ΒΆ
ocserv Security Hardening
Enforce modern TLS versions and ciphers.
Use certificate + strong user auth (MFA where possible).
Segment VPN clients with explicit route and ACL policies.
Monitor failed logins and unusual session durations.