Project

General

Profile

Bug #1627 » config-corphq.eyemdemr.com-20110711211921.xml

Abdiel Marin, 07/11/2011 09:23 PM

 
1
<?xml version="1.0"?>
2
<pfsense>
3
	<version>7.9</version>
4
	<lastchange/>
5
	<theme>metallic</theme>
6
	<system>
7
		<optimization>normal</optimization>
8
		<schedulertype>priq</schedulertype>
9
		<hostname>corphq</hostname>
10
		<domain>eyemdemr.com</domain>
11
		<timezone>EST</timezone>
12
		<time-update-interval/>
13
		<timeservers>0.pfsense.pool.ntp.org</timeservers>
14
		<webgui>
15
			<protocol>http</protocol>
16
			<certificate/>
17
			<private-key/>
18
			<port/>
19
			<auth_method>session</auth_method>
20
			<backing_method>htpasswd</backing_method>
21
		</webgui>
22
		<ssh>
23
			<authorizedkeys/>
24
			<port/>
25
		</ssh>
26
		<enablesshd>yes</enablesshd>
27
		<maximumstates/>
28
		<shapertype/>
29
		<group>
30
			<name>admins</name>
31
			<description><![CDATA[System Administrators]]></description>
32
			<scope>user</scope>
33
			<priv>page-all</priv>
34
			<home>index.php</home>
35
			<gid>2000</gid>
36
			<member>0</member>
37
			<member>2000</member>
38
		</group>
39
		<group>
40
			<name>all</name>
41
			<description><![CDATA[All Users]]></description>
42
			<scope>system</scope>
43
			<gid>1998</gid>
44
		</group>
45
		<user>
46
			<name>admin</name>
47
			<descr><![CDATA[System Administrator]]></descr>
48
			<scope>system</scope>
49
			<password>/</password>
50
			<uid>0</uid>
51
			<priv>user-shell-access</priv>
52
			<priv>user-copy-files</priv>
53
		</user>
54
		<user>
55
			<scope>user</scope>
56
			<password></password>
57
			<md5-hash>26ce87de16bd013feba7bc4a7bb26d50</md5-hash>
58
			<nt-hash>33d73b6949f17c86d35ede0da3b16ceb</nt-hash>
59
			<name>admintemp</name>
60
			<descr><![CDATA[admintemp]]></descr>
61
			<expires>06/28/2011</expires>
62
			<authorizedkeys/>
63
			<ipsecpsk/>
64
			<uid>2000</uid>
65
			<disabled/>
66
		</user>
67
		<nextuid>2001</nextuid>
68
		<nextgid>2001</nextgid>
69
		<disablesegmentationoffloading/>
70
		<disablelargereceiveoffloading/>
71
		<gitsync>
72
			<repositoryurl/>
73
			<branch/>
74
		</gitsync>
75
		<dns1gwint>none</dns1gwint>
76
		<dns2gwint>none</dns2gwint>
77
		<dns3gwint>none</dns3gwint>
78
		<dns4gwint>none</dns4gwint>
79
		<firmware>
80
			<allowinvalidsig/>
81
		</firmware>
82
		<dnsserver>208.67.222.222</dnsserver>
83
		<dnsallowoverride/>
84
		<maximumtableentries/>
85
		<enablebinatreflection>yes</enablebinatreflection>
86
		<reflectiontimeout/>
87
	</system>
88
	<interfaces>
89
		<lan>
90
			<if>vr0</if>
91
			<ipaddr>172.16.30.1</ipaddr>
92
			<subnet>24</subnet>
93
			<media/>
94
			<mediaopt/>
95
			<bandwidth>100</bandwidth>
96
			<bandwidthtype>Mb</bandwidthtype>
97
			<enable/>
98
		</lan>
99
		<wan>
100
			<if>vr1</if>
101
			<disableftpproxy/>
102
			<media/>
103
			<mediaopt/>
104
			<bandwidth>100</bandwidth>
105
			<bandwidthtype>Mb</bandwidthtype>
106
			<spoofmac/>
107
			<enable/>
108
			<descr><![CDATA[WAN]]></descr>
109
			<ipaddr>74.118.238.177</ipaddr>
110
			<subnet>29</subnet>
111
			<gateway>GW_WAN</gateway>
112
		</wan>
113
		<opt1>
114
			<descr><![CDATA[OPT1]]></descr>
115
			<if>vr2</if>
116
			<bridge/>
117
			<spoofmac/>
118
			<mtu>1492</mtu>
119
			<enable/>
120
			<ipaddr>69.68.153.131</ipaddr>
121
			<subnet>25</subnet>
122
			<gateway>GW_OPT1</gateway>
123
		</opt1>
124
	</interfaces>
125
	<staticroutes/>
126
	<bigpond>
127
		<username/>
128
		<password/>
129
		<authserver/>
130
		<authdomain/>
131
		<minheartbeatinterval/>
132
	</bigpond>
133
	<dhcpd>
134
		<lan>
135
			<enable/>
136
			<range>
137
				<from>172.16.30.100</from>
138
				<to>172.16.30.245</to>
139
			</range>
140
			<defaultleasetime/>
141
			<maxleasetime/>
142
			<netmask/>
143
			<failover_peerip/>
144
			<gateway/>
145
			<ddnsdomain/>
146
			<next-server/>
147
			<filename/>
148
			<domain/>
149
			<domainsearchlist/>
150
			<tftp/>
151
			<ldap/>
152
			<rootpath/>
153
			<numberoptions/>
154
			<winsserver>172.16.30.10</winsserver>
155
			<dnsserver>172.16.30.10</dnsserver>
156
			<dnsserver>208.67.222.222</dnsserver>
157
		</lan>
158
	</dhcpd>
159
	<pptpd>
160
		<mode>server</mode>
161
		<redir/>
162
		<localip>172.16.30.4</localip>
163
		<remoteip>172.16.30.208</remoteip>
164
		<radius>
165
			<server>
166
				<ip/>
167
				<port/>
168
				<acctport/>
169
				<secret/>
170
			</server>
171
			<secret/>
172
			<server2>
173
				<ip/>
174
				<port/>
175
				<acctport/>
176
				<secret2/>
177
			</server2>
178
			<nasip/>
179
			<acct_update/>
180
		</radius>
181
		<wins/>
182
		<user>
183
			<name>abdiel.marin</name>
184
			<ip/>
185
			<password></password>
186
		</user>
187
		<n_pptp_units>16</n_pptp_units>
188
	</pptpd>
189
	<ovpn/>
190
	<dnsmasq>
191
		<enable/>
192
	</dnsmasq>
193
	<snmpd>
194
		<syslocation/>
195
		<syscontact/>
196
		<rocommunity>public</rocommunity>
197
	</snmpd>
198
	<diag>
199
		<ipv6nat/>
200
	</diag>
201
	<syslog>
202
		<nentries>50</nentries>
203
		<rawfilter/>
204
	</syslog>
205
	<nat>
206
		<ipsecpassthru>
207
			<enable/>
208
		</ipsecpassthru>
209
		<rule>
210
			<protocol>tcp/udp</protocol>
211
			<target>172.16.30.14</target>
212
			<local-port>3390</local-port>
213
			<interface>wan</interface>
214
			<descr><![CDATA[Remote Desktop]]></descr>
215
			<source>
216
				<any/>
217
				<port/>
218
			</source>
219
			<destination>
220
				<port>3390</port>
221
				<network>wanip</network>
222
			</destination>
223
		</rule>
224
		<rule>
225
			<source>
226
				<any/>
227
			</source>
228
			<destination>
229
				<network>wanip</network>
230
				<port>25</port>
231
			</destination>
232
			<protocol>tcp/udp</protocol>
233
			<target>172.16.30.16</target>
234
			<local-port>25</local-port>
235
			<interface>wan</interface>
236
			<descr><![CDATA[SMTP]]></descr>
237
			<associated-rule-id/>
238
		</rule>
239
		<rule>
240
			<source>
241
				<any/>
242
			</source>
243
			<destination>
244
				<network>wanip</network>
245
				<port>80</port>
246
			</destination>
247
			<protocol>tcp</protocol>
248
			<target>172.16.30.18</target>
249
			<local-port>80</local-port>
250
			<interface>wan</interface>
251
			<descr><![CDATA[HTTP]]></descr>
252
			<associated-rule-id/>
253
		</rule>
254
		<rule>
255
			<protocol>tcp</protocol>
256
			<target>172.16.30.16</target>
257
			<local-port>81</local-port>
258
			<interface>wan</interface>
259
			<descr><![CDATA[Sharepoint]]></descr>
260
			<source>
261
				<any/>
262
				<port/>
263
			</source>
264
			<destination>
265
				<port>81</port>
266
				<network>wanip</network>
267
			</destination>
268
		</rule>
269
		<rule>
270
			<protocol>tcp</protocol>
271
			<target>172.16.30.13</target>
272
			<local-port>443</local-port>
273
			<interface>wan</interface>
274
			<descr><![CDATA[HTTPS]]></descr>
275
			<source>
276
				<any/>
277
				<port/>
278
			</source>
279
			<destination>
280
				<port>443</port>
281
				<network>wanip</network>
282
			</destination>
283
		</rule>
284
		<rule>
285
			<protocol>tcp/udp</protocol>
286
			<target>172.16.30.13</target>
287
			<local-port>587</local-port>
288
			<interface>wan</interface>
289
			<descr><![CDATA[SMTP]]></descr>
290
			<source>
291
				<any/>
292
				<port/>
293
			</source>
294
			<destination>
295
				<port>587</port>
296
				<network>wanip</network>
297
			</destination>
298
		</rule>
299
		<rule>
300
			<protocol>tcp</protocol>
301
			<target>172.16.30.13</target>
302
			<local-port>995</local-port>
303
			<interface>wan</interface>
304
			<descr><![CDATA[POP3TLS]]></descr>
305
			<source>
306
				<any/>
307
				<port/>
308
			</source>
309
			<destination>
310
				<port>995</port>
311
				<network>wanip</network>
312
			</destination>
313
		</rule>
314
		<rule>
315
			<protocol>tcp/udp</protocol>
316
			<target>172.16.30.16</target>
317
			<local-port>21</local-port>
318
			<interface>wan</interface>
319
			<descr><![CDATA[FTP]]></descr>
320
			<source>
321
				<any/>
322
				<port/>
323
			</source>
324
			<destination>
325
				<port>21</port>
326
				<network>wanip</network>
327
			</destination>
328
		</rule>
329
		<rule>
330
			<protocol>tcp/udp</protocol>
331
			<target>172.16.30.14</target>
332
			<local-port>3390</local-port>
333
			<interface>opt1</interface>
334
			<descr><![CDATA[Remote Desktop]]></descr>
335
			<source>
336
				<any/>
337
				<port/>
338
			</source>
339
			<destination>
340
				<port>3390</port>
341
				<network>opt1ip</network>
342
			</destination>
343
		</rule>
344
		<rule>
345
			<protocol>tcp/udp</protocol>
346
			<target>172.16.30.20</target>
347
			<local-port>5050</local-port>
348
			<interface>opt1</interface>
349
			<descr><![CDATA[VOIP SIP]]></descr>
350
			<source>
351
				<any/>
352
				<port/>
353
			</source>
354
			<destination>
355
				<port>5050-5080</port>
356
				<network>opt1ip</network>
357
			</destination>
358
		</rule>
359
		<rule>
360
			<protocol>udp</protocol>
361
			<target>172.16.30.20</target>
362
			<local-port>10000</local-port>
363
			<interface>opt1</interface>
364
			<descr><![CDATA[VOIP RTP]]></descr>
365
			<source>
366
				<any/>
367
				<port/>
368
			</source>
369
			<destination>
370
				<port>10000-20000</port>
371
				<network>opt1ip</network>
372
			</destination>
373
		</rule>
374
		<rule>
375
			<protocol>tcp</protocol>
376
			<target>172.16.30.20</target>
377
			<local-port>5038</local-port>
378
			<interface>opt1</interface>
379
			<descr><![CDATA[VOIP TAPI]]></descr>
380
			<source>
381
				<any/>
382
				<port/>
383
			</source>
384
			<destination>
385
				<port>5038</port>
386
				<network>opt1ip</network>
387
			</destination>
388
		</rule>
389
		<rule>
390
			<protocol>tcp</protocol>
391
			<target>172.16.30.20</target>
392
			<local-port>5222</local-port>
393
			<interface>opt1</interface>
394
			<descr><![CDATA[VOIP IM]]></descr>
395
			<source>
396
				<any/>
397
				<port/>
398
			</source>
399
			<destination>
400
				<port>5222</port>
401
				<network>opt1ip</network>
402
			</destination>
403
		</rule>
404
		<rule>
405
			<protocol>tcp/udp</protocol>
406
			<target>172.16.30.16</target>
407
			<local-port>25</local-port>
408
			<interface>opt1</interface>
409
			<descr><![CDATA[SMTP]]></descr>
410
			<source>
411
				<any/>
412
				<port/>
413
			</source>
414
			<destination>
415
				<port>25</port>
416
				<network>opt1ip</network>
417
			</destination>
418
		</rule>
419
		<rule>
420
			<protocol>tcp</protocol>
421
			<target>172.16.30.16</target>
422
			<local-port>80</local-port>
423
			<interface>opt1</interface>
424
			<descr><![CDATA[HTTP]]></descr>
425
			<source>
426
				<any/>
427
				<port/>
428
			</source>
429
			<destination>
430
				<port>80</port>
431
				<network>opt1ip</network>
432
			</destination>
433
		</rule>
434
		<rule>
435
			<protocol>tcp</protocol>
436
			<target>172.16.30.16</target>
437
			<local-port>81</local-port>
438
			<interface>opt1</interface>
439
			<descr><![CDATA[Sharepoint]]></descr>
440
			<source>
441
				<any/>
442
				<port/>
443
			</source>
444
			<destination>
445
				<port>81</port>
446
				<network>opt1ip</network>
447
			</destination>
448
		</rule>
449
		<rule>
450
			<protocol>tcp</protocol>
451
			<target>172.16.30.13</target>
452
			<local-port>443</local-port>
453
			<interface>opt1</interface>
454
			<descr><![CDATA[HTTPS]]></descr>
455
			<source>
456
				<any/>
457
				<port/>
458
			</source>
459
			<destination>
460
				<port>443</port>
461
				<network>opt1ip</network>
462
			</destination>
463
		</rule>
464
		<rule>
465
			<protocol>tcp/udp</protocol>
466
			<target>172.16.30.13</target>
467
			<local-port>587</local-port>
468
			<interface>opt1</interface>
469
			<descr><![CDATA[SMTP]]></descr>
470
			<source>
471
				<any/>
472
				<port/>
473
			</source>
474
			<destination>
475
				<port>587</port>
476
				<network>opt1ip</network>
477
			</destination>
478
		</rule>
479
		<rule>
480
			<protocol>tcp</protocol>
481
			<target>172.16.30.13</target>
482
			<local-port>995</local-port>
483
			<interface>opt1</interface>
484
			<descr><![CDATA[POP3TLS]]></descr>
485
			<source>
486
				<any/>
487
				<port/>
488
			</source>
489
			<destination>
490
				<port>995</port>
491
				<network>opt1ip</network>
492
			</destination>
493
		</rule>
494
		<rule>
495
			<protocol>tcp/udp</protocol>
496
			<target>172.16.30.16</target>
497
			<local-port>21</local-port>
498
			<interface>opt1</interface>
499
			<descr><![CDATA[FTP]]></descr>
500
			<source>
501
				<any/>
502
				<port/>
503
			</source>
504
			<destination>
505
				<port>21</port>
506
				<network>opt1ip</network>
507
			</destination>
508
		</rule>
509
		<rule>
510
			<protocol>tcp/udp</protocol>
511
			<target>172.16.30.17</target>
512
			<local-port>3391</local-port>
513
			<interface>wan</interface>
514
			<descr><![CDATA[Remote Desktop Demo]]></descr>
515
			<source>
516
				<any/>
517
				<port/>
518
			</source>
519
			<destination>
520
				<port>3391</port>
521
				<network>wanip</network>
522
			</destination>
523
		</rule>
524
		<rule>
525
			<protocol>tcp/udp</protocol>
526
			<target>172.16.30.17</target>
527
			<local-port>3391</local-port>
528
			<interface>opt1</interface>
529
			<descr><![CDATA[Remote Desktop Demo]]></descr>
530
			<source>
531
				<any/>
532
				<port/>
533
			</source>
534
			<destination>
535
				<port>3391</port>
536
				<network>opt1ip</network>
537
			</destination>
538
		</rule>
539
		<onetoone>
540
			<external>74.118.238.178</external>
541
			<descr><![CDATA[VOIP Server]]></descr>
542
			<interface>wan</interface>
543
			<source>
544
				<address>172.16.30.20</address>
545
			</source>
546
			<destination>
547
				<any/>
548
			</destination>
549
		</onetoone>
550
		<onetoone>
551
			<external>74.118.238.179</external>
552
			<descr><![CDATA[Web Server]]></descr>
553
			<interface>wan</interface>
554
			<source>
555
				<address>172.16.30.16</address>
556
			</source>
557
			<destination>
558
				<any/>
559
			</destination>
560
		</onetoone>
561
	</nat>
562
	<filter>
563
		<rule>
564
			<id/>
565
			<type>match</type>
566
			<tag/>
567
			<tagged/>
568
			<direction>any</direction>
569
			<floating>yes</floating>
570
			<max/>
571
			<max-src-nodes/>
572
			<max-src-conn/>
573
			<max-src-states/>
574
			<statetimeout/>
575
			<statetype>keep state</statetype>
576
			<os/>
577
			<protocol>udp</protocol>
578
			<source>
579
				<any/>
580
			</source>
581
			<destination>
582
				<any/>
583
				<port>10000-20000</port>
584
			</destination>
585
			<descr><![CDATA[VOIP]]></descr>
586
			<defaultqueue>VOIP</defaultqueue>
587
		</rule>
588
		<rule>
589
			<id/>
590
			<type>match</type>
591
			<tag/>
592
			<tagged/>
593
			<direction>any</direction>
594
			<floating>yes</floating>
595
			<max/>
596
			<max-src-nodes/>
597
			<max-src-conn/>
598
			<max-src-states/>
599
			<statetimeout/>
600
			<statetype>keep state</statetype>
601
			<os/>
602
			<protocol>udp</protocol>
603
			<source>
604
				<any/>
605
				<port>10000-20000</port>
606
			</source>
607
			<destination>
608
				<any/>
609
			</destination>
610
			<descr><![CDATA[VOIP]]></descr>
611
			<defaultqueue>VOIP</defaultqueue>
612
		</rule>
613
		<rule>
614
			<type>pass</type>
615
			<interface>wan</interface>
616
			<max-src-nodes/>
617
			<max-src-states/>
618
			<statetimeout/>
619
			<statetype>keep state</statetype>
620
			<os/>
621
			<protocol>tcp</protocol>
622
			<source>
623
				<any/>
624
			</source>
625
			<destination>
626
				<address>172.16.30.16</address>
627
				<port>80</port>
628
			</destination>
629
			<descr><![CDATA[NAT HTTP]]></descr>
630
		</rule>
631
		<rule>
632
			<id/>
633
			<type>pass</type>
634
			<interface>wan</interface>
635
			<tag/>
636
			<tagged/>
637
			<max/>
638
			<max-src-nodes/>
639
			<max-src-conn/>
640
			<max-src-states/>
641
			<statetimeout/>
642
			<statetype>keep state</statetype>
643
			<os/>
644
			<protocol>tcp</protocol>
645
			<source>
646
				<any/>
647
			</source>
648
			<destination>
649
				<address>172.16.30.16</address>
650
				<port>443</port>
651
			</destination>
652
			<descr><![CDATA[MyEyeCareRecord.com]]></descr>
653
		</rule>
654
		<rule>
655
			<id/>
656
			<type>pass</type>
657
			<interface>wan</interface>
658
			<tag/>
659
			<tagged/>
660
			<max/>
661
			<max-src-nodes/>
662
			<max-src-conn/>
663
			<max-src-states/>
664
			<statetimeout/>
665
			<statetype>keep state</statetype>
666
			<os/>
667
			<protocol>tcp</protocol>
668
			<source>
669
				<any/>
670
			</source>
671
			<destination>
672
				<address>172.16.30.18</address>
673
				<port>80</port>
674
			</destination>
675
			<descr><![CDATA[NAT HTTP Backup]]></descr>
676
		</rule>
677
		<rule>
678
			<id/>
679
			<type>pass</type>
680
			<interface>wan</interface>
681
			<tag/>
682
			<tagged/>
683
			<max/>
684
			<max-src-nodes/>
685
			<max-src-conn/>
686
			<max-src-states/>
687
			<statetimeout/>
688
			<statetype>keep state</statetype>
689
			<os/>
690
			<protocol>tcp</protocol>
691
			<source>
692
				<any/>
693
			</source>
694
			<destination>
695
				<address>172.16.30.20</address>
696
				<port>10000</port>
697
			</destination>
698
			<descr><![CDATA[VOIP HTTP DNS FAIL CHECK]]></descr>
699
		</rule>
700
		<rule>
701
			<id/>
702
			<type>pass</type>
703
			<interface>wan</interface>
704
			<tag/>
705
			<tagged/>
706
			<max/>
707
			<max-src-nodes/>
708
			<max-src-conn/>
709
			<max-src-states/>
710
			<statetimeout/>
711
			<statetype>keep state</statetype>
712
			<os/>
713
			<protocol>udp</protocol>
714
			<source>
715
				<any/>
716
			</source>
717
			<destination>
718
				<address>172.16.30.20</address>
719
				<port>10000-20000</port>
720
			</destination>
721
			<descr><![CDATA[NAT VOIP RTP]]></descr>
722
		</rule>
723
		<rule>
724
			<id/>
725
			<type>pass</type>
726
			<interface>wan</interface>
727
			<tag/>
728
			<tagged/>
729
			<max/>
730
			<max-src-nodes/>
731
			<max-src-conn/>
732
			<max-src-states/>
733
			<statetimeout/>
734
			<statetype>keep state</statetype>
735
			<os/>
736
			<protocol>udp</protocol>
737
			<source>
738
				<any/>
739
			</source>
740
			<destination>
741
				<address>172.16.30.20</address>
742
				<port>5004-5082</port>
743
			</destination>
744
			<descr><![CDATA[NAT VOIP SIP]]></descr>
745
		</rule>
746
		<rule>
747
			<interface>wan</interface>
748
			<protocol>udp</protocol>
749
			<source>
750
				<any/>
751
			</source>
752
			<destination>
753
				<address>172.16.30.20</address>
754
				<port>5038</port>
755
			</destination>
756
			<descr><![CDATA[NAT VOIP TAPI]]></descr>
757
		</rule>
758
		<rule>
759
			<interface>wan</interface>
760
			<protocol>tcp</protocol>
761
			<source>
762
				<any/>
763
			</source>
764
			<destination>
765
				<address>172.16.30.20</address>
766
				<port>5222</port>
767
			</destination>
768
			<descr><![CDATA[NAT VOIP IM]]></descr>
769
		</rule>
770
		<rule>
771
			<interface>wan</interface>
772
			<protocol>tcp</protocol>
773
			<source>
774
				<any/>
775
			</source>
776
			<destination>
777
				<address>172.16.30.16</address>
778
				<port>25</port>
779
			</destination>
780
			<descr><![CDATA[NAT SMTP]]></descr>
781
		</rule>
782
		<rule>
783
			<interface>wan</interface>
784
			<protocol>tcp</protocol>
785
			<source>
786
				<any/>
787
			</source>
788
			<destination>
789
				<address>172.16.30.13</address>
790
				<port>443</port>
791
			</destination>
792
			<descr><![CDATA[NAT HTTPS]]></descr>
793
		</rule>
794
		<rule>
795
			<interface>wan</interface>
796
			<protocol>tcp</protocol>
797
			<source>
798
				<any/>
799
			</source>
800
			<destination>
801
				<address>172.16.30.16</address>
802
				<port>1723</port>
803
			</destination>
804
			<descr><![CDATA[NAT PPTP]]></descr>
805
		</rule>
806
		<rule>
807
			<interface>wan</interface>
808
			<protocol>udp</protocol>
809
			<source>
810
				<any/>
811
			</source>
812
			<destination>
813
				<address>172.16.30.20</address>
814
				<port>5050-5080</port>
815
			</destination>
816
			<descr><![CDATA[NAT VOIP SIP]]></descr>
817
		</rule>
818
		<rule>
819
			<interface>wan</interface>
820
			<protocol>tcp</protocol>
821
			<source>
822
				<any/>
823
			</source>
824
			<destination>
825
				<address>172.16.30.16</address>
826
				<port>81</port>
827
			</destination>
828
			<descr><![CDATA[NAT Sharepoint]]></descr>
829
		</rule>
830
		<rule>
831
			<interface>wan</interface>
832
			<protocol>tcp</protocol>
833
			<source>
834
				<any/>
835
			</source>
836
			<destination>
837
				<address>172.16.30.13</address>
838
				<port>443</port>
839
			</destination>
840
			<descr><![CDATA[NAT HTTPS]]></descr>
841
		</rule>
842
		<rule>
843
			<interface>wan</interface>
844
			<protocol>tcp</protocol>
845
			<source>
846
				<any/>
847
			</source>
848
			<destination>
849
				<address>172.16.30.13</address>
850
				<port>587</port>
851
			</destination>
852
			<descr><![CDATA[NAT SMTP]]></descr>
853
		</rule>
854
		<rule>
855
			<interface>wan</interface>
856
			<protocol>tcp</protocol>
857
			<source>
858
				<any/>
859
			</source>
860
			<destination>
861
				<address>172.16.30.13</address>
862
				<port>995</port>
863
			</destination>
864
			<descr><![CDATA[NAT POP3TLS]]></descr>
865
		</rule>
866
		<rule>
867
			<interface>wan</interface>
868
			<protocol>tcp/udp</protocol>
869
			<source>
870
				<any/>
871
			</source>
872
			<destination>
873
				<address>172.16.30.16</address>
874
				<port>21</port>
875
			</destination>
876
			<descr><![CDATA[NAT FTP]]></descr>
877
		</rule>
878
		<rule>
879
			<type>pass</type>
880
			<interface>wan</interface>
881
			<max-src-nodes/>
882
			<max-src-states/>
883
			<statetimeout/>
884
			<statetype>keep state</statetype>
885
			<os/>
886
			<protocol>tcp/udp</protocol>
887
			<source>
888
				<any/>
889
			</source>
890
			<destination>
891
				<address>172.16.30.14</address>
892
				<port>3390</port>
893
			</destination>
894
			<descr><![CDATA[Remote Desktop]]></descr>
895
		</rule>
896
		<rule>
897
			<type>pass</type>
898
			<interface>wan</interface>
899
			<max-src-nodes/>
900
			<max-src-states/>
901
			<statetimeout/>
902
			<statetype>keep state</statetype>
903
			<os/>
904
			<protocol>tcp/udp</protocol>
905
			<source>
906
				<any/>
907
			</source>
908
			<destination>
909
				<address>172.16.30.17</address>
910
				<port>3391</port>
911
			</destination>
912
			<descr><![CDATA[Remote Desktop Demo]]></descr>
913
		</rule>
914
		<rule>
915
			<interface>wan</interface>
916
			<protocol>tcp/udp</protocol>
917
			<source>
918
				<any/>
919
			</source>
920
			<destination>
921
				<address>172.16.30.20</address>
922
				<port>4569</port>
923
			</destination>
924
			<descr><![CDATA[NAT VOIP IAX]]></descr>
925
		</rule>
926
		<rule>
927
			<type>block</type>
928
			<interface>lan</interface>
929
			<max-src-nodes/>
930
			<max-src-states/>
931
			<statetimeout/>
932
			<statetype>keep state</statetype>
933
			<os/>
934
			<protocol>tcp</protocol>
935
			<source>
936
				<any/>
937
			</source>
938
			<destination>
939
				<any/>
940
				<port>53</port>
941
			</destination>
942
			<descr/>
943
		</rule>
944
		<rule>
945
			<id/>
946
			<type>pass</type>
947
			<interface>lan</interface>
948
			<tag/>
949
			<tagged/>
950
			<max/>
951
			<max-src-nodes/>
952
			<max-src-conn/>
953
			<max-src-states/>
954
			<statetimeout/>
955
			<statetype>keep state</statetype>
956
			<os/>
957
			<protocol>tcp</protocol>
958
			<source>
959
				<any/>
960
			</source>
961
			<destination>
962
				<address>208.67.222.222</address>
963
				<port>53</port>
964
			</destination>
965
			<descr/>
966
			<gateway>USMetro_Failover</gateway>
967
		</rule>
968
		<rule>
969
			<id/>
970
			<type>pass</type>
971
			<interface>lan</interface>
972
			<tag/>
973
			<tagged/>
974
			<max/>
975
			<max-src-nodes/>
976
			<max-src-conn/>
977
			<max-src-states/>
978
			<statetimeout/>
979
			<statetype>keep state</statetype>
980
			<os/>
981
			<protocol>tcp</protocol>
982
			<source>
983
				<any/>
984
			</source>
985
			<destination>
986
				<address>208.67.220.220</address>
987
				<port>53</port>
988
			</destination>
989
			<descr/>
990
			<gateway>USMetro_Failover</gateway>
991
		</rule>
992
		<rule>
993
			<id/>
994
			<type>pass</type>
995
			<interface>lan</interface>
996
			<tag/>
997
			<tagged/>
998
			<max/>
999
			<max-src-nodes/>
1000
			<max-src-conn/>
1001
			<max-src-states/>
1002
			<statetimeout/>
1003
			<statetype>keep state</statetype>
1004
			<os/>
1005
			<source>
1006
				<network>lan</network>
1007
			</source>
1008
			<destination>
1009
				<any/>
1010
			</destination>
1011
			<descr><![CDATA[Default LAN -&gt; any]]></descr>
1012
			<gateway>USMetro_Failover</gateway>
1013
		</rule>
1014
		<rule>
1015
			<type>pass</type>
1016
			<interface>enc0</interface>
1017
			<max-src-nodes/>
1018
			<max-src-states/>
1019
			<statetimeout/>
1020
			<statetype>keep state</statetype>
1021
			<os/>
1022
			<source>
1023
				<any/>
1024
			</source>
1025
			<destination>
1026
				<any/>
1027
			</destination>
1028
			<descr/>
1029
		</rule>
1030
		<rule>
1031
			<id/>
1032
			<type>pass</type>
1033
			<interface>enc0</interface>
1034
			<tag/>
1035
			<tagged/>
1036
			<max/>
1037
			<max-src-nodes/>
1038
			<max-src-conn/>
1039
			<max-src-states/>
1040
			<statetimeout/>
1041
			<statetype>keep state</statetype>
1042
			<os/>
1043
			<protocol>tcp/udp</protocol>
1044
			<source>
1045
				<any/>
1046
			</source>
1047
			<destination>
1048
				<any/>
1049
				<port>10000-20000</port>
1050
			</destination>
1051
			<descr><![CDATA[VOIP RTP]]></descr>
1052
			<defaultqueue>VOIP</defaultqueue>
1053
		</rule>
1054
		<rule>
1055
			<interface>opt1</interface>
1056
			<protocol>tcp/udp</protocol>
1057
			<source>
1058
				<any/>
1059
			</source>
1060
			<destination>
1061
				<address>172.16.30.14</address>
1062
				<port>3390</port>
1063
			</destination>
1064
			<descr><![CDATA[NAT Remote Desktop]]></descr>
1065
		</rule>
1066
		<rule>
1067
			<id/>
1068
			<type>pass</type>
1069
			<interface>opt1</interface>
1070
			<tag/>
1071
			<tagged/>
1072
			<max/>
1073
			<max-src-nodes/>
1074
			<max-src-conn/>
1075
			<max-src-states/>
1076
			<statetimeout/>
1077
			<statetype>keep state</statetype>
1078
			<os/>
1079
			<protocol>tcp/udp</protocol>
1080
			<source>
1081
				<any/>
1082
			</source>
1083
			<destination>
1084
				<address>172.16.30.20</address>
1085
				<port>5050-5080</port>
1086
			</destination>
1087
			<descr><![CDATA[NAT VOIP SIP]]></descr>
1088
		</rule>
1089
		<rule>
1090
			<id/>
1091
			<type>pass</type>
1092
			<interface>opt1</interface>
1093
			<tag/>
1094
			<tagged/>
1095
			<max/>
1096
			<max-src-nodes/>
1097
			<max-src-conn/>
1098
			<max-src-states/>
1099
			<statetimeout/>
1100
			<statetype>keep state</statetype>
1101
			<os/>
1102
			<protocol>udp</protocol>
1103
			<source>
1104
				<any/>
1105
			</source>
1106
			<destination>
1107
				<address>172.16.30.20</address>
1108
				<port>10000-20000</port>
1109
			</destination>
1110
			<descr><![CDATA[NAT VOIP RTP]]></descr>
1111
		</rule>
1112
		<rule>
1113
			<interface>opt1</interface>
1114
			<protocol>tcp</protocol>
1115
			<source>
1116
				<any/>
1117
			</source>
1118
			<destination>
1119
				<address>172.16.30.20</address>
1120
				<port>5038</port>
1121
			</destination>
1122
			<descr><![CDATA[NAT VOIP TAPI]]></descr>
1123
		</rule>
1124
		<rule>
1125
			<interface>opt1</interface>
1126
			<protocol>tcp</protocol>
1127
			<source>
1128
				<any/>
1129
			</source>
1130
			<destination>
1131
				<address>172.16.30.20</address>
1132
				<port>5222</port>
1133
			</destination>
1134
			<descr><![CDATA[NAT VOIP IM]]></descr>
1135
		</rule>
1136
		<rule>
1137
			<interface>opt1</interface>
1138
			<protocol>tcp/udp</protocol>
1139
			<source>
1140
				<any/>
1141
			</source>
1142
			<destination>
1143
				<address>172.16.30.16</address>
1144
				<port>25</port>
1145
			</destination>
1146
			<descr><![CDATA[NAT SMTP]]></descr>
1147
		</rule>
1148
		<rule>
1149
			<interface>opt1</interface>
1150
			<protocol>tcp</protocol>
1151
			<source>
1152
				<any/>
1153
			</source>
1154
			<destination>
1155
				<address>172.16.30.16</address>
1156
				<port>80</port>
1157
			</destination>
1158
			<descr><![CDATA[NAT HTTP]]></descr>
1159
		</rule>
1160
		<rule>
1161
			<interface>opt1</interface>
1162
			<protocol>tcp</protocol>
1163
			<source>
1164
				<any/>
1165
			</source>
1166
			<destination>
1167
				<address>172.16.30.16</address>
1168
				<port>1723</port>
1169
			</destination>
1170
			<descr><![CDATA[NAT PPTP]]></descr>
1171
		</rule>
1172
		<rule>
1173
			<interface>opt1</interface>
1174
			<protocol>tcp</protocol>
1175
			<source>
1176
				<any/>
1177
			</source>
1178
			<destination>
1179
				<address>172.16.30.16</address>
1180
				<port>81</port>
1181
			</destination>
1182
			<descr><![CDATA[NAT Sharepoint]]></descr>
1183
		</rule>
1184
		<rule>
1185
			<interface>opt1</interface>
1186
			<protocol>tcp</protocol>
1187
			<source>
1188
				<any/>
1189
			</source>
1190
			<destination>
1191
				<address>172.16.30.13</address>
1192
				<port>443</port>
1193
			</destination>
1194
			<descr><![CDATA[NAT HTTPS]]></descr>
1195
		</rule>
1196
		<rule>
1197
			<interface>opt1</interface>
1198
			<protocol>tcp/udp</protocol>
1199
			<source>
1200
				<any/>
1201
			</source>
1202
			<destination>
1203
				<address>172.16.30.13</address>
1204
				<port>587</port>
1205
			</destination>
1206
			<descr><![CDATA[NAT SMTP]]></descr>
1207
		</rule>
1208
		<rule>
1209
			<interface>opt1</interface>
1210
			<protocol>tcp</protocol>
1211
			<source>
1212
				<any/>
1213
			</source>
1214
			<destination>
1215
				<address>172.16.30.13</address>
1216
				<port>995</port>
1217
			</destination>
1218
			<descr><![CDATA[NAT POP3TLS]]></descr>
1219
		</rule>
1220
		<rule>
1221
			<interface>opt1</interface>
1222
			<protocol>tcp/udp</protocol>
1223
			<source>
1224
				<any/>
1225
			</source>
1226
			<destination>
1227
				<address>172.16.30.16</address>
1228
				<port>21</port>
1229
			</destination>
1230
			<descr><![CDATA[NAT FTP]]></descr>
1231
		</rule>
1232
		<rule>
1233
			<interface>opt1</interface>
1234
			<protocol>tcp/udp</protocol>
1235
			<source>
1236
				<any/>
1237
			</source>
1238
			<destination>
1239
				<network>wanip</network>
1240
				<port>21</port>
1241
			</destination>
1242
			<descr><![CDATA[NAT FTP]]></descr>
1243
		</rule>
1244
		<rule>
1245
			<interface>opt1</interface>
1246
			<protocol>tcp/udp</protocol>
1247
			<source>
1248
				<any/>
1249
			</source>
1250
			<destination>
1251
				<address>172.16.30.17</address>
1252
				<port>3391</port>
1253
			</destination>
1254
			<descr><![CDATA[NAT Remote Desktop Demo]]></descr>
1255
		</rule>
1256
		<rule>
1257
			<type>pass</type>
1258
			<interface>pptp</interface>
1259
			<max-src-nodes/>
1260
			<max-src-states/>
1261
			<statetimeout/>
1262
			<statetype>keep state</statetype>
1263
			<os/>
1264
			<source>
1265
				<any/>
1266
			</source>
1267
			<destination>
1268
				<any/>
1269
			</destination>
1270
			<descr/>
1271
		</rule>
1272
	</filter>
1273
	<ipsec>
1274
		<preferredoldsa/>
1275
		<enable/>
1276
		<phase1>
1277
			<ikeid>1</ikeid>
1278
			<interface>wan</interface>
1279
			<remote-gateway>99.99.99.99</remote-gateway>
1280
			<mode>aggressive</mode>
1281
			<myid_type>myaddress</myid_type>
1282
			<myid_data/>
1283
			<peerid_type>peeraddress</peerid_type>
1284
			<peerid_data/>
1285
			<encryption-algorithm>
1286
				<name>3des</name>
1287
			</encryption-algorithm>
1288
			<hash-algorithm>md5</hash-algorithm>
1289
			<dhgroup>2</dhgroup>
1290
			<lifetime>28800</lifetime>
1291
			<pre-shared-key>key</pre-shared-key>
1292
			<private-key/>
1293
			<certref/>
1294
			<caref/>
1295
			<authentication_method>pre_shared_key</authentication_method>
1296
			<generate_policy/>
1297
			<proposal_check/>
1298
			<descr><![CDATA[HOMEOFFICE]]></descr>
1299
			<nat_traversal>on</nat_traversal>
1300
			<dpd_delay>10</dpd_delay>
1301
			<dpd_maxfail>5</dpd_maxfail>
1302
		</phase1>
1303
		<phase1>
1304
			<ikeid>2</ikeid>
1305
			<interface>wan</interface>
1306
			<remote-gateway>eyemdblakedorion.dyndns.org</remote-gateway>
1307
			<mode>main</mode>
1308
			<myid_type>myaddress</myid_type>
1309
			<myid_data/>
1310
			<peerid_type>peeraddress</peerid_type>
1311
			<peerid_data/>
1312
			<encryption-algorithm>
1313
				<name>3des</name>
1314
			</encryption-algorithm>
1315
			<hash-algorithm>md5</hash-algorithm>
1316
			<dhgroup>2</dhgroup>
1317
			<lifetime>28800</lifetime>
1318
			<pre-shared-key>key</pre-shared-key>
1319
			<private-key/>
1320
			<certref/>
1321
			<caref/>
1322
			<authentication_method>pre_shared_key</authentication_method>
1323
			<proposal_check/>
1324
			<descr><![CDATA[BLAKEDORIO]]></descr>
1325
			<nat_traversal>on</nat_traversal>
1326
			<dpd_delay>10</dpd_delay>
1327
			<dpd_maxfail>5</dpd_maxfail>
1328
		</phase1>
1329
		<phase1>
1330
			<ikeid>3</ikeid>
1331
			<interface>wan</interface>
1332
			<remote-gateway>eyemddanabisset.dyndns.org</remote-gateway>
1333
			<mode>main</mode>
1334
			<myid_type>myaddress</myid_type>
1335
			<myid_data/>
1336
			<peerid_type>peeraddress</peerid_type>
1337
			<peerid_data/>
1338
			<encryption-algorithm>
1339
				<name>3des</name>
1340
			</encryption-algorithm>
1341
			<hash-algorithm>md5</hash-algorithm>
1342
			<dhgroup>2</dhgroup>
1343
			<lifetime>28800</lifetime>
1344
			<pre-shared-key>key</pre-shared-key>
1345
			<private-key/>
1346
			<certref/>
1347
			<caref/>
1348
			<authentication_method>pre_shared_key</authentication_method>
1349
			<generate_policy/>
1350
			<proposal_check/>
1351
			<descr><![CDATA[DANABISSET]]></descr>
1352
			<nat_traversal>on</nat_traversal>
1353
			<dpd_delay>10</dpd_delay>
1354
			<dpd_maxfail>5</dpd_maxfail>
1355
		</phase1>
1356
		<phase1>
1357
			<ikeid>4</ikeid>
1358
			<interface>wan</interface>
1359
			<remote-gateway>eyemdgsavloff.dyndns.org</remote-gateway>
1360
			<descr><![CDATA[GSAVLOFF]]></descr>
1361
			<mode>main</mode>
1362
			<myid_type>myaddress</myid_type>
1363
			<peerid_type>peeraddress</peerid_type>
1364
			<encryption-algorithm>
1365
				<name>3des</name>
1366
			</encryption-algorithm>
1367
			<hash-algorithm>md5</hash-algorithm>
1368
			<dhgroup>2</dhgroup>
1369
			<lifetime>28800</lifetime>
1370
			<authentication_method>pre_shared_key</authentication_method>
1371
			<pre-shared-key>key</pre-shared-key>
1372
			<peercert/>
1373
			<private-key/>
1374
			<nat_traversal>on</nat_traversal>
1375
			<dpd_enable>1</dpd_enable>
1376
			<dpd_delay>10</dpd_delay>
1377
			<dpd_maxfail>5</dpd_maxfail>
1378
			<certref>4d71a1422b1e4</certref>
1379
		</phase1>
1380
		<phase2>
1381
			<ikeid>1</ikeid>
1382
			<mode>tunnel</mode>
1383
			<localid>
1384
				<type>lan</type>
1385
			</localid>
1386
			<remoteid>
1387
				<type>network</type>
1388
				<address>172.16.35.0</address>
1389
				<netbits>24</netbits>
1390
			</remoteid>
1391
			<protocol>esp</protocol>
1392
			<encryption-algorithm-option>
1393
				<name>3des</name>
1394
			</encryption-algorithm-option>
1395
			<hash-algorithm-option>hmac_md5</hash-algorithm-option>
1396
			<pfsgroup>2</pfsgroup>
1397
			<lifetime>3600</lifetime>
1398
			<pinghost>172.16.35.1</pinghost>
1399
			<descr><![CDATA[phase2 for HOMEOFFICE]]></descr>
1400
		</phase2>
1401
		<phase2>
1402
			<ikeid>2</ikeid>
1403
			<descr><![CDATA[phase2 for BLAKEDORIO]]></descr>
1404
			<localid>
1405
				<type>lan</type>
1406
			</localid>
1407
			<remoteid>
1408
				<type>network</type>
1409
				<address>172.16.36.0</address>
1410
				<netbits>24</netbits>
1411
			</remoteid>
1412
			<protocol>esp</protocol>
1413
			<encryption-algorithm-option>
1414
				<name>3des</name>
1415
			</encryption-algorithm-option>
1416
			<hash-algorithm-option>hmac_md5</hash-algorithm-option>
1417
			<pfsgroup>2</pfsgroup>
1418
			<lifetime>3600</lifetime>
1419
			<pinghost>172.16.36.1</pinghost>
1420
			<mode>tunnel</mode>
1421
		</phase2>
1422
		<phase2>
1423
			<ikeid>3</ikeid>
1424
			<mode>tunnel</mode>
1425
			<localid>
1426
				<type>lan</type>
1427
			</localid>
1428
			<remoteid>
1429
				<type>network</type>
1430
				<address>172.16.38.0</address>
1431
				<netbits>24</netbits>
1432
			</remoteid>
1433
			<protocol>esp</protocol>
1434
			<encryption-algorithm-option>
1435
				<name>3des</name>
1436
			</encryption-algorithm-option>
1437
			<hash-algorithm-option>hmac_md5</hash-algorithm-option>
1438
			<pfsgroup>2</pfsgroup>
1439
			<lifetime>3600</lifetime>
1440
			<pinghost>172.16.38.1</pinghost>
1441
			<descr><![CDATA[phase2 for DANABISSET]]></descr>
1442
		</phase2>
1443
		<phase2>
1444
			<ikeid>4</ikeid>
1445
			<descr><![CDATA[phase2 for GSAVLOFF]]></descr>
1446
			<localid>
1447
				<type>lan</type>
1448
			</localid>
1449
			<remoteid>
1450
				<type>network</type>
1451
				<address>172.16.37.0</address>
1452
				<netbits>24</netbits>
1453
			</remoteid>
1454
			<protocol>esp</protocol>
1455
			<encryption-algorithm-option>
1456
				<name>3des</name>
1457
			</encryption-algorithm-option>
1458
			<hash-algorithm-option>hmac_md5</hash-algorithm-option>
1459
			<pfsgroup>2</pfsgroup>
1460
			<lifetime>3600</lifetime>
1461
			<pinghost>172.16.37.1</pinghost>
1462
			<mode>tunnel</mode>
1463
		</phase2>
1464
		<client/>
1465
	</ipsec>
1466
	<aliases>
1467
		<alias>
1468
			<name>VOIPSERVER</name>
1469
			<address>172.16.30.20</address>
1470
			<descr/>
1471
			<type>host</type>
1472
			<detail><![CDATA[Entry added Thu, 10 Mar 2011 21:19:50 -0500]]></detail>
1473
		</alias>
1474
	</aliases>
1475
	<proxyarp/>
1476
	<wol>
1477
		<wolentry>
1478
			<interface>lan</interface>
1479
			<mac>00:30:48:f9:b6:c1</mac>
1480
			<descr><![CDATA[EYEMDFILESERVER]]></descr>
1481
		</wolentry>
1482
		<wolentry>
1483
			<interface>lan</interface>
1484
			<mac>00:22:19:f3:e4:77</mac>
1485
			<descr><![CDATA[XTECHDEV1]]></descr>
1486
		</wolentry>
1487
	</wol>
1488
	<cron>
1489
		<item>
1490
			<minute>0</minute>
1491
			<hour>*</hour>
1492
			<mday>*</mday>
1493
			<month>*</month>
1494
			<wday>*</wday>
1495
			<who>root</who>
1496
			<command>/usr/bin/nice -n20 newsyslog</command>
1497
		</item>
1498
		<item>
1499
			<minute>1,31</minute>
1500
			<hour>0-5</hour>
1501
			<mday>*</mday>
1502
			<month>*</month>
1503
			<wday>*</wday>
1504
			<who>root</who>
1505
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
1506
		</item>
1507
		<item>
1508
			<minute>1</minute>
1509
			<hour>3</hour>
1510
			<mday>1</mday>
1511
			<month>*</month>
1512
			<wday>*</wday>
1513
			<who>root</who>
1514
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
1515
		</item>
1516
		<item>
1517
			<minute>*/60</minute>
1518
			<hour>*</hour>
1519
			<mday>*</mday>
1520
			<month>*</month>
1521
			<wday>*</wday>
1522
			<who>root</who>
1523
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
1524
		</item>
1525
		<item>
1526
			<minute>1</minute>
1527
			<hour>1</hour>
1528
			<mday>*</mday>
1529
			<month>*</month>
1530
			<wday>*</wday>
1531
			<who>root</who>
1532
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
1533
		</item>
1534
		<item>
1535
			<minute>*/60</minute>
1536
			<hour>*</hour>
1537
			<mday>*</mday>
1538
			<month>*</month>
1539
			<wday>*</wday>
1540
			<who>root</who>
1541
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
1542
		</item>
1543
		<item>
1544
			<minute>*/60</minute>
1545
			<hour>*</hour>
1546
			<mday>*</mday>
1547
			<month>*</month>
1548
			<wday>*</wday>
1549
			<who>root</who>
1550
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 3600 snort2c</command>
1551
		</item>
1552
		<item>
1553
			<minute>*/5</minute>
1554
			<hour>*</hour>
1555
			<mday>*</mday>
1556
			<month>*</month>
1557
			<wday>*</wday>
1558
			<who>root</who>
1559
			<command>/etc/ping_hosts.sh</command>
1560
		</item>
1561
		<item>
1562
			<minute>*/140</minute>
1563
			<hour>*</hour>
1564
			<mday>*</mday>
1565
			<month>*</month>
1566
			<wday>*</wday>
1567
			<who>root</who>
1568
			<command>/usr/local/sbin/reset_slbd.sh</command>
1569
		</item>
1570
		<item>
1571
			<minute>30</minute>
1572
			<hour>12</hour>
1573
			<mday>*</mday>
1574
			<month>*</month>
1575
			<wday>*</wday>
1576
			<who>root</who>
1577
			<command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
1578
		</item>
1579
	</cron>
1580
	<installedpackages>
1581
		<package>
1582
			<name>AutoConfigBackup</name>
1583
			<maintainer>portal@bsdperimeter.com</maintainer>
1584
			<descr><![CDATA[Automatically backs up your pfSense configuration.  All contents are encrypted on the server.  Requires pfSense Premium Support Portal Subscription from https://portal.pfsense.org]]></descr>
1585
			<website>https://portal.pfsense.org</website>
1586
			<category>Services</category>
1587
			<version>1.19</version>
1588
			<status>Stable</status>
1589
			<required_version>1.2</required_version>
1590
			<pkginfolink>http://doc.pfsense.org/index.php/AutoConfigBackup</pkginfolink>
1591
			<config_file>http://www.pfsense.com/packages/config/autoconfigbackup/autoconfigbackup.xml</config_file>
1592
			<configurationfile>autoconfigbackup.xml</configurationfile>
1593
		</package>
1594
		<package>
1595
			<name>siproxd</name>
1596
			<website>http://siproxd.sourceforge.net/</website>
1597
			<descr><![CDATA[Proxy for handling NAT of multiple SIP devices to a single public IP.]]></descr>
1598
			<category>Services</category>
1599
			<config_file>http://www.pfsense.com/packages/config/siproxd.xml</config_file>
1600
			<depends_on_package_base_url>http://files.pfsense.org/packages/8/All/</depends_on_package_base_url>
1601
			<depends_on_package>siproxd-0.8.0.tbz</depends_on_package>
1602
			<pkginfolink>http://doc.pfsense.org/index.php/Siproxd_package</pkginfolink>
1603
			<build_port_path>/usr/ports/net/siproxd</build_port_path>
1604
			<version>0.8.0_2</version>
1605
			<status>Beta</status>
1606
			<required_version>1.2.1</required_version>
1607
			<configurationfile>siproxd.xml</configurationfile>
1608
			<filter_rule_function>siproxd_generate_rules</filter_rule_function>
1609
		</package>
1610
		<menu>
1611
			<name>AutoConfigBackup</name>
1612
			<tooltiptext>Set autoconfigbackup settings such as password and port.</tooltiptext>
1613
			<section>Diagnostics</section>
1614
			<url>/autoconfigbackup.php</url>
1615
		</menu>
1616
		<menu>
1617
			<name>siproxd</name>
1618
			<tooltiptext>Modify siproxd users and settings.</tooltiptext>
1619
			<section>Services</section>
1620
			<url>/pkg_edit.php?xml=siproxd.xml&amp;id=0</url>
1621
		</menu>
1622
		<carp/>
1623
		<siproxdsettings>
1624
			<config/>
1625
		</siproxdsettings>
1626
		<tab>
1627
			<text>Settings</text>
1628
			<url>/pkg_edit.php?xml=siproxd.xml&amp;id=0</url>
1629
			<active/>
1630
		</tab>
1631
		<service>
1632
			<name>siproxd</name>
1633
			<rcfile>siproxd.sh</rcfile>
1634
			<executable>siproxd</executable>
1635
		</service>
1636
	</installedpackages>
1637
	<revision>
1638
		<description><![CDATA[(system): Expired 1 user accounts]]></description>
1639
		<time>1310433501</time>
1640
		<username>(system)</username>
1641
	</revision>
1642
	<rrd>
1643
		<enable/>
1644
	</rrd>
1645
	<load_balancer/>
1646
	<sysctl>
1647
		<item>
1648
			<tunable>net.inet.tcp.blackhole</tunable>
1649
			<descr><![CDATA[Drop packets to closed TCP ports without returning a RST]]></descr>
1650
			<value>default</value>
1651
		</item>
1652
		<item>
1653
			<tunable>net.inet.udp.blackhole</tunable>
1654
			<descr><![CDATA[Do not send ICMP port unreachable messages for closed UDP ports]]></descr>
1655
			<value>default</value>
1656
		</item>
1657
		<item>
1658
			<tunable>net.inet.ip.random_id</tunable>
1659
			<descr><![CDATA[Randomize the ID field in IP packets (default is 0: sequential IP IDs)]]></descr>
1660
			<value>default</value>
1661
		</item>
1662
		<item>
1663
			<tunable>net.inet.tcp.drop_synfin</tunable>
1664
			<descr><![CDATA[Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)]]></descr>
1665
			<value>default</value>
1666
		</item>
1667
		<item>
1668
			<tunable>net.inet.ip.redirect</tunable>
1669
			<descr><![CDATA[Sending of IPv4 ICMP redirects]]></descr>
1670
			<value>default</value>
1671
		</item>
1672
		<item>
1673
			<tunable>net.inet6.ip6.redirect</tunable>
1674
			<descr><![CDATA[Sending of IPv6 ICMP redirects]]></descr>
1675
			<value>default</value>
1676
		</item>
1677
		<item>
1678
			<tunable>net.inet.tcp.syncookies</tunable>
1679
			<descr><![CDATA[Generate SYN cookies for outbound SYN-ACK packets]]></descr>
1680
			<value>default</value>
1681
		</item>
1682
		<item>
1683
			<tunable>net.inet.tcp.recvspace</tunable>
1684
			<descr><![CDATA[Maximum incoming TCP datagram size]]></descr>
1685
			<value>default</value>
1686
		</item>
1687
		<item>
1688
			<tunable>net.inet.tcp.sendspace</tunable>
1689
			<descr><![CDATA[Maximum outgoing TCP datagram size]]></descr>
1690
			<value>default</value>
1691
		</item>
1692
		<item>
1693
			<tunable>net.inet.ip.fastforwarding</tunable>
1694
			<descr><![CDATA[Fastforwarding (see http://lists.freebsd.org/pipermail/freebsd-net/2004-January/002534.html)]]></descr>
1695
			<value>default</value>
1696
		</item>
1697
		<item>
1698
			<tunable>net.inet.tcp.delayed_ack</tunable>
1699
			<descr><![CDATA[Do not delay ACK to try and piggyback it onto a data packet]]></descr>
1700
			<value>default</value>
1701
		</item>
1702
		<item>
1703
			<tunable>net.inet.udp.maxdgram</tunable>
1704
			<descr><![CDATA[Maximum outgoing UDP datagram size]]></descr>
1705
			<value>default</value>
1706
		</item>
1707
		<item>
1708
			<tunable>net.link.bridge.pfil_onlyip</tunable>
1709
			<descr><![CDATA[Handling of non-IP packets which are not passed to pfil (see if_bridge(4))]]></descr>
1710
			<value>default</value>
1711
		</item>
1712
		<item>
1713
			<tunable>net.link.tap.user_open</tunable>
1714
			<descr><![CDATA[Allow unprivileged access to tap(4) device nodes]]></descr>
1715
			<value>default</value>
1716
		</item>
1717
		<item>
1718
			<tunable>kern.rndtest.verbose</tunable>
1719
			<descr><![CDATA[Verbosity of the rndtest driver (0: do not display results on console)]]></descr>
1720
			<value>default</value>
1721
		</item>
1722
		<item>
1723
			<tunable>kern.randompid</tunable>
1724
			<descr><![CDATA[Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())]]></descr>
1725
			<value>default</value>
1726
		</item>
1727
		<item>
1728
			<tunable>net.inet.tcp.inflight.enable</tunable>
1729
			<descr><![CDATA[The system will attempt to calculate the bandwidth delay product for each connection and limit the amount of data queued to the network to just the amount required to maintain optimum throughput. ]]></descr>
1730
			<value>default</value>
1731
		</item>
1732
		<item>
1733
			<tunable>net.inet.icmp.icmplim</tunable>
1734
			<descr><![CDATA[Set ICMP Limits]]></descr>
1735
			<value>default</value>
1736
		</item>
1737
		<item>
1738
			<tunable>net.inet.tcp.tso</tunable>
1739
			<descr><![CDATA[TCP Offload engine]]></descr>
1740
			<value>default</value>
1741
		</item>
1742
		<item>
1743
			<tunable>net.inet.ip.portrange.first</tunable>
1744
			<descr><![CDATA[Set the ephemeral port range starting port]]></descr>
1745
			<value>default</value>
1746
		</item>
1747
		<item>
1748
			<tunable>hw.syscons.kbd_reboot</tunable>
1749
			<descr><![CDATA[Enables ctrl+alt+delete]]></descr>
1750
			<value>default</value>
1751
		</item>
1752
		<item>
1753
			<tunable>kern.ipc.maxsockbuf</tunable>
1754
			<descr><![CDATA[Maximum socket buffer size]]></descr>
1755
			<value>default</value>
1756
		</item>
1757
		<item>
1758
			<descr><![CDATA[Set to 0 to disable filtering on the incoming and outgoing member interfaces.]]></descr>
1759
			<tunable>net.link.bridge.pfil_member</tunable>
1760
			<value>1</value>
1761
		</item>
1762
		<item>
1763
			<descr><![CDATA[Set to 1 to enable filtering on the bridge interface]]></descr>
1764
			<tunable>net.link.bridge.pfil_bridge</tunable>
1765
			<value>0</value>
1766
		</item>
1767
	</sysctl>
1768
	<gateways>
1769
		<gateway_item>
1770
			<interface>wan</interface>
1771
			<gateway>74.118.238.182</gateway>
1772
			<name>GW_WAN</name>
1773
			<weight>1</weight>
1774
			<descr><![CDATA[Interface wan Static Gateway]]></descr>
1775
			<monitor>99.99.99.99</monitor>
1776
			<defaultgw/>
1777
		</gateway_item>
1778
		<gateway_item>
1779
			<interface>opt1</interface>
1780
			<gateway>99.99.99.99</gateway>
1781
			<name>GW_OPT1</name>
1782
			<weight>1</weight>
1783
			<descr><![CDATA[Interface opt1 Static Gateway]]></descr>
1784
		</gateway_item>
1785
		<gateway_group>
1786
			<name>USMetro_Failover</name>
1787
			<item>GW_WAN|1</item>
1788
			<item>GW_OPT1|2</item>
1789
			<trigger>down</trigger>
1790
			<descr/>
1791
		</gateway_group>
1792
		<gateway_group>
1793
			<name>DSL_Failover</name>
1794
			<item>GW_WAN|2</item>
1795
			<item>GW_OPT1|1</item>
1796
			<trigger>down</trigger>
1797
			<descr/>
1798
		</gateway_group>
1799
	</gateways>
1800
	<dyndnses>
1801
		<dyndns>
1802
			<type>dyndns</type>
1803
			<username/>
1804
			<password/>
1805
			<host/>
1806
			<mx/>
1807
			<interface>wan</interface>
1808
			<descr><![CDATA[Upgraded Dyndns dyndns]]></descr>
1809
		</dyndns>
1810
	</dyndnses>
1811
	<openvpn/>
1812
	<cert>
1813
		<refid>4d71a14218edf</refid>
1814
		<descr><![CDATA[IPsec Peer 99.99.99.99 Certificate]]></descr>
1815
		<crt/>
1816
		<prv/>
1817
	</cert>
1818
	<cert>
1819
		<refid>4d71a1422135f</refid>
1820
		<descr><![CDATA[IPsec Peer 99.99.99.99 Certificate]]></descr>
1821
		<crt/>
1822
		<prv/>
1823
	</cert>
1824
	<cert>
1825
		<refid>4d71a142252f6</refid>
1826
		<descr><![CDATA[IPsec Peer 99.99.99.99 Certificate]]></descr>
1827
		<crt/>
1828
		<prv/>
1829
	</cert>
1830
	<cert>
1831
		<refid>4d71a1422b1e4</refid>
1832
		<descr><![CDATA[IPsec Peer 99.99.99.99 Certificate]]></descr>
1833
		<crt/>
1834
		<prv/>
1835
	</cert>
1836
	<cert>
1837
		<refid>4d71a1422eb1d</refid>
1838
		<descr><![CDATA[IPsec Peer 99.99.99.99 Certificate]]></descr>
1839
		<crt/>
1840
		<prv/>
1841
	</cert>
1842
	<shaper>
1843
		<queue>
1844
			<interface>wan</interface>
1845
			<name>wan</name>
1846
			<scheduler>HFSC</scheduler>
1847
			<bandwidth>10000</bandwidth>
1848
			<bandwidthtype>Kb</bandwidthtype>
1849
			<enabled>on</enabled>
1850
			<queue>
1851
				<name>Default</name>
1852
				<interface>wan</interface>
1853
				<priority>3</priority>
1854
				<bandwidth>10</bandwidth>
1855
				<bandwidthtype>%</bandwidthtype>
1856
				<enabled>on</enabled>
1857
				<default>default</default>
1858
				<ecn>ecn</ecn>
1859
			</queue>
1860
			<queue>
1861
				<name>ACK</name>
1862
				<interface>wan</interface>
1863
				<priority>6</priority>
1864
				<bandwidth>18</bandwidth>
1865
				<bandwidthtype>%</bandwidthtype>
1866
				<enabled>on</enabled>
1867
				<ecn>ecn</ecn>
1868
				<linkshare3>18%</linkshare3>
1869
				<linkshare>on</linkshare>
1870
			</queue>
1871
			<queue>
1872
				<name>VOIP</name>
1873
				<interface>wan</interface>
1874
				<priority>7</priority>
1875
				<bandwidth>64</bandwidth>
1876
				<bandwidthtype>Kb</bandwidthtype>
1877
				<enabled>on</enabled>
1878
				<ecn>ecn</ecn>
1879
				<realtime3>64Kb</realtime3>
1880
				<realtime>on</realtime>
1881
			</queue>
1882
		</queue>
1883
		<queue>
1884
			<interface>opt1</interface>
1885
			<name>opt1</name>
1886
			<scheduler>HFSC</scheduler>
1887
			<bandwidth>1500</bandwidth>
1888
			<bandwidthtype>Kb</bandwidthtype>
1889
			<enabled>on</enabled>
1890
			<queue>
1891
				<name>Default</name>
1892
				<interface>opt1</interface>
1893
				<priority>3</priority>
1894
				<bandwidth>10</bandwidth>
1895
				<bandwidthtype>%</bandwidthtype>
1896
				<enabled>on</enabled>
1897
				<default>default</default>
1898
				<ecn>ecn</ecn>
1899
			</queue>
1900
			<queue>
1901
				<name>ACK</name>
1902
				<interface>opt1</interface>
1903
				<priority>6</priority>
1904
				<bandwidth>18</bandwidth>
1905
				<bandwidthtype>%</bandwidthtype>
1906
				<enabled>on</enabled>
1907
				<ecn>ecn</ecn>
1908
				<linkshare3>18%</linkshare3>
1909
				<linkshare>on</linkshare>
1910
			</queue>
1911
			<queue>
1912
				<name>VOIP</name>
1913
				<interface>opt1</interface>
1914
				<priority>7</priority>
1915
				<bandwidth>64</bandwidth>
1916
				<bandwidthtype>Kb</bandwidthtype>
1917
				<enabled>on</enabled>
1918
				<ecn>ecn</ecn>
1919
				<realtime3>64Kb</realtime3>
1920
				<realtime>on</realtime>
1921
			</queue>
1922
		</queue>
1923
	</shaper>
1924
	<ppps/>
1925
	<dhcrelay/>
1926
	<l7shaper>
1927
		<container/>
1928
	</l7shaper>
1929
	<dnshaper/>
1930
	<ezshaper>
1931
		<step1>
1932
			<numberofconnections>2</numberofconnections>
1933
		</step1>
1934
		<step3>
1935
			<enable>on</enable>
1936
			<provider>Asterisk</provider>
1937
			<download>64</download>
1938
			<downloadspeed>Kb</downloadspeed>
1939
			<conn0upload>64</conn0upload>
1940
			<conn0uploadspeed>Kb</conn0uploadspeed>
1941
			<conn1upload>64</conn1upload>
1942
			<conn1uploadspeed>Kb</conn1uploadspeed>
1943
		</step3>
1944
		<step5>
1945
			<enable>on</enable>
1946
			<p2pcatchall>on</p2pcatchall>
1947
			<bandwidth>5</bandwidth>
1948
			<bandwidthunit>%</bandwidthunit>
1949
		</step5>
1950
		<step7>
1951
			<enable>on</enable>
1952
			<msrdp>H</msrdp>
1953
			<vnc>D</vnc>
1954
			<appleremotedesktop>D</appleremotedesktop>
1955
			<pcanywhere>D</pcanywhere>
1956
			<irc>D</irc>
1957
			<jabber>D</jabber>
1958
			<icq>D</icq>
1959
			<aolinstantmessenger>D</aolinstantmessenger>
1960
			<msnmessenger>D</msnmessenger>
1961
			<teamspeak>D</teamspeak>
1962
			<pptp>D</pptp>
1963
			<ipsec>H</ipsec>
1964
			<streamingmp3>D</streamingmp3>
1965
			<rtsp>D</rtsp>
1966
			<http>D</http>
1967
			<smtp>D</smtp>
1968
			<pop3>D</pop3>
1969
			<imap>D</imap>
1970
			<lotusnotes>D</lotusnotes>
1971
			<dns>D</dns>
1972
			<icmp>D</icmp>
1973
			<smb>D</smb>
1974
			<snmp>D</snmp>
1975
			<mysqlserver>D</mysqlserver>
1976
			<nntp>D</nntp>
1977
			<cvsup>D</cvsup>
1978
			<slingbox>D</slingbox>
1979
			<hbci>D</hbci>
1980
		</step7>
1981
		<step2>
1982
			<downloadscheduler>HFSC</downloadscheduler>
1983
			<conn0uploadscheduler>HFSC</conn0uploadscheduler>
1984
			<conn0upload>2500</conn0upload>
1985
			<conn0uploadspeed>Kb</conn0uploadspeed>
1986
			<conn0download>19000</conn0download>
1987
			<conn0downloadspeed>Kb</conn0downloadspeed>
1988
			<conn0interface>wan</conn0interface>
1989
			<conn1uploadscheduler>HFSC</conn1uploadscheduler>
1990
			<conn1upload>700</conn1upload>
1991
			<conn1uploadspeed>Kb</conn1uploadspeed>
1992
			<conn1download>3000</conn1download>
1993
			<conn1downloadspeed>Kb</conn1downloadspeed>
1994
			<conn1interface>opt1</conn1interface>
1995
		</step2>
1996
	</ezshaper>
1997
	<schedules>
1998
		<schedule>
1999
			<name>Apply_P2P_Catch_All</name>
2000
			<descr/>
2001
			<timerange>
2002
				<position>1,2,3,4,5,6,7</position>
2003
				<hour>6:00-21:00</hour>
2004
				<rangedescr>Day</rangedescr>
2005
			</timerange>
2006
			<schedlabel>4d72124f5f289</schedlabel>
2007
		</schedule>
2008
	</schedules>
2009
	<l2tp>
2010
		<radius>
2011
			<server/>
2012
			<secret/>
2013
		</radius>
2014
		<remoteip>0.0.0.0</remoteip>
2015
		<localip>172.16.30.5</localip>
2016
		<l2tp_subnet>0</l2tp_subnet>
2017
		<mode>off</mode>
2018
		<interface>wan</interface>
2019
		<n_l2tp_units>0</n_l2tp_units>
2020
		<secret/>
2021
		<paporchap>chap</paporchap>
2022
		<user>
2023
			<name>name</name>
2024
			<ip/>
2025
			<password>pass</password>
2026
		</user>
2027
	</l2tp>
2028
	<virtualip>
2029
		<vip>
2030
			<mode>proxyarp</mode>
2031
			<interface>wan</interface>
2032
			<descr><![CDATA[Web Server Virtual IP]]></descr>
2033
			<type>single</type>
2034
			<subnet_bits>32</subnet_bits>
2035
			<subnet>99.99.99.99</subnet>
2036
		</vip>
2037
		<vip>
2038
			<mode>proxyarp</mode>
2039
			<interface>wan</interface>
2040
			<descr><![CDATA[VOIP Server Virtual IP]]></descr>
2041
			<type>single</type>
2042
			<subnet_bits>32</subnet_bits>
2043
			<subnet>99.99.99.99</subnet>
2044
		</vip>
2045
	</virtualip>
2046
</pfsense>
(1-1/2)