client
dev tun
proto {{ openvpn_protocol }}
remote {{ openvpn_server }} {{ openvpn_port }}
cipher {{ openvpn_cipher }}
auth {{ openvpn_auth_digest }}
resolv-retry infinite
nobind
persist-key
persist-tun
ns-cert-type server
comp-lzo
key-direction 1
verb 3
route {{ ansible_default_ipv4.address }} 255.255.255.255 net_gateway
{{ openvpn_tls_version_min }}
# If you'd like to enable 2FA support, uncomment the following line
;auth-user-pass
{{ openvpn_ca_contents.stdout }}
{{ item[1].stdout }}
{{ item[2].stdout }}
{{ openvpn_hmac_firewall_contents.stdout }}