Project

General

Profile

Bug #4876 » config-pfbng.xml

Kill Bill, 07/24/2015 02:26 AM

 
1
<pfblockerng>
2
			<config>
3
				<enable_cb>on</enable_cb>
4
				<pfb_keep>on</pfb_keep>
5
				<pfb_interval>1</pfb_interval>
6
				<pfb_min>30</pfb_min>
7
				<pfb_hour>0</pfb_hour>
8
				<pfb_dailystart>0</pfb_dailystart>
9
				<enable_dup>on</enable_dup>
10
				<suppression>on</suppression>
11
				<enable_log/>
12
				<database_cc/>
13
				<log_maxlines>20000</log_maxlines>
14
				<inbound_interface>opt2,wan</inbound_interface>
15
				<inbound_deny_action>block</inbound_deny_action>
16
				<outbound_interface>lan,opt3</outbound_interface>
17
				<outbound_deny_action>reject</outbound_deny_action>
18
				<openvpn_action>on</openvpn_action>
19
				<enable_float>on</enable_float>
20
				<pass_order>order_0</pass_order>
21
				<autorule_suffix>autorule</autorule_suffix>
22
				<killstates>on</killstates>
23
				<credits/>
24
				<pfb_reuse/>
25
			</config>
26
		</pfblockerng>
27
		<pfblockernglistsv4>
28
			<config>
29
				<aliasname>IBlock</aliasname>
30
				<description><![CDATA[pfBlockerNG IBlock]]></description>
31
				<row>
32
					<format>gz</format>
33
					<state>Disabled</state>
34
					<url>http://list.iblocklist.com/?list=usrcshglbiilevmyfhse&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
35
					<header>IBlock_BT_Hijack</header>
36
				</row>
37
				<row>
38
					<format>gz</format>
39
					<state>Disabled</state>
40
					<url>http://list.iblocklist.com/?list=ficutxiwawokxlcyoeye&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
41
					<header>IBlock_BT_FS</header>
42
				</row>
43
				<row>
44
					<format>gz</format>
45
					<state>Enabled</state>
46
					<url>http://list.iblocklist.com/?list=ghlzqtqxnzctvvajwwag&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
47
					<header>IBlock_BT_Web</header>
48
				</row>
49
				<row>
50
					<format>gz</format>
51
					<state>Enabled</state>
52
					<url>http://list.iblocklist.com/?list=llvtlsjyoyiczbkjsxpf&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
53
					<header>IBlock_BT_Spy</header>
54
				</row>
55
				<row>
56
					<format>gz</format>
57
					<state>Disabled</state>
58
					<url>http://list.iblocklist.com/?list=cwworuawihqvocglcoss&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
59
					<header>IBlock_Badpeer</header>
60
				</row>
61
				<row>
62
					<format>gz</format>
63
					<state>Disabled</state>
64
					<url>http://list.iblocklist.com/?list=dgxtneitpuvgqqcpfulq&amp;fileformat=p2p&amp;archiveformat=gz</url>
65
					<header>IBlock_Ads</header>
66
				</row>
67
				<row>
68
					<format>gz</format>
69
					<state>Disabled</state>
70
					<url>http://list.iblocklist.com/?list=xoebmbyexwuiogmbyprb&amp;amp;fileformat=p2p&amp;amp;archiveformat=gz</url>
71
					<header>IBlock_Proxy</header>
72
				</row>
73
				<row>
74
					<format>gz</format>
75
					<state>Enabled</state>
76
					<url>http://list.iblocklist.com/?list=xpbqleszmajjesnzddhv&amp;fileformat=p2p&amp;archiveformat=gz</url>
77
					<header>IBlock_dShield</header>
78
				</row>
79
				<action>Deny_Both</action>
80
				<cron>12hours</cron>
81
				<dow>1</dow>
82
				<aliaslog>enabled</aliaslog>
83
				<autoports/>
84
				<aliasports/>
85
				<autodest/>
86
				<aliasdest/>
87
				<autonot/>
88
				<autoproto/>
89
				<custom/>
90
				<custom_update>disabled</custom_update>
91
			</config>
92
			<config>
93
				<aliasname>PRI1</aliasname>
94
				<description><![CDATA[pfBlockerNG PRI1]]></description>
95
				<row>
96
					<format>txt</format>
97
					<state>Enabled</state>
98
					<url>https://rules.emergingthreats.net/blockrules/compromised-ips.txt</url>
99
					<header>ET_Comp</header>
100
				</row>
101
				<row>
102
					<format>txt</format>
103
					<state>Disabled</state>
104
					<url>https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt</url>
105
					<header>ET_Block</header>
106
				</row>
107
				<row>
108
					<format>txt</format>
109
					<state>Enabled</state>
110
					<url>http://www.spamhaus.org/drop/drop.txt</url>
111
					<header>Spamhaus_drop</header>
112
				</row>
113
				<row>
114
					<format>txt</format>
115
					<state>Disabled</state>
116
					<url>http://www.spamhaus.org/drop/edrop.txt</url>
117
					<header>Spamhaus_edrop</header>
118
				</row>
119
				<row>
120
					<format>txt</format>
121
					<state>Enabled</state>
122
					<url>http://cinsscore.com/list/ci-badguys.txt</url>
123
					<header>CIArmy</header>
124
				</row>
125
				<row>
126
					<format>txt</format>
127
					<state>Enabled</state>
128
					<url>https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist</url>
129
					<header>Abuse_Zeus</header>
130
				</row>
131
				<row>
132
					<format>txt</format>
133
					<state>Enabled</state>
134
					<url>https://palevotracker.abuse.ch/blocklists.php?download=ipblocklist</url>
135
					<header>Abuse_Palevo</header>
136
				</row>
137
				<row>
138
					<format>html</format>
139
					<state>Enabled</state>
140
					<url>https://sslbl.abuse.ch/blacklist/sslipblacklist.csv</url>
141
					<header>Abuse_SSLBL</header>
142
				</row>
143
				<row>
144
					<format>block</format>
145
					<state>Enabled</state>
146
					<url>https://feeds.dshield.org/block.txt</url>
147
					<header>dShield_Block</header>
148
				</row>
149
				<row>
150
					<format>txt</format>
151
					<state>Disabled</state>
152
					<url>https://labs.snort.org/feeds/ip-filter.blf</url>
153
					<header>Snort_BL</header>
154
				</row>
155
				<row>
156
					<format>html</format>
157
					<state>Disabled</state>
158
					<url>http://osint.bambenekconsulting.com/feeds/goz-iplist.txt</url>
159
					<header>BBC_Goz</header>
160
				</row>
161
				<action>Deny_Both</action>
162
				<cron>12hours</cron>
163
				<dow>1</dow>
164
				<aliaslog>enabled</aliaslog>
165
				<autoports/>
166
				<aliasports/>
167
				<autodest/>
168
				<aliasdest/>
169
				<autonot/>
170
				<autoproto/>
171
				<custom/>
172
				<custom_update>disabled</custom_update>
173
			</config>
174
			<config>
175
				<aliasname>PRI2</aliasname>
176
				<description><![CDATA[pfBlockerNG PRI2]]></description>
177
				<row>
178
					<format>gz_2</format>
179
					<state>Disabled</state>
180
					<url>https://reputation.alienvault.com/reputation.snort.gz</url>
181
					<header>Alienvault</header>
182
				</row>
183
				<row>
184
					<format>html</format>
185
					<state>Enabled</state>
186
					<url>https://atlas.arbor.net/summary/attacks.csv</url>
187
					<header>Atlas_Attacks</header>
188
				</row>
189
				<row>
190
					<format>html</format>
191
					<state>Enabled</state>
192
					<url>https://atlas.arbor.net/summary/botnets.csv</url>
193
					<header>Atlas_Botnets</header>
194
				</row>
195
				<row>
196
					<format>html</format>
197
					<state>Disabled</state>
198
					<url>https://atlas.arbor.net/summary/fastflux.csv</url>
199
					<header>Atlas_Fastflux</header>
200
				</row>
201
				<row>
202
					<format>html</format>
203
					<state>Enabled</state>
204
					<url>https://atlas.arbor.net/summary/phishing.csv</url>
205
					<header>Atlas_Phishing</header>
206
				</row>
207
				<row>
208
					<format>html</format>
209
					<state>Enabled</state>
210
					<url>https://atlas.arbor.net/summary/scans.csv</url>
211
					<header>Atlas_Scans</header>
212
				</row>
213
				<row>
214
					<format>txt</format>
215
					<state>Disabled</state>
216
					<url>http://www.cyber-ta.org/releases/malware/SOURCES/Attacker.Cumulative.Summary</url>
217
					<header>SRI_Attackers</header>
218
				</row>
219
				<row>
220
					<format>txt</format>
221
					<state>Disabled</state>
222
					<url>http://www.cyber-ta.org/releases/malware/SOURCES/CandC.Cumulative.Summary</url>
223
					<header>SRI_CC</header>
224
				</row>
225
				<row>
226
					<format>html</format>
227
					<state>Enabled</state>
228
					<url>https://www.projecthoneypot.org/list_of_ips.php?t=d&amp;rss=1</url>
229
					<header>HoneyPot_Dict_Attack</header>
230
				</row>
231
				<row>
232
					<format>html</format>
233
					<state>Enabled</state>
234
					<url>https://www.projecthoneypot.org/list_of_ips.php?t=s&amp;rss=1</url>
235
					<header>HoneyPot_Spam_Server</header>
236
				</row>
237
				<row>
238
					<format>html</format>
239
					<state>Enabled</state>
240
					<url>https://www.projecthoneypot.org/list_of_ips.php?t=w&amp;rss=1</url>
241
					<header>HoneyPot_Malicious_IPs</header>
242
				</row>
243
				<action>Deny_Both</action>
244
				<cron>12hours</cron>
245
				<dow>1</dow>
246
				<aliaslog>enabled</aliaslog>
247
				<autoports/>
248
				<aliasports/>
249
				<autodest/>
250
				<aliasdest/>
251
				<autonot/>
252
				<autoproto/>
253
				<custom/>
254
				<custom_update>disabled</custom_update>
255
			</config>
256
			<config>
257
				<aliasname>PRI3</aliasname>
258
				<description><![CDATA[pfBlockerNG PRI3]]></description>
259
				<row>
260
					<format>txt</format>
261
					<state>Enabled</state>
262
					<url>http://www.malwaredomainlist.com/hostslist/ip.txt</url>
263
					<header>MDL</header>
264
				</row>
265
				<row>
266
					<format>txt</format>
267
					<state>Disabled</state>
268
					<url>http://www.nothink.org/blacklist/blacklist_malware_http.txt</url>
269
					<header>Nothink_BL</header>
270
				</row>
271
				<row>
272
					<format>txt</format>
273
					<state>Disabled</state>
274
					<url>http://www.nothink.org/blacklist/blacklist_ssh_week.txt</url>
275
					<header>Nothink_SSH</header>
276
				</row>
277
				<row>
278
					<format>txt</format>
279
					<state>Disabled</state>
280
					<url>http://www.nothink.org/blacklist/blacklist_malware_dns.txt</url>
281
					<header>Nothink_Malware</header>
282
				</row>
283
				<row>
284
					<format>txt</format>
285
					<state>Enabled</state>
286
					<url>http://danger.rulez.sk/projects/bruteforceblocker/blist.php</url>
287
					<header>DangerRulez</header>
288
				</row>
289
				<row>
290
					<format>html</format>
291
					<state>Enabled</state>
292
					<url>https://www.autoshun.org/files/shunlist.csv</url>
293
					<header>Shunlist</header>
294
				</row>
295
				<row>
296
					<format>txt</format>
297
					<state>Disabled</state>
298
					<url>http://www.infiltrated.net/blacklisted</url>
299
					<header>Infiltrated</header>
300
				</row>
301
				<row>
302
					<format>txt</format>
303
					<state>Disabled</state>
304
					<url>https://www.dragonresearchgroup.org/insight/sshpwauth.txt</url>
305
					<header>DRG_SSH</header>
306
				</row>
307
				<row>
308
					<format>txt</format>
309
					<state>Disabled</state>
310
					<url>https://www.dragonresearchgroup.org/insight/vncprobe.txt</url>
311
					<header>DRG_VNC</header>
312
				</row>
313
				<row>
314
					<format>txt</format>
315
					<state>Disabled</state>
316
					<url>https://www.dragonresearchgroup.org/insight/http-report.txt</url>
317
					<header>DRG_HTTP</header>
318
				</row>
319
				<row>
320
					<format>txt</format>
321
					<state>Enabled</state>
322
					<url>https://feodotracker.abuse.ch/blocklist/?download=ipblocklist</url>
323
					<header>Feodo_Block</header>
324
				</row>
325
				<row>
326
					<format>txt</format>
327
					<state>Disabled</state>
328
					<url>https://feodotracker.abuse.ch/blocklist/?download=badips</url>
329
					<header>Feodo_Bad</header>
330
				</row>
331
				<row>
332
					<format>txt</format>
333
					<state>Disabled</state>
334
					<url>http://www.reputationauthority.org/toptens.php</url>
335
					<header>WatchGuard</header>
336
				</row>
337
				<row>
338
					<format>txt</format>
339
					<state>Disabled</state>
340
					<url>https://vmx.yourcmc.ru/BAD_HOSTS.IP4</url>
341
					<header>VMX</header>
342
				</row>
343
				<row>
344
					<format>html</format>
345
					<state>Disabled</state>
346
					<url>http://www.geopsy.org/blacklist.html</url>
347
					<header>Geopsy</header>
348
				</row>
349
				<row>
350
					<format>html</format>
351
					<state>Disabled</state>
352
					<url>https://www.maxmind.com/en/anonymous_proxies</url>
353
					<header>Maxmind</header>
354
				</row>
355
				<row>
356
					<format>html</format>
357
					<state>Disabled</state>
358
					<url>http://www.botscout.com/last_caught_cache.htm</url>
359
					<header>BotScout</header>
360
				</row>
361
				<row>
362
					<format>html</format>
363
					<state>Disabled</state>
364
					<url>https://www.juniper.net/security/auto/spam</url>
365
					<header>Juniper</header>
366
				</row>
367
				<row>
368
					<format>txt</format>
369
					<state>Disabled</state>
370
					<url>http://blocklist.greensnow.co/greensnow.txt</url>
371
					<header>Greensnow</header>
372
				</row>
373
				<row>
374
					<format>txt</format>
375
					<state>Disabled</state>
376
					<url>https://lists.blocklist.de/lists/all.txt</url>
377
					<header>BlocklistDE</header>
378
				</row>
379
				<row>
380
					<format>txt</format>
381
					<state>Disabled</state>
382
					<url>http://www.stopforumspam.com/downloads/toxic_ip_cidr.txt</url>
383
					<header>SFS_Toxic</header>
384
				</row>
385
				<action>Deny_Both</action>
386
				<cron>12hours</cron>
387
				<dow>1</dow>
388
				<aliaslog>enabled</aliaslog>
389
				<autoports/>
390
				<aliasports/>
391
				<autodest/>
392
				<aliasdest/>
393
				<autonot/>
394
				<autoproto/>
395
				<custom/>
396
				<custom_update>disabled</custom_update>
397
			</config>
398
			<config>
399
				<aliasname>SEC1</aliasname>
400
				<description><![CDATA[pfBlockerNG SEC1]]></description>
401
				<row>
402
					<format>html</format>
403
					<state>Enabled</state>
404
					<url>http://www.malwaregroup.com/ipaddresses/malicious</url>
405
					<header>MalwareGroup</header>
406
				</row>
407
				<row>
408
					<format>gz_2</format>
409
					<state>Enabled</state>
410
					<url>http://www.openbl.org/lists/base_7days.txt.gz</url>
411
					<header>OpenBL</header>
412
				</row>
413
				<row>
414
					<format>txt</format>
415
					<state>Disabled</state>
416
					<url>https://malc0de.com/bl/IP_Blacklist.txt</url>
417
					<header>Malcode</header>
418
				</row>
419
				<row>
420
					<format>txt</format>
421
					<state>Disabled</state>
422
					<url>https://www.badips.com/get/list/any/2</url>
423
					<header>BadIPs</header>
424
				</row>
425
				<action>Deny_Both</action>
426
				<cron>12hours</cron>
427
				<dow>1</dow>
428
				<aliaslog>enabled</aliaslog>
429
				<autoports/>
430
				<aliasports/>
431
				<autodest/>
432
				<aliasdest/>
433
				<autonot/>
434
				<autoproto/>
435
				<custom/>
436
				<custom_update>disabled</custom_update>
437
			</config>
438
			<config>
439
				<aliasname>SEC2</aliasname>
440
				<description><![CDATA[pfBlockerNG SEC2]]></description>
441
				<row>
442
					<format>html</format>
443
					<state>Enabled</state>
444
					<url>http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt</url>
445
					<header>CC_IP</header>
446
				</row>
447
				<row>
448
					<format>html</format>
449
					<state>Disabled</state>
450
					<url>http://osint.bambenekconsulting.com/feeds/c2-masterlist.txt</url>
451
					<header>CC_Indicator</header>
452
				</row>
453
				<action>Deny_Both</action>
454
				<cron>12hours</cron>
455
				<dow>1</dow>
456
				<aliaslog>enabled</aliaslog>
457
				<autoports/>
458
				<aliasports/>
459
				<autodest/>
460
				<aliasdest/>
461
				<autonot/>
462
				<autoproto/>
463
				<custom/>
464
				<custom_update>disabled</custom_update>
465
			</config>
466
			<config>
467
				<aliasname>TOR</aliasname>
468
				<description><![CDATA[pfBlockerNG TOR]]></description>
469
				<row>
470
					<format>gz</format>
471
					<state>Enabled</state>
472
					<url>http://list.iblocklist.com/?list=togdoptykrlolpddwbvz&amp;fileformat=p2p&amp;archiveformat=gz</url>
473
					<header>IBlock_Tor</header>
474
				</row>
475
				<row>
476
					<format>txt</format>
477
					<state>Enabled</state>
478
					<url>https://torstatus.blutmagie.de/ip_list_exit.php/Tor_ip_list_EXIT.csv</url>
479
					<header>Blut_Tor</header>
480
				</row>
481
				<row>
482
					<format>html</format>
483
					<state>Enabled</state>
484
					<url>https://rules.emergingthreats.net/open/suricata/rules/tor.rules</url>
485
					<header>ET_Tor</header>
486
				</row>
487
				<action>Disabled</action>
488
				<cron>Never</cron>
489
				<dow>1</dow>
490
				<aliaslog>enabled</aliaslog>
491
				<autoports/>
492
				<aliasports/>
493
				<autodest/>
494
				<aliasdest/>
495
				<autonot/>
496
				<autoproto/>
497
				<custom/>
498
				<custom_update>disabled</custom_update>
499
			</config>
500
			<config>
501
				<aliasname>MAIL</aliasname>
502
				<description><![CDATA[pfBlockerNG MAIL]]></description>
503
				<row>
504
					<format>txt</format>
505
					<state>Enabled</state>
506
					<url>https://virbl.bit.nl/download/virbl.dnsbl.bit.nl.txt</url>
507
					<header>VirBL</header>
508
				</row>
509
				<row>
510
					<format>zip</format>
511
					<state>Enabled</state>
512
					<url>http://www.stopforumspam.com/downloads/bannedips.zip</url>
513
					<header>SFS_All</header>
514
				</row>
515
				<row>
516
					<format>txt</format>
517
					<state>Enabled</state>
518
					<url>http://antispam.imp.ch/spamlist</url>
519
					<header>Improware</header>
520
				</row>
521
				<row>
522
					<format>html</format>
523
					<state>Enabled</state>
524
					<url>http://toastedspam.com/denylist.cgi</url>
525
					<header>ToastedSpam</header>
526
				</row>
527
				<row>
528
					<format>html</format>
529
					<state>Enabled</state>
530
					<url>http://rss.uribl.com/reports/7d/dns_a.html</url>
531
					<header>URIBL</header>
532
				</row>
533
				<row>
534
					<format>txt</format>
535
					<state>Enabled</state>
536
					<url>http://spamcop.net/w3m?action=map;net=cmaxcnt;mask=65535;sort=spamcnt;format=text</url>
537
					<header>SpamCop</header>
538
				</row>
539
				<row>
540
					<format>gz_2</format>
541
					<state>Enabled</state>
542
					<url>http://www.dnsbl.manitu.net/download/nixspam-ip.dump.gz</url>
543
					<header>Nix_Spam</header>
544
				</row>
545
				<action>Disabled</action>
546
				<cron>Never</cron>
547
				<dow>1</dow>
548
				<aliaslog>enabled</aliaslog>
549
				<autoports/>
550
				<aliasports/>
551
				<autodest/>
552
				<aliasdest/>
553
				<autonot/>
554
				<autoproto/>
555
				<custom/>
556
				<custom_update>disabled</custom_update>
557
			</config>
558
			<config>
559
				<aliasname>P2P</aliasname>
560
				<description><![CDATA[pfBlockerNG P2P]]></description>
561
				<row>
562
					<format>gz</format>
563
					<state>Enabled</state>
564
					<url>http://list.iblocklist.com/?list=cwworuawihqvocglcoss&amp;fileformat=p2p&amp;archiveformat=gz</url>
565
					<header>Bluetack_Badpeer</header>
566
				</row>
567
				<row>
568
					<format>gz</format>
569
					<state>Enabled</state>
570
					<url>http://list.iblocklist.com/?list=ydxerpxkpcfqjaybcssw&amp;fileformat=p2p&amp;archiveformat=gz</url>
571
					<header>Bluetack_Level1</header>
572
				</row>
573
				<row>
574
					<format>gz</format>
575
					<state>Enabled</state>
576
					<url>http://list.iblocklist.com/?list=ijfqtofzixtwayqovmxn&amp;fileformat=p2p&amp;archiveformat=gz</url>
577
					<header>TBG_Primary_Threats</header>
578
				</row>
579
				<action>Alias_Deny</action>
580
				<cron>12hours</cron>
581
				<dow>1</dow>
582
				<aliaslog>enabled</aliaslog>
583
				<autoports/>
584
				<aliasports/>
585
				<autodest/>
586
				<aliasdest/>
587
				<autonot/>
588
				<autoproto>tcp/udp</autoproto>
589
				<custom/>
590
				<custom_update>disabled</custom_update>
591
			</config>
592
			<config>
593
				<aliasname>CUST</aliasname>
594
				<description><![CDATA[pfBlockerNG CUSTOM]]></description>
595
				<row>
596
					<format>txt</format>
597
					<state>Enabled</state>
598
					<url>http://lists.blocklist.de/lists/all.txt</url>
599
					<header>BlocklistDE</header>
600
				</row>
601
				<action>Deny_Both</action>
602
				<cron>04hours</cron>
603
				<dow>1</dow>
604
				<aliaslog>enabled</aliaslog>
605
				<autoports/>
606
				<aliasports/>
607
				<autodest/>
608
				<aliasdest/>
609
				<autonot/>
610
				<autoproto/>
611
				<custom/>
612
				<custom_update>disabled</custom_update>
613
			</config>
614
		</pfblockernglistsv4>
615
		<pfblockerngproxyandsatellite>
616
			<config>
617
				<countries4>A1</countries4>
618
				<action>Deny_Inbound</action>
619
				<aliaslog>enabled</aliaslog>
620
				<autoports/>
621
				<aliasports/>
622
				<autodest/>
623
				<aliasdest/>
624
				<autonot/>
625
				<autoproto/>
626
			</config>
627
		</pfblockerngproxyandsatellite>
628
		<pfblockernglistsv6/>
(1-1/2)