diff --git a/roles/openvpn/templates/iiab-remote-off b/roles/openvpn/templates/iiab-remote-off index 991c50f01..953c3d878 100644 --- a/roles/openvpn/templates/iiab-remote-off +++ b/roles/openvpn/templates/iiab-remote-off @@ -1,17 +1,20 @@ #!/bin/bash -# script to turn on openvpn -# do nothing if it is not installed +# /usr/bin/iiab-remote-off is intended to fully turn off multiple remote +# support services like OpenVPN and others, to reduce risk of remote attacks. + +# Do nothing if OpenVPN not installed which openvpn if [ $? -ne 0 ]; then - echo Cannot find the OpenVPN program (openvpn). + echo 'Cannot find the OpenVPN program (openvpn).' exit 1 fi + systemctl disable openvpn systemctl stop openvpn sleep 5 -ps -e|grep vpn +ps -e | grep vpn if [ $? -eq 0 ]; then echo OpenVPN failed to stop. else