Project

General

Profile

Bug #6451 » config-pfSense.localdomain-20160610010853.xml

No previous tunnel, can't make new one work. - Adam Thompson, 06/05/2016 08:31 PM

 
1
<?xml version="1.0" encoding="utf-8"?>
2
<pfsense>
3
  <version>15.4</version>
4
  <lastchange />
5
  <theme>pfsense_ng</theme>
6
  <system>
7
    <optimization>normal</optimization>
8
    <hostname>pfSense</hostname>
9
    <domain>localdomain</domain>
10
    <group>
11
      <name>all</name>
12
      <description><![CDATA[All Users]]></description>
13
      <scope>system</scope>
14
      <gid>1998</gid>
15
    </group>
16
    <group>
17
      <name>admins</name>
18
      <description><![CDATA[System Administrators]]></description>
19
      <scope>system</scope>
20
      <gid>1999</gid>
21
      <member>0</member>
22
      <priv>page-all</priv>
23
    </group>
24
    <user>
25
      <name>admin</name>
26
      <descr><![CDATA[System Administrator]]></descr>
27
      <scope>system</scope>
28
      <groupname>admins</groupname>
29
      <password></password>
30
      <uid>0</uid>
31
      <priv>user-shell-access</priv>
32
      <md5-hash></md5-hash>
33
      <expires />
34
      <authorizedkeys />
35
      <ipsecpsk />
36
    </user>
37
    <nextuid>2000</nextuid>
38
    <nextgid>2000</nextgid>
39
    <timezone>America/Winnipeg</timezone>
40
    <time-update-interval />
41
    <timeservers>0.pfsense.pool.ntp.org</timeservers>
42
    <webgui>
43
      <protocol>http</protocol>
44
      <loginautocomplete />
45
      <ssl-certref>55b54303c1f44</ssl-certref>
46
      <port>8088</port>
47
      <max_procs>2</max_procs>
48
      <nohttpreferercheck />
49
      <pagenamefirst />
50
      <dashboardcolumns>2</dashboardcolumns>
51
    </webgui>
52
    <disablesegmentationoffloading />
53
    <disablelargereceiveoffloading />
54
    <ipv6allow />
55
    <powerd_ac_mode>hadp</powerd_ac_mode>
56
    <powerd_battery_mode>hadp</powerd_battery_mode>
57
    <powerd_normal_mode>hadp</powerd_normal_mode>
58
    <bogons>
59
      <interval>daily</interval>
60
    </bogons>
61
    <serialspeed>115200</serialspeed>
62
    <primaryconsole>serial</primaryconsole>
63
    <enablesshd>enabled</enablesshd>
64
    <ssh>
65
      <port>2022</port>
66
    </ssh>
67
    <maximumstates />
68
    <aliasesresolveinterval />
69
    <maximumtableentries />
70
    <maximumfrags />
71
    <enablebinatreflection>yes</enablebinatreflection>
72
    <enablenatreflectionhelper>yes</enablenatreflectionhelper>
73
    <reflectiontimeout />
74
    <disablechecksumoffloading />
75
    <host_uuid />
76
    <powerd_enable />
77
    <crypto_hardware>aesni</crypto_hardware>
78
    <use_mfs_tmp_size />
79
    <use_mfs_var_size />
80
    <thermal_hardware>coretemp</thermal_hardware>
81
    <language>en_US</language>
82
    <dns1gw>none</dns1gw>
83
    <dns2gw>none</dns2gw>
84
    <dns3gw>none</dns3gw>
85
    <dns4gw>none</dns4gw>
86
    <dnsserver>8.8.8.8</dnsserver>
87
    <dnsserver>8.8.4.4</dnsserver>
88
    <dnsallowoverride />
89
  </system>
90
  <interfaces>
91
    <wan>
92
      <if>em0</if>
93
      <blockpriv />
94
      <blockbogons />
95
      <descr><![CDATA[WAN_shaw]]></descr>
96
      <alias-address />
97
      <alias-subnet>32</alias-subnet>
98
      <spoofmac />
99
      <ipaddr>dhcp</ipaddr>
100
      <dhcphostname />
101
      <dhcprejectfrom />
102
      <adv_dhcp_pt_timeout />
103
      <adv_dhcp_pt_retry />
104
      <adv_dhcp_pt_select_timeout />
105
      <adv_dhcp_pt_reboot />
106
      <adv_dhcp_pt_backoff_cutoff />
107
      <adv_dhcp_pt_initial_interval />
108
      <adv_dhcp_pt_values>SavedCfg</adv_dhcp_pt_values>
109
      <adv_dhcp_send_options />
110
      <adv_dhcp_request_options />
111
      <adv_dhcp_required_options />
112
      <adv_dhcp_option_modifiers />
113
      <adv_dhcp_config_advanced />
114
      <adv_dhcp_config_file_override />
115
      <adv_dhcp_config_file_override_path />
116
    </wan>
117
    <lan>
118
      <enable />
119
      <if>em3</if>
120
      <descr><![CDATA[LAN]]></descr>
121
      <ipaddr>192.168.160.1</ipaddr>
122
      <subnet>24</subnet>
123
      <ipaddrv6>2001:470:1f17:9d::1</ipaddrv6>
124
      <subnetv6>64</subnetv6>
125
      <spoofmac />
126
    </lan>
127
    <opt1>
128
      <if>em1</if>
129
      <descr><![CDATA[OPT1_Voyageur]]></descr>
130
      <alias-address />
131
      <alias-subnet>32</alias-subnet>
132
      <blockpriv />
133
      <blockbogons />
134
      <spoofmac />
135
      <enable />
136
      <ipaddr>204.16.144.114</ipaddr>
137
      <subnet>30</subnet>
138
      <gateway>OPT1_VoyageurGW</gateway>
139
    </opt1>
140
    <opt2>
141
      <descr><![CDATA[HEtunnel]]></descr>
142
      <if>gif0</if>
143
      <enable />
144
      <spoofmac />
145
    </opt2>
146
  </interfaces>
147
  <staticroutes>
148
    <route>
149
      <network>192.168.100.0/25</network>
150
      <gateway>myself_ipsec_workaround</gateway>
151
      <descr />
152
    </route>
153
    <route>
154
      <network>192.168.158.0/25</network>
155
      <gateway>myself_ipsec_workaround</gateway>
156
      <descr />
157
    </route>
158
  </staticroutes>
159
  <dhcpd>
160
    <lan>
161
      <enable />
162
      <range>
163
        <from>192.168.160.101</from>
164
        <to>192.168.160.199</to>
165
      </range>
166
    </lan>
167
  </dhcpd>
168
  <snmpd>
169
    <syslocation />
170
    <syscontact />
171
    <rocommunity>public</rocommunity>
172
  </snmpd>
173
  <diag>
174
    <ipv6nat />
175
  </diag>
176
  <bridge />
177
  <syslog />
178
  <nat>
179
    <outbound>
180
      <mode>automatic</mode>
181
    </outbound>
182
  </nat>
183
  <filter>
184
    <rule>
185
      <id />
186
      <tracker>1437946438</tracker>
187
      <type>pass</type>
188
      <interface>wan</interface>
189
      <ipprotocol>inet46</ipprotocol>
190
      <tag />
191
      <tagged />
192
      <max />
193
      <max-src-nodes />
194
      <max-src-conn />
195
      <max-src-states />
196
      <statetimeout />
197
      <statetype>keep state</statetype>
198
      <os />
199
      <source>
200
        <any />
201
      </source>
202
      <destination>
203
        <network>(self)</network>
204
      </destination>
205
      <descr><![CDATA[allow traffic to firewall]]></descr>
206
      <updated>
207
        <time>1437946438</time>
208
        <username>admin@72.143.233.224</username>
209
      </updated>
210
      <created>
211
        <time>1437946438</time>
212
        <username>admin@72.143.233.224</username>
213
      </created>
214
    </rule>
215
    <rule>
216
      <id />
217
      <tracker>0100000101</tracker>
218
      <type>pass</type>
219
      <interface>lan</interface>
220
      <ipprotocol>inet</ipprotocol>
221
      <tag />
222
      <tagged />
223
      <max />
224
      <max-src-nodes />
225
      <max-src-conn />
226
      <max-src-states />
227
      <statetimeout />
228
      <statetype>keep state</statetype>
229
      <os />
230
      <source>
231
        <network>lan</network>
232
      </source>
233
      <destination>
234
        <any />
235
      </destination>
236
      <descr><![CDATA[Default allow LAN to any rule]]></descr>
237
      <updated>
238
        <time>1437972256</time>
239
        <username>admin@192.168.160.101</username>
240
      </updated>
241
    </rule>
242
    <rule>
243
      <id />
244
      <tracker>1452320191</tracker>
245
      <type>pass</type>
246
      <interface>enc0</interface>
247
      <ipprotocol>inet46</ipprotocol>
248
      <tag />
249
      <tagged />
250
      <max />
251
      <max-src-nodes />
252
      <max-src-conn />
253
      <max-src-states />
254
      <statetimeout />
255
      <statetype>keep state</statetype>
256
      <os />
257
      <source>
258
        <any />
259
      </source>
260
      <destination>
261
        <any />
262
      </destination>
263
      <descr><![CDATA[allow all IPSec traffic]]></descr>
264
      <updated>
265
        <time>1452320191</time>
266
        <username>admin@205.200.228.156</username>
267
      </updated>
268
      <created>
269
        <time>1452320191</time>
270
        <username>admin@205.200.228.156</username>
271
      </created>
272
    </rule>
273
    <rule>
274
      <id />
275
      <tracker>1454320284</tracker>
276
      <type>pass</type>
277
      <interface>openvpn</interface>
278
      <ipprotocol>inet46</ipprotocol>
279
      <tag />
280
      <tagged />
281
      <max />
282
      <max-src-nodes />
283
      <max-src-conn />
284
      <max-src-states />
285
      <statetimeout />
286
      <statetype>keep state</statetype>
287
      <os />
288
      <source>
289
        <any />
290
      </source>
291
      <destination>
292
        <any />
293
      </destination>
294
      <descr><![CDATA[allow all OpenVPN traffic]]></descr>
295
      <created>
296
        <time>1454320284</time>
297
        <username>admin@192.168.160.101</username>
298
      </created>
299
      <updated>
300
        <time>1454320327</time>
301
        <username>admin@192.168.160.101</username>
302
      </updated>
303
    </rule>
304
    <rule>
305
      <id />
306
      <tracker>1437946465</tracker>
307
      <type>pass</type>
308
      <interface>opt1</interface>
309
      <ipprotocol>inet46</ipprotocol>
310
      <tag />
311
      <tagged />
312
      <max />
313
      <max-src-nodes />
314
      <max-src-conn />
315
      <max-src-states />
316
      <statetimeout />
317
      <statetype>keep state</statetype>
318
      <os />
319
      <source>
320
        <any />
321
      </source>
322
      <destination>
323
        <network>(self)</network>
324
      </destination>
325
      <descr><![CDATA[allow traffic to firewall]]></descr>
326
      <updated>
327
        <time>1437946465</time>
328
        <username>admin@72.143.233.224</username>
329
      </updated>
330
      <created>
331
        <time>1437946465</time>
332
        <username>admin@72.143.233.224</username>
333
      </created>
334
    </rule>
335
    <separator>
336
      <lan />
337
    </separator>
338
  </filter>
339
  <shaper />
340
  <ipsec>
341
    <phase1>
342
      <ikeid>1</ikeid>
343
      <iketype>ikev2</iketype>
344
      <interface>opt1</interface>
345
      <remote-gateway>205.200.228.156</remote-gateway>
346
      <protocol>inet</protocol>
347
      <myid_type>myaddress</myid_type>
348
      <myid_data />
349
      <peerid_type>peeraddress</peerid_type>
350
      <peerid_data />
351
      <encryption-algorithm>
352
        <name>aes</name>
353
        <keylen>256</keylen>
354
      </encryption-algorithm>
355
      <hash-algorithm>sha1</hash-algorithm>
356
      <dhgroup>2</dhgroup>
357
      <lifetime>28800</lifetime>
358
      <pre-shared-key></pre-shared-key>
359
      <private-key />
360
      <certref />
361
      <caref />
362
      <authentication_method>pre_shared_key</authentication_method>
363
      <descr><![CDATA[Avant.ca]]></descr>
364
      <nat_traversal>on</nat_traversal>
365
      <mobike>off</mobike>
366
      <dpd_delay>10</dpd_delay>
367
      <dpd_maxfail>5</dpd_maxfail>
368
      <disabled />
369
    </phase1>
370
    <client />
371
    <phase2>
372
      <ikeid>1</ikeid>
373
      <uniqid>55edbd19acda1</uniqid>
374
      <mode>tunnel</mode>
375
      <reqid>1</reqid>
376
      <localid>
377
        <type>lan</type>
378
      </localid>
379
      <remoteid>
380
        <type>network</type>
381
        <address>192.168.158.0</address>
382
        <netbits>24</netbits>
383
      </remoteid>
384
      <protocol>esp</protocol>
385
      <encryption-algorithm-option>
386
        <name>aes</name>
387
        <keylen>auto</keylen>
388
      </encryption-algorithm-option>
389
      <hash-algorithm-option>hmac_sha1</hash-algorithm-option>
390
      <pfsgroup>0</pfsgroup>
391
      <lifetime>3600</lifetime>
392
      <pinghost />
393
      <descr />
394
    </phase2>
395
    <phase2>
396
      <ikeid>1</ikeid>
397
      <uniqid>55edbefd4ff6c</uniqid>
398
      <mode>tunnel</mode>
399
      <reqid>2</reqid>
400
      <localid>
401
        <type>lan</type>
402
      </localid>
403
      <remoteid>
404
        <type>network</type>
405
        <address>192.168.100.0</address>
406
        <netbits>24</netbits>
407
      </remoteid>
408
      <protocol>esp</protocol>
409
      <encryption-algorithm-option>
410
        <name>aes</name>
411
        <keylen>auto</keylen>
412
      </encryption-algorithm-option>
413
      <hash-algorithm-option>hmac_sha1</hash-algorithm-option>
414
      <pfsgroup>0</pfsgroup>
415
      <lifetime>3600</lifetime>
416
      <pinghost />
417
      <descr />
418
    </phase2>
419
    <enable />
420
    <logging>
421
      <dmn>1</dmn>
422
      <mgr>1</mgr>
423
      <ike>1</ike>
424
      <chd>1</chd>
425
      <job>1</job>
426
      <cfg>1</cfg>
427
      <knl>1</knl>
428
      <net>1</net>
429
      <asn>1</asn>
430
      <enc>1</enc>
431
      <imc>1</imc>
432
      <imv>1</imv>
433
      <pts>1</pts>
434
      <tls>1</tls>
435
      <esp>1</esp>
436
      <lib>1</lib>
437
    </logging>
438
  </ipsec>
439
  <aliases>
440
    <alias>
441
      <name>Route_via_Voyageur</name>
442
      <address>198.181.199.38/24 central.crashplan.com</address>
443
      <descr />
444
      <type>network</type>
445
      <detail><![CDATA[MBIX public subnet||Entry added Sun, 04 Oct 2015 10:53:08 -0500]]></detail>
446
    </alias>
447
  </aliases>
448
  <proxyarp />
449
  <cron>
450
    <item>
451
      <minute>1,31</minute>
452
      <hour>0-5</hour>
453
      <mday>*</mday>
454
      <month>*</month>
455
      <wday>*</wday>
456
      <who>root</who>
457
      <command>/usr/bin/nice -n20 adjkerntz -a</command>
458
    </item>
459
    <item>
460
      <minute>1</minute>
461
      <hour>3</hour>
462
      <mday>*</mday>
463
      <month>*</month>
464
      <wday>*</wday>
465
      <who>root</who>
466
      <command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
467
    </item>
468
    <item>
469
      <minute>*/60</minute>
470
      <hour>*</hour>
471
      <mday>*</mday>
472
      <month>*</month>
473
      <wday>*</wday>
474
      <who>root</who>
475
      <command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
476
    </item>
477
    <item>
478
      <minute>*/60</minute>
479
      <hour>*</hour>
480
      <mday>*</mday>
481
      <month>*</month>
482
      <wday>*</wday>
483
      <who>root</who>
484
      <command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 webConfiguratorlockout</command>
485
    </item>
486
    <item>
487
      <minute>1</minute>
488
      <hour>1</hour>
489
      <mday>*</mday>
490
      <month>*</month>
491
      <wday>*</wday>
492
      <who>root</who>
493
      <command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
494
    </item>
495
    <item>
496
      <minute>*/60</minute>
497
      <hour>*</hour>
498
      <mday>*</mday>
499
      <month>*</month>
500
      <wday>*</wday>
501
      <who>root</who>
502
      <command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
503
    </item>
504
    <item>
505
      <minute>30</minute>
506
      <hour>12</hour>
507
      <mday>*</mday>
508
      <month>*</month>
509
      <wday>*</wday>
510
      <who>root</who>
511
      <command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
512
    </item>
513
  </cron>
514
  <wol />
515
  <rrd>
516
    <enable />
517
  </rrd>
518
  <load_balancer>
519
    <monitor_type>
520
      <name>ICMP</name>
521
      <type>icmp</type>
522
      <descr><![CDATA[ICMP]]></descr>
523
      <options />
524
    </monitor_type>
525
    <monitor_type>
526
      <name>TCP</name>
527
      <type>tcp</type>
528
      <descr><![CDATA[Generic TCP]]></descr>
529
      <options />
530
    </monitor_type>
531
    <monitor_type>
532
      <name>HTTP</name>
533
      <type>http</type>
534
      <descr><![CDATA[Generic HTTP]]></descr>
535
      <options>
536
        <path>/</path>
537
        <host />
538
        <code>200</code>
539
      </options>
540
    </monitor_type>
541
    <monitor_type>
542
      <name>HTTPS</name>
543
      <type>https</type>
544
      <descr><![CDATA[Generic HTTPS]]></descr>
545
      <options>
546
        <path>/</path>
547
        <host />
548
        <code>200</code>
549
      </options>
550
    </monitor_type>
551
    <monitor_type>
552
      <name>SMTP</name>
553
      <type>send</type>
554
      <descr><![CDATA[Generic SMTP]]></descr>
555
      <options>
556
        <send />
557
        <expect>220 *</expect>
558
      </options>
559
    </monitor_type>
560
  </load_balancer>
561
  <widgets>
562
    <sequence>system_information:col1:open,smart_status:col1:open,gmirror_status:col1:open,interfaces:col2:open,gateways:col2:open,ipsec:col2:open,ntp_status:col2:open,openvpn:col2:open,undefined:col2:close,traffic_graphs:col2:open,services_status:col2:open</sequence>
563
  </widgets>
564
  <openvpn>
565
    <openvpn-server>
566
      <vpnid>1</vpnid>
567
      <disable />
568
      <mode>p2p_shared_key</mode>
569
      <protocol>UDP</protocol>
570
      <dev_mode>tun</dev_mode>
571
      <ipaddr />
572
      <interface>opt1</interface>
573
      <local_port>1194</local_port>
574
      <description />
575
      <custom_options />
576
      <shared_key></shared_key>
577
      <crypto>AES-128-CBC</crypto>
578
      <digest>SHA1</digest>
579
      <engine>cryptodev</engine>
580
      <tunnel_network>10.10.10.0/24</tunnel_network>
581
      <tunnel_networkv6 />
582
      <remote_network>192.168.53.0/24</remote_network>
583
      <remote_networkv6 />
584
      <gwredir />
585
      <local_network>192.168.160.0/24</local_network>
586
      <local_networkv6 />
587
      <maxclients />
588
      <compression>adaptive</compression>
589
      <passtos>yes</passtos>
590
      <client2client />
591
      <dynamic_ip />
592
      <pool_enable>yes</pool_enable>
593
      <topology>subnet</topology>
594
      <serverbridge_dhcp />
595
      <serverbridge_interface>none</serverbridge_interface>
596
      <serverbridge_dhcp_start />
597
      <serverbridge_dhcp_end />
598
      <netbios_enable />
599
      <netbios_ntype>0</netbios_ntype>
600
      <netbios_scope />
601
      <no_tun_ipv6 />
602
      <verbosity_level>1</verbosity_level>
603
    </openvpn-server>
604
    <openvpn-client>
605
      <auth_user />
606
      <auth_pass />
607
      <vpnid>2</vpnid>
608
      <disable />
609
      <protocol>UDP</protocol>
610
      <dev_mode>tun</dev_mode>
611
      <ipaddr />
612
      <interface>lan</interface>
613
      <local_port />
614
      <server_addr>remote.avant.ca</server_addr>
615
      <server_port>1160</server_port>
616
      <resolve_retry />
617
      <proxy_addr />
618
      <proxy_port />
619
      <proxy_authtype>none</proxy_authtype>
620
      <proxy_user />
621
      <proxy_passwd />
622
      <description><![CDATA[Avant.ca]]></description>
623
      <mode>p2p_shared_key</mode>
624
      <topology>subnet</topology>
625
      <custom_options />
626
      <shared_key></shared_key>
627
      <crypto>AES-128-CBC</crypto>
628
      <digest>SHA1</digest>
629
      <engine>cryptodev</engine>
630
      <tunnel_network>192.168.98.0/24</tunnel_network>
631
      <tunnel_networkv6 />
632
      <remote_network>192.168.100.0/24,192.168.158.0/24,192.168.10.0/24,192.168.101.0/24</remote_network>
633
      <remote_networkv6 />
634
      <use_shaper />
635
      <compression>adaptive</compression>
636
      <passtos />
637
      <no_tun_ipv6 />
638
      <route_no_pull />
639
      <route_no_exec />
640
      <verbosity_level>1</verbosity_level>
641
    </openvpn-client>
642
  </openvpn>
643
  <dnshaper />
644
  <unbound>
645
    <enable />
646
    <active_interface>lan,lo0</active_interface>
647
    <outgoing_interface>all</outgoing_interface>
648
    <custom_options />
649
    <hideidentity />
650
    <hideversion />
651
    <prefetch />
652
    <prefetchkey />
653
    <msgcachesize>4</msgcachesize>
654
    <outgoing_num_tcp>10</outgoing_num_tcp>
655
    <incoming_num_tcp>10</incoming_num_tcp>
656
    <edns_buffer_size>4096</edns_buffer_size>
657
    <num_queries_per_thread>512</num_queries_per_thread>
658
    <jostle_timeout>200</jostle_timeout>
659
    <cache_max_ttl>86400</cache_max_ttl>
660
    <cache_min_ttl>0</cache_min_ttl>
661
    <infra_host_ttl>900</infra_host_ttl>
662
    <infra_cache_numhosts>10000</infra_cache_numhosts>
663
    <unwanted_reply_threshold>disabled</unwanted_reply_threshold>
664
    <log_verbosity>2</log_verbosity>
665
    <regdhcp />
666
    <regdhcpstatic />
667
    <txtsupport />
668
    <domainoverrides>
669
      <domain>asg.local</domain>
670
      <ip>192.168.100.50</ip>
671
      <descr />
672
    </domainoverrides>
673
    <domainoverrides>
674
      <domain>asg.local</domain>
675
      <ip>192.168.100.52</ip>
676
      <descr />
677
    </domainoverrides>
678
    <domainoverrides>
679
      <domain>100.168.192.in-addr.arpa</domain>
680
      <ip>192.168.100.50</ip>
681
      <descr />
682
    </domainoverrides>
683
    <domainoverrides>
684
      <domain>100.168.192.in-addr.arpa</domain>
685
      <ip>192.168.100.52</ip>
686
      <descr />
687
    </domainoverrides>
688
    <domainoverrides>
689
      <domain>158.168.192.in-addr.arpa</domain>
690
      <ip>192.168.158.10</ip>
691
      <descr />
692
    </domainoverrides>
693
    <domainoverrides>
694
      <domain>158.168.192.in-addr.arpa</domain>
695
      <ip>192.168.158.20</ip>
696
      <descr />
697
    </domainoverrides>
698
    <domainoverrides>
699
      <domain>ad.avant.ca</domain>
700
      <ip>192.168.158.10</ip>
701
      <descr />
702
    </domainoverrides>
703
    <domainoverrides>
704
      <domain>ad.avant.ca</domain>
705
      <ip>192.168.158.20</ip>
706
      <descr />
707
    </domainoverrides>
708
    <port />
709
    <system_domain_local_zone_type>transparent</system_domain_local_zone_type>
710
  </unbound>
711
  <dhcpdv6 />
712
  <cert>
713
    <refid>55b54303c1f44</refid>
714
    <descr><![CDATA[webConfigurator default (55b54303c1f44)]]></descr>
715
    <type>server</type>
716
    <crt></crt>
717
    <prv>LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUV2UUlCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQktjd2dnU2pBZ0VBQW9JQkFRQ3BNQnJHQ3ZZYTRaRVoKeDZ0TUNWaGJHYmY2WVNxUlozNkZLU1ZGSWJwaXI2NVVhSisxL2s2Zm9zSXZtZXUrSVIyL1pCM2NNcm9CVy9XcwpWVkVSN2R0UGV1dHdqVEVpazlvMWZqd2xzUlJBZ2h0dlVGYitZZnNHdjhXTGlkUm9ZdXhYU1VjK0c3aVI5bVYyCktvcFUxMWN1a3FqVzJtcCtNU3lCSUs1UC9oM3NNU1RMRGpEYkMyRm42ZEo1REVCN3V3KzdDNGVkSU1KMzJtTGwKbVlIb2tveGNUK1p1WEhYVVdWRUwrZVd5L0lvaFhjWnVEZ2drblNrc0d6b1VmN2J6UXhvdjQxT2VZTXZ5ZFR3dQpXYXFyQks1aCtPRVhZdHFDSmc2WUcrNXBSeno5WmJvYlAyRDJJMkYwQWJ0SjFHOVpzRW9mVHVnNFFHcXdEOWxxClpxV21LRUI1QWdNQkFBRUNnZ0VBY2wybks0cExWRjU0SkZJWmsvdVpNM1BPTHIweDlqcGNodzBLT1pJVUdST2kKcDBKVis4TWRTTUhQdkRleTZNSWdCcmxaaWZqc1RYRHBRQVlvR0JPT05VcmxEaDhUUU1sckxzL1hQcTlWL2trMAozR2tWZFQyc1g2S1FtY09neHJOZ0NaenFRS3lpZG1CMXM0d01HRSs4aWludllkVWhPWTVxQkJ1Z1dVaHcxN0JDCmtRWW5sdXBsRmg3RmQyTmh6MTBkUkl5WGVPVCtoc1dCaXp0UndrMDZKa3JrVVFUSC94UnNid1cyRStNK2lhOE4KakpQcENlMDlIQXlLczVIT1MxTldsUHVDbXlYNSttWU1BSjNPVmpJcWtGTkNoTUZmZVVkY2NkNjhkTGRwaFZ5Ugpmb0hMVUdRbCtyNVk4enpycFpYbVNqdlMwRER1V0JRN2NmYTNCclh6RVFLQmdRRGZ4cytpT3U0NmdyRnpZQmY3Cm92dkhXNWR1dWJ1OE44eXp1VEpidW9hL2k1WFNDTzhFZVY2MUxqL0dLY3ZwRTY5bU9UN1FaNHpXSnhCVGVxWWwKdWFobWdhK3VodmxzOTBxelpLMmtMWDVYUFBFMm42KytEM2hjU0dEQWlaUkc3eXdnVWZDRGQzdHo3SGZaaU9OZwo2a2hGQURzNXRVMzNIMjc1TUhBNVBDeHcvUUtCZ1FEQmpQYUx1dDBEd2hxcWN6MmR2elM4WkkwVUJSTmdIQTFoCnlCQXZzQnl1dzJzY1kzckRNdi96ZmJKVHhBSk1tVkFrV21pUmFDT2MvQmxvR1pLTVo2VWFucGZUY2FiQm5WOXIKRUhrZG4weE9pdzJVRHRGWmQzeS9Sd1FUTW12VWswdVZzRmt4VkpGQUVvTms2Z0xnMzVXSWkyS3ViTHhFaUU5Qwp6eDdGSklrMExRS0JnUUNBb245dTZXTlNYUmgya3pHV0pFMkpmdndnMlVHeTQzeVhmNGtVTTdnTDJjaUkwVHZjCm5ZdzBxRjVlb2w0bUlIdStUbi91T3VnNW5vRURDOGtBZktYeUx2QjNhZjF0aHdYNDg1SGhnNGxSeXFWNldmY2oKVVM5R0ZSRVEvTVV3dFlIdkhrc2N0NDFPeVFyb0VJbHNoNkI5a2JGNTdkL2dnOEErSEhzV1c2SE1YUUtCZ0NlSgpMdGR1RFRWMlVkSWRoaW1SNUNqVGRVbndtM3VYWDFobzhIMTlRTzZsOWx3dktlVnpwbnJMWTBEZkdnVWhrQkJNCjgyMDRVNFgrclFYcHExakkxeDN2NVYySXFxS0VEZmlsdmNmQ1FXa04ySEUwOGFpUDBzaVRyZzVwejBMMTc0dWQKSVNzRmRrSWJSZ0c0RjJ4dDMzS3IzalY0K3FBWkkrK210VWRaNWpqbEFvR0FaOEozRklqZkpaRTdhV2hSUU1QVQpQYUhKWkNaWUFYbFNSRWRGTiswYTV3MEhCcUUxZXZheVlmN1FFNmZpWGtaMUtSK012bTRYVVd5L1ljczhQejRGCkcxREJ4UkQ4VWRnc0VWbkdqSkJBc0o5OVg4endsSVYwQ0ViUDM0UDdSODJ0MEVMRjRIS0ZJQkNNNDJ5ME1scEcKb3Q2SDRYL2x0ZndZTWU4bTgvTThBVVU9Ci0tLS0tRU5EIFBSSVZBVEUgS0VZLS0tLS0K</prv>
718
  </cert>
719
  <revision>
720
    <time>1465507441</time>
721
    <username>admin@192.168.160.101</username>
722
  </revision>
723
  <ppps />
724
  <gateways>
725
    <gateway_item>
726
      <interface>opt1</interface>
727
      <gateway>204.16.144.113</gateway>
728
      <name>OPT1_VoyageurGW</name>
729
      <weight>1</weight>
730
      <ipprotocol>inet</ipprotocol>
731
      <interval />
732
      <descr />
733
      <defaultgw />
734
    </gateway_item>
735
    <gateway_item>
736
      <interface>lan</interface>
737
      <gateway>192.168.160.1</gateway>
738
      <name>myself_ipsec_workaround</name>
739
      <weight>1</weight>
740
      <ipprotocol>inet</ipprotocol>
741
      <interval />
742
      <descr><![CDATA[workaround for IPSec braindeadness]]></descr>
743
      <monitor_disable />
744
    </gateway_item>
745
    <gateway_item>
746
      <interface>opt2</interface>
747
      <gateway>dynamic</gateway>
748
      <name>HETUNNEL_TUNNELV6</name>
749
      <weight>1</weight>
750
      <ipprotocol>inet6</ipprotocol>
751
      <descr><![CDATA[Interface HETUNNEL_TUNNELV6 Gateway]]></descr>
752
      <defaultgw />
753
    </gateway_item>
754
  </gateways>
755
  <installedpackages>
756
    <tab />
757
    <service />
758
    <service>
759
      <name>ladvd</name>
760
      <rcfile>ladvd.sh</rcfile>
761
      <executable>ladvd</executable>
762
      <description><![CDATA[Link Layer Discovery Protocol Daemon]]></description>
763
    </service>
764
    <package>
765
      <name>mtr-nox11</name>
766
      <descr><![CDATA[Enhanced traceroute replacement. mtr combines the functionality of the traceroute and ping programs in a single network diagnostic tool.]]></descr>
767
      <website>http://www.bitwizard.nl/mtr/</website>
768
      <version>0.85.6_1</version>
769
      <configurationfile>mtr-nox11.xml</configurationfile>
770
    </package>
771
    <package>
772
      <name>nmap</name>
773
      <descr><![CDATA[NMap is a utility for network exploration or security auditing.&lt;br/&gt;
774
			It supports ping scanning (determine which hosts are up), many port scanning techniques (determine what services the hosts are offering), version detection (determine what application/service is running on a port), and TCP/IP fingerprinting (remote host OS or device identification).
775
			It also offers flexible target and port specification, decoy/stealth scanning, SunRPC scanning, and more.]]></descr>
776
      <version>1.4.4_1</version>
777
      <pkginfolink>https://doc.pfsense.org/index.php/Nmap_package</pkginfolink>
778
      <configurationfile>nmap.xml</configurationfile>
779
    </package>
780
    <package>
781
      <name>LADVD</name>
782
      <descr><![CDATA[Send and decode link layer advertisements. Support for LLDP (Link Layer Discovery Protocol), CDP (Cisco Discovery Protocol), EDP (Extreme Discovery Protocol) and NDP (Nortel Discovery Protocol).]]></descr>
783
      <website>https://github.com/sspans/ladvd</website>
784
      <version>1.2.1_2</version>
785
      <configurationfile>ladvd.xml</configurationfile>
786
    </package>
787
    <package>
788
      <name>AutoConfigBackup</name>
789
      <descr><![CDATA[Automatically backs up your pfSense configuration. All contents are encrypted before being sent to the server.&lt;br /&gt;
790
			Requires Gold Subscription from &lt;a href=&quot;https://portal.pfsense.org&quot;&gt;pfSense Portal&lt;/a&gt;.]]></descr>
791
      <website>https://portal.pfsense.org</website>
792
      <version>1.45</version>
793
      <pkginfolink>https://doc.pfsense.org/index.php/AutoConfigBackup</pkginfolink>
794
      <configurationfile>autoconfigbackup.xml</configurationfile>
795
    </package>
796
    <menu>
797
      <name>mtr</name>
798
      <section>Diagnostics</section>
799
      <url>/pkg_edit.php?xml=mtr-nox11.xml</url>
800
    </menu>
801
    <menu>
802
      <name>NMap</name>
803
      <section>Diagnostics</section>
804
      <configfile>nmap.xml</configfile>
805
    </menu>
806
    <menu>
807
      <name>LADVD</name>
808
      <tooltiptext>Modify LADVD settings.</tooltiptext>
809
      <section>Services</section>
810
      <url>/pkg_edit.php?xml=ladvd.xml</url>
811
    </menu>
812
    <menu>
813
      <name>LADVD Status</name>
814
      <tooltiptext />
815
      <section>Status</section>
816
      <url>/status_ladvd.php</url>
817
    </menu>
818
    <menu>
819
      <name>AutoConfigBackup</name>
820
      <tooltiptext>Set autoconfigbackup settings such as password and port.</tooltiptext>
821
      <section>Diagnostics</section>
822
      <url>/autoconfigbackup.php</url>
823
    </menu>
824
    <ladvd>
825
      <config>
826
        <enable>on</enable>
827
        <iface_array>lan,opt1,lo0</iface_array>
828
        <autoenable>on</autoenable>
829
        <silent />
830
        <management>lan</management>
831
        <location />
832
        <lldp>on</lldp>
833
        <cdp>on</cdp>
834
        <edp>on</edp>
835
        <ndp>on</ndp>
836
      </config>
837
    </ladvd>
838
    <autoconfigbackup>
839
      <config>
840
        <username>athompso</username>
841
        <password></password>
842
        <passwordagain></passwordagain>
843
        <crypto_password></crypto_password>
844
        <crypto_password2></crypto_password2>
845
      </config>
846
    </autoconfigbackup>
847
  </installedpackages>
848
  <ntpd>
849
    <logpeer>yes</logpeer>
850
    <logsys>yes</logsys>
851
    <statsgraph>yes</statsgraph>
852
  </ntpd>
853
  <dhcrelay />
854
  <dhcrelay6 />
855
  <dyndnses />
856
  <gifs>
857
    <gif>
858
      <ipaddr />
859
      <if>opt1</if>
860
      <tunnel-local-addr>2001:470:1f16:9d::2</tunnel-local-addr>
861
      <tunnel-remote-addr>2001:470:1f16:9d::1</tunnel-remote-addr>
862
      <tunnel-remote-net>64</tunnel-remote-net>
863
      <remote-addr>184.105.255.26</remote-addr>
864
      <descr><![CDATA[Tunnel ID 260153]]></descr>
865
      <gifif>gif0</gifif>
866
    </gif>
867
  </gifs>
868
</pfsense>
(2-2/2)