Project

General

Profile

Bug #12294 ยป config-20210818131204.xml

itfabrica Tech, 08/21/2021 02:16 PM

 
1
<?xml version="1.0"?>
2
<pfsense>
3
	<version>21.7</version>
4
	<lastchange></lastchange>
5
	<system>
6
		<optimization>normal</optimization>
7
		<hostname>vrouter-asterisk</hostname>
8
		<domain>web.local</domain>
9
		<group>
10
			<name>all</name>
11
			<description><![CDATA[All Users]]></description>
12
			<scope>system</scope>
13
			<gid>1998</gid>
14
			<member>0</member>
15
		</group>
16
		<group>
17
			<name>admins</name>
18
			<description><![CDATA[System Administrators]]></description>
19
			<scope>system</scope>
20
			<gid>1999</gid>
21
			<member>0</member>
22
			<priv>page-all</priv>
23
		</group>
24
		<user>
25
			<name>admin</name>
26
			<descr><![CDATA[System Administrator]]></descr>
27
			<scope>system</scope>
28
			<groupname>admins</groupname>
29
			<bcrypt-hash>0000</bcrypt-hash>
30
			<uid>0</uid>
31
			<priv>user-shell-access</priv>
32
		</user>
33
		<nextuid>2000</nextuid>
34
		<nextgid>2000</nextgid>
35
		<timeservers>ru.pool.ntp.org</timeservers>
36
		<webgui>
37
			<protocol>https</protocol>
38
			<loginautocomplete></loginautocomplete>
39
			<ssl-certref>5f6f5d626b59b</ssl-certref>
40
			<dashboardcolumns>4</dashboardcolumns>
41
			<webguicss>pfSense.css</webguicss>
42
			<logincss>1e3f75;</logincss>
43
			<port>4756</port>
44
			<max_procs>2</max_procs>
45
			<systemlogsfilterpanel></systemlogsfilterpanel>
46
			<statusmonitoringsettingspanel></statusmonitoringsettingspanel>
47
		</webgui>
48
		<disablesegmentationoffloading></disablesegmentationoffloading>
49
		<disablelargereceiveoffloading></disablelargereceiveoffloading>
50
		<ipv6allow></ipv6allow>
51
		<maximumtableentries>400000</maximumtableentries>
52
		<powerd_ac_mode>hadp</powerd_ac_mode>
53
		<powerd_battery_mode>hadp</powerd_battery_mode>
54
		<powerd_normal_mode>hadp</powerd_normal_mode>
55
		<bogons>
56
			<interval>monthly</interval>
57
		</bogons>
58
		<already_run_config_upgrade></already_run_config_upgrade>
59
		<timezone>Europe/Moscow</timezone>
60
		<language>en_US</language>
61
		<dns1gw>none</dns1gw>
62
		<dns2gw>none</dns2gw>
63
		<ssh>
64
			<enable>enabled</enable>
65
			<port>4757</port>
66
		</ssh>
67
		<disableconsolemenu></disableconsolemenu>
68
		<serialspeed>115200</serialspeed>
69
		<primaryconsole>serial</primaryconsole>
70
		<sshguard_threshold></sshguard_threshold>
71
		<sshguard_blocktime></sshguard_blocktime>
72
		<sshguard_detection_time></sshguard_detection_time>
73
		<sshguard_whitelist></sshguard_whitelist>
74
		<scrubnodf>enabled</scrubnodf>
75
		<maximumstates></maximumstates>
76
		<aliasesresolveinterval></aliasesresolveinterval>
77
		<maximumfrags></maximumfrags>
78
		<enablenatreflectionpurenat>yes</enablenatreflectionpurenat>
79
		<reflectiontimeout></reflectiontimeout>
80
		<disablechecksumoffloading></disablechecksumoffloading>
81
		<crypto_hardware>aesni_cryptodev</crypto_hardware>
82
		<thermal_hardware>coretemp</thermal_hardware>
83
		<mds_disable>0</mds_disable>
84
		<use_mfs_tmp_size>200</use_mfs_tmp_size>
85
		<use_mfs_var_size>200</use_mfs_var_size>
86
		<use_mfs_tmpvar></use_mfs_tmpvar>
87
		<rrdbackup>1</rrdbackup>
88
		<dhcpbackup>1</dhcpbackup>
89
		<logsbackup>1</logsbackup>
90
		<dnsserver>8.8.4.4</dnsserver>
91
		<dnsserver>1.0.0.1</dnsserver>
92
		<hn_altq_enable></hn_altq_enable>
93
	</system>
94
	<interfaces>
95
		<wan>
96
			<enable></enable>
97
			<if>vtnet0</if>
98
			<blockpriv></blockpriv>
99
			<blockbogons></blockbogons>
100
			<descr><![CDATA[WAN]]></descr>
101
			<ipaddr>56.39.67.56</ipaddr>
102
			<subnet>24</subnet>
103
			<gateway>WANGW_2</gateway>
104
			<spoofmac></spoofmac>
105
			<ipaddrv6></ipaddrv6>
106
			<subnetv6></subnetv6>
107
			<gatewayv6></gatewayv6>
108
		</wan>
109
		<lan>
110
			<enable></enable>
111
			<if>vtnet1</if>
112
			<descr><![CDATA[LAN]]></descr>
113
			<spoofmac></spoofmac>
114
			<ipaddr>192.168.0.1</ipaddr>
115
			<subnet>24</subnet>
116
		</lan>
117
	</interfaces>
118
	<staticroutes></staticroutes>
119
	<dhcpd>
120
		<lan>
121
			<range>
122
				<from>192.168.0.10</from>
123
				<to>192.168.0.230</to>
124
			</range>
125
		</lan>
126
		<dhcpddata>
127
			<xmldatafile>
128
				<filename>dhcpd.leases</filename>
129
				<data>bY2xbsMwDER3fQXhDG2ByLBjJx26FfFWNItHLYxF2wJkKaDkBvn7Mi2yZSAP4PHdbaCfCcbIC2aII+TZJRidJxC1cVgXCpksuCAWgZ2Hiy09YaL0un+DBcOKHi44Uak2kiXUn/ufccUEV3Y5U4DzTSIHfU/QbdmWtRIA1zxHdmHS51smHdkSgzTy/RkmCsQo9Vs4nuD71MOx++r6Tj3FvPR40hSsw/ChVCL+IdZ2dRYKU1WVTP3QF1k7UzW1adrG7N4Ppqg/Fzm2haC/</data>
130
			</xmldatafile>
131
		</dhcpddata>
132
	</dhcpd>
133
	<dhcpdv6>
134
		<lan>
135
			<range>
136
				<from>::1000</from>
137
				<to>::2000</to>
138
			</range>
139
			<ramode>assist</ramode>
140
			<rapriority>medium</rapriority>
141
		</lan>
142
		<dhcpdv6data>
143
			<xmldatafile>
144
				<filename>dhcpd6.leases</filename>
145
				<data>AwA=</data>
146
			</xmldatafile>
147
		</dhcpdv6data>
148
	</dhcpdv6>
149
	<snmpd>
150
		<syslocation></syslocation>
151
		<syscontact></syscontact>
152
		<rocommunity>public</rocommunity>
153
	</snmpd>
154
	<diag>
155
		<ipv6nat></ipv6nat>
156
	</diag>
157
	<syslog>
158
		<filterdescriptions>1</filterdescriptions>
159
	</syslog>
160
	<nat>
161
		<outbound>
162
			<mode>advanced</mode>
163
			<rule>
164
				<source>
165
					<network>192.168.0.166/32</network>
166
				</source>
167
				<sourceport></sourceport>
168
				<descr><![CDATA[nat_rule_for_voip]]></descr>
169
				<target></target>
170
				<targetip></targetip>
171
				<targetip_subnet></targetip_subnet>
172
				<interface>wan</interface>
173
				<poolopts></poolopts>
174
				<source_hash_key></source_hash_key>
175
				<ipprotocol>inet</ipprotocol>
176
				<destination>
177
					<address>89.20.155.20/32</address>
178
				</destination>
179
				<natport>5057</natport>
180
				<created>
181
					<time>1619432566</time>
182
					<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
183
				</created>
184
				<updated>
185
					<time>1619432596</time>
186
					<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
187
				</updated>
188
			</rule>
189
			<rule>
190
				<source>
191
					<network>192.168.0.166/32</network>
192
				</source>
193
				<sourceport></sourceport>
194
				<descr><![CDATA[nat_rule_for_voip]]></descr>
195
				<target></target>
196
				<targetip></targetip>
197
				<targetip_subnet></targetip_subnet>
198
				<interface>wan</interface>
199
				<poolopts></poolopts>
200
				<source_hash_key></source_hash_key>
201
				<staticnatport></staticnatport>
202
				<destination>
203
					<any></any>
204
				</destination>
205
				<created>
206
					<time>1601305598</time>
207
					<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
208
				</created>
209
				<updated>
210
					<time>1619431392</time>
211
					<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
212
				</updated>
213
			</rule>
214
			<rule>
215
				<interface>wan</interface>
216
				<source>
217
					<network>127.0.0.0/8</network>
218
				</source>
219
				<dstport>500</dstport>
220
				<target></target>
221
				<destination>
222
					<any></any>
223
				</destination>
224
				<staticnatport></staticnatport>
225
				<descr><![CDATA[Auto created rule for ISAKMP - localhost to WAN]]></descr>
226
				<created>
227
					<time>1601305553</time>
228
					<username><![CDATA[Manual Outbound NAT Switch]]></username>
229
				</created>
230
			</rule>
231
			<rule>
232
				<interface>wan</interface>
233
				<source>
234
					<network>127.0.0.0/8</network>
235
				</source>
236
				<sourceport></sourceport>
237
				<target></target>
238
				<destination>
239
					<any></any>
240
				</destination>
241
				<natport></natport>
242
				<descr><![CDATA[Auto created rule - localhost to WAN]]></descr>
243
				<created>
244
					<time>1601305553</time>
245
					<username><![CDATA[Manual Outbound NAT Switch]]></username>
246
				</created>
247
			</rule>
248
			<rule>
249
				<interface>wan</interface>
250
				<source>
251
					<network>::1/128</network>
252
				</source>
253
				<dstport>500</dstport>
254
				<target></target>
255
				<destination>
256
					<any></any>
257
				</destination>
258
				<staticnatport></staticnatport>
259
				<descr><![CDATA[Auto created rule for ISAKMP - localhost to WAN]]></descr>
260
				<created>
261
					<time>1601305553</time>
262
					<username><![CDATA[Manual Outbound NAT Switch]]></username>
263
				</created>
264
			</rule>
265
			<rule>
266
				<interface>wan</interface>
267
				<source>
268
					<network>::1/128</network>
269
				</source>
270
				<sourceport></sourceport>
271
				<target></target>
272
				<destination>
273
					<any></any>
274
				</destination>
275
				<natport></natport>
276
				<descr><![CDATA[Auto created rule - localhost to WAN]]></descr>
277
				<created>
278
					<time>1601305553</time>
279
					<username><![CDATA[Manual Outbound NAT Switch]]></username>
280
				</created>
281
			</rule>
282
			<rule>
283
				<interface>wan</interface>
284
				<source>
285
					<network>192.168.0.0/24</network>
286
				</source>
287
				<dstport>500</dstport>
288
				<target></target>
289
				<destination>
290
					<any></any>
291
				</destination>
292
				<staticnatport></staticnatport>
293
				<descr><![CDATA[Auto created rule for ISAKMP - LAN to WAN]]></descr>
294
				<created>
295
					<time>1601305553</time>
296
					<username><![CDATA[Manual Outbound NAT Switch]]></username>
297
				</created>
298
			</rule>
299
			<rule>
300
				<interface>wan</interface>
301
				<source>
302
					<network>192.168.0.0/24</network>
303
				</source>
304
				<sourceport></sourceport>
305
				<target></target>
306
				<destination>
307
					<any></any>
308
				</destination>
309
				<natport></natport>
310
				<descr><![CDATA[Auto created rule - LAN to WAN]]></descr>
311
				<created>
312
					<time>1601305553</time>
313
					<username><![CDATA[Manual Outbound NAT Switch]]></username>
314
				</created>
315
			</rule>
316
		</outbound>
317
		<separator></separator>
318
		<rule>
319
			<source>
320
				<address>web_support</address>
321
			</source>
322
			<destination>
323
				<network>wanip</network>
324
				<port>4758</port>
325
			</destination>
326
			<protocol>tcp</protocol>
327
			<target>192.168.0.166</target>
328
			<local-port>22</local-port>
329
			<interface>wan</interface>
330
			<descr><![CDATA[redirect_to_ssh_aster]]></descr>
331
			<associated-rule-id>nat_5f73385ed494f7.29539021</associated-rule-id>
332
			<updated>
333
				<time>1601386590</time>
334
				<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
335
			</updated>
336
			<created>
337
				<time>1601386590</time>
338
				<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
339
			</created>
340
		</rule>
341
		<rule>
342
			<source>
343
				<address>SIP_ACCESS</address>
344
			</source>
345
			<destination>
346
				<network>wanip</network>
347
				<port>5060</port>
348
			</destination>
349
			<protocol>tcp/udp</protocol>
350
			<target>192.168.0.166</target>
351
			<local-port>5060</local-port>
352
			<interface>wan</interface>
353
			<descr><![CDATA[redirect_sip_to_freepbx]]></descr>
354
			<associated-rule-id>nat_5f71fc5a55d103.60374185</associated-rule-id>
355
			<created>
356
				<time>1601305690</time>
357
				<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
358
			</created>
359
			<updated>
360
				<time>1607604500</time>
361
				<username><![CDATA[admin@99.32.165.21 (Local Database)]]></username>
362
			</updated>
363
		</rule>
364
		<rule>
365
			<source>
366
				<address>SIP_ACCESS</address>
367
			</source>
368
			<destination>
369
				<network>wanip</network>
370
				<port>10000-20000</port>
371
			</destination>
372
			<protocol>udp</protocol>
373
			<target>192.168.0.166</target>
374
			<local-port>10000</local-port>
375
			<interface>wan</interface>
376
			<descr><![CDATA[redirect_rtp_to_freepbx]]></descr>
377
			<associated-rule-id>nat_5f71fcc40c28e4.34133250</associated-rule-id>
378
			<created>
379
				<time>1601305796</time>
380
				<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
381
			</created>
382
			<updated>
383
				<time>1607604514</time>
384
				<username><![CDATA[admin@99.32.165.21 (Local Database)]]></username>
385
			</updated>
386
		</rule>
387
		<rule>
388
			<source>
389
				<address>web_support</address>
390
			</source>
391
			<destination>
392
				<network>wanip</network>
393
				<port>80</port>
394
			</destination>
395
			<protocol>tcp</protocol>
396
			<target>192.168.0.166</target>
397
			<local-port>80</local-port>
398
			<interface>wan</interface>
399
			<descr><![CDATA[access_to_web_freepbx]]></descr>
400
			<associated-rule-id>nat_5f71fcecf267c2.15924992</associated-rule-id>
401
			<updated>
402
				<time>1601305836</time>
403
				<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
404
			</updated>
405
			<created>
406
				<time>1601305836</time>
407
				<username><![CDATA[admin@99.32.97.226 (Local Database)]]></username>
408
			</created>
409
		</rule>
410
	</nat>
411
	<filter>
412
		<rule>
413
			<id></id>
414
			<tracker>1601144841</tracker>
415
			<type>pass</type>
416
			<interface>wan</interface>
417
			<ipprotocol>inet</ipprotocol>
418
			<tag></tag>
419
			<tagged></tagged>
420
			<max></max>
421
			<max-src-nodes></max-src-nodes>
422
			<max-src-conn></max-src-conn>
423
			<max-src-states></max-src-states>
424
			<statetimeout></statetimeout>
425
			<statetype><![CDATA[keep state]]></statetype>
426
			<os></os>
427
			<protocol>tcp</protocol>
428
			<source>
429
				<address>web_support</address>
430
			</source>
431
			<destination>
432
				<network>wanip</network>
433
				<port>4756</port>
434
			</destination>
435
			<descr><![CDATA[access_to_webgui]]></descr>
436
			<updated>
437
				<time>1601144841</time>
438
				<username><![CDATA[admin@192.168.0.164 (Local Database)]]></username>
439
			</updated>
440
			<created>
441
				<time>1601144841</time>
442
				<username><![CDATA[admin@192.168.0.164 (Local Database)]]></username>
443
			</created>
444
		</rule>
445
		<rule>
446
			<id></id>
447
			<tracker>1601144866</tracker>
448
			<type>pass</type>
449
			<interface>wan</interface>
450
			<ipprotocol>inet</ipprotocol>
451
			<tag></tag>
452
			<tagged></tagged>
453
			<max></max>
454
			<max-src-nodes></max-src-nodes>
455
			<max-src-conn></max-src-conn>
456
			<max-src-states></max-src-states>
457
			<statetimeout></statetimeout>
458
			<statetype><![CDATA[keep state]]></statetype>
459
			<os></os>
460
			<protocol>tcp</protocol>
461
			<source>
462
				<address>web_support</address>
463
			</source>
464
			<destination>
465
				<network>wanip</network>
466
				<port>4757</port>
467
			</destination>
468
			<descr><![CDATA[access_to_ssh]]></descr>
469
			<updated>
470
				<time>1601144866</time>
471
				<username><![CDATA[admin@192.168.0.164 (Local Database)]]></username>
472
			</updated>
473
			<created>
474
				<time>1601144866</time>
475
				<username><![CDATA[admin@192.168.0.164 (Local Database)]]></username>
476
			</created>
477
		</rule>
478
		<rule>
479
			<source>
480
				<address>SIP_ACCESS</address>
481
			</source>
482
			<interface>wan</interface>
483
			<protocol>tcp/udp</protocol>
484
			<destination>
485
				<address>192.168.0.166</address>
486
				<port>5060</port>
487
			</destination>
488
			<descr><![CDATA[NAT redirect_sip_to_freepbx]]></descr>
489
			<associated-rule-id>nat_5f71fc5a55d103.60374185</associated-rule-id>
490
			<tracker>1601305690</tracker>
491
			<created>
492
				<time>1601305690</time>
493
				<username><![CDATA[NAT Port Forward]]></username>
494
			</created>
495
		</rule>
496
		<rule>
497
			<source>
498
				<address>SIP_ACCESS</address>
499
			</source>
500
			<interface>wan</interface>
501
			<protocol>udp</protocol>
502
			<destination>
503
				<address>192.168.0.166</address>
504
				<port>10000-20000</port>
505
			</destination>
506
			<descr><![CDATA[NAT redirect_rtp_to_freepbx]]></descr>
507
			<associated-rule-id>nat_5f71fcc40c28e4.34133250</associated-rule-id>
508
			<tracker>1601305796</tracker>
509
			<created>
510
				<time>1601305796</time>
511
				<username><![CDATA[NAT Port Forward]]></username>
512
			</created>
513
		</rule>
514
		<rule>
515
			<source>
516
				<address>web_support</address>
517
			</source>
518
			<interface>wan</interface>
519
			<protocol>tcp</protocol>
520
			<destination>
521
				<address>192.168.0.166</address>
522
				<port>80</port>
523
			</destination>
524
			<descr><![CDATA[NAT access_to_web_freepbx]]></descr>
525
			<associated-rule-id>nat_5f71fcecf267c2.15924992</associated-rule-id>
526
			<tracker>1601305836</tracker>
527
			<created>
528
				<time>1601305836</time>
529
				<username><![CDATA[NAT Port Forward]]></username>
530
			</created>
531
		</rule>
532
		<rule>
533
			<source>
534
				<address>web_support</address>
535
			</source>
536
			<interface>wan</interface>
537
			<protocol>tcp</protocol>
538
			<destination>
539
				<address>192.168.0.166</address>
540
				<port>22</port>
541
			</destination>
542
			<descr><![CDATA[NAT redirect_to_ssh_aster]]></descr>
543
			<associated-rule-id>nat_5f73385ed494f7.29539021</associated-rule-id>
544
			<tracker>1601386590</tracker>
545
			<created>
546
				<time>1601386590</time>
547
				<username><![CDATA[NAT Port Forward]]></username>
548
			</created>
549
		</rule>
550
		<rule>
551
			<type>pass</type>
552
			<ipprotocol>inet</ipprotocol>
553
			<descr><![CDATA[Default allow LAN to any rule]]></descr>
554
			<interface>lan</interface>
555
			<tracker>0100000101</tracker>
556
			<source>
557
				<network>lan</network>
558
			</source>
559
			<destination>
560
				<any></any>
561
			</destination>
562
		</rule>
563
		<rule>
564
			<type>pass</type>
565
			<ipprotocol>inet6</ipprotocol>
566
			<descr><![CDATA[Default allow LAN IPv6 to any rule]]></descr>
567
			<interface>lan</interface>
568
			<tracker>0100000102</tracker>
569
			<source>
570
				<network>lan</network>
571
			</source>
572
			<destination>
573
				<any></any>
574
			</destination>
575
			<disabled></disabled>
576
		</rule>
577
		<separator>
578
			<wan></wan>
579
		</separator>
580
	</filter>
581
	<shaper>
582
		<queue>
583
			<interface>wan</interface>
584
			<name>wan</name>
585
			<scheduler>CODELQ</scheduler>
586
			<bandwidth>20</bandwidth>
587
			<bandwidthtype>Mb</bandwidthtype>
588
			<enabled>on</enabled>
589
		</queue>
590
		<queue>
591
			<interface>lan</interface>
592
			<name>lan</name>
593
			<scheduler>CODELQ</scheduler>
594
			<bandwidth>20</bandwidth>
595
			<bandwidthtype>Mb</bandwidthtype>
596
			<enabled>on</enabled>
597
		</queue>
598
	</shaper>
599
	<ipsec>
600
		<vtimaps></vtimaps>
601
	</ipsec>
602
	<aliases>
603
		<alias>
604
			<name>web_support</name>
605
			<type>host</type>
606
			<address>backup.web.ru office.web.ru</address>
607
			<descr></descr>
608
			<detail><![CDATA[web home||web office]]></detail>
609
		</alias>
610
		<alias>
611
			<name>SIP_ACCESS</name>
612
			<type>host</type>
613
			<address>office.web.ru backup.web.ru</address>
614
			<descr></descr>
615
			<detail><![CDATA[Entry added Thu, 10 Dec 2020 15:47:16 +0300||Entry added Thu, 10 Dec 2020 15:47:16 +0300]]></detail>
616
		</alias>
617
	</aliases>
618
	<proxyarp></proxyarp>
619
	<cron>
620
		<item>
621
			<minute>1,31</minute>
622
			<hour>0-5</hour>
623
			<mday>*</mday>
624
			<month>*</month>
625
			<wday>*</wday>
626
			<who>root</who>
627
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
628
		</item>
629
		<item>
630
			<minute>1</minute>
631
			<hour>3</hour>
632
			<mday>1</mday>
633
			<month>*</month>
634
			<wday>*</wday>
635
			<who>root</who>
636
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
637
		</item>
638
		<item>
639
			<minute>1</minute>
640
			<hour>1</hour>
641
			<mday>*</mday>
642
			<month>*</month>
643
			<wday>*</wday>
644
			<who>root</who>
645
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
646
		</item>
647
		<item>
648
			<minute>*/60</minute>
649
			<hour>*</hour>
650
			<mday>*</mday>
651
			<month>*</month>
652
			<wday>*</wday>
653
			<who>root</who>
654
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
655
		</item>
656
		<item>
657
			<minute>30</minute>
658
			<hour>12</hour>
659
			<mday>*</mday>
660
			<month>*</month>
661
			<wday>*</wday>
662
			<who>root</who>
663
			<command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
664
		</item>
665
		<item>
666
			<minute>1</minute>
667
			<hour>0</hour>
668
			<mday>*</mday>
669
			<month>*</month>
670
			<wday>*</wday>
671
			<who>root</who>
672
			<command>/usr/bin/nice -n20 /etc/rc.update_pkg_metadata</command>
673
		</item>
674
		<item>
675
			<minute>0</minute>
676
			<hour>*/1</hour>
677
			<mday>*</mday>
678
			<month>*</month>
679
			<wday>*</wday>
680
			<who>root</who>
681
			<command>/etc/rc.backup_rrd.sh</command>
682
		</item>
683
		<item>
684
			<minute>0</minute>
685
			<hour>*/1</hour>
686
			<mday>*</mday>
687
			<month>*</month>
688
			<wday>*</wday>
689
			<who>root</who>
690
			<command>/etc/rc.backup_dhcpleases.sh</command>
691
		</item>
692
		<item>
693
			<minute>0</minute>
694
			<hour>*/1</hour>
695
			<mday>*</mday>
696
			<month>*</month>
697
			<wday>*</wday>
698
			<who>root</who>
699
			<command>/etc/rc.backup_logs.sh</command>
700
		</item>
701
		<item>
702
			<minute>*/1</minute>
703
			<hour>*</hour>
704
			<mday>*</mday>
705
			<month>*</month>
706
			<wday>*</wday>
707
			<who>root</who>
708
			<command>/usr/sbin/newsyslog</command>
709
		</item>
710
		<item>
711
			<minute>1</minute>
712
			<hour>3</hour>
713
			<mday>*</mday>
714
			<month>*</month>
715
			<wday>*</wday>
716
			<who>root</who>
717
			<command>/etc/rc.periodic daily</command>
718
		</item>
719
		<item>
720
			<minute>15</minute>
721
			<hour>4</hour>
722
			<mday>*</mday>
723
			<month>*</month>
724
			<wday>6</wday>
725
			<who>root</who>
726
			<command>/etc/rc.periodic weekly</command>
727
		</item>
728
		<item>
729
			<minute>30</minute>
730
			<hour>5</hour>
731
			<mday>1</mday>
732
			<month>*</month>
733
			<wday>*</wday>
734
			<who>root</who>
735
			<command>/etc/rc.periodic monthly</command>
736
		</item>
737
	</cron>
738
	<wol></wol>
739
	<rrd>
740
		<enable></enable>
741
	</rrd>
742
	<widgets>
743
		<sequence>system_information:col1:open:0,traffic_graphs:col2:open:0,interface_statistics:col2:open:0,gateways:col3:open:0,interfaces:col3:open:0,services_status:col3:open:0,log:col4:open:0</sequence>
744
		<period>10</period>
745
		<system_information-0>
746
			<filter>system,bios,dns_servers,last_config_change,temperature,load_average</filter>
747
		</system_information-0>
748
		<traffic_graphs>
749
			<refreshinterval>1</refreshinterval>
750
			<invert>false</invert>
751
			<backgroundupdate>true</backgroundupdate>
752
			<smoothfactor>0</smoothfactor>
753
			<size>8</size>
754
			<filter></filter>
755
		</traffic_graphs>
756
		<log-0>
757
			<descr><![CDATA[Firewall Logs]]></descr>
758
			<filterlogentries>10</filterlogentries>
759
			<filterlogentriesacts>Block Reject</filterlogentriesacts>
760
			<filterlogentriesinterval>15</filterlogentriesinterval>
761
		</log-0>
762
	</widgets>
763
	<openvpn></openvpn>
764
	<dnshaper>
765
		<queue>
766
			<name>limit_in</name>
767
			<number>1</number>
768
			<qlimit></qlimit>
769
			<plr></plr>
770
			<description></description>
771
			<bandwidth>
772
				<item>
773
					<bw>20</bw>
774
					<burst></burst>
775
					<bwscale>Mb</bwscale>
776
					<bwsched>none</bwsched>
777
				</item>
778
			</bandwidth>
779
			<enabled>on</enabled>
780
			<buckets></buckets>
781
			<mask>none</mask>
782
			<maskbits></maskbits>
783
			<maskbitsv6></maskbitsv6>
784
			<delay>0</delay>
785
			<sched>fq_codel</sched>
786
			<param_fq_codel_target>0</param_fq_codel_target>
787
			<param_fq_codel_interval>0</param_fq_codel_interval>
788
			<param_fq_codel_quantum></param_fq_codel_quantum>
789
			<param_fq_codel_limit></param_fq_codel_limit>
790
			<param_fq_codel_flows></param_fq_codel_flows>
791
			<aqm>codel</aqm>
792
			<param_codel_target>0</param_codel_target>
793
			<param_codel_interval>0</param_codel_interval>
794
			<ecn>on</ecn>
795
		</queue>
796
		<queue>
797
			<name>limit_out</name>
798
			<number>2</number>
799
			<qlimit></qlimit>
800
			<plr></plr>
801
			<description></description>
802
			<bandwidth>
803
				<item>
804
					<bw>20</bw>
805
					<burst></burst>
806
					<bwscale>Mb</bwscale>
807
					<bwsched>none</bwsched>
808
				</item>
809
			</bandwidth>
810
			<enabled>on</enabled>
811
			<buckets></buckets>
812
			<mask>none</mask>
813
			<maskbits></maskbits>
814
			<maskbitsv6></maskbitsv6>
815
			<delay>0</delay>
816
			<sched>fq_codel</sched>
817
			<param_fq_codel_target>5</param_fq_codel_target>
818
			<param_fq_codel_interval>100</param_fq_codel_interval>
819
			<param_fq_codel_quantum>1514</param_fq_codel_quantum>
820
			<param_fq_codel_limit>10240</param_fq_codel_limit>
821
			<param_fq_codel_flows>1024</param_fq_codel_flows>
822
			<aqm>codel</aqm>
823
			<param_codel_target>5</param_codel_target>
824
			<param_codel_interval>100</param_codel_interval>
825
			<ecn>on</ecn>
826
		</queue>
827
	</dnshaper>
828
	<unbound>
829
		<enable></enable>
830
		<active_interface>lan,lo0</active_interface>
831
		<outgoing_interface>wan</outgoing_interface>
832
		<custom_options></custom_options>
833
		<hideidentity></hideidentity>
834
		<hideversion></hideversion>
835
		<port></port>
836
		<sslcertref>5f6f5d626b59b</sslcertref>
837
		<forwarding></forwarding>
838
		<system_domain_local_zone_type>transparent</system_domain_local_zone_type>
839
		<qname-minimisation></qname-minimisation>
840
		<prefetch></prefetch>
841
		<prefetchkey></prefetchkey>
842
		<msgcachesize>4</msgcachesize>
843
		<outgoing_num_tcp>10</outgoing_num_tcp>
844
		<incoming_num_tcp>10</incoming_num_tcp>
845
		<edns_buffer_size>auto</edns_buffer_size>
846
		<num_queries_per_thread>512</num_queries_per_thread>
847
		<jostle_timeout>200</jostle_timeout>
848
		<cache_max_ttl>86400</cache_max_ttl>
849
		<cache_min_ttl>60</cache_min_ttl>
850
		<infra_host_ttl>900</infra_host_ttl>
851
		<infra_cache_numhosts>10000</infra_cache_numhosts>
852
		<unwanted_reply_threshold>disabled</unwanted_reply_threshold>
853
		<log_verbosity>0</log_verbosity>
854
		<acls>
855
			<aclid>0</aclid>
856
			<aclname><![CDATA[default]]></aclname>
857
			<aclaction>allow</aclaction>
858
			<description></description>
859
			<row>
860
				<acl_network>0.0.0.0</acl_network>
861
				<mask>0</mask>
862
				<description></description>
863
			</row>
864
		</acls>
865
		<tlsport></tlsport>
866
	</unbound>
867
	<revision>
868
		<time>1627403759</time>
869
		<description><![CDATA[(system): Overwrote previous installation of Zabbix Agent 5.0.]]></description>
870
		<username><![CDATA[(system)]]></username>
871
	</revision>
872
	<cert>
873
		<refid>5f6f5d626b59b</refid>
874
		<descr><![CDATA[webConfigurator default (5f6f5d626b59b)]]></descr>
875
		<type>server</type>
876
		<crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUVoRENDQTJ5Z0F3SUJBZ0lCQURBOXcwQkFRc0ZBREJhTVRnd05nWURWUVFLRXk5d1psTmwKYm5ObElIZGxZa052Ym1acFozVnlZWFJ2Y2lCVFpXeG1MVk5wWjI1bFpDQkRaWEowYVdacFkyRjBaVEVlTUJ3RwpBMVVFQXhNVmNHWlRaVzV6WlMwMVpqWm1OV1EyTWpaaU5UbGlNQjRYRFRJd01Ea3lOakUxTWpVeU1sb1hEVEl4Ck1UQXlPVEUxTWpVeU1sb3dXakU0TURZR0ExVUVDaE12Y0daVFpXNXpaU0IzWldKRGIyNW1hV2QxY21GMGIzSWcKVTJWc1ppMVRhV2R1WldRZ1EyVnlkR2xtYVdOaGRHVXhIakFjQmdOVkJBTVRGWEJtVTJWdWMyVXROV1kyWmpWawpOakkyWWpVNVlqQ0NBU0l3RFFZSktvWklodmNOQVFFQkJRQURnZ0VQQURDQ0FRb0NnZ0VCQU5pbG9zU29tdXc4Cjk5YnZ4NlJFcWpXbHVOdWNFTFpLekRNRlFacFVoS0NaRjk1aW5BVW9sQzRYTXdnRUhlODJ2RjVnS1ovUWV6d2UKWXhmb0NxNmd2NXYwUGloUnA5ZURvcnBPemszVVE4cGw5UTY4VklLaElNams3T2tCOWtuTUxuZHNKYnVpcnl6dgpCQkp2d3AxNUQ1Y3IyTElpMlRkbE1Lak9QaXMwaEhTYTRUeTFBN01IUWMwMDg2V0ZxZTA2WkUxNmZoaXZyVUplCjZ3dVlPN3dGRFlQRlM0aSs0SmJPK3hIQnBwdXVldWlGVDN4YmtVekxPeXR5RUVBLzN0L2xnaHdCZFhWdmUvNEgKVy9OeWhxZHdXdmQwQnEyeEkvWXVEYzlyamQxMTFxVHFpTlFhc1JJb0hhcDBXVEFFNjJJdjUrSUZhdWNOWmU1Twp5cXZja3VIdzhXTUNBd0VBQWFPQ0FWTXdnZ0ZQTUFrR0ExVWRFd1FDTUFBd0VRWUpZSVpJQVliNFFnRUJCQVFECkFnWkFNQXNHQTFVZER3UUVBd0lGb0RBekJnbGdoa2dCaHZoQ0FRMEVKaFlrVDNCbGJsTlRUQ0JIWlc1bGNtRjAKWldRZ1UyVnlkbVZ5SUVObGNuUnBabWxqWVhSbE1CMEdBMVVkRGdRV0JCUk92MEJsUTZXQWNMczI1RFYyb2ZTbAovZ1lkNlRDQmdnWURWUjBqQkhzd2VZQVVUcjlBWlVPbGdIQzdOdVExZHFIMHBmNEdIZW1oWHFSY01Gb3hPREEyCkJnTlZCQW9UTDNCbVUyVnVjMlVnZDJWaVEyOXVabWxuZFhKaGRHOXlJRk5sYkdZdFUybG5ibVZrSUVObGNuUnAKWm1sallYUmxNUjR3SEFZRFZRUURFeFZ3WmxObGJuTmxMVFZtTm1ZMVpEWXlObUkxT1dLQ0FRQXdKd1lEVlIwbApCQ0F3SGdZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ0JnZ3JCZ0VGQlFnQ0FqQWdCZ05WSFJFRUdUQVhnaFZ3ClpsTmxibk5sTFRWbU5tWTFaRFl5Tm1JMU9XSXdEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJBQzF5WU1HNmViVHoKUGpPQXAxdVROMXRraytIOTZ3YUhzazZXK1JCZkdOdFMvQ0JXWEhacmFVTWRta25FQlBITzdGS0llalZka3VWSApaV1htMENjbXBHZVovK1hIOTkzYTRKbWVPTGRvT2p3eEVGMFB2VGRkOWpLRkpoYzBuemtNZTBqdWZSMU5GdjNjCmZtUHlxWmhPcU0rc2xIL2lBNjNvbGNzUFJOYWNnZ25ZTWUxMHMrMmVLQmxkM3JUV1VHWTN4R09lelAwbDA3N0gKRjlnWEpTeC82NzZsY2M3OVlmY2pnUlg2R0lpYkpyTnVtVXM0RmFqRWh4djVmczBHaklMYUhIQVY1cXk3OE5QeQpBODQ1bDVhNDFYdWl1azVTbEozQzQrOVB5Z1RqZSs2TUlkRTVXcE9rcFNuYWV3OXEzOGg1WFhjdkkra1JkbURoCnA2dXh2MVJ5dEVBPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==</crt>
877
		<prv>LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUV2Z0lCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQktnd2dnU2tBZ0VBQW9JQkFRRFlwYUxFcUpyc1BQZlcKNzhla1JLbzFwYmpibkJDMlNzd3pCVUdhVklTZ21SZmVZcHdGS0pRdUZ6TUlCQjN2TnJ4ZVlDbWYwSHM4SG1NWAo2QXF1b0wrYjlENG9VYWZYZzZLNlRzNU4xRVBLWmZVT3ZGU0NvU0RJNU96cEFmWkp6QzUzYkNXN29xOHM3d1FTCmI4S2RlUStYSzlpeUl0azNaVENvemo0ck5JUjBtdUU4dFFPekIwSE5OUE9saGFudE9tUk5lbjRZcjYxQ1h1c0wKbUR1OEJRMkR4VXVJdnVDV3p2c1J3YWFicm5yb2hVOThXNUZNeXpzcmNoQkFQOTdmNVlJY0FYVjFiM3YrQjF2egpjb2FuY0ZyM2RBYXRzU1AyTGczUGE0M2RkZGFrNm9qVUdyRVNLQjJxZEZrd0JPdGlMK2ZpQldybkRXWHVUc3FyCjNKTGg4UEZqQWdNQkFBRUNnZ0VCQUpNK1VCZ1U5K1pqc1paMXRWeGlCc1ViY3o1ZkhjU25wWTF2bnh6RElMaisKRkFqalFHTUpKMTBFQzMwQlAwOGNCbjZtSU9RcmovWldPTWRBd0RIYnN4N05xNGsvcGpHRm1BM0VEZGM3MHk4MgppSTJSVm1iS0dEd3h5d3E2ZUtmRGpEbENXWXJqa09lYk0wdE1oaHI4OHFtdDlVTnRCL0RzWjF2emdMRmdxajJNCjNVM3c1elR6eEtQK0lYYzl0QjBES2JhdWp6bEpUT08yRkJ1YkNleHd4ZG1iVjVFMWR4WkpTNEp0b2gyWEV6MVoKcWRLYTQ3bUhRQ0lDVFNFcVp5cmYwL0R3RGNOeXRLamQvTk9QdTVObEd2emFYeTlrWkQraXFZQzV2akpXakFjMgorcEJ2VFRFdVhmYU0zZUxRNUdRNmRrRS9yNTBYTVpOTEdjNk5WdnNicmtFQ2dZRUEvZUJHTVpxYlJuUFl0TXpuCkdWTnBjMHlVRm53SVV6RGRNUW5XbElHSHJtZDg5V3lHY2VKNHdsUEU0bm1vNWhxTEdKbWJMUVJPUDFPRThRMloKb1RwdmVWazRpWUpWQ2c1UUdESStGMGNtS1UvWDloQUxMN0xTeEx2N21XaHdockRubUpTblpxWGpZcHpaMnROWAp2MldqMmo0UnMwVFpEWWkwNXNGdjZrWWsyUEVDZ1lFQTJuV2cwK3lFaG9kekxrQlhhbnJtUDZEdHVqbkl3UzZoCkFVRFZTZnhrRjhXU0YzQUYybyt3ZE80cXVCZEJmNnk5cHpqN0w0SWVET2ZzcXNKSGVkd3VrL3NxcmoraC9hS0EKZFprKzdGb3VvNGljcHFLcGs3cloyUW81RFBPMk9laFdwL2pjbTZGMUVqT0NLd3k4dzJhUjVyNXB6ME1zTGlDNAplTGV1RVFrMlQ1TUNnWUFIUm1QOGkrZWpMektvaTY2YnBTNUNaWkZneTVFWmdTNzFkc2kxWExqY29JNk9JZHdBCmEzTDJicHdYdVZERHQwTUJJM1cwNW9pdmU5ODFZU1JqNEY3TlpXY2ZXYUxDTlFMS2pyWUV5TDhwTSthR1lKTlIKZkpoWmx1RncxZk5UaU1JNk54aE04cmYvWFd0SXdBR2x0RzNybFJmQXdWcE83dm53R3Q3d0lhNXdvUUtCZ0ZkbAoxZGpTOTlZR1hIczFmSU41OWFHaEZWcDZnYWxmcVVRaUZ2S0ppZFhFMGdTVWFaTWVCejlRaFVDdTlTSktEbm5YCkh3N0xwSkFQUFN5M212YlNzc083S1VFYTdnalZ1VVRTOFV5SGE3ODdDVWpWTExpUWVWVU9kUEtNa2V1cTJ2aEsKWkovU3dVNXQwdmE4R3N5bHZWc3Q5SkRaMDlRRWZTaTJlMm9QWUc0SEFvR0JBS1FuOHZuczhhVnc0cnVEOFgvdQpyMy96Q1poK0tYSXMxZlBOTmR0Wm00d2w3M3JQUHFDTkVKUlF0WSttTHQ1K1NSTXNCbGY2azRMT0pzdkQxeGtGCjFUK1lJOWxUazhZTjVzNnkwaDRWZDNJS0YrRHkzNjRPWFFyNWVNTXVqWVZpc3RiclJNVXViQUFMT252TGJMTGQKTGpWMVZML3c1L0ZUdlVGZ0pZNklEdU5PCi0tLS0tRU5EIFBSSVZBVEUgS0VZLS0tLS0K</prv>
878
	</cert>
879
	<ppps></ppps>
880
	<gateways>
881
		<gateway_item>
882
			<interface>wan</interface>
883
			<gateway>89.20.155.20.1</gateway>
884
			<name>WANGW_2</name>
885
			<weight>1</weight>
886
			<ipprotocol>inet</ipprotocol>
887
			<interval></interval>
888
			<descr><![CDATA[Interface wan Gateway]]></descr>
889
		</gateway_item>
890
		<defaultgw4>WANGW_2</defaultgw4>
891
	</gateways>
892
	<sysctl>
893
		<item>
894
			<tunable>hw.ibrs_disable</tunable>
895
			<value>0</value>
896
			<descr><![CDATA[Disable Indirect Branch Restricted Speculation]]></descr>
897
		</item>
898
		<item>
899
			<tunable>hw.intr_storm_threshold</tunable>
900
			<value>9000</value>
901
			<descr><![CDATA[Number of consecutive interrupts before storm protection is enabled]]></descr>
902
		</item>
903
		<item>
904
			<tunable>hw.mds_disable</tunable>
905
			<value>3</value>
906
			<descr><![CDATA[Microarchitectural Data Sampling Mitigation (0 - off, 1 - on VERW, 2 - on SW, 3 - on AUTO]]></descr>
907
		</item>
908
		<item>
909
			<tunable>hw.usb.no_shutdown_wait</tunable>
910
			<value>1</value>
911
			<descr><![CDATA[No USB device waiting at system shutdown]]></descr>
912
		</item>
913
		<item>
914
			<tunable>hw.usb.no_suspend_wait</tunable>
915
			<value>1</value>
916
			<descr><![CDATA[No USB device waiting at system suspend]]></descr>
917
		</item>
918
		<item>
919
			<tunable>kern.dirdelay</tunable>
920
			<value>4</value>
921
			<descr><![CDATA[Time to delay syncing directories (in seconds)]]></descr>
922
		</item>
923
		<item>
924
			<tunable>kern.filedelay</tunable>
925
			<value>5</value>
926
			<descr><![CDATA[Time to delay syncing files (in seconds)]]></descr>
927
		</item>
928
		<item>
929
			<tunable>kern.metadelay</tunable>
930
			<value>3</value>
931
			<descr><![CDATA[Time to delay syncing metadata (in seconds)]]></descr>
932
		</item>
933
		<item>
934
			<tunable>kern.ipc.shm_use_phys</tunable>
935
			<value>1</value>
936
			<descr><![CDATA[Enable/Disable locking of shared memory pages in core]]></descr>
937
		</item>
938
		<item>
939
			<tunable>kern.ipc.soacceptqueue</tunable>
940
			<value>4096</value>
941
			<descr><![CDATA[Maximum listen socket pending connection accept queue size]]></descr>
942
		</item>
943
		<item>
944
			<tunable>kern.maxfiles</tunable>
945
			<value>1000000</value>
946
			<descr><![CDATA[Maximum number of files]]></descr>
947
		</item>
948
		<item>
949
			<tunable>kern.maxfilesperproc</tunable>
950
			<value>1000000</value>
951
			<descr><![CDATA[Maximum files allowed open per process]]></descr>
952
		</item>
953
		<item>
954
			<tunable>kern.sync_on_panic</tunable>
955
			<value>1</value>
956
			<descr><![CDATA[Do a sync before rebooting from a panic]]></descr>
957
		</item>
958
		<item>
959
			<tunable>net.graph.maxdgram</tunable>
960
			<value>8388608</value>
961
			<descr><![CDATA[Maximum outgoing Netgraph datagram size]]></descr>
962
		</item>
963
		<item>
964
			<tunable>net.graph.recvspace</tunable>
965
			<value>8388608</value>
966
			<descr><![CDATA[Maximum space for incoming Netgraph datagrams]]></descr>
967
		</item>
968
		<item>
969
			<tunable>net.inet.icmp.drop_redirect</tunable>
970
			<value>1</value>
971
			<descr><![CDATA[Ignore ICMP redirects]]></descr>
972
		</item>
973
		<item>
974
			<tunable>net.inet.icmp.log_redirect</tunable>
975
			<value>1</value>
976
			<descr><![CDATA[Log ICMP redirects to the console]]></descr>
977
		</item>
978
		<item>
979
			<tunable>net.inet.ip.ttl</tunable>
980
			<value>128</value>
981
			<descr><![CDATA[Maximum TTL on IP packets]]></descr>
982
		</item>
983
		<item>
984
			<tunable>net.inet.tcp.abc_l_var</tunable>
985
			<value>44</value>
986
			<descr><![CDATA[Cap the max cwnd increment during slow-start to this number of segments]]></descr>
987
		</item>
988
		<item>
989
			<tunable>net.inet.tcp.cc.algorithm</tunable>
990
			<value>htcp</value>
991
			<descr><![CDATA[Default congestion control algorithm]]></descr>
992
		</item>
993
		<item>
994
			<tunable>net.inet.tcp.cc.htcp.adaptive_backoff</tunable>
995
			<value>1</value>
996
			<descr><![CDATA[enable H-TCP adaptive backoff]]></descr>
997
		</item>
998
		<item>
999
			<tunable>net.inet.tcp.cc.htcp.rtt_scaling</tunable>
1000
			<value>1</value>
1001
			<descr><![CDATA[enable H-TCP RTT scaling]]></descr>
1002
		</item>
1003
		<item>
1004
			<tunable>net.inet.tcp.fast_finwait2_recycle</tunable>
1005
			<value>1</value>
1006
			<descr><![CDATA[Recycle closed FIN_WAIT_2 connections faster]]></descr>
1007
		</item>
1008
		<item>
1009
			<tunable>net.inet.tcp.finwait2_timeout</tunable>
1010
			<value>5000</value>
1011
			<descr><![CDATA[FIN-WAIT2 timeout]]></descr>
1012
		</item>
1013
		<item>
1014
			<tunable>net.inet.tcp.icmp_may_rst</tunable>
1015
			<value>0</value>
1016
			<descr><![CDATA[Certain ICMP unreachable messages may abort connections in SYN_SENT]]></descr>
1017
		</item>
1018
		<item>
1019
			<tunable>net.inet.tcp.initcwnd_segments</tunable>
1020
			<value>44</value>
1021
			<descr><![CDATA[Slow-start flight size (initial congestion window) in number of segments]]></descr>
1022
		</item>
1023
		<item>
1024
			<tunable>net.inet.tcp.keepinit</tunable>
1025
			<value>5000</value>
1026
			<descr><![CDATA[time to establish connection]]></descr>
1027
		</item>
1028
		<item>
1029
			<tunable>net.inet.tcp.log_in_vain</tunable>
1030
			<value>1</value>
1031
			<descr><![CDATA[Log all incoming TCP segments to closed ports]]></descr>
1032
		</item>
1033
		<item>
1034
			<tunable>net.inet.tcp.maxtcptw</tunable>
1035
			<value>32768</value>
1036
			<descr><![CDATA[Maximum number of compressed TCP TIME_WAIT entries]]></descr>
1037
		</item>
1038
		<item>
1039
			<tunable>net.inet.tcp.minmss</tunable>
1040
			<value>536</value>
1041
			<descr><![CDATA[Minimum TCP Maximum Segment Size]]></descr>
1042
		</item>
1043
		<item>
1044
			<tunable>net.inet.tcp.msl</tunable>
1045
			<value>15000</value>
1046
			<descr><![CDATA[Maximum segment lifetime]]></descr>
1047
		</item>
1048
		<item>
1049
			<tunable>net.inet.tcp.mssdflt</tunable>
1050
			<value>1460</value>
1051
			<descr><![CDATA[Default TCP Maximum Segment Size]]></descr>
1052
		</item>
1053
		<item>
1054
			<tunable>net.inet.tcp.recvbuf_auto</tunable>
1055
			<value>0</value>
1056
			<descr><![CDATA[Enable automatic receive buffer sizing]]></descr>
1057
		</item>
1058
		<item>
1059
			<tunable>net.inet.tcp.recvbuf_inc</tunable>
1060
			<value>65536</value>
1061
			<descr><![CDATA[Incrementor step size of automatic receive buffer]]></descr>
1062
		</item>
1063
		<item>
1064
			<tunable>net.inet.tcp.recvbuf_max</tunable>
1065
			<value>16777216</value>
1066
			<descr><![CDATA[Max size of automatic receive buffer]]></descr>
1067
		</item>
1068
		<item>
1069
			<tunable>net.inet.tcp.rfc6675_pipe</tunable>
1070
			<value>1</value>
1071
			<descr><![CDATA[Use calculated pipe/in-flight bytes per RFC 6675]]></descr>
1072
		</item>
1073
		<item>
1074
			<tunable>net.inet.tcp.sack.enable</tunable>
1075
			<value>0</value>
1076
			<descr><![CDATA[Enable/Disable TCP SACK support]]></descr>
1077
		</item>
1078
		<item>
1079
			<tunable>net.inet.tcp.sendbuf_auto</tunable>
1080
			<value>0</value>
1081
			<descr><![CDATA[Enable automatic send buffer sizing]]></descr>
1082
		</item>
1083
		<item>
1084
			<tunable>net.inet.tcp.sendbuf_inc</tunable>
1085
			<value>65536</value>
1086
			<descr><![CDATA[Incrementor step size of automatic send buffer]]></descr>
1087
		</item>
1088
		<item>
1089
			<tunable>net.inet.tcp.sendbuf_max</tunable>
1090
			<value>16777216</value>
1091
			<descr><![CDATA[Max size of automatic send buffer]]></descr>
1092
		</item>
1093
		<item>
1094
			<tunable>net.inet.udp.log_in_vain</tunable>
1095
			<value>1</value>
1096
			<descr><![CDATA[Log all incoming UDP packets]]></descr>
1097
		</item>
1098
		<item>
1099
			<tunable>net.inet.udp.recvspace</tunable>
1100
			<value>65536</value>
1101
			<descr><![CDATA[Maximum space for incoming UDP datagrams]]></descr>
1102
		</item>
1103
		<item>
1104
			<tunable>net.link.gif.parallel_tunnels</tunable>
1105
			<value>1</value>
1106
			<descr><![CDATA[Allow parallel tunnels?]]></descr>
1107
		</item>
1108
		<item>
1109
			<tunable>net.local.dgram.maxdgram</tunable>
1110
			<value>65536</value>
1111
			<descr><![CDATA[Default datagram send space]]></descr>
1112
		</item>
1113
		<item>
1114
			<tunable>net.local.dgram.recvspace</tunable>
1115
			<value>65536</value>
1116
			<descr><![CDATA[Default datagram receive space]]></descr>
1117
		</item>
1118
		<item>
1119
			<tunable>net.local.stream.recvspace</tunable>
1120
			<value>65536</value>
1121
			<descr><![CDATA[Default stream receive space]]></descr>
1122
		</item>
1123
		<item>
1124
			<tunable>net.local.stream.sendspace</tunable>
1125
			<value>65536</value>
1126
			<descr><![CDATA[Default stream send space]]></descr>
1127
		</item>
1128
		<item>
1129
			<tunable>security.bsd.hardlink_check_gid</tunable>
1130
			<value>1</value>
1131
			<descr><![CDATA[Unprivileged processes cannot create hard links to files owned by other groups]]></descr>
1132
		</item>
1133
		<item>
1134
			<tunable>security.bsd.hardlink_check_uid</tunable>
1135
			<value>1</value>
1136
			<descr><![CDATA[Unprivileged processes cannot create hard links to files owned by other users]]></descr>
1137
		</item>
1138
		<item>
1139
			<tunable>security.bsd.unprivileged_proc_debug</tunable>
1140
			<value>0</value>
1141
			<descr><![CDATA[Unprivileged processes may use process debugging facilities]]></descr>
1142
		</item>
1143
		<item>
1144
			<tunable>security.bsd.unprivileged_read_msgbuf</tunable>
1145
			<value>0</value>
1146
			<descr><![CDATA[Unprivileged processes may read the kernel message buffer]]></descr>
1147
		</item>
1148
		<item>
1149
			<tunable>vfs.vmiodirenable</tunable>
1150
			<value>0</value>
1151
			<descr><![CDATA[Use the VM system for directory writes]]></descr>
1152
		</item>
1153
		<item>
1154
			<tunable>vfs.write_behind</tunable>
1155
			<value>0</value>
1156
			<descr><![CDATA[Cluster write-behind; 0: disable, 1: enable, 2: backed off]]></descr>
1157
		</item>
1158
		<item>
1159
			<tunable>vfs.ufs.dirhash_maxmem</tunable>
1160
			<value>134217728</value>
1161
			<descr><![CDATA[maximum allowed dirhash memory usage]]></descr>
1162
		</item>
1163
		<item>
1164
			<tunable>vm.overcommit</tunable>
1165
			<value>2</value>
1166
			<descr><![CDATA[Configure virtual memory overcommit behavior]]></descr>
1167
		</item>
1168
	</sysctl>
1169
	<installedpackages>
1170
		<package>
1171
			<name>Cron</name>
1172
			<descr><![CDATA[The cron utility is used to manage commands on a schedule.]]></descr>
1173
			<version>0.3.7_5</version>
1174
			<configurationfile>cron.xml</configurationfile>
1175
			<include_file>/usr/local/pkg/cron.inc</include_file>
1176
		</package>
1177
		<package>
1178
			<name>iperf</name>
1179
			<website>http://www.freshports.org/benchmarks/iperf/</website>
1180
			<descr><![CDATA[Iperf is a tool for testing network throughput, loss, and jitter.]]></descr>
1181
			<version>3.0.2_5</version>
1182
			<pkginfolink>https://docs.netgate.com/pfsense/en/latest/packages/iperf.html</pkginfolink>
1183
			<configurationfile>iperf.xml</configurationfile>
1184
			<tabs>
1185
				<tab>
1186
					<text><![CDATA[Client]]></text>
1187
					<url>/pkg_edit.php?xml=iperf.xml</url>
1188
					<active></active>
1189
				</tab>
1190
				<tab>
1191
					<text><![CDATA[Server]]></text>
1192
					<url>/pkg_edit.php?xml=iperfserver.xml</url>
1193
				</tab>
1194
			</tabs>
1195
		</package>
1196
		<package>
1197
			<name>nmap</name>
1198
			<descr><![CDATA[NMap is a utility for network exploration or security auditing.&lt;br/&gt;
1199
			It supports ping scanning (determine which hosts are up), many port scanning techniques (determine what services the hosts are offering), version detection (determine what application/service is running on a port), and TCP/IP fingerprinting (remote host OS or device identification).
1200
			It also offers flexible target and port specification, decoy/stealth scanning, SunRPC scanning, and more.]]></descr>
1201
			<version>1.4.4_2</version>
1202
			<pkginfolink>https://docs.netgate.com/pfsense/en/latest/packages/nmap.html</pkginfolink>
1203
			<configurationfile>nmap.xml</configurationfile>
1204
			<include_file>/usr/local/pkg/nmap.inc</include_file>
1205
		</package>
1206
		<package>
1207
			<name>Traffic Totals</name>
1208
			<internal_name>Status_Traffic_Totals</internal_name>
1209
			<descr><![CDATA[Traffic Totals page under the Status menu, which will give a total amount of traffic passed In/Out over the period of hours, days, and months. Uses vnStat for data collection.]]></descr>
1210
			<version>2.3.2_2</version>
1211
			<configurationfile>Status_Traffic_Totals.xml</configurationfile>
1212
			<include_file>/usr/local/pkg/status_traffic_totals.inc</include_file>
1213
		</package>
1214
		<package>
1215
			<name>Zabbix Agent 5.0</name>
1216
			<internal_name>zabbix-agent5</internal_name>
1217
			<descr><![CDATA[LTS (Long Term Support) release. Zabbix LTS releases are supported for 
1218
			Zabbix customers during five (5) years i.e. 3 years of Full Support (general, critical and security issues) 
1219
			and 2 additional years of Limited Support (critical and security issues only). Zabbix LTS version release 
1220
			will result in change of the first version number.&lt;br /&gt;
1221
			Standard release. Standard Zabbix releases are supported for Zabbix customers during
1222
			six (6) months of Full Support (general, critical and security issues) until the next
1223
			Zabbix stable release, plus one (1) additional month of Limited Support (critical and
1224
			security issues only). Zabbix Standard version release will result in change of the
1225
			second version number.&lt;br /&gt;
1226
			More info in &lt;a href=&quot;http://www.zabbix.com/life_cycle_and_release_policy.php&quot;&gt;Zabbix Life Cycle and Release Policy&lt;/a&gt;.]]></descr>
1227
			<website>http://www.zabbix.com/product.php</website>
1228
			<version>1.0.4_10</version>
1229
			<configurationfile>zabbix-agent.xml</configurationfile>
1230
			<logging>
1231
				<logfilename>zabbix-agent/zabbix_agentd.log</logfilename>
1232
			</logging>
1233
			<tabs>
1234
				<tab>
1235
					<text><![CDATA[Agent]]></text>
1236
					<url>/pkg_edit.php?xml=zabbix-agent.xml&amp;id=0</url>
1237
					<active></active>
1238
				</tab>
1239
			</tabs>
1240
			<include_file>/usr/local/pkg/zabbix-agent.inc</include_file>
1241
			<plugins>
1242
				<item>
1243
					<type>plugin_certificates</type>
1244
				</item>
1245
			</plugins>
1246
		</package>
1247
		<menu>
1248
			<name>NMap</name>
1249
			<section>Diagnostics</section>
1250
			<configfile>nmap.xml</configfile>
1251
		</menu>
1252
		<menu>
1253
			<name>iperf Client</name>
1254
			<tooltiptext>Run iperf in client mode.</tooltiptext>
1255
			<section>Diagnostics</section>
1256
			<url>/pkg_edit.php?xml=iperf.xml</url>
1257
		</menu>
1258
		<menu>
1259
			<name>iperf Server</name>
1260
			<tooltiptext>Run iperf in server mode.</tooltiptext>
1261
			<section>Diagnostics</section>
1262
			<url>/pkg_edit.php?xml=iperfserver.xml</url>
1263
		</menu>
1264
		<menu>
1265
			<name>Traffic Totals</name>
1266
			<tooltiptext>Traffic totals per interface for different periods of time.</tooltiptext>
1267
			<section>Status</section>
1268
			<url>/status_traffic_totals.php</url>
1269
		</menu>
1270
		<menu>
1271
			<name>Cron</name>
1272
			<section>Services</section>
1273
			<configfile>cron.xml</configfile>
1274
			<url>/packages/cron/cron.php</url>
1275
		</menu>
1276
		<menu>
1277
			<name>Zabbix Agent 5.0</name>
1278
			<section>Services</section>
1279
			<url>/pkg_edit.php?xml=zabbix-agent.xml&amp;id=0</url>
1280
		</menu>
1281
		<service>
1282
			<name>iperf</name>
1283
			<executable>iperf3</executable>
1284
			<description><![CDATA[iperf Network Performance Testing Daemon/Client]]></description>
1285
			<stopcmd>mwexec(&quot;/usr/bin/killall iperf3&quot;);</stopcmd>
1286
		</service>
1287
		<service>
1288
			<name>vnstatd</name>
1289
			<rcfile>vnstatd.sh</rcfile>
1290
			<executable>vnstatd</executable>
1291
			<description><![CDATA[Status Traffic Totals data collection daemon]]></description>
1292
		</service>
1293
		<service>
1294
			<name>zabbix_agentd</name>
1295
			<rcfile>zabbix_agentd.sh</rcfile>
1296
			<executable>zabbix_agentd</executable>
1297
			<description><![CDATA[Zabbix Agent Host Monitor Daemon]]></description>
1298
		</service>
1299
		<traffictotals>
1300
			<config>
1301
				<enabled></enabled>
1302
				<timeperiod>hour</timeperiod>
1303
				<interfaces>[&quot;vtnet0&quot;,&quot;vtnet1&quot;]</interfaces>
1304
				<graphtype>bar</graphtype>
1305
				<invert>true</invert>
1306
				<cumulative>false</cumulative>
1307
				<startday>1</startday>
1308
			</config>
1309
		</traffictotals>
1310
		<zabbixagentlts>
1311
			<config>
1312
				<agentenabled>on</agentenabled>
1313
				<server>monitor.web.ru</server>
1314
				<serveractive>monitor.web.ru</serveractive>
1315
				<hostname>pfsense-asterisk.itf</hostname>
1316
				<listenip>0.0.0.0</listenip>
1317
				<listenport>10050</listenport>
1318
				<refreshactchecks>120</refreshactchecks>
1319
				<timeout>10</timeout>
1320
				<buffersend>5</buffersend>
1321
				<buffersize>100</buffersize>
1322
				<startagents>0</startagents>
1323
				<tlsconnect>psk</tlsconnect>
1324
				<tlsaccept>psk</tlsaccept>
1325
				<tlscafile>none</tlscafile>
1326
				<tlscaso></tlscaso>
1327
				<tlscrlfile>none</tlscrlfile>
1328
				<tlscertfile>none</tlscertfile>
1329
				<tlspskidentity>01e3589494185035</tlspskidentity>
1330
				<tlspskfile>OGM4MWY0MTZiMmM2ZTgzMWQxYzQ1ODM0OTJjOG2E0YhlOTMwYTZhMjYzMzlkM2U=</tlspskfile>
1331
				<userparams>VW5KRWjQ==</userparams>
1332
			</config>
1333
		</zabbixagentlts>
1334
	</installedpackages>
1335
	<ntpd>
1336
		<interface>lan,lo0</interface>
1337
		<ispool>ru.pool.ntp.org </ispool>
1338
		<orphan></orphan>
1339
		<logsys>yes</logsys>
1340
		<restrictions>
1341
			<row>
1342
				<acl_network>0.0.0.0</acl_network>
1343
				<mask>8</mask>
1344
			</row>
1345
		</restrictions>
1346
	</ntpd>
1347
</pfsense>
    (1-1/1)