Add openvpn and openconnect

This commit is contained in:
世界
2026-08-30 17:41:43 +08:00
parent 23ca3b415f
commit 2df7a9bac7
65 changed files with 12495 additions and 386 deletions
+7 -4
View File
@@ -19,10 +19,13 @@ An endpoint is a protocol with inbound and outbound behavior.
### Fields
| Type | Format |
|-------------|---------------------------|
| `wireguard` | [WireGuard](./wireguard/) |
| `tailscale` | [Tailscale](./tailscale/) |
| Type | Format |
|------------------|-----------------------------------------|
| `wireguard` | [WireGuard](./wireguard/) |
| `tailscale` | [Tailscale](./tailscale/) |
| `openconnect` | [OpenConnect Client](./openconnect/) |
| `openvpn-client` | [OpenVPN Client](./openvpn-client/) |
| `openvpn-server` | [OpenVPN Server](./openvpn-server/) |
#### tag
+7 -4
View File
@@ -19,10 +19,13 @@
### 字段
| 类型 | 格式 |
|-------------|---------------------------|
| `wireguard` | [WireGuard](./wireguard/) |
| `tailscale` | [Tailscale](./tailscale/) |
| 类型 | 格式 |
|------------------|-----------------------------------------|
| `wireguard` | [WireGuard](./wireguard/) |
| `tailscale` | [Tailscale](./tailscale/) |
| `openconnect` | [OpenConnect 客户端](./openconnect/) |
| `openvpn-client` | [OpenVPN 客户端](./openvpn-client/) |
| `openvpn-server` | [OpenVPN 服务器](./openvpn-server/) |
#### tag
+387
View File
@@ -0,0 +1,387 @@
# OpenConnect Client
!!! question "Since sing-box 1.14.0"
==Client only==
## Structure
```json
{
"type": "openconnect",
"tag": "oc-client",
"system": false,
"name": "",
"server": "vpn.example.com",
"flavor": "anyconnect",
"username": "",
"password": "",
"auth_group": "",
"token": {
"mode": "",
"secret": "",
"pin": "",
"password": "",
"device_id": "",
"counter": 0
},
"reported_os": "",
"user_agent": "",
"csd": {
"wrapper_path": ""
},
"hip": {
"wrapper_path": ""
},
"tncc": {
"wrapper_path": "",
"device_id": "",
"user_agent": "",
"machine_identification_enabled": false,
"certificates": [
{
"certificate": [],
"certificate_path": ""
}
]
},
"no_udp": false,
"allow_insecure_crypto": false,
"tls": {
"certificate_authority": [],
"certificate_authority_path": "",
"client_certificate": [],
"client_certificate_path": "",
"client_key": [],
"client_key_path": "",
"client_key_password": "",
"mca_certificate": [],
"mca_certificate_path": "",
"mca_key": [],
"mca_key_path": "",
"mca_key_password": ""
},
"form_entries": [
{
"form_id": "",
"submission_key": "",
"name": "",
"value": "",
"promote": false
}
],
... // Dial Fields
}
```
!!! note ""
You can ignore the JSON Array [] tag when the content is only one item.
## Fields
### system
Use a system interface.
Requires privilege and cannot conflict with existing system interfaces.
If disabled, sing-box uses the internal network stack.
### name
Custom interface name for the system interface.
An automatically generated `oc` interface name is used by default.
### server
==Required==
OpenConnect VPN server HTTPS URL.
The `https://` scheme is added if omitted. URL user information, queries, and fragments are not supported.
### flavor
OpenConnect protocol flavor, one of `anyconnect`, `gp`, `fortinet`, `f5`, `pulse`, or `nc`.
`anyconnect` is used by default.
### username
Username used to fill matching authentication form fields.
### password
Password used to fill matching authentication form fields.
### auth_group
Authentication group used to preselect a matching group, realm, domain, or gateway choice when supported by the selected flavor.
### token
Software token configuration for automatically answering matching token fields.
### token.mode
==Required==
Software token mode, one of:
- `totp`: Time-based One-Time Password.
- `hotp`: HMAC-based One-Time Password.
- `stoken`: RSA SecurID software token.
### token.secret
==Required==
Software token secret.
For `totp` and `hotp`, this can be a Base32 secret, a `base32:`-prefixed secret, or an `otpauth://` URI of the matching type.
For `stoken`, this is the encoded RSA SecurID CTF token content.
### token.pin
RSA SecurID PIN for `stoken` mode.
### token.password
Password for decrypting a password-protected RSA SecurID token in `stoken` mode.
### token.device_id
Device ID for decrypting a device-bound RSA SecurID token in `stoken` mode.
### token.counter
Initial counter for `hotp` mode.
If zero, the counter from an `otpauth://` URI is used when present; otherwise the counter starts at zero.
### reported_os
Operating system identity reported to the VPN server when supported by the selected flavor.
For `anyconnect`, `gp`, and `pulse`, the supported values are `linux`, `linux-64`, `win`, `mac-intel`, `android`, and `apple-ios`.
`anyconnect` uses `linux-64` by default. `gp` and `pulse` select a value based on the system platform by default.
### user_agent
User agent reported to the VPN server when supported by the selected flavor.
The default is flavor-specific.
### csd
AnyConnect CSD/host scan compliance options.
Built-in CSD handling is used by default when requested by the server.
### csd.wrapper_path
Path to an external AnyConnect CSD wrapper executable.
Built-in CSD handling is used if empty.
### hip
GlobalProtect HIP check and report options.
Built-in HIP reporting is used by default when requested by the server.
### hip.wrapper_path
Path to an external GlobalProtect HIP report wrapper executable.
Built-in HIP reporting is used if empty.
### tncc
Network Connect TNCC compliance options.
Built-in TNCC handling is used by default when requested by the server.
### tncc.wrapper_path
Path to an external Network Connect TNCC wrapper executable.
Built-in TNCC handling is used if empty.
Conflict with `tncc.device_id`, `tncc.user_agent`, `tncc.machine_identification_enabled`, and `tncc.certificates`.
### tncc.device_id
Device ID reported by the built-in TNCC handler.
Conflict with `tncc.wrapper_path`.
### tncc.user_agent
User agent used by the built-in TNCC handler.
`Neoteris HC Http` is used by default.
Conflict with `tncc.wrapper_path`.
### tncc.machine_identification_enabled
Enable built-in TNCC machine identification, including the platform, hostname, and observed MAC addresses.
Conflict with `tncc.wrapper_path`.
### tncc.certificates
Machine certificates used by the built-in TNCC handler to answer certificate requests.
Requires `tncc.machine_identification_enabled`.
Conflict with `tncc.wrapper_path`.
### tncc.certificates.certificate
TNCC machine certificate content in PEM format.
Conflict with `tncc.certificates.certificate_path`.
### tncc.certificates.certificate_path
TNCC machine certificate path in PEM format.
Conflict with `tncc.certificates.certificate`.
### no_udp
Disable the DTLS or ESP secondary data channel and use the TLS data channel only.
### allow_insecure_crypto
Allow deprecated TLS and DTLS versions and cipher suites required by legacy VPN servers.
Disabled by default. This option does not disable server certificate verification.
### tls
OpenConnect TLS configuration.
### tls.certificate_authority
Additional trusted CA certificate content in PEM format.
The certificates are added to the system certificate pool.
Conflict with `tls.certificate_authority_path`.
### tls.certificate_authority_path
Path to additional trusted CA certificates in PEM format.
The certificates are added to the system certificate pool.
Conflict with `tls.certificate_authority`.
### tls.client_certificate
Client certificate chain content in PEM format.
Conflict with `tls.client_certificate_path`.
### tls.client_certificate_path
Client certificate chain path in PEM format.
Conflict with `tls.client_certificate`.
### tls.client_key
Client private key content in PEM format.
Conflict with `tls.client_key_path`.
### tls.client_key_path
Client private key path in PEM format.
Conflict with `tls.client_key`.
The client certificate and key must both be set or both be empty.
### tls.client_key_password
Password for the encrypted client private key.
### tls.mca_certificate
AnyConnect multiple-certificate authentication (MCA) certificate chain content in PEM format.
Conflict with `tls.mca_certificate_path`.
### tls.mca_certificate_path
AnyConnect multiple-certificate authentication (MCA) certificate chain path in PEM format.
Conflict with `tls.mca_certificate`.
### tls.mca_key
AnyConnect multiple-certificate authentication (MCA) private key content in PEM format.
Conflict with `tls.mca_key_path`.
### tls.mca_key_path
AnyConnect multiple-certificate authentication (MCA) private key path in PEM format.
Conflict with `tls.mca_key`.
The MCA certificate and key must both be set or both be empty.
### tls.mca_key_password
Password for the encrypted MCA private key.
### form_entries
Authentication form field overrides.
An entry matches by `submission_key` when set, or by the combination of `form_id` and `name`. Later matching entries take precedence.
### form_entries.form_id
Authentication form identifier used with `form_entries.name` when `form_entries.submission_key` is empty.
### form_entries.submission_key
Authentication field submission key.
Either `form_entries.submission_key` or both `form_entries.form_id` and `form_entries.name` are required.
### form_entries.name
Authentication field name used with `form_entries.form_id` when `form_entries.submission_key` is empty.
### form_entries.value
Value supplied automatically for the matching authentication field.
Conflict with `form_entries.promote`.
### form_entries.promote
Ask for the matching authentication field interactively instead of supplying an automatic value.
Conflict with `form_entries.value`.
## Dial Fields
See [Dial Fields](/configuration/shared/dial/) for details.
## Interactive authentication
Use `Tools` > `Endpoints` in the sing-box dashboard or any sing-box graphical client to authenticate and manage the endpoint.
@@ -0,0 +1,387 @@
# OpenConnect 客户端
!!! question "自 sing-box 1.14.0 起"
==仅客户端==
## 结构
```json
{
"type": "openconnect",
"tag": "oc-client",
"system": false,
"name": "",
"server": "vpn.example.com",
"flavor": "anyconnect",
"username": "",
"password": "",
"auth_group": "",
"token": {
"mode": "",
"secret": "",
"pin": "",
"password": "",
"device_id": "",
"counter": 0
},
"reported_os": "",
"user_agent": "",
"csd": {
"wrapper_path": ""
},
"hip": {
"wrapper_path": ""
},
"tncc": {
"wrapper_path": "",
"device_id": "",
"user_agent": "",
"machine_identification_enabled": false,
"certificates": [
{
"certificate": [],
"certificate_path": ""
}
]
},
"no_udp": false,
"allow_insecure_crypto": false,
"tls": {
"certificate_authority": [],
"certificate_authority_path": "",
"client_certificate": [],
"client_certificate_path": "",
"client_key": [],
"client_key_path": "",
"client_key_password": "",
"mca_certificate": [],
"mca_certificate_path": "",
"mca_key": [],
"mca_key_path": "",
"mca_key_password": ""
},
"form_entries": [
{
"form_id": "",
"submission_key": "",
"name": "",
"value": "",
"promote": false
}
],
... // 拨号字段
}
```
!!! note ""
当内容只有一项时,可以忽略 JSON 数组 [] 标签。
## 字段
### system
使用系统接口。
需要权限,且不能与现有系统接口冲突。
禁用时,sing-box 使用内部网络栈。
### name
系统接口的自定义接口名称。
默认使用自动生成的 `oc` 接口名称。
### server
==必填==
OpenConnect VPN 服务器 HTTPS URL。
省略协议时会添加 `https://`。不支持 URL 用户信息、查询和片段。
### flavor
OpenConnect 协议 flavor,可选值为 `anyconnect`、`gp`、`fortinet`、`f5`、`pulse` 或 `nc`。
默认使用 `anyconnect`。
### username
用于填充匹配认证表单字段的用户名。
### password
用于填充匹配认证表单字段的密码。
### auth_group
认证组,用于在所选 flavor 支持时预选匹配的组、realm、domain 或 gateway 选项。
### token
用于自动回答匹配 token 字段的软件 token 配置。
### token.mode
==必填==
软件 token 模式,可选值为:
- `totp`:基于时间的一次性密码。
- `hotp`:基于 HMAC 的一次性密码。
- `stoken`:RSA SecurID 软件 token。
### token.secret
==必填==
软件 token 密钥。
对于 `totp` 和 `hotp`,可以是 Base32 密钥、带 `base32:` 前缀的密钥或类型匹配的 `otpauth://` URI。
对于 `stoken`,这是编码后的 RSA SecurID CTF token 内容。
### token.pin
`stoken` 模式的 RSA SecurID PIN。
### token.password
`stoken` 模式下用于解密受密码保护的 RSA SecurID token 的密码。
### token.device_id
`stoken` 模式下用于解密设备绑定 RSA SecurID token 的设备 ID。
### token.counter
`hotp` 模式的初始计数器。
为零时,如果 `otpauth://` URI 中存在计数器,则使用该计数器;否则从零开始。
### reported_os
所选 flavor 支持时向 VPN 服务器报告的操作系统标识。
对于 `anyconnect`、`gp` 和 `pulse`,支持的值为 `linux`、`linux-64`、`win`、`mac-intel`、`android` 和 `apple-ios`。
`anyconnect` 默认使用 `linux-64`。`gp` 和 `pulse` 默认根据系统平台选择值。
### user_agent
所选 flavor 支持时向 VPN 服务器报告的 User-Agent。
默认值由 flavor 决定。
### csd
AnyConnect CSD/host scan 合规性选项。
服务器请求 CSD 时,默认使用内置 CSD 处理。
### csd.wrapper_path
外部 AnyConnect CSD wrapper 可执行文件的路径。
为空时使用内置 CSD 处理。
### hip
GlobalProtect HIP 检查和报告选项。
服务器请求 HIP 时,默认使用内置 HIP 报告。
### hip.wrapper_path
外部 GlobalProtect HIP report wrapper 可执行文件的路径。
为空时使用内置 HIP 报告。
### tncc
Network Connect TNCC 合规性选项。
服务器请求 TNCC 时,默认使用内置 TNCC 处理。
### tncc.wrapper_path
外部 Network Connect TNCC wrapper 可执行文件的路径。
为空时使用内置 TNCC 处理。
与 `tncc.device_id`、`tncc.user_agent`、`tncc.machine_identification_enabled` 和 `tncc.certificates` 冲突。
### tncc.device_id
内置 TNCC 处理程序报告的设备 ID。
与 `tncc.wrapper_path` 冲突。
### tncc.user_agent
内置 TNCC 处理程序使用的 User-Agent。
默认使用 `Neoteris HC Http`。
与 `tncc.wrapper_path` 冲突。
### tncc.machine_identification_enabled
启用内置 TNCC 机器标识,包括平台、主机名和观测到的 MAC 地址。
与 `tncc.wrapper_path` 冲突。
### tncc.certificates
内置 TNCC 处理程序用于回答证书请求的机器证书。
需要启用 `tncc.machine_identification_enabled`。
与 `tncc.wrapper_path` 冲突。
### tncc.certificates.certificate
PEM 格式的 TNCC 机器证书内容。
与 `tncc.certificates.certificate_path` 冲突。
### tncc.certificates.certificate_path
PEM 格式的 TNCC 机器证书路径。
与 `tncc.certificates.certificate` 冲突。
### no_udp
禁用 DTLS 或 ESP 辅助数据通道,仅使用 TLS 数据通道。
### allow_insecure_crypto
允许旧版 VPN 服务器所需的已弃用 TLS 和 DTLS 版本及密码套件。
默认禁用。此选项不会禁用服务器证书验证。
### tls
OpenConnect TLS 配置。
### tls.certificate_authority
PEM 格式的附加受信任 CA 证书内容。
这些证书会添加到系统证书池。
与 `tls.certificate_authority_path` 冲突。
### tls.certificate_authority_path
PEM 格式的附加受信任 CA 证书路径。
这些证书会添加到系统证书池。
与 `tls.certificate_authority` 冲突。
### tls.client_certificate
PEM 格式的客户端证书链内容。
与 `tls.client_certificate_path` 冲突。
### tls.client_certificate_path
PEM 格式的客户端证书链路径。
与 `tls.client_certificate` 冲突。
### tls.client_key
PEM 格式的客户端私钥内容。
与 `tls.client_key_path` 冲突。
### tls.client_key_path
PEM 格式的客户端私钥路径。
与 `tls.client_key` 冲突。
客户端证书和私钥必须同时设置或同时为空。
### tls.client_key_password
加密客户端私钥的密码。
### tls.mca_certificate
PEM 格式的 AnyConnect 多证书认证(MCA)证书链内容。
与 `tls.mca_certificate_path` 冲突。
### tls.mca_certificate_path
PEM 格式的 AnyConnect 多证书认证(MCA)证书链路径。
与 `tls.mca_certificate` 冲突。
### tls.mca_key
PEM 格式的 AnyConnect 多证书认证(MCA)私钥内容。
与 `tls.mca_key_path` 冲突。
### tls.mca_key_path
PEM 格式的 AnyConnect 多证书认证(MCA)私钥路径。
与 `tls.mca_key` 冲突。
MCA 证书和私钥必须同时设置或同时为空。
### tls.mca_key_password
加密 MCA 私钥的密码。
### form_entries
认证表单字段覆盖。
设置 `submission_key` 时按该字段匹配,否则按 `form_id` 和 `name` 的组合匹配。后面的匹配项优先。
### form_entries.form_id
`form_entries.submission_key` 为空时,与 `form_entries.name` 一起使用的认证表单标识符。
### form_entries.submission_key
认证字段提交键。
`form_entries.submission_key` 或 `form_entries.form_id` 与 `form_entries.name` 的组合之一必填。
### form_entries.name
`form_entries.submission_key` 为空时,与 `form_entries.form_id` 一起使用的认证字段名称。
### form_entries.value
自动提供给匹配认证字段的值。
与 `form_entries.promote` 冲突。
### form_entries.promote
交互询问匹配的认证字段,而不是自动提供值。
与 `form_entries.value` 冲突。
## 拨号字段
参阅[拨号字段](/zh/configuration/shared/dial/)了解详情。
## 交互式认证
在 sing-box dashboard 或任意 sing-box 图形客户端的 `工具` > `端点` 中认证和管理 endpoint。
@@ -0,0 +1,501 @@
# OpenVPN Client
!!! question "Since sing-box 1.14.0"
## Structure
```json
{
"type": "openvpn-client",
"tag": "ovpn-client",
"server": "127.0.0.1",
"server_port": 1194,
"servers": [
{
"server": "127.0.0.1",
"server_port": 1194,
"network": "udp"
}
],
"remote_random": false,
"network": "udp",
"username": "",
"password": "",
"auth_retry": "none",
"static_challenge": "",
"static_challenge_echo": false,
"tls": {
"server_name": "",
"server_name_type": "name",
"certificate": [],
"certificate_path": "",
"client_certificate": [],
"client_certificate_path": "",
"client_key": [],
"client_key_path": "",
"peer_fingerprint": [],
"crl_path": "",
"remote_certificate_ku": [],
"remote_certificate_eku": "",
"version_min": "1.2",
"version_max": "",
"cipher": "",
"groups": "",
"control_wrap": {
"type": "",
"key": [],
"key_path": "",
"direction": ""
}
},
"data_ciphers": [],
"data_ciphers_fallback": "",
"auth": "",
"mss_fix": 0,
"fragment": 0,
"compression": "",
"compression_lzo": "",
"allow_compression": "no",
"route_no_pull": false,
"pull_filters": [
{
"action": "ignore",
"text": "route "
}
],
"routes": [],
"route_gateway": "",
"route_metric": 0,
"redirect_gateway": false,
"redirect_gateway_flags": [],
"keepalive_interval": "",
"keepalive_timeout": "",
"renegotiate_interval": "",
"explicit_exit_notify": 0,
"system": false,
"name": "",
"mtu": 1500,
"udp_timeout": "",
... // Dial Fields
}
```
!!! note ""
You can ignore the JSON Array [] tag when the content is only one item.
## Fields
### server
OpenVPN server address.
Either `server` or `servers` is required.
Conflict with `servers`.
### server_port
OpenVPN server port.
Required when `server` is set.
### servers
List of OpenVPN servers.
The client tries the servers in order and moves to the next server when a connection fails.
Either `server` or `servers` is required.
Conflict with `server`.
### servers.server
==Required==
OpenVPN server address.
### servers.server_port
==Required==
OpenVPN server port.
### servers.network
OpenVPN transport network for this server, one of `udp` or `tcp`.
The top-level `network` is used by default.
### remote_random
Randomize the `servers` order before connecting.
Disabled by default.
### network
Default OpenVPN transport network, one of `udp` or `tcp`.
`udp` is used by default.
This value applies to `server` and to `servers` entries without their own `network`.
### username
Username for OpenVPN username/password authentication.
### password
Password for OpenVPN username/password authentication.
### auth_retry
Behavior after username/password authentication fails, one of `none`, `nointeract`, or `interact`.
`none` is used by default and treats a permanent authentication failure as terminal.
`nointeract` and `interact` allow authentication retries.
### static_challenge
Static challenge text shown when requesting an authentication response.
### static_challenge_echo
Show the static challenge response as plain text.
### tls
==Required==
OpenVPN control channel TLS configuration.
### tls.server_name
Expected server certificate name.
Certificate name verification is disabled if empty. The certificate chain or fingerprint and server certificate usage are still verified.
### tls.server_name_type
Certificate field matched by `tls.server_name`, one of `subject`, `name`, or `name-prefix`.
`name` is used by default when `tls.server_name` is set.
`subject` matches the full certificate subject, `name` matches the common name exactly, and `name-prefix` matches a common name prefix.
### tls.certificate
Trusted CA certificate content.
One of `tls.certificate`, `tls.certificate_path`, or `tls.peer_fingerprint` is required.
Conflict with `tls.certificate_path`.
### tls.certificate_path
Trusted CA certificate path.
One of `tls.certificate`, `tls.certificate_path`, or `tls.peer_fingerprint` is required.
Conflict with `tls.certificate`.
### tls.client_certificate
Client certificate content.
Conflict with `tls.client_certificate_path`.
### tls.client_certificate_path
Client certificate path.
Conflict with `tls.client_certificate`.
### tls.client_key
Client private key content.
Conflict with `tls.client_key_path`.
### tls.client_key_path
Client private key path.
Conflict with `tls.client_key`.
The client certificate and key must both be set or both be empty.
### tls.peer_fingerprint
Allowed SHA-256 fingerprints of the server leaf certificate.
Each fingerprint must be 64 lowercase hexadecimal characters without separators.
When a trusted CA is also configured, both the certificate chain and fingerprint are verified. Without a trusted CA, the fingerprint, certificate validity period, configured name, and certificate usage are verified, but the certificate chain is not.
### tls.crl_path
Path to a PEM or DER certificate revocation list used to reject revoked server certificates.
The CRL signature and validity period are verified against the trusted certificate chain.
Disabled by default.
### tls.remote_certificate_ku
Required server certificate key usage masks, written as hexadecimal values in OpenVPN `remote-cert-ku` format.
Multiple values are combined, and all requested usages must be present.
Disabled by default.
### tls.remote_certificate_eku
Required server certificate extended key usage, one of `server` or `client`.
Disabled by default. The standard OpenVPN server certificate usage check still applies.
### tls.version_min
Minimum TLS version, one of `1.0`, `1.1`, `1.2`, or `1.3`.
`1.2` is used by default.
### tls.version_max
Maximum TLS version, one of `1.0`, `1.1`, `1.2`, or `1.3`.
The maximum supported version is used by default.
The value cannot be lower than `tls.version_min`.
### tls.cipher
Colon-separated OpenSSL cipher suite names allowed for TLS 1.2 and earlier.
The default TLS cipher suites are used when empty. TLS 1.3 cipher suites are not controlled by this field.
### tls.groups
Colon-separated TLS key exchange groups in preference order.
Supported groups are `X25519`, `SECP256R1`, `SECP384R1`, and `SECP521R1`, including their common OpenSSL and NIST aliases.
The default TLS groups are used when empty.
### tls.control_wrap
OpenVPN control channel wrapping.
Equivalent to OpenVPN `tls-auth`, `tls-crypt`, and `tls-crypt-v2`.
Disabled if empty.
### tls.control_wrap.type
Control channel wrapping type, one of `tls_auth`, `tls_crypt`, or `tls_crypt_v2`.
### tls.control_wrap.key
Control channel wrapping key content.
Conflict with `tls.control_wrap.key_path`.
### tls.control_wrap.key_path
Control channel wrapping key path.
Conflict with `tls.control_wrap.key`.
### tls.control_wrap.direction
`tls-auth` key direction, one of `server` or `client`.
Only available when `tls.control_wrap.type` is `tls_auth`. The key is used bidirectionally if empty.
### data_ciphers
Allowed OpenVPN data channel ciphers.
`AES-256-GCM`, `AES-128-GCM`, and `CHACHA20-POLY1305` are used by default.
### data_ciphers_fallback
Data channel cipher for peers that do not support cipher negotiation.
Disabled by default.
### auth
OpenVPN data channel authentication digest.
`SHA1` is used by default. It only applies to non-AEAD data ciphers and `tls_auth`.
### mss_fix
Maximum OpenVPN UDP packet size used to clamp the MSS of TCP connections sent through the tunnel.
This prevents TCP packets from exceeding the path MTU after OpenVPN encapsulation.
Disabled when `0`.
### fragment
Maximum OpenVPN UDP packet size used for OpenVPN data channel fragmentation.
Disabled when `0`. A non-zero value must be at least `68`.
Conflict with TCP transport.
### compression
OpenVPN `compress` framing mode, one of `none`, `no`, `lz4`, `lz4-v2`, `stub`, `stub-v2`, `disabled`, or `off`.
Disabled by default.
Compression can weaken traffic confidentiality. Prefer `stub` or `stub-v2` only when framing compatibility is required.
### compression_lzo
OpenVPN `comp-lzo` mode, one of `none`, `no`, `yes`, `adaptive`, `asym`, `disabled`, or `off`.
Disabled by default.
Compression can weaken traffic confidentiality. Enable it only when required by the server.
### allow_compression
Policy for compression pushed by the server, one of `no`, `asym`, or `yes`.
`no` is used by default and permits only compression stub framing. `asym` accepts compressed packets from the server but does not compress outgoing packets. `yes` permits compression in both directions.
Conflict with non-stub compression enabled by `compression` or `compression_lzo` when set to `no`.
### route_no_pull
Ignore routes, route gateways, and redirect-gateway options pushed by the server.
Other pushed options are still accepted, and locally configured `routes` are still used.
Disabled by default.
### pull_filters
Ordered filters for options pushed by the server.
The first filter whose `text` is a case-insensitive prefix of the complete pushed option is applied. Options that match no filter are accepted.
### pull_filters.action
==Required==
Filter action, one of `accept`, `ignore`, or `reject`.
`accept` applies the option, `ignore` discards it, and `reject` terminates the connection.
### pull_filters.text
==Required==
Case-insensitive prefix to match against the pushed option name and value.
For example, `route ` matches pushed IPv4 route options without matching `route-gateway`.
### routes
IPv4 and IPv6 route prefixes routed through the OpenVPN endpoint.
These routes are used in addition to routes accepted from the server.
### route_gateway
IPv4 gateway for routes through the OpenVPN endpoint.
When empty, the VPN gateway received from the server is used.
### route_metric
Default metric for routes through the OpenVPN endpoint.
The platform default is used when `0`.
### redirect_gateway
Route all IPv4 traffic through the OpenVPN endpoint.
Disabled by default.
### redirect_gateway_flags
OpenVPN `redirect-gateway` flags.
`!ipv4` disables the IPv4 default route, and `ipv6` also routes all IPv6 traffic through the endpoint. Other OpenVPN flags are accepted for compatibility but do not change endpoint routing.
Empty by default.
### keepalive_interval
Interval for sending OpenVPN keepalive ping packets.
Locally configured values take precedence over server-pushed keepalive values.
Disabled by default.
### keepalive_timeout
Time without receiving OpenVPN traffic before the connection is restarted.
Locally configured values take precedence over server-pushed keepalive values.
Disabled by default.
### renegotiate_interval
OpenVPN TLS renegotiation interval.
If empty or set to `0s`, the OpenVPN default `1h` is used.
### explicit_exit_notify
Number of OpenVPN exit notifications sent when closing a UDP connection.
Disabled when `0`. At most `10` notifications are sent.
### system
Use a system interface.
Requires privilege and cannot conflict with existing system interfaces.
If disabled, sing-box uses the internal network stack.
### name
Custom interface name for the system interface.
An automatically generated `ovpn` interface name is used by default.
### mtu
OpenVPN interface MTU.
When empty, `1500` is used until a server-pushed MTU is received.
### udp_timeout
UDP NAT expiration time.
`5m` is used by default.
## Dial Fields
See [Dial Fields](/configuration/shared/dial/) for details.
## Interactive authentication
Use `Tools` > `Endpoints` in the sing-box dashboard or any sing-box graphical client to authenticate and manage the endpoint.
@@ -0,0 +1,501 @@
# OpenVPN 客户端
!!! question "自 sing-box 1.14.0 起"
## 结构
```json
{
"type": "openvpn-client",
"tag": "ovpn-client",
"server": "127.0.0.1",
"server_port": 1194,
"servers": [
{
"server": "127.0.0.1",
"server_port": 1194,
"network": "udp"
}
],
"remote_random": false,
"network": "udp",
"username": "",
"password": "",
"auth_retry": "none",
"static_challenge": "",
"static_challenge_echo": false,
"tls": {
"server_name": "",
"server_name_type": "name",
"certificate": [],
"certificate_path": "",
"client_certificate": [],
"client_certificate_path": "",
"client_key": [],
"client_key_path": "",
"peer_fingerprint": [],
"crl_path": "",
"remote_certificate_ku": [],
"remote_certificate_eku": "",
"version_min": "1.2",
"version_max": "",
"cipher": "",
"groups": "",
"control_wrap": {
"type": "",
"key": [],
"key_path": "",
"direction": ""
}
},
"data_ciphers": [],
"data_ciphers_fallback": "",
"auth": "",
"mss_fix": 0,
"fragment": 0,
"compression": "",
"compression_lzo": "",
"allow_compression": "no",
"route_no_pull": false,
"pull_filters": [
{
"action": "ignore",
"text": "route "
}
],
"routes": [],
"route_gateway": "",
"route_metric": 0,
"redirect_gateway": false,
"redirect_gateway_flags": [],
"keepalive_interval": "",
"keepalive_timeout": "",
"renegotiate_interval": "",
"explicit_exit_notify": 0,
"system": false,
"name": "",
"mtu": 1500,
"udp_timeout": "",
... // 拨号字段
}
```
!!! note ""
当内容只有一项时,可以忽略 JSON 数组 [] 标签。
## 字段
### server
OpenVPN 服务器地址。
`server` 和 `servers` 之一必填。
与 `servers` 冲突。
### server_port
OpenVPN 服务器端口。
设置 `server` 时必填。
### servers
OpenVPN 服务器列表。
客户端按顺序尝试服务器,并在连接失败时尝试下一台服务器。
`server` 和 `servers` 之一必填。
与 `server` 冲突。
### servers.server
==必填==
OpenVPN 服务器地址。
### servers.server_port
==必填==
OpenVPN 服务器端口。
### servers.network
该服务器的 OpenVPN 传输网络,可选值为 `udp` 或 `tcp`。
默认使用顶层 `network`。
### remote_random
连接前随机排列 `servers` 顺序。
默认禁用。
### network
默认 OpenVPN 传输网络,可选值为 `udp` 或 `tcp`。
默认使用 `udp`。
该值应用于 `server` 和未单独设置 `network` 的 `servers` 条目。
### username
OpenVPN 用户名/密码认证的用户名。
### password
OpenVPN 用户名/密码认证的密码。
### auth_retry
用户名/密码认证失败后的行为,可选值为 `none`、`nointeract` 或 `interact`。
默认使用 `none`,并将永久认证失败视为终止错误。
`nointeract` 和 `interact` 允许重试认证。
### static_challenge
请求认证响应时显示的静态质询文本。
### static_challenge_echo
以明文显示静态质询响应。
### tls
==必填==
OpenVPN 控制通道 TLS 配置。
### tls.server_name
预期的服务器证书名称。
为空时禁用证书名称验证,但仍会验证证书链或 fingerprint 与服务器证书用途。
### tls.server_name_type
与 `tls.server_name` 匹配的证书字段,可选值为 `subject`、`name` 或 `name-prefix`。
设置 `tls.server_name` 时默认使用 `name`。
`subject` 匹配完整证书 subject,`name` 精确匹配 common name,`name-prefix` 匹配 common name 前缀。
### tls.certificate
受信任 CA 证书内容。
`tls.certificate`、`tls.certificate_path` 和 `tls.peer_fingerprint` 之一必填。
与 `tls.certificate_path` 冲突。
### tls.certificate_path
受信任 CA 证书路径。
`tls.certificate`、`tls.certificate_path` 和 `tls.peer_fingerprint` 之一必填。
与 `tls.certificate` 冲突。
### tls.client_certificate
客户端证书内容。
与 `tls.client_certificate_path` 冲突。
### tls.client_certificate_path
客户端证书路径。
与 `tls.client_certificate` 冲突。
### tls.client_key
客户端私钥内容。
与 `tls.client_key_path` 冲突。
### tls.client_key_path
客户端私钥路径。
与 `tls.client_key` 冲突。
客户端证书和私钥必须同时设置或同时为空。
### tls.peer_fingerprint
允许的服务器 leaf certificate 的 SHA-256 fingerprint。
每个 fingerprint 必须是不带分隔符的 64 字符小写十六进制字符串。
同时配置受信任 CA 时,会同时验证证书链和 fingerprint。未配置受信任 CA 时,会验证 fingerprint、证书有效期、配置的名称和证书用途,但不验证证书链。
### tls.crl_path
用于拒绝已吊销服务器证书的 PEM 或 DER CRL 文件路径。
根据受信任证书链验证 CRL 签名和有效期。
默认禁用。
### tls.remote_certificate_ku
服务器证书所需的 Key Usage mask,使用 OpenVPN `remote-cert-ku` 格式的十六进制值。
多个值会被组合,证书必须包含所有要求的用途。
默认禁用。
### tls.remote_certificate_eku
服务器证书所需的 Extended Key Usage,可选值为 `server` 或 `client`。
默认禁用。标准 OpenVPN 服务器证书用途检查仍然生效。
### tls.version_min
最低 TLS 版本,可选值为 `1.0`、`1.1`、`1.2` 或 `1.3`。
默认使用 `1.2`。
### tls.version_max
最高 TLS 版本,可选值为 `1.0`、`1.1`、`1.2` 或 `1.3`。
默认使用支持的最高版本。
该值不能低于 `tls.version_min`。
### tls.cipher
TLS 1.2 及更低版本允许的 OpenSSL cipher suite 名称,以冒号分隔。
为空时使用默认 TLS cipher suite。该字段不控制 TLS 1.3 cipher suite。
### tls.groups
按偏好顺序排列的 TLS key exchange group,以冒号分隔。
支持 `X25519`、`SECP256R1`、`SECP384R1` 和 `SECP521R1`,包括其常用 OpenSSL 和 NIST 别名。
为空时使用默认 TLS group。
### tls.control_wrap
OpenVPN 控制通道封装。
等价于 OpenVPN `tls-auth`、`tls-crypt` 和 `tls-crypt-v2`。
为空时禁用。
### tls.control_wrap.type
控制通道封装类型,可选值为 `tls_auth`、`tls_crypt` 或 `tls_crypt_v2`。
### tls.control_wrap.key
控制通道封装密钥内容。
与 `tls.control_wrap.key_path` 冲突。
### tls.control_wrap.key_path
控制通道封装密钥路径。
与 `tls.control_wrap.key` 冲突。
### tls.control_wrap.direction
`tls-auth` 密钥方向,可选值为 `server` 或 `client`。
仅当 `tls.control_wrap.type` 为 `tls_auth` 时可用。为空时双向使用密钥。
### data_ciphers
允许的 OpenVPN 数据通道 cipher。
默认使用 `AES-256-GCM`、`AES-128-GCM` 和 `CHACHA20-POLY1305`。
### data_ciphers_fallback
用于不支持 cipher 协商的对端的数据通道 cipher。
默认禁用。
### auth
OpenVPN 数据通道认证摘要。
默认使用 `SHA1`,仅应用于非 AEAD 数据 cipher 和 `tls_auth`。
### mss_fix
OpenVPN UDP packet 的最大大小,用于限制通过隧道发送的 TCP 连接 MSS。
这可以避免 TCP packet 在 OpenVPN 封装后超过 path MTU。
设为 `0` 时禁用。
### fragment
用于 OpenVPN 数据通道 fragmentation 的最大 OpenVPN UDP packet 大小。
设为 `0` 时禁用。非零值必须至少为 `68`。
与 TCP 传输冲突。
### compression
OpenVPN `compress` framing 模式,可选值为 `none`、`no`、`lz4`、`lz4-v2`、`stub`、`stub-v2`、`disabled` 或 `off`。
默认禁用。
Compression 可能削弱流量机密性。仅在需要 framing 兼容性时使用 `stub` 或 `stub-v2`。
### compression_lzo
OpenVPN `comp-lzo` 模式,可选值为 `none`、`no`、`yes`、`adaptive`、`asym`、`disabled` 或 `off`。
默认禁用。
Compression 可能削弱流量机密性。仅在服务器要求时启用。
### allow_compression
服务器推送的 compression 策略,可选值为 `no`、`asym` 或 `yes`。
默认使用 `no`,仅允许 compression stub framing。`asym` 接受来自服务器的 compressed packet,但不压缩出站 packet。`yes` 允许双向 compression。
当设为 `no` 时,与通过 `compression` 或 `compression_lzo` 启用的非 stub compression 冲突。
### route_no_pull
忽略服务器推送的 route、route gateway 和 redirect-gateway 选项。
仍会接受其他推送选项,并继续使用本地配置的 `routes`。
默认禁用。
### pull_filters
服务器推送选项的有序 pull filter 列表。
应用第一个 `text` 为完整推送选项大小写不敏感前缀的 filter。未匹配任何 filter 的选项会被接受。
### pull_filters.action
==必填==
Filter action,可选值为 `accept`、`ignore` 或 `reject`。
`accept` 应用选项,`ignore` 丢弃选项,`reject` 终止连接。
### pull_filters.text
==必填==
用于匹配推送选项名称和值的大小写不敏感前缀。
例如,`route ` 会匹配推送的 IPv4 route 选项,但不会匹配 `route-gateway`。
### routes
通过 OpenVPN endpoint 路由的 IPv4 和 IPv6 route prefix。
这些 route 会与从服务器接受的 route 一起使用。
### route_gateway
通过 OpenVPN endpoint 路由的 IPv4 gateway。
为空时使用从服务器接收的 VPN gateway。
### route_metric
通过 OpenVPN endpoint 路由的默认 metric。
设为 `0` 时使用平台默认值。
### redirect_gateway
通过 OpenVPN endpoint 路由所有 IPv4 流量。
默认禁用。
### redirect_gateway_flags
OpenVPN `redirect-gateway` flag。
`!ipv4` 禁用 IPv4 default route,`ipv6` 还会通过 endpoint 路由所有 IPv6 流量。接受其他 OpenVPN flag 以兼容配置,但它们不会改变 endpoint 路由。
默认为空。
### keepalive_interval
发送 OpenVPN keepalive ping packet 的间隔。
本地配置值优先于服务器推送的 keepalive 值。
默认禁用。
### keepalive_timeout
未接收 OpenVPN 流量后重新启动连接的时间。
本地配置值优先于服务器推送的 keepalive 值。
默认禁用。
### renegotiate_interval
OpenVPN TLS 重新协商间隔。
如果为空或设为 `0s`,使用 OpenVPN 默认值 `1h`。
### explicit_exit_notify
关闭 UDP 连接时发送的 OpenVPN exit notification 数量。
设为 `0` 时禁用。最多发送 `10` 个 notification。
### system
使用系统接口。
需要权限,且不能与现有系统接口冲突。
禁用时,sing-box 使用内部网络栈。
### name
系统接口的自定义接口名称。
默认使用自动生成的 `ovpn` 接口名称。
### mtu
OpenVPN 接口 MTU。
为空时使用服务器推送的 MTU;收到服务器配置前使用 `1500`。
### udp_timeout
UDP NAT 过期时间。
默认使用 `5m`。
## 拨号字段
参阅[拨号字段](/zh/configuration/shared/dial/)。
## 交互式认证
在 sing-box dashboard 或任意 sing-box 图形客户端的 `工具` > `端点` 中认证和管理 endpoint。
@@ -0,0 +1,319 @@
# OpenVPN Server
!!! question "Since sing-box 1.14.0"
## Structure
```json
{
"type": "openvpn-server",
"tag": "ovpn-server",
... // Listen Fields
"system": false,
"name": "",
"mtu": 1500,
"network": "udp",
"max_clients": 1024,
"address": [],
"topology": "subnet",
"users": [
{
"username": "",
"password": ""
}
],
"tls": {
"certificate": [],
"certificate_path": "",
"key": [],
"key_path": "",
"client_certificate": [],
"client_certificate_path": "",
"verify_client_certificate": "require",
"control_wrap": {
"type": "tls_crypt",
"key": [],
"key_path": "",
"direction": ""
}
},
"data_ciphers": [],
"data_ciphers_fallback": "",
"auth": "",
"push": {
"routes": [],
"dns": [],
"redirect_gateway": false,
"redirect_gateway_flags": [],
"block_outside_dns": false
},
"keepalive_interval": "",
"keepalive_timeout": "",
"renegotiate_interval": "",
"udp_timeout": ""
}
```
!!! note ""
You can ignore the JSON Array [] tag when the content is only one item
## Listen Fields
See [Listen Fields](/configuration/shared/listen/) for details.
## Fields
### system
Use system interface.
Requires privilege and cannot conflict with existing system interfaces.
If disabled, sing-box uses the internal network stack.
### name
Custom interface name for system interface.
An automatically generated `ovpn` interface name is used by default.
### mtu
OpenVPN interface MTU.
`1500` will be used by default.
### network
OpenVPN transport network, one of `udp` or `tcp`.
`udp` will be used by default.
Only one transport network is served per endpoint; to serve both TCP and UDP,
configure two endpoints with separate `address` subnets,
matching upstream OpenVPN which requires two server processes.
### max_clients
Maximum number of established and pending TLS client sessions.
`1024` is used by default. The value must be smaller than `16777216`, the size of the OpenVPN peer-id space.
### address
==Required==
List of OpenVPN server address prefixes.
At most one IPv4 prefix and one IPv6 prefix are supported.
The prefix address is assigned to the server interface. The masked prefix is used as the client address pool and route.
The first IPv4 and IPv6 prefix addresses are used as the endpoint's local addresses.
### topology
OpenVPN topology pushed to clients, one of `subnet`, `p2p` or `net30`.
`subnet` will be used by default.
### users
List of OpenVPN username/password users.
If set, clients must pass username/password authentication in addition to any certificate policy configured by `tls.verify_client_certificate`.
### users.username
Username.
### users.password
Password.
### tls
==Required==
OpenVPN control channel TLS configuration.
### tls.certificate
TLS server certificate content.
Either `tls.certificate` or `tls.certificate_path` is required.
Conflict with `tls.certificate_path`.
### tls.certificate_path
TLS server certificate path.
Either `tls.certificate` or `tls.certificate_path` is required.
Conflict with `tls.certificate`.
### tls.key
TLS server private key content.
Either `tls.key` or `tls.key_path` is required.
Conflict with `tls.key_path`.
### tls.key_path
TLS server private key path.
Either `tls.key` or `tls.key_path` is required.
Conflict with `tls.key`.
### tls.client_certificate
TLS CA certificate content, used to verify client certificates.
Either `tls.client_certificate` or `tls.client_certificate_path` is required.
Conflict with `tls.client_certificate_path`.
### tls.client_certificate_path
TLS CA certificate path, used to verify client certificates.
Either `tls.client_certificate` or `tls.client_certificate_path` is required.
Conflict with `tls.client_certificate`.
### tls.verify_client_certificate
OpenVPN client certificate policy, one of `require`, `optional` or `none`.
`require` will be used by default.
If set to `optional`, a client certificate is verified when provided, but clients without a certificate are allowed.
If set to `none`, client certificates are not requested.
This field does not replace `users`; when `users` is set, username/password authentication is still required.
### tls.control_wrap
OpenVPN control channel wrapping.
Equivalent to OpenVPN `tls-auth`, `tls-crypt` and `tls-crypt-v2`.
Disabled by default.
### tls.control_wrap.type
==Required==
Control channel wrapping type, one of `tls_auth`, `tls_crypt` or `tls_crypt_v2`.
For `tls_crypt_v2`, the key is the server key.
### tls.control_wrap.key
Control channel wrapping key content.
Either `tls.control_wrap.key` or `tls.control_wrap.key_path` is required.
Conflict with `tls.control_wrap.key_path`.
### tls.control_wrap.key_path
Control channel wrapping key path.
Either `tls.control_wrap.key` or `tls.control_wrap.key_path` is required.
Conflict with `tls.control_wrap.key`.
### tls.control_wrap.direction
OpenVPN `tls-auth` key direction, one of `server` or `client`.
Only available when `tls.control_wrap.type` is `tls_auth`.
`server` maps to OpenVPN key direction `0`, and `client` maps to `1`; by convention servers use `0` and clients use `1`.
If empty, the key is used bidirectionally, matching an omitted `key-direction` on both peers.
### data_ciphers
Allowed OpenVPN data channel ciphers.
`AES-256-GCM`, `AES-128-GCM` and `CHACHA20-POLY1305` are used by default.
### data_ciphers_fallback
OpenVPN data channel cipher for legacy clients that do not support cipher negotiation.
Equivalent to OpenVPN `data-ciphers-fallback`.
Disabled by default.
### auth
OpenVPN data channel authentication digest.
`SHA1` will be used by default, matching the upstream default; it only applies to non-AEAD data ciphers and `tls_auth`.
### push
Options pushed to clients.
### push.routes
Routes to push to clients.
IPv4 and IPv6 prefixes can be mixed.
### push.dns
DNS server addresses to push to clients.
### push.redirect_gateway
Push `redirect-gateway` to clients, which routes client traffic through the VPN according to `push.redirect_gateway_flags`.
When `push.redirect_gateway_flags` is empty, `def1` is used by default.
### push.redirect_gateway_flags
OpenVPN `redirect-gateway` flags to push to clients.
Only available when `push.redirect_gateway` is enabled.
`def1` is used by default.
### push.block_outside_dns
Push `block-outside-dns` to clients, which blocks DNS queries outside the VPN on Windows clients.
### keepalive_interval
OpenVPN keepalive ping interval to push to clients.
Disabled by default.
### keepalive_timeout
OpenVPN keepalive ping timeout to push to clients.
Disabled by default.
### renegotiate_interval
OpenVPN TLS renegotiation interval.
If empty or set to `0s`, the OpenVPN default `1h` is used.
### udp_timeout
UDP NAT expiration time for traffic through the OpenVPN interface.
`5m` will be used by default.
@@ -0,0 +1,319 @@
# OpenVPN 服务器
!!! question "自 sing-box 1.14.0 起"
## 结构
```json
{
"type": "openvpn-server",
"tag": "ovpn-server",
... // 监听字段
"system": false,
"name": "",
"mtu": 1500,
"network": "udp",
"max_clients": 1024,
"address": [],
"topology": "subnet",
"users": [
{
"username": "",
"password": ""
}
],
"tls": {
"certificate": [],
"certificate_path": "",
"key": [],
"key_path": "",
"client_certificate": [],
"client_certificate_path": "",
"verify_client_certificate": "require",
"control_wrap": {
"type": "tls_crypt",
"key": [],
"key_path": "",
"direction": ""
}
},
"data_ciphers": [],
"data_ciphers_fallback": "",
"auth": "",
"push": {
"routes": [],
"dns": [],
"redirect_gateway": false,
"redirect_gateway_flags": [],
"block_outside_dns": false
},
"keepalive_interval": "",
"keepalive_timeout": "",
"renegotiate_interval": "",
"udp_timeout": ""
}
```
!!! note ""
当内容只有一项时,可以忽略 JSON 数组 [] 标签
## 监听字段
参阅 [监听字段](/zh/configuration/shared/listen/)。
## 字段
### system
使用系统接口。
需要特权且不能与已有系统接口冲突。
如果禁用,sing-box 将使用内部网络栈。
### name
系统接口的自定义接口名称。
默认使用自动生成的 `ovpn` 接口名称。
### mtu
OpenVPN 接口 MTU。
默认使用 `1500`。
### network
OpenVPN 传输网络,`udp` 或 `tcp` 之一。
默认使用 `udp`。
每个端点仅服务一种传输网络;如需同时服务 TCP 与 UDP,
需要配置两个端点并使用互不重叠的 `address` 子网,
与上游 OpenVPN 需要两个服务进程一致。
### max_clients
已建立与握手中的 TLS 客户端会话的最大数量。
默认使用 `1024`。该值必须小于 OpenVPN peer-id 空间的大小 `16777216`。
### address
==必填==
OpenVPN 服务器地址前缀列表。
最多支持一个 IPv4 前缀和一个 IPv6 前缀。
前缀地址被分配给服务器接口。掩码后的前缀用作客户端地址池和路由。
第一个 IPv4 和 IPv6 前缀地址用作端点的本地地址。
### topology
推送给客户端的 OpenVPN topology,`subnet`、`p2p` 或 `net30` 之一。
默认使用 `subnet`。
### users
OpenVPN 用户名/密码用户列表。
如果设置,客户端除了通过 `tls.verify_client_certificate` 配置的证书策略外,还必须通过用户名/密码认证。
### users.username
用户名。
### users.password
密码。
### tls
==必填==
OpenVPN 控制信道 TLS 配置。
### tls.certificate
TLS 服务器证书内容。
`tls.certificate` 或 `tls.certificate_path` 必填其一。
与 `tls.certificate_path` 冲突。
### tls.certificate_path
TLS 服务器证书路径。
`tls.certificate` 或 `tls.certificate_path` 必填其一。
与 `tls.certificate` 冲突。
### tls.key
TLS 服务器私钥内容。
`tls.key` 或 `tls.key_path` 必填其一。
与 `tls.key_path` 冲突。
### tls.key_path
TLS 服务器私钥路径。
`tls.key` 或 `tls.key_path` 必填其一。
与 `tls.key` 冲突。
### tls.client_certificate
TLS CA 证书内容,用于验证客户端证书。
`tls.client_certificate` 或 `tls.client_certificate_path` 必填其一。
与 `tls.client_certificate_path` 冲突。
### tls.client_certificate_path
TLS CA 证书路径,用于验证客户端证书。
`tls.client_certificate` 或 `tls.client_certificate_path` 必填其一。
与 `tls.client_certificate` 冲突。
### tls.verify_client_certificate
OpenVPN 客户端证书策略,`require`、`optional` 或 `none` 之一。
默认使用 `require`。
设为 `optional` 时,客户端提供证书则验证,不提供证书的客户端也被允许。
设为 `none` 时,不请求客户端证书。
该字段不替代 `users`;设置 `users` 后仍然要求用户名/密码认证。
### tls.control_wrap
OpenVPN 控制信道包装。
等价于 OpenVPN `tls-auth`、`tls-crypt` 和 `tls-crypt-v2`。
默认禁用。
### tls.control_wrap.type
==必填==
控制信道包装类型,`tls_auth`、`tls_crypt` 或 `tls_crypt_v2` 之一。
对于 `tls_crypt_v2`,密钥为服务器密钥。
### tls.control_wrap.key
控制信道包装密钥内容。
`tls.control_wrap.key` 或 `tls.control_wrap.key_path` 必填其一。
与 `tls.control_wrap.key_path` 冲突。
### tls.control_wrap.key_path
控制信道包装密钥路径。
`tls.control_wrap.key` 或 `tls.control_wrap.key_path` 必填其一。
与 `tls.control_wrap.key` 冲突。
### tls.control_wrap.direction
OpenVPN `tls-auth` 密钥方向,`server` 或 `client` 之一。
仅当 `tls.control_wrap.type` 为 `tls_auth` 时可用。
`server` 对应 OpenVPN 密钥方向 `0`,`client` 对应 `1`;按照惯例服务器使用 `0`,客户端使用 `1`。
如果为空,密钥被双向使用,与两端均省略 `key-direction` 的行为一致。
### data_ciphers
允许的 OpenVPN 数据信道加密方式。
默认使用 `AES-256-GCM`、`AES-128-GCM` 和 `CHACHA20-POLY1305`。
### data_ciphers_fallback
用于不支持加密方式协商的遗留客户端的 OpenVPN 数据信道加密方式。
等价于 OpenVPN `data-ciphers-fallback`。
默认禁用。
### auth
OpenVPN 数据信道认证摘要。
默认使用 `SHA1`,与上游默认值一致;仅对非 AEAD 数据信道加密方式和 `tls_auth` 生效。
### push
推送给客户端的选项。
### push.routes
推送给客户端的路由。
IPv4 和 IPv6 前缀可以混用。
### push.dns
推送给客户端的 DNS 服务器地址。
### push.redirect_gateway
向客户端推送 `redirect-gateway`,根据 `push.redirect_gateway_flags` 通过 VPN 路由客户端流量。
当 `push.redirect_gateway_flags` 为空时,默认使用 `def1`。
### push.redirect_gateway_flags
向客户端推送的 OpenVPN `redirect-gateway` flag。
仅当启用 `push.redirect_gateway` 时可用。
默认使用 `def1`。
### push.block_outside_dns
向客户端推送 `block-outside-dns`,在 Windows 客户端上阻止 VPN 之外的 DNS 查询。
### keepalive_interval
推送给客户端的 OpenVPN keepalive ping 间隔。
默认禁用。
### keepalive_timeout
推送给客户端的 OpenVPN keepalive ping 超时。
默认禁用。
### renegotiate_interval
OpenVPN TLS 重协商间隔。
如果为空或设为 `0s`,使用 OpenVPN 默认值 `1h`。
### udp_timeout
通过 OpenVPN 接口的流量的 UDP NAT 过期时间。
默认使用 `5m`。
+5 -1
View File
@@ -60,7 +60,7 @@ Example: `$HOME/.tailscale`
!!! note
Auth key is not required. By default, sing-box will log the login URL (or popup a notification on graphical clients).
Auth key is not required. By default, sing-box will log the login URL.
The auth key to create the node. If the node is already created (from state previously stored), then this field is not
used.
@@ -208,3 +208,7 @@ Refuse local and remote TCP and Unix-socket forwarding, including SSH agent forw
Dial Fields in Tailscale endpoints only control how it connects to the control plane and have nothing to do with actual connections.
See [Dial Fields](/configuration/shared/dial/) for details.
### Interactive authentication
Use `Tools` > `Endpoints` in the sing-box dashboard or any sing-box graphical client to authenticate and manage the endpoint.
+5 -1
View File
@@ -60,7 +60,7 @@ icon: material/new-box
!!! note
认证密钥不是必需的。默认情况下,sing-box 将记录登录 URL(或在图形客户端上弹出通知)。
认证密钥不是必需的。默认情况下,sing-box 将记录登录 URL。
用于创建节点的认证密钥。如果节点已经创建(从之前存储的状态),则不使用此字段。
@@ -207,3 +207,7 @@ UDP NAT 过期时间。
Tailscale 端点中的拨号字段仅控制它如何连接到控制平面,与实际连接无关。
参阅 [拨号字段](/zh/configuration/shared/dial/) 了解详情。
### 交互式认证
在 sing-box dashboard 或任意 sing-box 图形客户端的 `工具` > `端点` 中认证和管理 endpoint。