The default is selected from the system platform: `win` on Windows, `mac-intel` on macOS, `android` on Android, `apple-ios` on iOS, and `linux-64` or `linux` on other 64-bit or 32-bit systems.
Local UDP port used by the direct DTLS or ESP secondary data channel.
An automatically selected ephemeral port is used by default.
### compression_disabled
Disable AnyConnect compression negotiation.
By default, stateless `oc-lz4` and `lzs` compression is negotiated for CSTP and DTLS when supported by the server.
Compression can weaken traffic confidentiality when an attacker can influence plaintext sent through the VPN tunnel.
Conflict with `compression_mode` set to `all`.
### compression_mode
AnyConnect compression mode, one of:
-`stateless`: Advertise stateless `oc-lz4` and `lzs` compression.
-`all`: Additionally advertise stateful `deflate` compression for CSTP.
`stateless` is used by default. DTLS always uses stateless compression, including when `all` is selected.
Stateful compression has additional traffic confidentiality risks and should only be enabled when required by the VPN server.
### ipv6_disabled
Disable requesting and using IPv6 tunnel configuration.
### http_keepalive_disabled
Disable HTTP connection reuse during authentication and configuration requests.
### xml_post_disabled
Disable AnyConnect XML POST authentication and start authentication with the legacy GET flow.
### external_auth_disabled
Disable external browser authentication such as SSO and SAML for AnyConnect and GlobalProtect.
When enabled, external authentication is not advertised to the server and an unexpected external authentication request is rejected.
### password_authentication_disabled
Abort AnyConnect authentication if the server returns a non-success authentication form, matching OpenConnect `--no-passwd` behavior.
This does not affect the other flavors or a session supplied by `cookie`.
### tcp_keep_alive_enabled
Enable TCP keep alive for direct VPN server connections.
Disabled by default to match OpenConnect. Setting `tcp_keep_alive` or `tcp_keep_alive_interval` also enables it without requiring this field. When enabled without either duration, the operating system TCP keep alive timing is retained.
Conflict with `disable_tcp_keep_alive`.
### pfs
Require forward-secret TLS cipher suites for TLS 1.2 and earlier.
Disabled by default for compatibility with VPN servers that require RSA key exchange. This does not enable deprecated cipher suites; see `allow_insecure_crypto` for legacy crypto support.
### mtu
Preferred tunnel MTU.
The negotiated MTU is limited to this value for all flavors. For AnyConnect, this value is also sent to the server. GlobalProtect, F5, and Fortinet remove their protocol overhead before using it as the tunnel MTU.
Non-zero values below `576` are treated as `576`. The maximum value is `65535`.
### base_mtu
Base path MTU used to calculate the AnyConnect, GlobalProtect, F5, and Fortinet tunnel MTU after outer IP, transport, and protocol overhead.
`1406` is used by default.
These flavors treat values below `1280` as `1280`. The maximum value is `65535`.
### dpd_interval
Override the Dead Peer Detection interval.
The server-provided or flavor-specific interval is used by default.
Positive values below `2s` are treated as `2s`. The value must not be negative.
### reconnect_timeout
Maximum accumulated backoff time after failed reconnect attempts. The first reconnect attempt starts immediately, and this timeout does not cancel an attempt already in progress.
`300s` is used by default.
The value must not be negative.
### trojan_interval
Override the interval between GlobalProtect HIP reports or Network Connect TNCC checks.
The server-provided interval is used by default. GlobalProtect uses `1h` when the server does not provide one.
The value must not be negative.
### queue_length
Inbound and outbound packet queue length between the VPN transport and the tunnel interface.
`32` is used by default. A full queue applies backpressure until its consumer makes room; queued packets are not discarded.
Disable verification of the VPN server certificate and hostname.
Disabled by default. Enabling this permits an active attacker to impersonate the VPN server. Prefer `tls.certificate_authority` or `tls.peer_fingerprint` when possible.
### tls.server_name
Server name used for TLS SNI and certificate hostname verification.
The hostname from `server` is used by default.
### tls.peer_fingerprint
Allowed server certificate fingerprints. A single string or a list can be specified.
Supported formats:
- An unprefixed SHA-1 certificate fingerprint compatible with OpenConnect `--servercert`.
The encoded fingerprint in every format can be abbreviated to a prefix of at least four characters. When configured, the peer certificate must match one of these fingerprints; a match can authorize a certificate that is not otherwise trusted.
### tls.system_trust_disabled
Disable the system CA certificate pool.
Use `tls.certificate_authority` or `tls.peer_fingerprint` to establish trust when enabled.
Pushed DNS settings are not installed into the operating system. Configure an [OpenConnect DNS server](/configuration/dns/server/openconnect/) to use them through sing-box.