Project

General

Profile

Bug #4862 » config-pfSense.localdomain-20150721214931.xml

Michael Nobile, 07/21/2015 08:47 PM

 
1
<?xml version="1.0"?>
2
<pfsense>
3
	<version>11.7</version>
4
	<lastchange/>
5
	<theme>pfsense_ng</theme>
6
	<system>
7
		<optimization>normal</optimization>
8
		<hostname>pfSense</hostname>
9
		<domain>localdomain</domain>
10
		<group>
11
			<name>all</name>
12
			<description><![CDATA[All Users]]></description>
13
			<scope>system</scope>
14
			<gid>1998</gid>
15
			<member>0</member>
16
		</group>
17
		<group>
18
			<name>admins</name>
19
			<description><![CDATA[System Administrators]]></description>
20
			<scope>system</scope>
21
			<gid>1999</gid>
22
			<member>0</member>
23
			<priv>page-all</priv>
24
		</group>
25
		<user>
26
			<name>admin</name>
27
			<descr><![CDATA[System Administrator]]></descr>
28
			<scope>system</scope>
29
			<groupname>admins</groupname>
30
			<password>$1$ZjNJHfnC$VH6i5mPe6qH0v5xDEs416/</password>
31
			<uid>0</uid>
32
			<priv>user-shell-access</priv>
33
			<md5-hash>f3a6d55c73fe1eaec44eec13651f897b</md5-hash>
34
			<nt-hash>3839386530653964623334326536356132656364383435386663643238316537</nt-hash>
35
		</user>
36
		<nextuid>2000</nextuid>
37
		<nextgid>2000</nextgid>
38
		<timezone>America/New_York</timezone>
39
		<time-update-interval/>
40
		<timeservers>0.pfsense.pool.ntp.org</timeservers>
41
		<webgui>
42
			<protocol>https</protocol>
43
			<loginautocomplete/>
44
			<ssl-certref>53daa0066bba1</ssl-certref>
45
			<port/>
46
			<max_procs>2</max_procs>
47
		</webgui>
48
		<disablenatreflection>yes</disablenatreflection>
49
		<disablesegmentationoffloading/>
50
		<disablelargereceiveoffloading/>
51
		<ipv6allow/>
52
		<powerd_ac_mode>hadp</powerd_ac_mode>
53
		<powerd_battery_mode>hadp</powerd_battery_mode>
54
		<powerd_normal_mode>hadp</powerd_normal_mode>
55
		<bogons>
56
			<interval>monthly</interval>
57
		</bogons>
58
		<kill_states/>
59
		<enableserial/>
60
		<language>en_US</language>
61
		<dns1gw>none</dns1gw>
62
		<dns2gw>none</dns2gw>
63
		<dns3gw>none</dns3gw>
64
		<dns4gw>none</dns4gw>
65
		<dnslocalhost/>
66
		<serialspeed>115200</serialspeed>
67
		<primaryconsole>serial</primaryconsole>
68
		<enablesshd>enabled</enablesshd>
69
		<dnsallowoverride/>
70
		<maximumtableentries>2000000</maximumtableentries>
71
	</system>
72
	<interfaces>
73
		<wan>
74
			<enable/>
75
			<if>re0</if>
76
			<blockpriv/>
77
			<blockbogons/>
78
			<descr><![CDATA[WAN]]></descr>
79
			<ipaddr>dhcp</ipaddr>
80
			<dhcphostname/>
81
			<alias-address/>
82
			<alias-subnet>32</alias-subnet>
83
			<dhcprejectfrom/>
84
			<adv_dhcp_pt_timeout/>
85
			<adv_dhcp_pt_retry/>
86
			<adv_dhcp_pt_select_timeout/>
87
			<adv_dhcp_pt_reboot/>
88
			<adv_dhcp_pt_backoff_cutoff/>
89
			<adv_dhcp_pt_initial_interval/>
90
			<adv_dhcp_pt_values>SavedCfg</adv_dhcp_pt_values>
91
			<adv_dhcp_send_options/>
92
			<adv_dhcp_request_options/>
93
			<adv_dhcp_required_options/>
94
			<adv_dhcp_option_modifiers/>
95
			<adv_dhcp_config_advanced/>
96
			<adv_dhcp_config_file_override/>
97
			<adv_dhcp_config_file_override_path/>
98
			<spoofmac/>
99
		</wan>
100
		<lan>
101
			<enable/>
102
			<if>re1</if>
103
			<descr><![CDATA[LAN]]></descr>
104
			<ipaddr>10.0.0.1</ipaddr>
105
			<subnet>24</subnet>
106
			<spoofmac/>
107
		</lan>
108
		<opt1>
109
			<if>re2</if>
110
			<descr><![CDATA[OPT1]]></descr>
111
		</opt1>
112
	</interfaces>
113
	<staticroutes/>
114
	<dhcpd>
115
		<lan>
116
			<enable/>
117
			<range>
118
				<from>10.0.0.10</from>
119
				<to>10.0.0.245</to>
120
			</range>
121
		</lan>
122
	</dhcpd>
123
	<pptpd>
124
		<mode/>
125
		<redir/>
126
		<localip/>
127
		<remoteip/>
128
	</pptpd>
129
	<snmpd>
130
		<syslocation/>
131
		<syscontact/>
132
		<rocommunity>public</rocommunity>
133
	</snmpd>
134
	<diag>
135
		<ipv6nat>
136
			<ipaddr/>
137
		</ipv6nat>
138
	</diag>
139
	<bridge/>
140
	<syslog/>
141
	<nat>
142
		<outbound>
143
			<mode>automatic</mode>
144
		</outbound>
145
	</nat>
146
	<filter>
147
		<rule>
148
			<id/>
149
			<tracker>1425650750</tracker>
150
			<type>pass</type>
151
			<interface>wan</interface>
152
			<ipprotocol>inet6</ipprotocol>
153
			<tag/>
154
			<tagged/>
155
			<max/>
156
			<max-src-nodes/>
157
			<max-src-conn/>
158
			<max-src-states/>
159
			<statetimeout/>
160
			<statetype>keep state</statetype>
161
			<os/>
162
			<protocol>tcp</protocol>
163
			<source>
164
				<any/>
165
			</source>
166
			<destination>
167
				<address>2600:380:18f7:ebfb:9901:e1d0:886f:2dc6</address>
168
			</destination>
169
			<descr/>
170
			<updated>
171
				<time>1425650750</time>
172
				<username>admin@10.0.0.10</username>
173
			</updated>
174
			<created>
175
				<time>1425650750</time>
176
				<username>admin@10.0.0.10</username>
177
			</created>
178
		</rule>
179
		<rule>
180
			<type>pass</type>
181
			<ipprotocol>inet</ipprotocol>
182
			<descr><![CDATA[Default allow LAN to any rule]]></descr>
183
			<interface>lan</interface>
184
			<tracker>0100000101</tracker>
185
			<source>
186
				<network>lan</network>
187
			</source>
188
			<destination>
189
				<any/>
190
			</destination>
191
		</rule>
192
		<rule>
193
			<type>pass</type>
194
			<ipprotocol>inet6</ipprotocol>
195
			<descr><![CDATA[Default allow LAN IPv6 to any rule]]></descr>
196
			<interface>lan</interface>
197
			<tracker>0100000102</tracker>
198
			<source>
199
				<network>lan</network>
200
			</source>
201
			<destination>
202
				<any/>
203
			</destination>
204
		</rule>
205
		<rule>
206
			<id/>
207
			<tracker>1425650122</tracker>
208
			<type>pass</type>
209
			<interface>lan</interface>
210
			<ipprotocol>inet6</ipprotocol>
211
			<tag/>
212
			<tagged/>
213
			<max/>
214
			<max-src-nodes/>
215
			<max-src-conn/>
216
			<max-src-states/>
217
			<statetimeout/>
218
			<statetype>keep state</statetype>
219
			<os/>
220
			<protocol>tcp</protocol>
221
			<source>
222
				<address>2600:380:18f7:ebfb:9901:e1d0:886f:2dc6</address>
223
			</source>
224
			<destination>
225
				<any/>
226
			</destination>
227
			<descr><![CDATA[Easy Rule: Passed from Firewall Log View]]></descr>
228
			<created>
229
				<time>1425649947</time>
230
				<username>Easy Rule</username>
231
			</created>
232
			<updated>
233
				<time>1425650122</time>
234
				<username>admin@10.0.0.10</username>
235
			</updated>
236
		</rule>
237
		<rule>
238
			<id/>
239
			<tracker>1425650255</tracker>
240
			<type>pass</type>
241
			<interface>lan</interface>
242
			<ipprotocol>inet6</ipprotocol>
243
			<tag/>
244
			<tagged/>
245
			<max/>
246
			<max-src-nodes/>
247
			<max-src-conn/>
248
			<max-src-states/>
249
			<statetimeout/>
250
			<statetype>keep state</statetype>
251
			<os/>
252
			<protocol>tcp</protocol>
253
			<source>
254
				<address>2600:380:18f7:ebfb:9901:e1d0:886f:2dc6</address>
255
			</source>
256
			<destination>
257
				<address>2600:1408:e::1700:a371</address>
258
			</destination>
259
			<descr><![CDATA[Easy Rule: Passed from Firewall Log View]]></descr>
260
			<created>
261
				<time>1425650238</time>
262
				<username>Easy Rule</username>
263
			</created>
264
			<updated>
265
				<time>1425650255</time>
266
				<username>admin@10.0.0.10</username>
267
			</updated>
268
		</rule>
269
	</filter>
270
	<shaper/>
271
	<ipsec/>
272
	<aliases/>
273
	<proxyarp/>
274
	<cron>
275
		<item>
276
			<minute>1,31</minute>
277
			<hour>0-5</hour>
278
			<mday>*</mday>
279
			<month>*</month>
280
			<wday>*</wday>
281
			<who>root</who>
282
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
283
		</item>
284
		<item>
285
			<minute>1</minute>
286
			<hour>3</hour>
287
			<mday>1</mday>
288
			<month>*</month>
289
			<wday>*</wday>
290
			<who>root</who>
291
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
292
		</item>
293
		<item>
294
			<minute>*/60</minute>
295
			<hour>*</hour>
296
			<mday>*</mday>
297
			<month>*</month>
298
			<wday>*</wday>
299
			<who>root</who>
300
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
301
		</item>
302
		<item>
303
			<minute>*/60</minute>
304
			<hour>*</hour>
305
			<mday>*</mday>
306
			<month>*</month>
307
			<wday>*</wday>
308
			<who>root</who>
309
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 webConfiguratorlockout</command>
310
		</item>
311
		<item>
312
			<minute>1</minute>
313
			<hour>1</hour>
314
			<mday>*</mday>
315
			<month>*</month>
316
			<wday>*</wday>
317
			<who>root</who>
318
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
319
		</item>
320
		<item>
321
			<minute>*/60</minute>
322
			<hour>*</hour>
323
			<mday>*</mday>
324
			<month>*</month>
325
			<wday>*</wday>
326
			<who>root</who>
327
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
328
		</item>
329
		<item>
330
			<minute>30</minute>
331
			<hour>12</hour>
332
			<mday>*</mday>
333
			<month>*</month>
334
			<wday>*</wday>
335
			<who>root</who>
336
			<command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
337
		</item>
338
		<item>
339
			<minute>*/5</minute>
340
			<hour>*</hour>
341
			<mday>*</mday>
342
			<month>*</month>
343
			<wday>*</wday>
344
			<who>root</who>
345
			<command>/usr/bin/nice -n20 /usr/local/bin/php -f /usr/local/pkg/snort/snort_check_cron_misc.inc</command>
346
		</item>
347
		<item>
348
			<minute>*/5</minute>
349
			<hour>*</hour>
350
			<mday>*</mday>
351
			<month>*</month>
352
			<wday>*</wday>
353
			<who>root</who>
354
			<command>/usr/bin/nice -n20 /sbin/pfctl -q -t snort2c -T expire 3600</command>
355
		</item>
356
		<item>
357
			<minute>5</minute>
358
			<hour>0</hour>
359
			<mday>*/1</mday>
360
			<month>*</month>
361
			<wday>*</wday>
362
			<who>root</who>
363
			<command>/usr/bin/nice -n20 /usr/local/bin/php -f /usr/local/pkg/snort/snort_check_for_rule_updates.php</command>
364
		</item>
365
		<item>
366
			<task_name>squid_rotate_logs</task_name>
367
			<minute>0</minute>
368
			<hour>0</hour>
369
			<mday>*</mday>
370
			<month>*</month>
371
			<wday>*</wday>
372
			<who>root</who>
373
			<command>/bin/rm /var/squid/cache/swap.state; /usr/pbi/squid-amd64/sbin/squid -k rotate</command>
374
		</item>
375
		<item>
376
			<task_name>squid_check_swapstate</task_name>
377
			<minute>*/15</minute>
378
			<hour>*</hour>
379
			<mday>*</mday>
380
			<month>*</month>
381
			<wday>*</wday>
382
			<who>root</who>
383
			<command>/usr/local/pkg/swapstate_check.php</command>
384
		</item>
385
		<item>
386
			<minute>0</minute>
387
			<hour>*/4</hour>
388
			<mday>*</mday>
389
			<month>*</month>
390
			<wday>*</wday>
391
			<who>root</who>
392
			<command>/usr/bin/nice -n20 /usr/local/etc/rc.d/havp_avupdate</command>
393
		</item>
394
	</cron>
395
	<wol/>
396
	<rrd>
397
		<enable/>
398
	</rrd>
399
	<load_balancer>
400
		<monitor_type>
401
			<name>ICMP</name>
402
			<type>icmp</type>
403
			<descr><![CDATA[ICMP]]></descr>
404
			<options/>
405
		</monitor_type>
406
		<monitor_type>
407
			<name>TCP</name>
408
			<type>tcp</type>
409
			<descr><![CDATA[Generic TCP]]></descr>
410
			<options/>
411
		</monitor_type>
412
		<monitor_type>
413
			<name>HTTP</name>
414
			<type>http</type>
415
			<descr><![CDATA[Generic HTTP]]></descr>
416
			<options>
417
				<path>/</path>
418
				<host/>
419
				<code>200</code>
420
			</options>
421
		</monitor_type>
422
		<monitor_type>
423
			<name>HTTPS</name>
424
			<type>https</type>
425
			<descr><![CDATA[Generic HTTPS]]></descr>
426
			<options>
427
				<path>/</path>
428
				<host/>
429
				<code>200</code>
430
			</options>
431
		</monitor_type>
432
		<monitor_type>
433
			<name>SMTP</name>
434
			<type>send</type>
435
			<descr><![CDATA[Generic SMTP]]></descr>
436
			<options>
437
				<send/>
438
				<expect>220 *</expect>
439
			</options>
440
		</monitor_type>
441
	</load_balancer>
442
	<widgets>
443
		<sequence>system_information-container:col1:show,captive_portal_status-container:col1:close,carp_status-container:col1:close,cpu_graphs-container:col1:close,gateways-container:col1:close,gmirror_status-container:col1:close,installed_packages-container:col1:close,interface_statistics-container:col1:close,interfaces-container:col2:show,ipsec-container:col2:close,load_balancer_status-container:col2:close,log-container:col2:close,picture-container:col2:close,rss-container:col2:close,services_status-container:col2:close,traffic_graphs-container:col2:close,snort_alerts-container:col2:close,pfblockerng-container:col2:show</sequence>
444
	</widgets>
445
	<openvpn/>
446
	<dnshaper/>
447
	<unbound>
448
		<enable/>
449
		<dnssec/>
450
		<active_interface/>
451
		<outgoing_interface/>
452
		<custom_options/>
453
	</unbound>
454
	<revision>
455
		<time>1437529230</time>
456
		<description><![CDATA[admin@10.0.0.11: Installed pfBlockerNG package.]]></description>
457
		<username>admin@10.0.0.11</username>
458
	</revision>
459
	<dhcpdv6/>
460
	<cert>
461
		<refid>53daa0066bba1</refid>
462
		<descr><![CDATA[webConfigurator default (53daa0066bba1)]]></descr>
463
		<type>server</type>
464
		<crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUZZekNDQkV1Z0F3SUJBZ0lCQURBTkJna3Foa2lHOXcwQkFRc0ZBRENCdERFTE1Ba0dBMVVFQmhNQ1ZWTXgKRGpBTUJnTlZCQWdUQlZOMFlYUmxNUkV3RHdZRFZRUUhFd2hNYjJOaGJHbDBlVEU0TURZR0ExVUVDaE12Y0daVApaVzV6WlNCM1pXSkRiMjVtYVdkMWNtRjBiM0lnVTJWc1ppMVRhV2R1WldRZ1EyVnlkR2xtYVdOaGRHVXhLREFtCkJna3Foa2lHOXcwQkNRRVdHV0ZrYldsdVFIQm1VMlZ1YzJVdWJHOWpZV3hrYjIxaGFXNHhIakFjQmdOVkJBTVQKRlhCbVUyVnVjMlV0TlROa1lXRXdNRFkyWW1KaE1UQWVGdzB4TkRBM016RXhPVFU1TURKYUZ3MHlNREF4TWpFeApPVFU1TURKYU1JRzBNUXN3Q1FZRFZRUUdFd0pWVXpFT01Bd0dBMVVFQ0JNRlUzUmhkR1V4RVRBUEJnTlZCQWNUCkNFeHZZMkZzYVhSNU1UZ3dOZ1lEVlFRS0V5OXdabE5sYm5ObElIZGxZa052Ym1acFozVnlZWFJ2Y2lCVFpXeG0KTFZOcFoyNWxaQ0JEWlhKMGFXWnBZMkYwWlRFb01DWUdDU3FHU0liM0RRRUpBUllaWVdSdGFXNUFjR1pUWlc1egpaUzVzYjJOaGJHUnZiV0ZwYmpFZU1Cd0dBMVVFQXhNVmNHWlRaVzV6WlMwMU0yUmhZVEF3TmpaaVltRXhNSUlCCklqQU5CZ2txaGtpRzl3MEJBUUVGQUFPQ0FROEFNSUlCQ2dLQ0FRRUFxTlovbXBoRWJWaThBalFOdmJ5ZTlHK2UKT1ByUzdqVWNZakQ5a3V6NHNRbGE2Y1V0dlRsL2lKVUljTzlEM0ZvbHY4d2xRVy94QytVUVlYQ2l4ZTVuWkIxKwp1WUI5TmQzR0dCZXhMMzFnR3RoUXFaelRwVkxGZG9iVnpwMEFMZ3lIK1lLTEtCbkd5ZGRHU2VHZjNialdKNlNTCjE2akEwbE5vYlFEVWw5UVh0QnFlZnk4RitmUWJZK1RzNTNxZ2l5YjhvNk1NdFRVTExSZjFOODloKzl6cTIyYk0KSERkZDJoOCtGMGdrL21aQnBHbTIyakN2aEl3NHNTUXRzYk14RTdFNUdhVUVjUEUreEx1ditGRUd6VzFXalpaTApUdk96eFVmTmtxK0V0WmdIa3d5Y3A2M0FLZmZSK0lzdElMbDZzK1Bjbk85Y1d1WVFiUU5PZDdhMjJ2YVNOd0lECkFRQUJvNElCZkRDQ0FYZ3dDUVlEVlIwVEJBSXdBREFSQmdsZ2hrZ0JodmhDQVFFRUJBTUNCa0F3TXdZSllJWkkKQVliNFFnRU5CQ1lXSkU5d1pXNVRVMHdnUjJWdVpYSmhkR1ZrSUZObGNuWmxjaUJEWlhKMGFXWnBZMkYwWlRBZApCZ05WSFE0RUZnUVV1Vk53OFlkWGczK3FIam5TeDN2cng5a1Rwd2t3Z2VFR0ExVWRJd1NCMlRDQjFvQVV1Vk53CjhZZFhnMytxSGpuU3gzdnJ4OWtUcHdtaGdicWtnYmN3Z2JReEN6QUpCZ05WQkFZVEFsVlRNUTR3REFZRFZRUUkKRXdWVGRHRjBaVEVSTUE4R0ExVUVCeE1JVEc5allXeHBkSGt4T0RBMkJnTlZCQW9UTDNCbVUyVnVjMlVnZDJWaQpRMjl1Wm1sbmRYSmhkRzl5SUZObGJHWXRVMmxuYm1Wa0lFTmxjblJwWm1sallYUmxNU2d3SmdZSktvWklodmNOCkFRa0JGaGxoWkcxcGJrQndabE5sYm5ObExteHZZMkZzWkc5dFlXbHVNUjR3SEFZRFZRUURFeFZ3WmxObGJuTmwKTFRVelpHRmhNREEyTm1KaVlUR0NBUUF3RXdZRFZSMGxCQXd3Q2dZSUt3WUJCUVVIQXdFd0N3WURWUjBQQkFRRApBZ1dnTUEwR0NTcUdTSWIzRFFFQkN3VUFBNElCQVFBTzU2c2lGaHlJKzF5MGFRM1pQb2J5NDYxR0h4MW5sSUl0CloxdTdESTNKdjFnc25vMVVOTlFLN3JaWC9FcDBMUVFuMk45Z0I1djZ3eXRUZnZLbUJ0cUlyRzRJVjBHSmxmNzQKOVV6N2Vxc0Q5SElTRTNaM1A0bUpZYW1mbUJ2dVJqYzJNQ3JzRXFQTXBldUpnZnVZZzhMZ3VhRHc3ZXpmT0gxNgpkRnllc3l6RWs3UGExcGZVT3hUZVVndllEbzcyV2pTTndSOTVXTW9CYzBvQWZseVI0VlllUk40UmhQN1ZLYjNyCnU2SGhwR0c2eUgxbytnU2JadVpVVGdYb3NBcUd0WjFVcFppTlBsZWRVQzNFblZyUHdXZ085dWhVNWxPT0RCY1UKbWREZzFhU0RCSmlUcXJRZHRzZXNWcXpIU0VPSU1qeEpiOGFaSFgxeEp6TElMZHpERUVpQgotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==</crt>
465
		<prv>LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUV2QUlCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQktZd2dnU2lBZ0VBQW9JQkFRQ28xbithbUVSdFdMd0MKTkEyOXZKNzBiNTQ0K3RMdU5SeGlNUDJTN1BpeENWcnB4UzI5T1grSWxRaHc3MFBjV2lXL3pDVkJiL0VMNVJCaApjS0xGN21ka0hYNjVnSDAxM2NZWUY3RXZmV0FhMkZDcG5OT2xVc1YyaHRYT25RQXVESWY1Z29zb0djYkoxMFpKCjRaL2R1TllucEpMWHFNRFNVMmh0QU5TWDFCZTBHcDUvTHdYNTlCdGo1T3puZXFDTEp2eWpvd3kxTlFzdEYvVTMKejJINzNPcmJac3djTjEzYUh6NFhTQ1QrWmtHa2FiYmFNSytFakRpeEpDMnhzekVUc1RrWnBRUnc4VDdFdTYvNApVUWJOYlZhTmxrdE84N1BGUjgyU3I0UzFtQWVUREp5bnJjQXA5OUg0aXkwZ3VYcXo0OXljNzF4YTVoQnRBMDUzCnRyYmE5cEkzQWdNQkFBRUNnZ0VBTWViRDdFTlk1aUMxNE1qVnp1Qnk4cmdTd2JDUXEwc1RTb3BFU0NxMkRrMC8KaTV4MXVsbkdNZTRxZ29hVlBnbCs0c05KdDUrSVZRV3M0Ny9RdkVPTVYzRElSYmVPU2w5ejd5Y0JmWkhHMStoYgpYdVkxUDhYSkN4RXJIRmdXOTRWSW94eE1XTnZWZjA2YlBiYnI4ekp3U1dOQTYzQzdITzcrREVtVWpCTnB0aGMxCkhuUG44YnVFM3JlNFM1RHliY1pwVVhYTDl3VW5LeURvZTMyN0lSZU9JTE5YLyttNzY5eFdaUVNTWWtRRUw4WnIKLzdQaHVVSVBwaHE5SlQ2MG9pcS8yb3RFdjg3ZkliaC83QjhYaWdHdjV3NnRvWDVlOUo3RHlsTFhHNFlxbWMzQwpnK0QrNVpUbVpjWFNUUWhKTjNCR2pEZHpFT1JUd1JSV1l5WUhGRUpJa1FLQmdRRFNFeDBZdHBCRGFQc0dLTXBzCnhOZm5odEVmZHB0YUNPQnl5NmlpdUtMUGdVd3o1SjN5Z0pPdWcySTBLM2lHTVUybEdSdDVZWWVYUm9Vc2pLOS8KelF1VThnbExkOEpFNm5ldUtwZVBONXBFTHdUOU1PTHZlcTBjR1M3c0NPRjMyQjUvMUdCQWQwQW9rTlBDTTNidApRZEV1K2h0UVM1SXN4S21ZbXJSejdtUENpd0tCZ1FETnY0NmhkWkQweWQrVVNOWFE0WEd4M0JrazBsRktYaUUwCm1Yc0Jram1kYkcyK0RWWklXN3hUWDJxcXRxcTRNNEUwSFhDbVJuNVhQbzJFRjQvclQzdlRGUHdodGk2S1o2SFkKKzhHMzllclYvTWtmSzdzc0JzRmluSmkxNEwzOHcrTFNWOURpbWZQbTU2eUd4b2RHS1JLZ0poNkViZmJxeldHZQo3VFRnZkRlQWhRS0JnQ3J2QVJsVjVuSUFlSjB2cFA5SjA1NWI3VTF5M2hrdWkwQ3E0dEl1emdkK3MyWS9xUkF3CnV2NEZtQUoxaC9KVkRUdGF3RVMwYkJPOHMrY0E4YlU2NE0wV0VsUThLNVlPSFZ1WkZOU09WcGJzelNZNTRZZDAKR1FFUEhJbmMzc2V4Z2JvNlcxbVJoYWxFd0NLR2hoM0RQODlNQ2wwRXRPRTFhRHZxRWt0SFExZzFBb0dBWGZtMgp2Z3lpN3d3ZDhPN3Jxb0t1bVp4OFo1TWd5aVVBYWJRSXVRai9BK1o0b2F3WjB1Y0R0OWtITVg1SnIrVG1pTlZCCmxORHgrQXQ4Tys4L0x5MlkweXJzbHNGTnRLM3RBTnpNK0tkOFljMGFXQUJ6ZDRLR1pmSTgxaVlXNFJMZjBVK0cKKzFseVMrOVpvQjJodit3V3M4dDFlT3Q1TW5vb3NweUo0RmNjU3JrQ2dZQi9ROVhhT0ZPMSs4MHlVTXBsQkVEcgpSZFdmOHlMNGxYMHJpRU1qSlViT280MG5KYTBJTk8xQjJmV3R4MnlKU0tzWWJjSmJjUmJabmFZZk8wN3V0ZnVBCkxHRVlrUzB3RW1NK3JPY0k5YXhCbU1aTzR3TUlmeXVtK241emkrSjdORm40bDAvZkRQNnhjUkdKQzZFY1daQnMKTkt5d3FUTThmdlFTdkZZeUNPOWppdz09Ci0tLS0tRU5EIFBSSVZBVEUgS0VZLS0tLS0K</prv>
466
	</cert>
467
	<ppps/>
468
	<installedpackages>
469
		<miniupnpd>
470
			<config>
471
				<enable>on</enable>
472
				<enable_upnp>on</enable_upnp>
473
				<enable_natpmp/>
474
				<ext_iface>wan</ext_iface>
475
				<iface_array>lan</iface_array>
476
				<download/>
477
				<upload/>
478
				<overridewanip/>
479
				<upnpqueue/>
480
				<logpackets/>
481
				<sysuptime/>
482
				<permdefault/>
483
				<permuser1/>
484
				<permuser2/>
485
				<permuser3/>
486
				<permuser4/>
487
			</config>
488
		</miniupnpd>
489
		<ntopng>
490
			<config>
491
				<password>admin</password>
492
				<passwordagain>admin</passwordagain>
493
				<interface_array>lan</interface_array>
494
				<dns_mode>0</dns_mode>
495
				<local_networks>rfc1918</local_networks>
496
				<dump_flows/>
497
			</config>
498
		</ntopng>
499
		<package>
500
			<name>snort</name>
501
			<pkginfolink>https://doc.pfsense.org/index.php/Setup_Snort_Package</pkginfolink>
502
			<website>http://www.snort.org</website>
503
			<descr><![CDATA[Snort is an open source network intrusion prevention and detection system (IDS/IPS). Combining the benefits of signature, protocol, and anomaly-based inspection.]]></descr>
504
			<category>Security</category>
505
			<run_depends>bin/snort:security/snort</run_depends>
506
			<port_category>security</port_category>
507
			<depends_on_package_pbi>snort-2.9.7.3-amd64.pbi</depends_on_package_pbi>
508
			<build_pbi>
509
				<port>security/snort</port>
510
				<ports_after>security/barnyard2</ports_after>
511
			</build_pbi>
512
			<build_options>barnyard2_UNSET_FORCE=ODBC PGSQL PRELUDE;barnyard2_SET_FORCE=GRE IPV6 MPLS MYSQL PORT_PCAP BRO;snort_SET_FORCE=BARNYARD PERFPROFILE SOURCEFIRE GRE IPV6 NORMALIZER APPID;snort_UNSET_FORCE=PULLEDPORK FILEINSPECT HA</build_options>
513
			<config_file>https://packages.pfsense.org/packages/config/snort/snort.xml</config_file>
514
			<version>3.2.6</version>
515
			<required_version>2.2</required_version>
516
			<status>Stable</status>
517
			<configurationfile>/snort.xml</configurationfile>
518
			<after_install_info>Please visit the Snort settings tab first and select your desired rules. Afterwards visit the update rules tab to download your configured rules.</after_install_info>
519
			<depends_on_package_base_url>https://files.pfsense.org/packages/10/All/</depends_on_package_base_url>
520
		</package>
521
		<package>
522
			<name>squid</name>
523
			<descr><![CDATA[High performance web proxy cache.]]></descr>
524
			<website>http://www.squid-cache.org/</website>
525
			<category>Network</category>
526
			<version>2.7.9 pkg v.4.3.6</version>
527
			<status>Stable</status>
528
			<required_version>2.2</required_version>
529
			<maintainer>fernando@netfilter.com.br seth.mos@dds.nl mfuchs77@googlemail.com jimp@pfsense.org</maintainer>
530
			<depends_on_package_pbi>squid-2.7.9_4-amd64.pbi</depends_on_package_pbi>
531
			<build_pbi>
532
				<ports_before>www/libwww</ports_before>
533
				<port>www/squid</port>
534
				<ports_after>www/squid_radius_auth</ports_after>
535
			</build_pbi>
536
			<build_options>squid_UNSET_FORCE=DNS_HELPER IPFILTER PINGER STACKTRACES STRICT_HTTP_DESC USERAGENT_LOG WCCPV2;squid_SET_FORCE=PF LDAP_AUTH NIS_AUTH SASL_AUTH ARP_ACL AUFS CACHE_DIGESTS CARP COSS DELAY_POOLS FOLLOW_XFF HTCP IDENT KERB_AUTH KQUEUE LARGEFILE REFERER_LOG SNMP SSL VIA_DB WCCP;SQUID_UID=proxy;SQUID_GID=proxy</build_options>
537
			<config_file>https://packages.pfsense.org/packages/config/squid/squid.xml</config_file>
538
			<configurationfile>squid.xml</configurationfile>
539
			<maximum_version>2.2.999</maximum_version>
540
			<depends_on_package_base_url>https://files.pfsense.org/packages/10/All/</depends_on_package_base_url>
541
			<filter_rule_function>squid_generate_rules</filter_rule_function>
542
		</package>
543
		<package>
544
			<name>HAVP antivirus</name>
545
			<pkginfolink/>
546
			<website>http://www.server-side.de/</website>
547
			<descr><![CDATA[Antivirus:  HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanner. The main aims are continuous, non-blocking downloads and smooth scanning of dynamic and password protected HTTP traffic. Havp antivirus proxy has a parent and transparent proxy mode. It can be used with squid or standalone. And File Scanner for local files.]]></descr>
548
			<category>Network Management</category>
549
			<depends_on_package_pbi>havp-0.91_3-amd64.pbi</depends_on_package_pbi>
550
			<build_pbi>
551
				<port>www/havp</port>
552
				<ports_after>security/clamav</ports_after>
553
			</build_pbi>
554
			<build_options>CLAMAVUSER=havp;CLAMAVGROUP=havp</build_options>
555
			<version>0.91_3 pkg v1.05_1</version>
556
			<status>BETA</status>
557
			<required_version>2.2</required_version>
558
			<config_file>https://packages.pfsense.org/packages/config/havp/havp.xml</config_file>
559
			<configurationfile>havp.xml</configurationfile>
560
			<maintainer>dv_serg@mail.ru</maintainer>
561
			<after_install_info>Please check the HAVP settings.</after_install_info>
562
			<maximum_version>2.2.999</maximum_version>
563
			<depends_on_package_base_url>https://files.pfsense.org/packages/10/All/</depends_on_package_base_url>
564
		</package>
565
		<package>
566
			<name>pfBlockerNG</name>
567
			<website/>
568
			<descr><![CDATA[pfBlockerNG is the Next Generation of pfBlocker.&lt;br /&gt;
569
				Manage IPv4/v6 List Sources into 'Deny, Permit or Match' formats&lt;br /&gt;
570
				Country Blocking Database by MaxMind Inc. (GeoLite Free version).&lt;br /&gt;
571
				De-Duplication, Suppression, and Reputation enhancements.&lt;br /&gt;
572
				Provision to download from diverse List formats. Advanced Integration&lt;br /&gt;
573
				for Emerging Threats IQRisk IP Reputation Threat Sources.]]></descr>
574
			<category>Firewall</category>
575
			<pkginfolink>https://forum.pfsense.org/index.php?topic=86212.0</pkginfolink>
576
			<config_file>https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.xml</config_file>
577
			<version>1.09</version>
578
			<status>Stable</status>
579
			<required_version>2.2</required_version>
580
			<maintainer>BBCan177@gmail.com</maintainer>
581
			<configurationfile>pfblockerng.xml</configurationfile>
582
			<run_depends>bin/geoiplookup:net/GeoIP bin/grepcidr:net-mgmt/grepcidr</run_depends>
583
			<port_category>net</port_category>
584
			<depends_on_package_pbi>pfblockerng-1.6.3_1-amd64.pbi</depends_on_package_pbi>
585
			<build_pbi>
586
				<port>net/GeoIP</port>
587
				<ports_after>net-mgmt/grepcidr</ports_after>
588
				<custom_name>pfblockerng</custom_name>
589
			</build_pbi>
590
			<depends_on_package_base_url>https://files.pfsense.org/packages/10/All/</depends_on_package_base_url>
591
		</package>
592
		<snortglobal>
593
			<snort_config_ver>3.2.6</snort_config_ver>
594
			<rule>
595
				<interface>wan</interface>
596
				<enable>on</enable>
597
				<uuid>11584</uuid>
598
				<descr><![CDATA[WAN]]></descr>
599
				<performance>ac-bnfa</performance>
600
				<blockoffenders7>on</blockoffenders7>
601
				<blockoffendersip>both</blockoffendersip>
602
				<whitelistname>EmptyPassList</whitelistname>
603
				<homelistname>default</homelistname>
604
				<externallistname>default</externallistname>
605
				<suppresslistname>default</suppresslistname>
606
				<alertsystemlog>off</alertsystemlog>
607
				<alertsystemlog_facility>log_auth</alertsystemlog_facility>
608
				<alertsystemlog_priority>log_alert</alertsystemlog_priority>
609
				<cksumcheck>off</cksumcheck>
610
				<fpm_split_any_any>off</fpm_split_any_any>
611
				<fpm_search_optimize>on</fpm_search_optimize>
612
				<fpm_no_stream_inserts>off</fpm_no_stream_inserts>
613
				<max_attribute_hosts>10000</max_attribute_hosts>
614
				<max_attribute_services_per_host>10</max_attribute_services_per_host>
615
				<max_paf>16000</max_paf>
616
				<ftp_preprocessor>on</ftp_preprocessor>
617
				<ftp_telnet_inspection_type>stateful</ftp_telnet_inspection_type>
618
				<ftp_telnet_alert_encrypted>off</ftp_telnet_alert_encrypted>
619
				<ftp_telnet_check_encrypted>on</ftp_telnet_check_encrypted>
620
				<ftp_telnet_normalize>on</ftp_telnet_normalize>
621
				<ftp_telnet_detect_anomalies>on</ftp_telnet_detect_anomalies>
622
				<ftp_telnet_ayt_attack_threshold>20</ftp_telnet_ayt_attack_threshold>
623
				<ftp_client_engine>
624
					<item>
625
						<name>default</name>
626
						<bind_to>all</bind_to>
627
						<max_resp_len>256</max_resp_len>
628
						<telnet_cmds>no</telnet_cmds>
629
						<ignore_telnet_erase_cmds>yes</ignore_telnet_erase_cmds>
630
						<bounce>yes</bounce>
631
						<bounce_to_net/>
632
						<bounce_to_port/>
633
					</item>
634
				</ftp_client_engine>
635
				<ftp_server_engine>
636
					<item>
637
						<name>default</name>
638
						<bind_to>all</bind_to>
639
						<ports>default</ports>
640
						<telnet_cmds>no</telnet_cmds>
641
						<ignore_telnet_erase_cmds>yes</ignore_telnet_erase_cmds>
642
						<ignore_data_chan>no</ignore_data_chan>
643
						<def_max_param_len>100</def_max_param_len>
644
					</item>
645
				</ftp_server_engine>
646
				<smtp_preprocessor>on</smtp_preprocessor>
647
				<smtp_memcap>838860</smtp_memcap>
648
				<smtp_max_mime_mem>838860</smtp_max_mime_mem>
649
				<smtp_b64_decode_depth>0</smtp_b64_decode_depth>
650
				<smtp_qp_decode_depth>0</smtp_qp_decode_depth>
651
				<smtp_bitenc_decode_depth>0</smtp_bitenc_decode_depth>
652
				<smtp_uu_decode_depth>0</smtp_uu_decode_depth>
653
				<smtp_email_hdrs_log_depth>1464</smtp_email_hdrs_log_depth>
654
				<smtp_ignore_data>off</smtp_ignore_data>
655
				<smtp_ignore_tls_data>on</smtp_ignore_tls_data>
656
				<smtp_log_mail_from>on</smtp_log_mail_from>
657
				<smtp_log_rcpt_to>on</smtp_log_rcpt_to>
658
				<smtp_log_filename>on</smtp_log_filename>
659
				<smtp_log_email_hdrs>on</smtp_log_email_hdrs>
660
				<dce_rpc_2>on</dce_rpc_2>
661
				<dns_preprocessor>on</dns_preprocessor>
662
				<ssl_preproc>on</ssl_preproc>
663
				<pop_preproc>on</pop_preproc>
664
				<pop_memcap>838860</pop_memcap>
665
				<pop_b64_decode_depth>0</pop_b64_decode_depth>
666
				<pop_qp_decode_depth>0</pop_qp_decode_depth>
667
				<pop_bitenc_decode_depth>0</pop_bitenc_decode_depth>
668
				<pop_uu_decode_depth>0</pop_uu_decode_depth>
669
				<imap_preproc>on</imap_preproc>
670
				<imap_memcap>838860</imap_memcap>
671
				<imap_b64_decode_depth>0</imap_b64_decode_depth>
672
				<imap_qp_decode_depth>0</imap_qp_decode_depth>
673
				<imap_bitenc_decode_depth>0</imap_bitenc_decode_depth>
674
				<imap_uu_decode_depth>0</imap_uu_decode_depth>
675
				<sip_preproc>on</sip_preproc>
676
				<other_preprocs>on</other_preprocs>
677
				<pscan_protocol>all</pscan_protocol>
678
				<pscan_type>all</pscan_type>
679
				<pscan_memcap>10000000</pscan_memcap>
680
				<pscan_sense_level>medium</pscan_sense_level>
681
				<http_inspect>on</http_inspect>
682
				<http_inspect_proxy_alert>off</http_inspect_proxy_alert>
683
				<http_inspect_memcap>150994944</http_inspect_memcap>
684
				<http_inspect_max_gzip_mem>838860</http_inspect_max_gzip_mem>
685
				<http_inspect_engine>
686
					<item>
687
						<name>default</name>
688
						<bind_to>all</bind_to>
689
						<server_profile>all</server_profile>
690
						<enable_xff>off</enable_xff>
691
						<log_uri>off</log_uri>
692
						<log_hostname>off</log_hostname>
693
						<server_flow_depth>65535</server_flow_depth>
694
						<enable_cookie>on</enable_cookie>
695
						<client_flow_depth>1460</client_flow_depth>
696
						<extended_response_inspection>on</extended_response_inspection>
697
						<no_alerts>off</no_alerts>
698
						<unlimited_decompress>on</unlimited_decompress>
699
						<inspect_gzip>on</inspect_gzip>
700
						<normalize_cookies>on</normalize_cookies>
701
						<normalize_headers>on</normalize_headers>
702
						<normalize_utf>on</normalize_utf>
703
						<normalize_javascript>on</normalize_javascript>
704
						<allow_proxy_use>off</allow_proxy_use>
705
						<inspect_uri_only>off</inspect_uri_only>
706
						<max_javascript_whitespaces>200</max_javascript_whitespaces>
707
						<post_depth>-1</post_depth>
708
						<max_headers>0</max_headers>
709
						<max_spaces>0</max_spaces>
710
						<max_header_length>0</max_header_length>
711
						<ports>default</ports>
712
					</item>
713
				</http_inspect_engine>
714
				<frag3_max_frags>8192</frag3_max_frags>
715
				<frag3_memcap>4194304</frag3_memcap>
716
				<frag3_detection>on</frag3_detection>
717
				<frag3_engine>
718
					<item>
719
						<name>default</name>
720
						<bind_to>all</bind_to>
721
						<policy>bsd</policy>
722
						<timeout>60</timeout>
723
						<min_ttl>1</min_ttl>
724
						<detect_anomalies>on</detect_anomalies>
725
						<overlap_limit>0</overlap_limit>
726
						<min_frag_len>0</min_frag_len>
727
					</item>
728
				</frag3_engine>
729
				<stream5_reassembly>on</stream5_reassembly>
730
				<stream5_flush_on_alert>off</stream5_flush_on_alert>
731
				<stream5_prune_log_max>1048576</stream5_prune_log_max>
732
				<stream5_track_tcp>on</stream5_track_tcp>
733
				<stream5_max_tcp>262144</stream5_max_tcp>
734
				<stream5_track_udp>on</stream5_track_udp>
735
				<stream5_max_udp>131072</stream5_max_udp>
736
				<stream5_udp_timeout>30</stream5_udp_timeout>
737
				<stream5_track_icmp>off</stream5_track_icmp>
738
				<stream5_max_icmp>65536</stream5_max_icmp>
739
				<stream5_icmp_timeout>30</stream5_icmp_timeout>
740
				<stream5_mem_cap>8388608</stream5_mem_cap>
741
				<stream5_tcp_engine>
742
					<item>
743
						<name>default</name>
744
						<bind_to>all</bind_to>
745
						<policy>bsd</policy>
746
						<timeout>30</timeout>
747
						<max_queued_bytes>1048576</max_queued_bytes>
748
						<detect_anomalies>off</detect_anomalies>
749
						<overlap_limit>0</overlap_limit>
750
						<max_queued_segs>2621</max_queued_segs>
751
						<require_3whs>off</require_3whs>
752
						<startup_3whs_timeout>0</startup_3whs_timeout>
753
						<no_reassemble_async>off</no_reassemble_async>
754
						<max_window>0</max_window>
755
						<use_static_footprint_sizes>off</use_static_footprint_sizes>
756
						<check_session_hijacking>off</check_session_hijacking>
757
						<dont_store_lg_pkts>off</dont_store_lg_pkts>
758
						<ports_client>default</ports_client>
759
						<ports_both>default</ports_both>
760
						<ports_server>none</ports_server>
761
					</item>
762
				</stream5_tcp_engine>
763
				<appid_preproc>on</appid_preproc>
764
				<sf_appid_mem_cap>256</sf_appid_mem_cap>
765
				<sf_appid_statslog>on</sf_appid_statslog>
766
				<sf_appid_stats_period>300</sf_appid_stats_period>
767
				<rulesets/>
768
				<ips_policy_enable>on</ips_policy_enable>
769
				<ips_policy>balanced</ips_policy>
770
				<autoflowbitrules>on</autoflowbitrules>
771
				<sdf_alert_data_type>Credit Card,Email Addresses,U.S. Phone Numbers,U.S. Social Security Numbers</sdf_alert_data_type>
772
				<sdf_alert_threshold>25</sdf_alert_threshold>
773
				<sdf_mask_output>off</sdf_mask_output>
774
				<ssh_preproc>on</ssh_preproc>
775
				<pscan_ignore_scanners/>
776
				<perform_stat>off</perform_stat>
777
				<host_attribute_table>off</host_attribute_table>
778
				<sf_portscan>off</sf_portscan>
779
				<sensitive_data>off</sensitive_data>
780
				<dnp3_preproc>off</dnp3_preproc>
781
				<modbus_preproc>off</modbus_preproc>
782
				<gtp_preproc>off</gtp_preproc>
783
				<preproc_auto_rule_disable>off</preproc_auto_rule_disable>
784
				<protect_preproc_rules>off</protect_preproc_rules>
785
			</rule>
786
			<snortdownload>on</snortdownload>
787
			<snortcommunityrules>off</snortcommunityrules>
788
			<emergingthreats>off</emergingthreats>
789
			<emergingthreats_pro>off</emergingthreats_pro>
790
			<clearblocks>off</clearblocks>
791
			<verbose_logging>off</verbose_logging>
792
			<openappid_detectors>on</openappid_detectors>
793
			<hide_deprecated_rules>off</hide_deprecated_rules>
794
			<oinkmastercode>45065f07ffa1978fcd788b7597c9886ed1d6046a</oinkmastercode>
795
			<etpro_code/>
796
			<rm_blocked>1h_b</rm_blocked>
797
			<autorulesupdate7>1d_up</autorulesupdate7>
798
			<rule_update_starttime>00:05</rule_update_starttime>
799
			<forcekeepsettings>on</forcekeepsettings>
800
			<last_rule_upd_status>success</last_rule_upd_status>
801
			<last_rule_upd_time>1437523513</last_rule_upd_time>
802
			<whitelist>
803
				<item>
804
					<name>EmptyPassList</name>
805
					<uuid>6140</uuid>
806
					<localnets>no</localnets>
807
					<wanips>no</wanips>
808
					<wangateips>no</wangateips>
809
					<wandnsips>no</wandnsips>
810
					<vips>no</vips>
811
					<vpnips>no</vpnips>
812
					<address/>
813
					<descr/>
814
				</item>
815
			</whitelist>
816
			<enable_log_mgmt>on</enable_log_mgmt>
817
			<clearlogs>off</clearlogs>
818
			<snortloglimit>on</snortloglimit>
819
			<snortloglimitsize>478</snortloglimitsize>
820
			<alert_log_limit_size>500</alert_log_limit_size>
821
			<alert_log_retention>336</alert_log_retention>
822
			<stats_log_limit_size>500</stats_log_limit_size>
823
			<stats_log_retention>168</stats_log_retention>
824
			<sid_changes_log_limit_size>250</sid_changes_log_limit_size>
825
			<sid_changes_log_retention>336</sid_changes_log_retention>
826
			<event_pkts_log_limit_size>0</event_pkts_log_limit_size>
827
			<event_pkts_log_retention>336</event_pkts_log_retention>
828
			<appid_stats_log_limit_size>1000</appid_stats_log_limit_size>
829
			<appid_stats_log_retention>168</appid_stats_log_retention>
830
			<alertsblocks>
831
				<arefresh>off</arefresh>
832
				<alertnumber>250</alertnumber>
833
			</alertsblocks>
834
		</snortglobal>
835
		<menu>
836
			<name>Snort</name>
837
			<tooltiptext>Set up snort specific settings</tooltiptext>
838
			<section>Services</section>
839
			<url>/snort/snort_interfaces.php</url>
840
		</menu>
841
		<menu>
842
			<name>Antivirus</name>
843
			<tooltiptext>Antivirus service</tooltiptext>
844
			<section>Services</section>
845
			<url>/antivirus.php</url>
846
		</menu>
847
		<menu>
848
			<name>pfBlockerNG</name>
849
			<configfile>pfblockerng.xml</configfile>
850
			<tooltiptext>Configure pfBlockerNG</tooltiptext>
851
			<section>Firewall</section>
852
			<url>/pkg_edit.php?xml=pfblockerng.xml</url>
853
		</menu>
854
		<service>
855
			<name>snort</name>
856
			<rcfile>snort.sh</rcfile>
857
			<executable>snort</executable>
858
			<description><![CDATA[Snort IDS/IPS Daemon]]></description>
859
		</service>
860
		<service>
861
			<name>havp</name>
862
			<rcfile>havp.sh</rcfile>
863
			<executable>havp</executable>
864
			<description><![CDATA[Antivirus HTTP proxy Service]]></description>
865
		</service>
866
		<havp>
867
			<config>
868
				<enable>on</enable>
869
				<useclamd>true</useclamd>
870
				<proxymode>transparent</proxymode>
871
				<proxyinterface>lan</proxyinterface>
872
				<proxyport>3125</proxyport>
873
				<parentproxy/>
874
				<enablexforwardedfor/>
875
				<enableforwardedip/>
876
				<lang>en</lang>
877
				<maxdownloadsize/>
878
				<range/>
879
				<whitelist/>
880
				<blacklist/>
881
				<failscanerror/>
882
				<enableramdisk>on</enableramdisk>
883
				<scanmaxsize>5000</scanmaxsize>
884
				<scanimg>on</scanimg>
885
				<scanstream/>
886
				<scanbrokenexe>on</scanbrokenexe>
887
				<log>on</log>
888
				<syslog/>
889
			</config>
890
		</havp>
891
		<havpavset>
892
			<config>
893
				<havpavupdate>4</havpavupdate>
894
				<dbregion>us</dbregion>
895
				<avupdateserver/>
896
				<avsetlog>on</avsetlog>
897
				<avsetsyslog/>
898
			</config>
899
		</havpavset>
900
		<squid>
901
			<config>
902
				<active_interface>lan</active_interface>
903
				<allow_interface>on</allow_interface>
904
				<transparent_proxy>on</transparent_proxy>
905
				<private_subnet_proxy_off/>
906
				<defined_ip_proxy_off/>
907
				<defined_ip_proxy_off_dest/>
908
				<log_enabled>on</log_enabled>
909
				<log_dir>/var/squid/logs</log_dir>
910
				<log_rotate>2</log_rotate>
911
				<proxy_port>3128</proxy_port>
912
				<icp_port/>
913
				<visible_hostname>localhost</visible_hostname>
914
				<admin_email>admin@localhost</admin_email>
915
				<error_language>English</error_language>
916
				<disable_xforward/>
917
				<disable_via/>
918
				<uri_whitespace>strip</uri_whitespace>
919
				<dns_nameservers/>
920
				<disable_squidversion/>
921
				<custom_options/>
922
			</config>
923
		</squid>
924
		<squidcache>
925
			<config>
926
				<harddisk_cache_size>500</harddisk_cache_size>
927
				<harddisk_cache_system>ufs</harddisk_cache_system>
928
				<harddisk_cache_location>/var/squid/cache</harddisk_cache_location>
929
				<memory_cache_size>8</memory_cache_size>
930
				<minimum_object_size>0</minimum_object_size>
931
				<maximum_object_size>4</maximum_object_size>
932
				<maximum_objsize_in_mem>32</maximum_objsize_in_mem>
933
				<level1_subdirs>16</level1_subdirs>
934
				<memory_replacement_policy>heap GDSF</memory_replacement_policy>
935
				<cache_replacement_policy>heap LFUDA</cache_replacement_policy>
936
				<cache_swap_low>90</cache_swap_low>
937
				<cache_swap_high>95</cache_swap_high>
938
				<donotcache/>
939
				<enable_offline/>
940
			</config>
941
		</squidcache>
942
		<tab>
943
			<text>General</text>
944
			<url>/pkg_edit.php?xml=pfblockerng.xml&amp;id=0</url>
945
			<active/>
946
		</tab>
947
	</installedpackages>
948
	<gateways/>
949
</pfsense>
(6-6/6)