General Information

A description of this override for administrative reference.
Set this option to disable this client-specific override without removing it from the list.

Override Configuration

Enter the X.509 common name for the client certificate, or the username for VPNs utilizing password authentication. This match is case sensitive. Enter "DEFAULT" to override default client behavior.
Prevents the client from connecting to this server. Do not use this option to permanently disable a client due to a compromised key or password. Use a CRL (certificate revocation list) instead.
Select the servers that will utilize this override. When no servers are selected, the override will apply to all servers.
If unchecked, any client options specified in below form or Advanced section will be added to server options.
If checked, you can select the server options you want to remove. Any specified client option in below form or Advanced section will thus override the corresponding server-defined options.

Tunnel Settings

The virtual IPv4 network or network type alias with a single entry used for private communications between this client and the server expressed using CIDR (e.g. 10.0.8.5/24).
With subnet topology, enter the client IP address and the subnet mask must match the IPv4 Tunnel Network on the server.
With net30 topology, the first network address of the /30 is assumed to be the server address and the second network address will be assigned to the client.
The virtual IPv6 network or network type alias with a single entry used for private communications between this client and the server expressed using prefix (e.g. 2001:db9:1:1::100/64).
Enter the client IPv6 address and prefix. The prefix must match the IPv6 Tunnel Network prefix on the server.

Local Routes Settings

This is the IPv4 Gateway to push to the client. Normally it is left blank and configured on the server. The gateway IP should be entered if any of the options "Remove Server Local Routes" or "Remove All Server Options" is checked, as these 2 options will remove the gateway defined on the server and connection from the client will likely fail.
NOTE: Remember that, unless configured specifically, the gateway should match the IPv4 Tunnel gateway configured on the selected OpenVPN servers settings.
This is the IPv6 Gateway to push to the client. Normally it is left blank and configured on the server. The gateway IP should be entered if any of the options "Remove Server Local Routes" or "Remove All Server Options" is checked, as these 2 options will remove the gateway defined on the server and connection from the client will likely fail.
NOTE: Remember that, unless configured specifically, the gateway should match the IPv4 Tunnel gateway configured on the selected OpenVPN servers settings.

Remote Routes Settings

These are the IPv4 client-side networks that will be routed to this client specifically using iroute, so that a site-to-site VPN can be established. Expressed as a comma-separated list of one or more CIDR ranges. May be left blank if there are no client-side networks to be routed.
NOTE: Remember to add these subnets to the IPv4 Remote Networks list on the corresponding OpenVPN server settings.
These are the IPv6 client-side networks that will be routed to this client specifically using iroute, so that a site-to-site VPN can be established. Expressed as a comma-separated list of one or more IP/PREFIX networks. May be left blank if there are no client-side networks to be routed.
NOTE: Remember to add these subnets to the IPv6 Remote Networks list on the corresponding OpenVPN server settings.

Other Client Settings

Server 1
Server 2
Server 3
Server 4
Server 1
Server 2
If this option is not set, all NetBIOS-over-TCP/IP options (including WINS) will be disabled.
Enter any additional options to add for this client specific override, separated by a semicolon.
EXAMPLE: push "route 10.0.0.0 255.255.255.0";