mca_key_path`.
|
||||
|
||||
### tls.mca_key_path
|
||||
|
||||
AnyConnect multiple-certificate authentication (MCA) private key path in PEM format.
|
||||
|
||||
Conflict with `tls.mca_key`.
|
||||
|
||||
The MCA certificate and key must both be set or both be empty.
|
||||
|
||||
### tls.mca_key_password
|
||||
|
||||
Password for the encrypted MCA private key.
|
||||
|
||||
### form_entries
|
||||
|
||||
Authentication form field overrides.
|
||||
|
||||
An entry matches by `submission_key` when set, or by the combination of `form_id` and `name`. Later matching entries take precedence.
|
||||
|
||||
### form_entries.form_id
|
||||
|
||||
Authentication form identifier used with `form_entries.name` when `form_entries.submission_key` is empty.
|
||||
|
||||
### form_entries.submission_key
|
||||
|
||||
Authentication field submission key.
|
||||
|
||||
Either `form_entries.submission_key` or both `form_entries.form_id` and `form_entries.name` are required.
|
||||
|
||||
### form_entries.name
|
||||
|
||||
Authentication field name used with `form_entries.form_id` when `form_entries.submission_key` is empty.
|
||||
|
||||
### form_entries.value
|
||||
|
||||
Value supplied automatically for the matching authentication field.
|
||||
|
||||
Conflict with `form_entries.promote`.
|
||||
|
||||
### form_entries.promote
|
||||
|
||||
Ask for the matching authentication field interactively instead of supplying an automatic value.
|
||||
|
||||
Conflict with `form_entries.value`.
|
||||
|
||||
## Dial Fields
|
||||
|
||||
See [Dial Fields](/configuration/shared/dial/) for details.
|
||||
|
||||
## Interactive authentication
|
||||
|
||||
Use `Tools` > `Endpoints` in the sing-box dashboard or any sing-box graphical client to authenticate and manage the endpoint.
|
||||
@@ -0,0 +1,387 @@
|
||||
# OpenConnect 客户端
|
||||
|
||||
!!! question "自 sing-box 1.14.0 起"
|
||||
|
||||
==仅客户端==
|
||||
|
||||
## 结构
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "openconnect",
|
||||
"tag": "oc-client",
|
||||
|
||||
"system": false,
|
||||
"name": "",
|
||||
"server": "vpn.example.com",
|
||||
"flavor": "anyconnect",
|
||||
"username": "",
|
||||
"password": "",
|
||||
"auth_group": "",
|
||||
"token": {
|
||||
"mode": "",
|
||||
"secret": "",
|
||||
"pin": "",
|
||||
"password": "",
|
||||
"device_id": "",
|
||||
"counter": 0
|
||||
},
|
||||
"reported_os": "",
|
||||
"user_agent": "",
|
||||
"csd": {
|
||||
"wrapper_path": ""
|
||||
},
|
||||
"hip": {
|
||||
"wrapper_path": ""
|
||||
},
|
||||
"tncc": {
|
||||
"wrapper_path": "",
|
||||
"device_id": "",
|
||||
"user_agent": "",
|
||||
"machine_identification_enabled": false,
|
||||
"certificates": [
|
||||
{
|
||||
"certificate": [],
|
||||
"certificate_path": ""
|
||||
}
|
||||
]
|
||||
},
|
||||
"no_udp": false,
|
||||
"allow_insecure_crypto": false,
|
||||
"tls": {
|
||||
"certificate_authority": [],
|
||||
"certificate_authority_path": "",
|
||||
"client_certificate": [],
|
||||
"client_certificate_path": "",
|
||||
"client_key": [],
|
||||
"client_key_path": "",
|
||||
"client_key_password": "",
|
||||
"mca_certificate": [],
|
||||
"mca_certificate_path": "",
|
||||
"mca_key": [],
|
||||
"mca_key_path": "",
|
||||
"mca_key_password": ""
|
||||
},
|
||||
"form_entries": [
|
||||
{
|
||||
"form_id": "",
|
||||
"submission_key": "",
|
||||
"name": "",
|
||||
"value": "",
|
||||
"promote": false
|
||||
}
|
||||
],
|
||||
|
||||
... // 拨号字段
|
||||
}
|
||||
```
|
||||
|
||||
!!! note ""
|
||||
|
||||
当内容只有一项时,可以忽略 JSON 数组 [] 标签。
|
||||
|
||||
## 字段
|
||||
|
||||
### system
|
||||
|
||||
使用系统接口。
|
||||
|
||||
需要权限,且不能与现有系统接口冲突。
|
||||
|
||||
禁用时,sing-box 使用内部网络栈。
|
||||
|
||||
### name
|
||||
|
||||
系统接口的自定义接口名称。
|
||||
|
||||
默认使用自动生成的 `oc` 接口名称。
|
||||
|
||||
### server
|
||||
|
||||
==必填==
|
||||
|
||||
OpenConnect VPN 服务器 HTTPS URL。
|
||||
|
||||
省略协议时会添加 `https://`。不支持 URL 用户信息、查询和片段。
|
||||
|
||||
### flavor
|
||||
|
||||
OpenConnect 协议 flavor,可选值为 `anyconnect`、`gp`、`fortinet`、`f5`、`pulse` 或 `nc`。
|
||||
|
||||
默认使用 `anyconnect`。
|
||||
|
||||
### username
|
||||
|
||||
用于填充匹配认证表单字段的用户名。
|
||||
|
||||
### password
|
||||
|
||||
用于填充匹配认证表单字段的密码。
|
||||
|
||||
### auth_group
|
||||
|
||||
认证组,用于在所选 flavor 支持时预选匹配的组、realm、domain 或 gateway 选项。
|
||||
|
||||
### token
|
||||
|
||||
用于自动回答匹配 token 字段的软件 token 配置。
|
||||
|
||||
### token.mode
|
||||
|
||||
==必填==
|
||||
|
||||
软件 token 模式,可选值为:
|
||||
|
||||
- `totp`:基于时间的一次性密码。
|
||||
- `hotp`:基于 HMAC 的一次性密码。
|
||||
- `stoken`:RSA SecurID 软件 token。
|
||||
|
||||
### token.secret
|
||||
|
||||
==必填==
|
||||
|
||||
软件 token 密钥。
|
||||
|
||||
对于 `totp` 和 `hotp`,可以是 Base32 密钥、带 `base32:` 前缀的密钥或类型匹配的 `otpauth://` URI。
|
||||
|
||||
对于 `stoken`,这是编码后的 RSA SecurID CTF token 内容。
|
||||
|
||||
### token.pin
|
||||
|
||||
`stoken` 模式的 RSA SecurID PIN。
|
||||
|
||||
### token.password
|
||||
|
||||
`stoken` 模式下用于解密受密码保护的 RSA SecurID token 的密码。
|
||||
|
||||
### token.device_id
|
||||
|
||||
`stoken` 模式下用于解密设备绑定 RSA SecurID token 的设备 ID。
|
||||
|
||||
### token.counter
|
||||
|
||||
`hotp` 模式的初始计数器。
|
||||
|
||||
为零时,如果 `otpauth://` URI 中存在计数器,则使用该计数器;否则从零开始。
|
||||
|
||||
### reported_os
|
||||
|
||||
所选 flavor 支持时向 VPN 服务器报告的操作系统标识。
|
||||
|
||||
对于 `anyconnect`、`gp` 和 `pulse`,支持的值为 `linux`、`linux-64`、`win`、`mac-intel`、`android` 和 `apple-ios`。
|
||||
|
||||
`anyconnect` 默认使用 `linux-64`。`gp` 和 `pulse` 默认根据系统平台选择值。
|
||||
|
||||
### user_agent
|
||||
|
||||
所选 flavor 支持时向 VPN 服务器报告的 User-Agent。
|
||||
|
||||
默认值由 flavor 决定。
|
||||
|
||||
### csd
|
||||
|
||||
AnyConnect CSD/host scan 合规性选项。
|
||||
|
||||
服务器请求 CSD 时,默认使用内置 CSD 处理。
|
||||
|
||||
### csd.wrapper_path
|
||||
|
||||
外部 AnyConnect CSD wrapper 可执行文件的路径。
|
||||
|
||||
为空时使用内置 CSD 处理。
|
||||
|
||||
### hip
|
||||
|
||||
GlobalProtect HIP 检查和报告选项。
|
||||
|
||||
服务器请求 HIP 时,默认使用内置 HIP 报告。
|
||||
|
||||
### hip.wrapper_path
|
||||
|
||||
外部 GlobalProtect HIP report wrapper 可执行文件的路径。
|
||||
|
||||
为空时使用内置 HIP 报告。
|
||||
|
||||
### tncc
|
||||
|
||||
Network Connect TNCC 合规性选项。
|
||||
|
||||
服务器请求 TNCC 时,默认使用内置 TNCC 处理。
|
||||
|
||||
### tncc.wrapper_path
|
||||
|
||||
外部 Network Connect TNCC wrapper 可执行文件的路径。
|
||||
|
||||
为空时使用内置 TNCC 处理。
|
||||
|
||||
与 `tncc.device_id`、`tncc.user_agent`、`tncc.machine_identification_enabled` 和 `tncc.certificates` 冲突。
|
||||
|
||||
### tncc.device_id
|
||||
|
||||
内置 TNCC 处理程序报告的设备 ID。
|
||||
|
||||
与 `tncc.wrapper_path` 冲突。
|
||||
|
||||
### tncc.user_agent
|
||||
|
||||
内置 TNCC 处理程序使用的 User-Agent。
|
||||
|
||||
默认使用 `Neoteris HC Http`。
|
||||
|
||||
与 `tncc.wrapper_path` 冲突。
|
||||
|
||||
### tncc.machine_identification_enabled
|
||||
|
||||
启用内置 TNCC 机器标识,包括平台、主机名和观测到的 MAC 地址。
|
||||
|
||||
与 `tncc.wrapper_path` 冲突。
|
||||
|
||||
### tncc.certificates
|
||||
|
||||
内置 TNCC 处理程序用于回答证书请求的机器证书。
|
||||
|
||||
需要启用 `tncc.machine_identification_enabled`。
|
||||
|
||||
与 `tncc.wrapper_path` 冲突。
|
||||
|
||||
### tncc.certificates.certificate
|
||||
|
||||
PEM 格式的 TNCC 机器证书内容。
|
||||
|
||||
与 `tncc.certificates.certificate_path` 冲突。
|
||||
|
||||
### tncc.certificates.certificate_path
|
||||
|
||||
PEM 格式的 TNCC 机器证书路径。
|
||||
|
||||
与 `tncc.certificates.certificate` 冲突。
|
||||
|
||||
### no_udp
|
||||
|
||||
禁用 DTLS 或 ESP 辅助数据通道,仅使用 TLS 数据通道。
|
||||
|
||||
### allow_insecure_crypto
|
||||
|
||||
允许旧版 VPN 服务器所需的已弃用 TLS 和 DTLS 版本及密码套件。
|
||||
|
||||
默认禁用。此选项不会禁用服务器证书验证。
|
||||
|
||||
### tls
|
||||
|
||||
OpenConnect TLS 配置。
|
||||
|
||||
### tls.certificate_authority
|
||||
|
||||
PEM 格式的附加受信任 CA 证书内容。
|
||||
|
||||
这些证书会添加到系统证书池。
|
||||
|
||||
与 `tls.certificate_authority_path` 冲突。
|
||||
|
||||
### tls.certificate_authority_path
|
||||
|
||||
PEM 格式的附加受信任 CA 证书路径。
|
||||
|
||||
这些证书会添加到系统证书池。
|
||||
|
||||
与 `tls.certificate_authority` 冲突。
|
||||
|
||||
### tls.client_certificate
|
||||
|
||||
PEM 格式的客户端证书链内容。
|
||||
|
||||
与 `tls.client_certificate_path` 冲突。
|
||||
|
||||
### tls.client_certificate_path
|
||||
|
||||
PEM 格式的客户端证书链路径。
|
||||
|
||||
与 `tls.client_certificate` 冲突。
|
||||
|
||||
### tls.client_key
|
||||
|
||||
PEM 格式的客户端私钥内容。
|
||||
|
||||
与 `tls.client_key_path` 冲突。
|
||||
|
||||
### tls.client_key_path
|
||||
|
||||
PEM 格式的客户端私钥路径。
|
||||
|
||||
与 `tls.client_key` 冲突。
|
||||
|
||||
客户端证书和私钥必须同时设置或同时为空。
|
||||
|
||||
### tls.client_key_password
|
||||
|
||||
加密客户端私钥的密码。
|
||||
|
||||
### tls.mca_certificate
|
||||
|
||||
PEM 格式的 AnyConnect 多证书认证(MCA)证书链内容。
|
||||
|
||||
与 `tls.mca_certificate_path` 冲突。
|
||||
|
||||
### tls.mca_certificate_path
|
||||
|
||||
PEM 格式的 AnyConnect 多证书认证(MCA)证书链路径。
|
||||
|
||||
与 `tls.mca_certificate` 冲突。
|
||||
|
||||
### tls.mca_key
|
||||
|
||||
PEM 格式的 AnyConnect 多证书认证(MCA)私钥内容。
|
||||
|
||||
与 `tls.mca_key_path` 冲突。
|
||||
|
||||
### tls.mca_key_path
|
||||
|
||||
PEM 格式的 AnyConnect 多证书认证(MCA)私钥路径。
|
||||
|
||||
与 `tls.mca_key` 冲突。
|
||||
|
||||
MCA 证书和私钥必须同时设置或同时为空。
|
||||
|
||||
### tls.mca_key_password
|
||||
|
||||
加密 MCA 私钥的密码。
|
||||
|
||||
### form_entries
|
||||
|
||||
认证表单字段覆盖。
|
||||
|
||||
设置 `submission_key` 时按该字段匹配,否则按 `form_id` 和 `name` 的组合匹配。后面的匹配项优先。
|
||||
|
||||
### form_entries.form_id
|
||||
|
||||
`form_entries.submission_key` 为空时,与 `form_entries.name` 一起使用的认证表单标识符。
|
||||
|
||||
### form_entries.submission_key
|
||||
|
||||
认证字段提交键。
|
||||
|
||||
`form_entries.submission_key` 或 `form_entries.form_id` 与 `form_entries.name` 的组合之一必填。
|
||||
|
||||
### form_entries.name
|
||||
|
||||
`form_entries.submission_key` 为空时,与 `form_entries.form_id` 一起使用的认证字段名称。
|
||||
|
||||
### form_entries.value
|
||||
|
||||
自动提供给匹配认证字段的值。
|
||||
|
||||
与 `form_entries.promote` 冲突。
|
||||
|
||||
### form_entries.promote
|
||||
|
||||
交互询问匹配的认证字段,而不是自动提供值。
|
||||
|
||||
与 `form_entries.value` 冲突。
|
||||
|
||||
## 拨号字段
|
||||
|
||||
参阅[拨号字段](/zh/configuration/shared/dial/)了解详情。
|
||||
|
||||
## 交互式认证
|
||||
|
||||
在 sing-box dashboard 或任意 sing-box 图形客户端的 `工具` > `端点` 中认证和管理 endpoint。
|
||||
@@ -0,0 +1,501 @@
|
||||
# OpenVPN Client
|
||||
|
||||
!!! question "Since sing-box 1.14.0"
|
||||
|
||||
## Structure
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "openvpn-client",
|
||||
"tag": "ovpn-client",
|
||||
|
||||
"server": "127.0.0.1",
|
||||
"server_port": 1194,
|
||||
"servers": [
|
||||
{
|
||||
"server": "127.0.0.1",
|
||||
"server_port": 1194,
|
||||
"network": "udp"
|
||||
}
|
||||
],
|
||||
"remote_random": false,
|
||||
"network": "udp",
|
||||
"username": "",
|
||||
"password": "",
|
||||
"auth_retry": "none",
|
||||
"static_challenge": "",
|
||||
"static_challenge_echo": false,
|
||||
"tls": {
|
||||
"server_name": "",
|
||||
"server_name_type": "name",
|
||||
"certificate": [],
|
||||
"certificate_path": "",
|
||||
"client_certificate": [],
|
||||
"client_certificate_path": "",
|
||||
"client_key": [],
|
||||
"client_key_path": "",
|
||||
"peer_fingerprint": [],
|
||||
"crl_path": "",
|
||||
"remote_certificate_ku": [],
|
||||
"remote_certificate_eku": "",
|
||||
"version_min": "1.2",
|
||||
"version_max": "",
|
||||
"cipher": "",
|
||||
"groups": "",
|
||||
"control_wrap": {
|
||||
"type": "",
|
||||
"key": [],
|
||||
"key_path": "",
|
||||
"direction": ""
|
||||
}
|
||||
},
|
||||
"data_ciphers": [],
|
||||
"data_ciphers_fallback": "",
|
||||
"auth": "",
|
||||
"mss_fix": 0,
|
||||
"fragment": 0,
|
||||
"compression": "",
|
||||
"compression_lzo": "",
|
||||
"allow_compression": "no",
|
||||
"route_no_pull": false,
|
||||
"pull_filters": [
|
||||
{
|
||||
"action": "ignore",
|
||||
"text": "route "
|
||||
}
|
||||
],
|
||||
"routes": [],
|
||||
"route_gateway": "",
|
||||
"route_metric": 0,
|
||||
"redirect_gateway": false,
|
||||
"redirect_gateway_flags": [],
|
||||
"keepalive_interval": "",
|
||||
"keepalive_timeout": "",
|
||||
"renegotiate_interval": "",
|
||||
"explicit_exit_notify": 0,
|
||||
"system": false,
|
||||
"name": "",
|
||||
"mtu": 1500,
|
||||
"udp_timeout": "",
|
||||
|
||||
... // Dial Fields
|
||||
}
|
||||
```
|
||||
|
||||
!!! note ""
|
||||
|
||||
You can ignore the JSON Array [] tag when the content is only one item.
|
||||
|
||||
## Fields
|
||||
|
||||
### server
|
||||
|
||||
OpenVPN server address.
|
||||
|
||||
Either `server` or `servers` is required.
|
||||
|
||||
Conflict with `servers`.
|
||||
|
||||
### server_port
|
||||
|
||||
OpenVPN server port.
|
||||
|
||||
Required when `server` is set.
|
||||
|
||||
### servers
|
||||
|
||||
List of OpenVPN servers.
|
||||
|
||||
The client tries the servers in order and moves to the next server when a connection fails.
|
||||
|
||||
Either `server` or `servers` is required.
|
||||
|
||||
Conflict with `server`.
|
||||
|
||||
### servers.server
|
||||
|
||||
==Required==
|
||||
|
||||
OpenVPN server address.
|
||||
|
||||
### servers.server_port
|
||||
|
||||
==Required==
|
||||
|
||||
OpenVPN server port.
|
||||
|
||||
### servers.network
|
||||
|
||||
OpenVPN transport network for this server, one of `udp` or `tcp`.
|
||||
|
||||
The top-level `network` is used by default.
|
||||
|
||||
### remote_random
|
||||
|
||||
Randomize the `servers` order before connecting.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### network
|
||||
|
||||
Default OpenVPN transport network, one of `udp` or `tcp`.
|
||||
|
||||
`udp` is used by default.
|
||||
|
||||
This value applies to `server` and to `servers` entries without their own `network`.
|
||||
|
||||
### username
|
||||
|
||||
Username for OpenVPN username/password authentication.
|
||||
|
||||
### password
|
||||
|
||||
Password for OpenVPN username/password authentication.
|
||||
|
||||
### auth_retry
|
||||
|
||||
Behavior after username/password authentication fails, one of `none`, `nointeract`, or `interact`.
|
||||
|
||||
`none` is used by default and treats a permanent authentication failure as terminal.
|
||||
|
||||
`nointeract` and `interact` allow authentication retries.
|
||||
|
||||
### static_challenge
|
||||
|
||||
Static challenge text shown when requesting an authentication response.
|
||||
|
||||
### static_challenge_echo
|
||||
|
||||
Show the static challenge response as plain text.
|
||||
|
||||
### tls
|
||||
|
||||
==Required==
|
||||
|
||||
OpenVPN control channel TLS configuration.
|
||||
|
||||
### tls.server_name
|
||||
|
||||
Expected server certificate name.
|
||||
|
||||
Certificate name verification is disabled if empty. The certificate chain or fingerprint and server certificate usage are still verified.
|
||||
|
||||
### tls.server_name_type
|
||||
|
||||
Certificate field matched by `tls.server_name`, one of `subject`, `name`, or `name-prefix`.
|
||||
|
||||
`name` is used by default when `tls.server_name` is set.
|
||||
|
||||
`subject` matches the full certificate subject, `name` matches the common name exactly, and `name-prefix` matches a common name prefix.
|
||||
|
||||
### tls.certificate
|
||||
|
||||
Trusted CA certificate content.
|
||||
|
||||
One of `tls.certificate`, `tls.certificate_path`, or `tls.peer_fingerprint` is required.
|
||||
|
||||
Conflict with `tls.certificate_path`.
|
||||
|
||||
### tls.certificate_path
|
||||
|
||||
Trusted CA certificate path.
|
||||
|
||||
One of `tls.certificate`, `tls.certificate_path`, or `tls.peer_fingerprint` is required.
|
||||
|
||||
Conflict with `tls.certificate`.
|
||||
|
||||
### tls.client_certificate
|
||||
|
||||
Client certificate content.
|
||||
|
||||
Conflict with `tls.client_certificate_path`.
|
||||
|
||||
### tls.client_certificate_path
|
||||
|
||||
Client certificate path.
|
||||
|
||||
Conflict with `tls.client_certificate`.
|
||||
|
||||
### tls.client_key
|
||||
|
||||
Client private key content.
|
||||
|
||||
Conflict with `tls.client_key_path`.
|
||||
|
||||
### tls.client_key_path
|
||||
|
||||
Client private key path.
|
||||
|
||||
Conflict with `tls.client_key`.
|
||||
|
||||
The client certificate and key must both be set or both be empty.
|
||||
|
||||
### tls.peer_fingerprint
|
||||
|
||||
Allowed SHA-256 fingerprints of the server leaf certificate.
|
||||
|
||||
Each fingerprint must be 64 lowercase hexadecimal characters without separators.
|
||||
|
||||
When a trusted CA is also configured, both the certificate chain and fingerprint are verified. Without a trusted CA, the fingerprint, certificate validity period, configured name, and certificate usage are verified, but the certificate chain is not.
|
||||
|
||||
### tls.crl_path
|
||||
|
||||
Path to a PEM or DER certificate revocation list used to reject revoked server certificates.
|
||||
|
||||
The CRL signature and validity period are verified against the trusted certificate chain.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### tls.remote_certificate_ku
|
||||
|
||||
Required server certificate key usage masks, written as hexadecimal values in OpenVPN `remote-cert-ku` format.
|
||||
|
||||
Multiple values are combined, and all requested usages must be present.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### tls.remote_certificate_eku
|
||||
|
||||
Required server certificate extended key usage, one of `server` or `client`.
|
||||
|
||||
Disabled by default. The standard OpenVPN server certificate usage check still applies.
|
||||
|
||||
### tls.version_min
|
||||
|
||||
Minimum TLS version, one of `1.0`, `1.1`, `1.2`, or `1.3`.
|
||||
|
||||
`1.2` is used by default.
|
||||
|
||||
### tls.version_max
|
||||
|
||||
Maximum TLS version, one of `1.0`, `1.1`, `1.2`, or `1.3`.
|
||||
|
||||
The maximum supported version is used by default.
|
||||
|
||||
The value cannot be lower than `tls.version_min`.
|
||||
|
||||
### tls.cipher
|
||||
|
||||
Colon-separated OpenSSL cipher suite names allowed for TLS 1.2 and earlier.
|
||||
|
||||
The default TLS cipher suites are used when empty. TLS 1.3 cipher suites are not controlled by this field.
|
||||
|
||||
### tls.groups
|
||||
|
||||
Colon-separated TLS key exchange groups in preference order.
|
||||
|
||||
Supported groups are `X25519`, `SECP256R1`, `SECP384R1`, and `SECP521R1`, including their common OpenSSL and NIST aliases.
|
||||
|
||||
The default TLS groups are used when empty.
|
||||
|
||||
### tls.control_wrap
|
||||
|
||||
OpenVPN control channel wrapping.
|
||||
|
||||
Equivalent to OpenVPN `tls-auth`, `tls-crypt`, and `tls-crypt-v2`.
|
||||
|
||||
Disabled if empty.
|
||||
|
||||
### tls.control_wrap.type
|
||||
|
||||
Control channel wrapping type, one of `tls_auth`, `tls_crypt`, or `tls_crypt_v2`.
|
||||
|
||||
### tls.control_wrap.key
|
||||
|
||||
Control channel wrapping key content.
|
||||
|
||||
Conflict with `tls.control_wrap.key_path`.
|
||||
|
||||
### tls.control_wrap.key_path
|
||||
|
||||
Control channel wrapping key path.
|
||||
|
||||
Conflict with `tls.control_wrap.key`.
|
||||
|
||||
### tls.control_wrap.direction
|
||||
|
||||
`tls-auth` key direction, one of `server` or `client`.
|
||||
|
||||
Only available when `tls.control_wrap.type` is `tls_auth`. The key is used bidirectionally if empty.
|
||||
|
||||
### data_ciphers
|
||||
|
||||
Allowed OpenVPN data channel ciphers.
|
||||
|
||||
`AES-256-GCM`, `AES-128-GCM`, and `CHACHA20-POLY1305` are used by default.
|
||||
|
||||
### data_ciphers_fallback
|
||||
|
||||
Data channel cipher for peers that do not support cipher negotiation.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### auth
|
||||
|
||||
OpenVPN data channel authentication digest.
|
||||
|
||||
`SHA1` is used by default. It only applies to non-AEAD data ciphers and `tls_auth`.
|
||||
|
||||
### mss_fix
|
||||
|
||||
Maximum OpenVPN UDP packet size used to clamp the MSS of TCP connections sent through the tunnel.
|
||||
|
||||
This prevents TCP packets from exceeding the path MTU after OpenVPN encapsulation.
|
||||
|
||||
Disabled when `0`.
|
||||
|
||||
### fragment
|
||||
|
||||
Maximum OpenVPN UDP packet size used for OpenVPN data channel fragmentation.
|
||||
|
||||
Disabled when `0`. A non-zero value must be at least `68`.
|
||||
|
||||
Conflict with TCP transport.
|
||||
|
||||
### compression
|
||||
|
||||
OpenVPN `compress` framing mode, one of `none`, `no`, `lz4`, `lz4-v2`, `stub`, `stub-v2`, `disabled`, or `off`.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
Compression can weaken traffic confidentiality. Prefer `stub` or `stub-v2` only when framing compatibility is required.
|
||||
|
||||
### compression_lzo
|
||||
|
||||
OpenVPN `comp-lzo` mode, one of `none`, `no`, `yes`, `adaptive`, `asym`, `disabled`, or `off`.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
Compression can weaken traffic confidentiality. Enable it only when required by the server.
|
||||
|
||||
### allow_compression
|
||||
|
||||
Policy for compression pushed by the server, one of `no`, `asym`, or `yes`.
|
||||
|
||||
`no` is used by default and permits only compression stub framing. `asym` accepts compressed packets from the server but does not compress outgoing packets. `yes` permits compression in both directions.
|
||||
|
||||
Conflict with non-stub compression enabled by `compression` or `compression_lzo` when set to `no`.
|
||||
|
||||
### route_no_pull
|
||||
|
||||
Ignore routes, route gateways, and redirect-gateway options pushed by the server.
|
||||
|
||||
Other pushed options are still accepted, and locally configured `routes` are still used.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### pull_filters
|
||||
|
||||
Ordered filters for options pushed by the server.
|
||||
|
||||
The first filter whose `text` is a case-insensitive prefix of the complete pushed option is applied. Options that match no filter are accepted.
|
||||
|
||||
### pull_filters.action
|
||||
|
||||
==Required==
|
||||
|
||||
Filter action, one of `accept`, `ignore`, or `reject`.
|
||||
|
||||
`accept` applies the option, `ignore` discards it, and `reject` terminates the connection.
|
||||
|
||||
### pull_filters.text
|
||||
|
||||
==Required==
|
||||
|
||||
Case-insensitive prefix to match against the pushed option name and value.
|
||||
|
||||
For example, `route ` matches pushed IPv4 route options without matching `route-gateway`.
|
||||
|
||||
### routes
|
||||
|
||||
IPv4 and IPv6 route prefixes routed through the OpenVPN endpoint.
|
||||
|
||||
These routes are used in addition to routes accepted from the server.
|
||||
|
||||
### route_gateway
|
||||
|
||||
IPv4 gateway for routes through the OpenVPN endpoint.
|
||||
|
||||
When empty, the VPN gateway received from the server is used.
|
||||
|
||||
### route_metric
|
||||
|
||||
Default metric for routes through the OpenVPN endpoint.
|
||||
|
||||
The platform default is used when `0`.
|
||||
|
||||
### redirect_gateway
|
||||
|
||||
Route all IPv4 traffic through the OpenVPN endpoint.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### redirect_gateway_flags
|
||||
|
||||
OpenVPN `redirect-gateway` flags.
|
||||
|
||||
`!ipv4` disables the IPv4 default route, and `ipv6` also routes all IPv6 traffic through the endpoint. Other OpenVPN flags are accepted for compatibility but do not change endpoint routing.
|
||||
|
||||
Empty by default.
|
||||
|
||||
### keepalive_interval
|
||||
|
||||
Interval for sending OpenVPN keepalive ping packets.
|
||||
|
||||
Locally configured values take precedence over server-pushed keepalive values.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### keepalive_timeout
|
||||
|
||||
Time without receiving OpenVPN traffic before the connection is restarted.
|
||||
|
||||
Locally configured values take precedence over server-pushed keepalive values.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### renegotiate_interval
|
||||
|
||||
OpenVPN TLS renegotiation interval.
|
||||
|
||||
If empty or set to `0s`, the OpenVPN default `1h` is used.
|
||||
|
||||
### explicit_exit_notify
|
||||
|
||||
Number of OpenVPN exit notifications sent when closing a UDP connection.
|
||||
|
||||
Disabled when `0`. At most `10` notifications are sent.
|
||||
|
||||
### system
|
||||
|
||||
Use a system interface.
|
||||
|
||||
Requires privilege and cannot conflict with existing system interfaces.
|
||||
|
||||
If disabled, sing-box uses the internal network stack.
|
||||
|
||||
### name
|
||||
|
||||
Custom interface name for the system interface.
|
||||
|
||||
An automatically generated `ovpn` interface name is used by default.
|
||||
|
||||
### mtu
|
||||
|
||||
OpenVPN interface MTU.
|
||||
|
||||
When empty, `1500` is used until a server-pushed MTU is received.
|
||||
|
||||
### udp_timeout
|
||||
|
||||
UDP NAT expiration time.
|
||||
|
||||
`5m` is used by default.
|
||||
|
||||
## Dial Fields
|
||||
|
||||
See [Dial Fields](/configuration/shared/dial/) for details.
|
||||
|
||||
## Interactive authentication
|
||||
|
||||
Use `Tools` > `Endpoints` in the sing-box dashboard or any sing-box graphical client to authenticate and manage the endpoint.
|
||||
@@ -0,0 +1,501 @@
|
||||
# OpenVPN 客户端
|
||||
|
||||
!!! question "自 sing-box 1.14.0 起"
|
||||
|
||||
## 结构
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "openvpn-client",
|
||||
"tag": "ovpn-client",
|
||||
|
||||
"server": "127.0.0.1",
|
||||
"server_port": 1194,
|
||||
"servers": [
|
||||
{
|
||||
"server": "127.0.0.1",
|
||||
"server_port": 1194,
|
||||
"network": "udp"
|
||||
}
|
||||
],
|
||||
"remote_random": false,
|
||||
"network": "udp",
|
||||
"username": "",
|
||||
"password": "",
|
||||
"auth_retry": "none",
|
||||
"static_challenge": "",
|
||||
"static_challenge_echo": false,
|
||||
"tls": {
|
||||
"server_name": "",
|
||||
"server_name_type": "name",
|
||||
"certificate": [],
|
||||
"certificate_path": "",
|
||||
"client_certificate": [],
|
||||
"client_certificate_path": "",
|
||||
"client_key": [],
|
||||
"client_key_path": "",
|
||||
"peer_fingerprint": [],
|
||||
"crl_path": "",
|
||||
"remote_certificate_ku": [],
|
||||
"remote_certificate_eku": "",
|
||||
"version_min": "1.2",
|
||||
"version_max": "",
|
||||
"cipher": "",
|
||||
"groups": "",
|
||||
"control_wrap": {
|
||||
"type": "",
|
||||
"key": [],
|
||||
"key_path": "",
|
||||
"direction": ""
|
||||
}
|
||||
},
|
||||
"data_ciphers": [],
|
||||
"data_ciphers_fallback": "",
|
||||
"auth": "",
|
||||
"mss_fix": 0,
|
||||
"fragment": 0,
|
||||
"compression": "",
|
||||
"compression_lzo": "",
|
||||
"allow_compression": "no",
|
||||
"route_no_pull": false,
|
||||
"pull_filters": [
|
||||
{
|
||||
"action": "ignore",
|
||||
"text": "route "
|
||||
}
|
||||
],
|
||||
"routes": [],
|
||||
"route_gateway": "",
|
||||
"route_metric": 0,
|
||||
"redirect_gateway": false,
|
||||
"redirect_gateway_flags": [],
|
||||
"keepalive_interval": "",
|
||||
"keepalive_timeout": "",
|
||||
"renegotiate_interval": "",
|
||||
"explicit_exit_notify": 0,
|
||||
"system": false,
|
||||
"name": "",
|
||||
"mtu": 1500,
|
||||
"udp_timeout": "",
|
||||
|
||||
... // 拨号字段
|
||||
}
|
||||
```
|
||||
|
||||
!!! note ""
|
||||
|
||||
当内容只有一项时,可以忽略 JSON 数组 [] 标签。
|
||||
|
||||
## 字段
|
||||
|
||||
### server
|
||||
|
||||
OpenVPN 服务器地址。
|
||||
|
||||
`server` 和 `servers` 之一必填。
|
||||
|
||||
与 `servers` 冲突。
|
||||
|
||||
### server_port
|
||||
|
||||
OpenVPN 服务器端口。
|
||||
|
||||
设置 `server` 时必填。
|
||||
|
||||
### servers
|
||||
|
||||
OpenVPN 服务器列表。
|
||||
|
||||
客户端按顺序尝试服务器,并在连接失败时尝试下一台服务器。
|
||||
|
||||
`server` 和 `servers` 之一必填。
|
||||
|
||||
与 `server` 冲突。
|
||||
|
||||
### servers.server
|
||||
|
||||
==必填==
|
||||
|
||||
OpenVPN 服务器地址。
|
||||
|
||||
### servers.server_port
|
||||
|
||||
==必填==
|
||||
|
||||
OpenVPN 服务器端口。
|
||||
|
||||
### servers.network
|
||||
|
||||
该服务器的 OpenVPN 传输网络,可选值为 `udp` 或 `tcp`。
|
||||
|
||||
默认使用顶层 `network`。
|
||||
|
||||
### remote_random
|
||||
|
||||
连接前随机排列 `servers` 顺序。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### network
|
||||
|
||||
默认 OpenVPN 传输网络,可选值为 `udp` 或 `tcp`。
|
||||
|
||||
默认使用 `udp`。
|
||||
|
||||
该值应用于 `server` 和未单独设置 `network` 的 `servers` 条目。
|
||||
|
||||
### username
|
||||
|
||||
OpenVPN 用户名/密码认证的用户名。
|
||||
|
||||
### password
|
||||
|
||||
OpenVPN 用户名/密码认证的密码。
|
||||
|
||||
### auth_retry
|
||||
|
||||
用户名/密码认证失败后的行为,可选值为 `none`、`nointeract` 或 `interact`。
|
||||
|
||||
默认使用 `none`,并将永久认证失败视为终止错误。
|
||||
|
||||
`nointeract` 和 `interact` 允许重试认证。
|
||||
|
||||
### static_challenge
|
||||
|
||||
请求认证响应时显示的静态质询文本。
|
||||
|
||||
### static_challenge_echo
|
||||
|
||||
以明文显示静态质询响应。
|
||||
|
||||
### tls
|
||||
|
||||
==必填==
|
||||
|
||||
OpenVPN 控制通道 TLS 配置。
|
||||
|
||||
### tls.server_name
|
||||
|
||||
预期的服务器证书名称。
|
||||
|
||||
为空时禁用证书名称验证,但仍会验证证书链或 fingerprint 与服务器证书用途。
|
||||
|
||||
### tls.server_name_type
|
||||
|
||||
与 `tls.server_name` 匹配的证书字段,可选值为 `subject`、`name` 或 `name-prefix`。
|
||||
|
||||
设置 `tls.server_name` 时默认使用 `name`。
|
||||
|
||||
`subject` 匹配完整证书 subject,`name` 精确匹配 common name,`name-prefix` 匹配 common name 前缀。
|
||||
|
||||
### tls.certificate
|
||||
|
||||
受信任 CA 证书内容。
|
||||
|
||||
`tls.certificate`、`tls.certificate_path` 和 `tls.peer_fingerprint` 之一必填。
|
||||
|
||||
与 `tls.certificate_path` 冲突。
|
||||
|
||||
### tls.certificate_path
|
||||
|
||||
受信任 CA 证书路径。
|
||||
|
||||
`tls.certificate`、`tls.certificate_path` 和 `tls.peer_fingerprint` 之一必填。
|
||||
|
||||
与 `tls.certificate` 冲突。
|
||||
|
||||
### tls.client_certificate
|
||||
|
||||
客户端证书内容。
|
||||
|
||||
与 `tls.client_certificate_path` 冲突。
|
||||
|
||||
### tls.client_certificate_path
|
||||
|
||||
客户端证书路径。
|
||||
|
||||
与 `tls.client_certificate` 冲突。
|
||||
|
||||
### tls.client_key
|
||||
|
||||
客户端私钥内容。
|
||||
|
||||
与 `tls.client_key_path` 冲突。
|
||||
|
||||
### tls.client_key_path
|
||||
|
||||
客户端私钥路径。
|
||||
|
||||
与 `tls.client_key` 冲突。
|
||||
|
||||
客户端证书和私钥必须同时设置或同时为空。
|
||||
|
||||
### tls.peer_fingerprint
|
||||
|
||||
允许的服务器 leaf certificate 的 SHA-256 fingerprint。
|
||||
|
||||
每个 fingerprint 必须是不带分隔符的 64 字符小写十六进制字符串。
|
||||
|
||||
同时配置受信任 CA 时,会同时验证证书链和 fingerprint。未配置受信任 CA 时,会验证 fingerprint、证书有效期、配置的名称和证书用途,但不验证证书链。
|
||||
|
||||
### tls.crl_path
|
||||
|
||||
用于拒绝已吊销服务器证书的 PEM 或 DER CRL 文件路径。
|
||||
|
||||
根据受信任证书链验证 CRL 签名和有效期。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### tls.remote_certificate_ku
|
||||
|
||||
服务器证书所需的 Key Usage mask,使用 OpenVPN `remote-cert-ku` 格式的十六进制值。
|
||||
|
||||
多个值会被组合,证书必须包含所有要求的用途。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### tls.remote_certificate_eku
|
||||
|
||||
服务器证书所需的 Extended Key Usage,可选值为 `server` 或 `client`。
|
||||
|
||||
默认禁用。标准 OpenVPN 服务器证书用途检查仍然生效。
|
||||
|
||||
### tls.version_min
|
||||
|
||||
最低 TLS 版本,可选值为 `1.0`、`1.1`、`1.2` 或 `1.3`。
|
||||
|
||||
默认使用 `1.2`。
|
||||
|
||||
### tls.version_max
|
||||
|
||||
最高 TLS 版本,可选值为 `1.0`、`1.1`、`1.2` 或 `1.3`。
|
||||
|
||||
默认使用支持的最高版本。
|
||||
|
||||
该值不能低于 `tls.version_min`。
|
||||
|
||||
### tls.cipher
|
||||
|
||||
TLS 1.2 及更低版本允许的 OpenSSL cipher suite 名称,以冒号分隔。
|
||||
|
||||
为空时使用默认 TLS cipher suite。该字段不控制 TLS 1.3 cipher suite。
|
||||
|
||||
### tls.groups
|
||||
|
||||
按偏好顺序排列的 TLS key exchange group,以冒号分隔。
|
||||
|
||||
支持 `X25519`、`SECP256R1`、`SECP384R1` 和 `SECP521R1`,包括其常用 OpenSSL 和 NIST 别名。
|
||||
|
||||
为空时使用默认 TLS group。
|
||||
|
||||
### tls.control_wrap
|
||||
|
||||
OpenVPN 控制通道封装。
|
||||
|
||||
等价于 OpenVPN `tls-auth`、`tls-crypt` 和 `tls-crypt-v2`。
|
||||
|
||||
为空时禁用。
|
||||
|
||||
### tls.control_wrap.type
|
||||
|
||||
控制通道封装类型,可选值为 `tls_auth`、`tls_crypt` 或 `tls_crypt_v2`。
|
||||
|
||||
### tls.control_wrap.key
|
||||
|
||||
控制通道封装密钥内容。
|
||||
|
||||
与 `tls.control_wrap.key_path` 冲突。
|
||||
|
||||
### tls.control_wrap.key_path
|
||||
|
||||
控制通道封装密钥路径。
|
||||
|
||||
与 `tls.control_wrap.key` 冲突。
|
||||
|
||||
### tls.control_wrap.direction
|
||||
|
||||
`tls-auth` 密钥方向,可选值为 `server` 或 `client`。
|
||||
|
||||
仅当 `tls.control_wrap.type` 为 `tls_auth` 时可用。为空时双向使用密钥。
|
||||
|
||||
### data_ciphers
|
||||
|
||||
允许的 OpenVPN 数据通道 cipher。
|
||||
|
||||
默认使用 `AES-256-GCM`、`AES-128-GCM` 和 `CHACHA20-POLY1305`。
|
||||
|
||||
### data_ciphers_fallback
|
||||
|
||||
用于不支持 cipher 协商的对端的数据通道 cipher。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### auth
|
||||
|
||||
OpenVPN 数据通道认证摘要。
|
||||
|
||||
默认使用 `SHA1`,仅应用于非 AEAD 数据 cipher 和 `tls_auth`。
|
||||
|
||||
### mss_fix
|
||||
|
||||
OpenVPN UDP packet 的最大大小,用于限制通过隧道发送的 TCP 连接 MSS。
|
||||
|
||||
这可以避免 TCP packet 在 OpenVPN 封装后超过 path MTU。
|
||||
|
||||
设为 `0` 时禁用。
|
||||
|
||||
### fragment
|
||||
|
||||
用于 OpenVPN 数据通道 fragmentation 的最大 OpenVPN UDP packet 大小。
|
||||
|
||||
设为 `0` 时禁用。非零值必须至少为 `68`。
|
||||
|
||||
与 TCP 传输冲突。
|
||||
|
||||
### compression
|
||||
|
||||
OpenVPN `compress` framing 模式,可选值为 `none`、`no`、`lz4`、`lz4-v2`、`stub`、`stub-v2`、`disabled` 或 `off`。
|
||||
|
||||
默认禁用。
|
||||
|
||||
Compression 可能削弱流量机密性。仅在需要 framing 兼容性时使用 `stub` 或 `stub-v2`。
|
||||
|
||||
### compression_lzo
|
||||
|
||||
OpenVPN `comp-lzo` 模式,可选值为 `none`、`no`、`yes`、`adaptive`、`asym`、`disabled` 或 `off`。
|
||||
|
||||
默认禁用。
|
||||
|
||||
Compression 可能削弱流量机密性。仅在服务器要求时启用。
|
||||
|
||||
### allow_compression
|
||||
|
||||
服务器推送的 compression 策略,可选值为 `no`、`asym` 或 `yes`。
|
||||
|
||||
默认使用 `no`,仅允许 compression stub framing。`asym` 接受来自服务器的 compressed packet,但不压缩出站 packet。`yes` 允许双向 compression。
|
||||
|
||||
当设为 `no` 时,与通过 `compression` 或 `compression_lzo` 启用的非 stub compression 冲突。
|
||||
|
||||
### route_no_pull
|
||||
|
||||
忽略服务器推送的 route、route gateway 和 redirect-gateway 选项。
|
||||
|
||||
仍会接受其他推送选项,并继续使用本地配置的 `routes`。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### pull_filters
|
||||
|
||||
服务器推送选项的有序 pull filter 列表。
|
||||
|
||||
应用第一个 `text` 为完整推送选项大小写不敏感前缀的 filter。未匹配任何 filter 的选项会被接受。
|
||||
|
||||
### pull_filters.action
|
||||
|
||||
==必填==
|
||||
|
||||
Filter action,可选值为 `accept`、`ignore` 或 `reject`。
|
||||
|
||||
`accept` 应用选项,`ignore` 丢弃选项,`reject` 终止连接。
|
||||
|
||||
### pull_filters.text
|
||||
|
||||
==必填==
|
||||
|
||||
用于匹配推送选项名称和值的大小写不敏感前缀。
|
||||
|
||||
例如,`route ` 会匹配推送的 IPv4 route 选项,但不会匹配 `route-gateway`。
|
||||
|
||||
### routes
|
||||
|
||||
通过 OpenVPN endpoint 路由的 IPv4 和 IPv6 route prefix。
|
||||
|
||||
这些 route 会与从服务器接受的 route 一起使用。
|
||||
|
||||
### route_gateway
|
||||
|
||||
通过 OpenVPN endpoint 路由的 IPv4 gateway。
|
||||
|
||||
为空时使用从服务器接收的 VPN gateway。
|
||||
|
||||
### route_metric
|
||||
|
||||
通过 OpenVPN endpoint 路由的默认 metric。
|
||||
|
||||
设为 `0` 时使用平台默认值。
|
||||
|
||||
### redirect_gateway
|
||||
|
||||
通过 OpenVPN endpoint 路由所有 IPv4 流量。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### redirect_gateway_flags
|
||||
|
||||
OpenVPN `redirect-gateway` flag。
|
||||
|
||||
`!ipv4` 禁用 IPv4 default route,`ipv6` 还会通过 endpoint 路由所有 IPv6 流量。接受其他 OpenVPN flag 以兼容配置,但它们不会改变 endpoint 路由。
|
||||
|
||||
默认为空。
|
||||
|
||||
### keepalive_interval
|
||||
|
||||
发送 OpenVPN keepalive ping packet 的间隔。
|
||||
|
||||
本地配置值优先于服务器推送的 keepalive 值。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### keepalive_timeout
|
||||
|
||||
未接收 OpenVPN 流量后重新启动连接的时间。
|
||||
|
||||
本地配置值优先于服务器推送的 keepalive 值。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### renegotiate_interval
|
||||
|
||||
OpenVPN TLS 重新协商间隔。
|
||||
|
||||
如果为空或设为 `0s`,使用 OpenVPN 默认值 `1h`。
|
||||
|
||||
### explicit_exit_notify
|
||||
|
||||
关闭 UDP 连接时发送的 OpenVPN exit notification 数量。
|
||||
|
||||
设为 `0` 时禁用。最多发送 `10` 个 notification。
|
||||
|
||||
### system
|
||||
|
||||
使用系统接口。
|
||||
|
||||
需要权限,且不能与现有系统接口冲突。
|
||||
|
||||
禁用时,sing-box 使用内部网络栈。
|
||||
|
||||
### name
|
||||
|
||||
系统接口的自定义接口名称。
|
||||
|
||||
默认使用自动生成的 `ovpn` 接口名称。
|
||||
|
||||
### mtu
|
||||
|
||||
OpenVPN 接口 MTU。
|
||||
|
||||
为空时使用服务器推送的 MTU;收到服务器配置前使用 `1500`。
|
||||
|
||||
### udp_timeout
|
||||
|
||||
UDP NAT 过期时间。
|
||||
|
||||
默认使用 `5m`。
|
||||
|
||||
## 拨号字段
|
||||
|
||||
参阅[拨号字段](/zh/configuration/shared/dial/)。
|
||||
|
||||
## 交互式认证
|
||||
|
||||
在 sing-box dashboard 或任意 sing-box 图形客户端的 `工具` > `端点` 中认证和管理 endpoint。
|
||||
@@ -0,0 +1,319 @@
|
||||
# OpenVPN Server
|
||||
|
||||
!!! question "Since sing-box 1.14.0"
|
||||
|
||||
## Structure
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "openvpn-server",
|
||||
"tag": "ovpn-server",
|
||||
|
||||
... // Listen Fields
|
||||
|
||||
"system": false,
|
||||
"name": "",
|
||||
"mtu": 1500,
|
||||
"network": "udp",
|
||||
"max_clients": 1024,
|
||||
"address": [],
|
||||
"topology": "subnet",
|
||||
"users": [
|
||||
{
|
||||
"username": "",
|
||||
"password": ""
|
||||
}
|
||||
],
|
||||
"tls": {
|
||||
"certificate": [],
|
||||
"certificate_path": "",
|
||||
"key": [],
|
||||
"key_path": "",
|
||||
"client_certificate": [],
|
||||
"client_certificate_path": "",
|
||||
"verify_client_certificate": "require",
|
||||
"control_wrap": {
|
||||
"type": "tls_crypt",
|
||||
"key": [],
|
||||
"key_path": "",
|
||||
"direction": ""
|
||||
}
|
||||
},
|
||||
"data_ciphers": [],
|
||||
"data_ciphers_fallback": "",
|
||||
"auth": "",
|
||||
"push": {
|
||||
"routes": [],
|
||||
"dns": [],
|
||||
"redirect_gateway": false,
|
||||
"redirect_gateway_flags": [],
|
||||
"block_outside_dns": false
|
||||
},
|
||||
"keepalive_interval": "",
|
||||
"keepalive_timeout": "",
|
||||
"renegotiate_interval": "",
|
||||
"udp_timeout": ""
|
||||
}
|
||||
```
|
||||
|
||||
!!! note ""
|
||||
|
||||
You can ignore the JSON Array [] tag when the content is only one item
|
||||
|
||||
## Listen Fields
|
||||
|
||||
See [Listen Fields](/configuration/shared/listen/) for details.
|
||||
|
||||
## Fields
|
||||
|
||||
### system
|
||||
|
||||
Use system interface.
|
||||
|
||||
Requires privilege and cannot conflict with existing system interfaces.
|
||||
|
||||
If disabled, sing-box uses the internal network stack.
|
||||
|
||||
### name
|
||||
|
||||
Custom interface name for system interface.
|
||||
|
||||
An automatically generated `ovpn` interface name is used by default.
|
||||
|
||||
### mtu
|
||||
|
||||
OpenVPN interface MTU.
|
||||
|
||||
`1500` will be used by default.
|
||||
|
||||
### network
|
||||
|
||||
OpenVPN transport network, one of `udp` or `tcp`.
|
||||
|
||||
`udp` will be used by default.
|
||||
|
||||
Only one transport network is served per endpoint; to serve both TCP and UDP,
|
||||
configure two endpoints with separate `address` subnets,
|
||||
matching upstream OpenVPN which requires two server processes.
|
||||
|
||||
### max_clients
|
||||
|
||||
Maximum number of established and pending TLS client sessions.
|
||||
|
||||
`1024` is used by default. The value must be smaller than `16777216`, the size of the OpenVPN peer-id space.
|
||||
|
||||
### address
|
||||
|
||||
==Required==
|
||||
|
||||
List of OpenVPN server address prefixes.
|
||||
|
||||
At most one IPv4 prefix and one IPv6 prefix are supported.
|
||||
|
||||
The prefix address is assigned to the server interface. The masked prefix is used as the client address pool and route.
|
||||
|
||||
The first IPv4 and IPv6 prefix addresses are used as the endpoint's local addresses.
|
||||
|
||||
### topology
|
||||
|
||||
OpenVPN topology pushed to clients, one of `subnet`, `p2p` or `net30`.
|
||||
|
||||
`subnet` will be used by default.
|
||||
|
||||
### users
|
||||
|
||||
List of OpenVPN username/password users.
|
||||
|
||||
If set, clients must pass username/password authentication in addition to any certificate policy configured by `tls.verify_client_certificate`.
|
||||
|
||||
### users.username
|
||||
|
||||
Username.
|
||||
|
||||
### users.password
|
||||
|
||||
Password.
|
||||
|
||||
### tls
|
||||
|
||||
==Required==
|
||||
|
||||
OpenVPN control channel TLS configuration.
|
||||
|
||||
### tls.certificate
|
||||
|
||||
TLS server certificate content.
|
||||
|
||||
Either `tls.certificate` or `tls.certificate_path` is required.
|
||||
|
||||
Conflict with `tls.certificate_path`.
|
||||
|
||||
### tls.certificate_path
|
||||
|
||||
TLS server certificate path.
|
||||
|
||||
Either `tls.certificate` or `tls.certificate_path` is required.
|
||||
|
||||
Conflict with `tls.certificate`.
|
||||
|
||||
### tls.key
|
||||
|
||||
TLS server private key content.
|
||||
|
||||
Either `tls.key` or `tls.key_path` is required.
|
||||
|
||||
Conflict with `tls.key_path`.
|
||||
|
||||
### tls.key_path
|
||||
|
||||
TLS server private key path.
|
||||
|
||||
Either `tls.key` or `tls.key_path` is required.
|
||||
|
||||
Conflict with `tls.key`.
|
||||
|
||||
### tls.client_certificate
|
||||
|
||||
TLS CA certificate content, used to verify client certificates.
|
||||
|
||||
Either `tls.client_certificate` or `tls.client_certificate_path` is required.
|
||||
|
||||
Conflict with `tls.client_certificate_path`.
|
||||
|
||||
### tls.client_certificate_path
|
||||
|
||||
TLS CA certificate path, used to verify client certificates.
|
||||
|
||||
Either `tls.client_certificate` or `tls.client_certificate_path` is required.
|
||||
|
||||
Conflict with `tls.client_certificate`.
|
||||
|
||||
### tls.verify_client_certificate
|
||||
|
||||
OpenVPN client certificate policy, one of `require`, `optional` or `none`.
|
||||
|
||||
`require` will be used by default.
|
||||
|
||||
If set to `optional`, a client certificate is verified when provided, but clients without a certificate are allowed.
|
||||
|
||||
If set to `none`, client certificates are not requested.
|
||||
|
||||
This field does not replace `users`; when `users` is set, username/password authentication is still required.
|
||||
|
||||
### tls.control_wrap
|
||||
|
||||
OpenVPN control channel wrapping.
|
||||
|
||||
Equivalent to OpenVPN `tls-auth`, `tls-crypt` and `tls-crypt-v2`.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### tls.control_wrap.type
|
||||
|
||||
==Required==
|
||||
|
||||
Control channel wrapping type, one of `tls_auth`, `tls_crypt` or `tls_crypt_v2`.
|
||||
|
||||
For `tls_crypt_v2`, the key is the server key.
|
||||
|
||||
### tls.control_wrap.key
|
||||
|
||||
Control channel wrapping key content.
|
||||
|
||||
Either `tls.control_wrap.key` or `tls.control_wrap.key_path` is required.
|
||||
|
||||
Conflict with `tls.control_wrap.key_path`.
|
||||
|
||||
### tls.control_wrap.key_path
|
||||
|
||||
Control channel wrapping key path.
|
||||
|
||||
Either `tls.control_wrap.key` or `tls.control_wrap.key_path` is required.
|
||||
|
||||
Conflict with `tls.control_wrap.key`.
|
||||
|
||||
### tls.control_wrap.direction
|
||||
|
||||
OpenVPN `tls-auth` key direction, one of `server` or `client`.
|
||||
|
||||
Only available when `tls.control_wrap.type` is `tls_auth`.
|
||||
|
||||
`server` maps to OpenVPN key direction `0`, and `client` maps to `1`; by convention servers use `0` and clients use `1`.
|
||||
|
||||
If empty, the key is used bidirectionally, matching an omitted `key-direction` on both peers.
|
||||
|
||||
### data_ciphers
|
||||
|
||||
Allowed OpenVPN data channel ciphers.
|
||||
|
||||
`AES-256-GCM`, `AES-128-GCM` and `CHACHA20-POLY1305` are used by default.
|
||||
|
||||
### data_ciphers_fallback
|
||||
|
||||
OpenVPN data channel cipher for legacy clients that do not support cipher negotiation.
|
||||
|
||||
Equivalent to OpenVPN `data-ciphers-fallback`.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### auth
|
||||
|
||||
OpenVPN data channel authentication digest.
|
||||
|
||||
`SHA1` will be used by default, matching the upstream default; it only applies to non-AEAD data ciphers and `tls_auth`.
|
||||
|
||||
### push
|
||||
|
||||
Options pushed to clients.
|
||||
|
||||
### push.routes
|
||||
|
||||
Routes to push to clients.
|
||||
|
||||
IPv4 and IPv6 prefixes can be mixed.
|
||||
|
||||
### push.dns
|
||||
|
||||
DNS server addresses to push to clients.
|
||||
|
||||
### push.redirect_gateway
|
||||
|
||||
Push `redirect-gateway` to clients, which routes client traffic through the VPN according to `push.redirect_gateway_flags`.
|
||||
|
||||
When `push.redirect_gateway_flags` is empty, `def1` is used by default.
|
||||
|
||||
### push.redirect_gateway_flags
|
||||
|
||||
OpenVPN `redirect-gateway` flags to push to clients.
|
||||
|
||||
Only available when `push.redirect_gateway` is enabled.
|
||||
|
||||
`def1` is used by default.
|
||||
|
||||
### push.block_outside_dns
|
||||
|
||||
Push `block-outside-dns` to clients, which blocks DNS queries outside the VPN on Windows clients.
|
||||
|
||||
### keepalive_interval
|
||||
|
||||
OpenVPN keepalive ping interval to push to clients.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### keepalive_timeout
|
||||
|
||||
OpenVPN keepalive ping timeout to push to clients.
|
||||
|
||||
Disabled by default.
|
||||
|
||||
### renegotiate_interval
|
||||
|
||||
OpenVPN TLS renegotiation interval.
|
||||
|
||||
If empty or set to `0s`, the OpenVPN default `1h` is used.
|
||||
|
||||
### udp_timeout
|
||||
|
||||
UDP NAT expiration time for traffic through the OpenVPN interface.
|
||||
|
||||
`5m` will be used by default.
|
||||
@@ -0,0 +1,319 @@
|
||||
# OpenVPN 服务器
|
||||
|
||||
!!! question "自 sing-box 1.14.0 起"
|
||||
|
||||
## 结构
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "openvpn-server",
|
||||
"tag": "ovpn-server",
|
||||
|
||||
... // 监听字段
|
||||
|
||||
"system": false,
|
||||
"name": "",
|
||||
"mtu": 1500,
|
||||
"network": "udp",
|
||||
"max_clients": 1024,
|
||||
"address": [],
|
||||
"topology": "subnet",
|
||||
"users": [
|
||||
{
|
||||
"username": "",
|
||||
"password": ""
|
||||
}
|
||||
],
|
||||
"tls": {
|
||||
"certificate": [],
|
||||
"certificate_path": "",
|
||||
"key": [],
|
||||
"key_path": "",
|
||||
"client_certificate": [],
|
||||
"client_certificate_path": "",
|
||||
"verify_client_certificate": "require",
|
||||
"control_wrap": {
|
||||
"type": "tls_crypt",
|
||||
"key": [],
|
||||
"key_path": "",
|
||||
"direction": ""
|
||||
}
|
||||
},
|
||||
"data_ciphers": [],
|
||||
"data_ciphers_fallback": "",
|
||||
"auth": "",
|
||||
"push": {
|
||||
"routes": [],
|
||||
"dns": [],
|
||||
"redirect_gateway": false,
|
||||
"redirect_gateway_flags": [],
|
||||
"block_outside_dns": false
|
||||
},
|
||||
"keepalive_interval": "",
|
||||
"keepalive_timeout": "",
|
||||
"renegotiate_interval": "",
|
||||
"udp_timeout": ""
|
||||
}
|
||||
```
|
||||
|
||||
!!! note ""
|
||||
|
||||
当内容只有一项时,可以忽略 JSON 数组 [] 标签
|
||||
|
||||
## 监听字段
|
||||
|
||||
参阅 [监听字段](/zh/configuration/shared/listen/)。
|
||||
|
||||
## 字段
|
||||
|
||||
### system
|
||||
|
||||
使用系统接口。
|
||||
|
||||
需要特权且不能与已有系统接口冲突。
|
||||
|
||||
如果禁用,sing-box 将使用内部网络栈。
|
||||
|
||||
### name
|
||||
|
||||
系统接口的自定义接口名称。
|
||||
|
||||
默认使用自动生成的 `ovpn` 接口名称。
|
||||
|
||||
### mtu
|
||||
|
||||
OpenVPN 接口 MTU。
|
||||
|
||||
默认使用 `1500`。
|
||||
|
||||
### network
|
||||
|
||||
OpenVPN 传输网络,`udp` 或 `tcp` 之一。
|
||||
|
||||
默认使用 `udp`。
|
||||
|
||||
每个端点仅服务一种传输网络;如需同时服务 TCP 与 UDP,
|
||||
需要配置两个端点并使用互不重叠的 `address` 子网,
|
||||
与上游 OpenVPN 需要两个服务进程一致。
|
||||
|
||||
### max_clients
|
||||
|
||||
已建立与握手中的 TLS 客户端会话的最大数量。
|
||||
|
||||
默认使用 `1024`。该值必须小于 OpenVPN peer-id 空间的大小 `16777216`。
|
||||
|
||||
### address
|
||||
|
||||
==必填==
|
||||
|
||||
OpenVPN 服务器地址前缀列表。
|
||||
|
||||
最多支持一个 IPv4 前缀和一个 IPv6 前缀。
|
||||
|
||||
前缀地址被分配给服务器接口。掩码后的前缀用作客户端地址池和路由。
|
||||
|
||||
第一个 IPv4 和 IPv6 前缀地址用作端点的本地地址。
|
||||
|
||||
### topology
|
||||
|
||||
推送给客户端的 OpenVPN topology,`subnet`、`p2p` 或 `net30` 之一。
|
||||
|
||||
默认使用 `subnet`。
|
||||
|
||||
### users
|
||||
|
||||
OpenVPN 用户名/密码用户列表。
|
||||
|
||||
如果设置,客户端除了通过 `tls.verify_client_certificate` 配置的证书策略外,还必须通过用户名/密码认证。
|
||||
|
||||
### users.username
|
||||
|
||||
用户名。
|
||||
|
||||
### users.password
|
||||
|
||||
密码。
|
||||
|
||||
### tls
|
||||
|
||||
==必填==
|
||||
|
||||
OpenVPN 控制信道 TLS 配置。
|
||||
|
||||
### tls.certificate
|
||||
|
||||
TLS 服务器证书内容。
|
||||
|
||||
`tls.certificate` 或 `tls.certificate_path` 必填其一。
|
||||
|
||||
与 `tls.certificate_path` 冲突。
|
||||
|
||||
### tls.certificate_path
|
||||
|
||||
TLS 服务器证书路径。
|
||||
|
||||
`tls.certificate` 或 `tls.certificate_path` 必填其一。
|
||||
|
||||
与 `tls.certificate` 冲突。
|
||||
|
||||
### tls.key
|
||||
|
||||
TLS 服务器私钥内容。
|
||||
|
||||
`tls.key` 或 `tls.key_path` 必填其一。
|
||||
|
||||
与 `tls.key_path` 冲突。
|
||||
|
||||
### tls.key_path
|
||||
|
||||
TLS 服务器私钥路径。
|
||||
|
||||
`tls.key` 或 `tls.key_path` 必填其一。
|
||||
|
||||
与 `tls.key` 冲突。
|
||||
|
||||
### tls.client_certificate
|
||||
|
||||
TLS CA 证书内容,用于验证客户端证书。
|
||||
|
||||
`tls.client_certificate` 或 `tls.client_certificate_path` 必填其一。
|
||||
|
||||
与 `tls.client_certificate_path` 冲突。
|
||||
|
||||
### tls.client_certificate_path
|
||||
|
||||
TLS CA 证书路径,用于验证客户端证书。
|
||||
|
||||
`tls.client_certificate` 或 `tls.client_certificate_path` 必填其一。
|
||||
|
||||
与 `tls.client_certificate` 冲突。
|
||||
|
||||
### tls.verify_client_certificate
|
||||
|
||||
OpenVPN 客户端证书策略,`require`、`optional` 或 `none` 之一。
|
||||
|
||||
默认使用 `require`。
|
||||
|
||||
设为 `optional` 时,客户端提供证书则验证,不提供证书的客户端也被允许。
|
||||
|
||||
设为 `none` 时,不请求客户端证书。
|
||||
|
||||
该字段不替代 `users`;设置 `users` 后仍然要求用户名/密码认证。
|
||||
|
||||
### tls.control_wrap
|
||||
|
||||
OpenVPN 控制信道包装。
|
||||
|
||||
等价于 OpenVPN `tls-auth`、`tls-crypt` 和 `tls-crypt-v2`。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### tls.control_wrap.type
|
||||
|
||||
==必填==
|
||||
|
||||
控制信道包装类型,`tls_auth`、`tls_crypt` 或 `tls_crypt_v2` 之一。
|
||||
|
||||
对于 `tls_crypt_v2`,密钥为服务器密钥。
|
||||
|
||||
### tls.control_wrap.key
|
||||
|
||||
控制信道包装密钥内容。
|
||||
|
||||
`tls.control_wrap.key` 或 `tls.control_wrap.key_path` 必填其一。
|
||||
|
||||
与 `tls.control_wrap.key_path` 冲突。
|
||||
|
||||
### tls.control_wrap.key_path
|
||||
|
||||
控制信道包装密钥路径。
|
||||
|
||||
`tls.control_wrap.key` 或 `tls.control_wrap.key_path` 必填其一。
|
||||
|
||||
与 `tls.control_wrap.key` 冲突。
|
||||
|
||||
### tls.control_wrap.direction
|
||||
|
||||
OpenVPN `tls-auth` 密钥方向,`server` 或 `client` 之一。
|
||||
|
||||
仅当 `tls.control_wrap.type` 为 `tls_auth` 时可用。
|
||||
|
||||
`server` 对应 OpenVPN 密钥方向 `0`,`client` 对应 `1`;按照惯例服务器使用 `0`,客户端使用 `1`。
|
||||
|
||||
如果为空,密钥被双向使用,与两端均省略 `key-direction` 的行为一致。
|
||||
|
||||
### data_ciphers
|
||||
|
||||
允许的 OpenVPN 数据信道加密方式。
|
||||
|
||||
默认使用 `AES-256-GCM`、`AES-128-GCM` 和 `CHACHA20-POLY1305`。
|
||||
|
||||
### data_ciphers_fallback
|
||||
|
||||
用于不支持加密方式协商的遗留客户端的 OpenVPN 数据信道加密方式。
|
||||
|
||||
等价于 OpenVPN `data-ciphers-fallback`。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### auth
|
||||
|
||||
OpenVPN 数据信道认证摘要。
|
||||
|
||||
默认使用 `SHA1`,与上游默认值一致;仅对非 AEAD 数据信道加密方式和 `tls_auth` 生效。
|
||||
|
||||
### push
|
||||
|
||||
推送给客户端的选项。
|
||||
|
||||
### push.routes
|
||||
|
||||
推送给客户端的路由。
|
||||
|
||||
IPv4 和 IPv6 前缀可以混用。
|
||||
|
||||
### push.dns
|
||||
|
||||
推送给客户端的 DNS 服务器地址。
|
||||
|
||||
### push.redirect_gateway
|
||||
|
||||
向客户端推送 `redirect-gateway`,根据 `push.redirect_gateway_flags` 通过 VPN 路由客户端流量。
|
||||
|
||||
当 `push.redirect_gateway_flags` 为空时,默认使用 `def1`。
|
||||
|
||||
### push.redirect_gateway_flags
|
||||
|
||||
向客户端推送的 OpenVPN `redirect-gateway` flag。
|
||||
|
||||
仅当启用 `push.redirect_gateway` 时可用。
|
||||
|
||||
默认使用 `def1`。
|
||||
|
||||
### push.block_outside_dns
|
||||
|
||||
向客户端推送 `block-outside-dns`,在 Windows 客户端上阻止 VPN 之外的 DNS 查询。
|
||||
|
||||
### keepalive_interval
|
||||
|
||||
推送给客户端的 OpenVPN keepalive ping 间隔。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### keepalive_timeout
|
||||
|
||||
推送给客户端的 OpenVPN keepalive ping 超时。
|
||||
|
||||
默认禁用。
|
||||
|
||||
### renegotiate_interval
|
||||
|
||||
OpenVPN TLS 重协商间隔。
|
||||
|
||||
如果为空或设为 `0s`,使用 OpenVPN 默认值 `1h`。
|
||||
|
||||
### udp_timeout
|
||||
|
||||
通过 OpenVPN 接口的流量的 UDP NAT 过期时间。
|
||||
|
||||
默认使用 `5m`。
|
||||
@@ -60,7 +60,7 @@ Example: `$HOME/.tailscale`
|
||||
|
||||
!!! note
|
||||
|
||||
Auth key is not required. By default, sing-box will log the login URL (or popup a notification on graphical clients).
|
||||
Auth key is not required. By default, sing-box will log the login URL.
|
||||
|
||||
The auth key to create the node. If the node is already created (from state previously stored), then this field is not
|
||||
used.
|
||||
@@ -208,3 +208,7 @@ Refuse local and remote TCP and Unix-socket forwarding, including SSH agent forw
|
||||
Dial Fields in Tailscale endpoints only control how it connects to the control plane and have nothing to do with actual connections.
|
||||
|
||||
See [Dial Fields](/configuration/shared/dial/) for details.
|
||||
|
||||
### Interactive authentication
|
||||
|
||||
Use `Tools` > `Endpoints` in the sing-box dashboard or any sing-box graphical client to authenticate and manage the endpoint.
|
||||
|
||||
@@ -60,7 +60,7 @@ icon: material/new-box
|
||||
|
||||
!!! note
|
||||
|
||||
认证密钥不是必需的。默认情况下,sing-box 将记录登录 URL(或在图形客户端上弹出通知)。
|
||||
认证密钥不是必需的。默认情况下,sing-box 将记录登录 URL。
|
||||
|
||||
用于创建节点的认证密钥。如果节点已经创建(从之前存储的状态),则不使用此字段。
|
||||
|
||||
@@ -207,3 +207,7 @@ UDP NAT 过期时间。
|
||||
Tailscale 端点中的拨号字段仅控制它如何连接到控制平面,与实际连接无关。
|
||||
|
||||
参阅 [拨号字段](/zh/configuration/shared/dial/) 了解详情。
|
||||
|
||||
### 交互式认证
|
||||
|
||||
在 sing-box dashboard 或任意 sing-box 图形客户端的 `工具` > `端点` 中认证和管理 endpoint。
|
||||
|
||||
Reference in New Issue
Block a user