TLS Cipher: restrict the encryption algorithms used by TLS to the specified list. An 
empty list means no restrictions. 
Use LZO Compression: enable or disable use LZO compression for data transfer 
NAT: enable or disable NAT through function 
Bridge TAP to br0: enable or disable bridge TAP to br0 
IP Address / Subnet Mask: the modems LAN subnet 
TUN MTU Setting: set MTU value of the tunnel 
MSS-Fix/Fragment across the tunnel: Force TCP MSS low enough to fit in 
tunnel without fragmenting packets or not 
nsCertType verification: require “TLS server” cert type be set on server 
certificate – this prevents client certificates being spoofed as server certificates. 
 
 
CA Cert: CA certificate (that verifies server cert) 
Public Client Cert: client certificate 
Private Client Key: client key