24 lines
549 B
SYSTEMD
24 lines
549 B
SYSTEMD
|
[Unit]
|
||
|
Description=SoftEther VPN Bridge
|
||
|
After=network.target auditd.service
|
||
|
ConditionPathExists=!/opt/vpnbridge/do_not_run
|
||
|
|
||
|
[Service]
|
||
|
Type=forking
|
||
|
ExecStart=/opt/vpnbridge/vpnbridge start
|
||
|
ExecStop=/opt/vpnbridge/vpnbridge stop
|
||
|
KillMode=process
|
||
|
Restart=on-failure
|
||
|
|
||
|
# Hardening
|
||
|
PrivateTmp=yes
|
||
|
ProtectHome=yes
|
||
|
ProtectSystem=full
|
||
|
ReadOnlyDirectories=/
|
||
|
ReadWriteDirectories=-/opt/vpnbridge
|
||
|
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW CAP_SYS_NICE CAP_SYS_ADMIN CAP_SETUID
|
||
|
|
||
|
[Install]
|
||
|
WantedBy=multi-user.target
|
||
|
|