Project

General

Profile

Bug #304 ยป config-redmine304.xml

Chris Buechler, 02/14/2010 01:52 AM

 
1
<?xml version="1.0"?>
2
<pfsense>
3
	<version>6.0</version>
4
	<lastchange/>
5
	<theme>pfsense_ng</theme>
6
	<sysctl>
7
		<item>
8
			<desc>Set the ephemeral port range to be lower.</desc>
9
			<tunable>net.inet.ip.portrange.first</tunable>
10
			<value>default</value>
11
		</item>
12
		<item>
13
			<desc>Drop packets to closed TCP ports without returning a RST</desc>
14
			<tunable>net.inet.tcp.blackhole</tunable>
15
			<value>default</value>
16
		</item>
17
		<item>
18
			<desc>Do not send ICMP port unreachable messages for closed UDP ports</desc>
19
			<tunable>net.inet.udp.blackhole</tunable>
20
			<value>default</value>
21
		</item>
22
		<item>
23
			<desc>Randomize the ID field in IP packets (default is 0: sequential IP IDs)</desc>
24
			<tunable>net.inet.ip.random_id</tunable>
25
			<value>default</value>
26
		</item>
27
		<item>
28
			<desc>Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)</desc>
29
			<tunable>net.inet.tcp.drop_synfin</tunable>
30
			<value>default</value>
31
		</item>
32
		<item>
33
			<desc>Enable sending IPv4 redirects</desc>
34
			<tunable>net.inet.ip.redirect</tunable>
35
			<value>default</value>
36
		</item>
37
		<item>
38
			<desc>Enable sending IPv6 redirects</desc>
39
			<tunable>net.inet6.ip6.redirect</tunable>
40
			<value>default</value>
41
		</item>
42
		<item>
43
			<desc>Generate SYN cookies for outbound SYN-ACK packets</desc>
44
			<tunable>net.inet.tcp.syncookies</tunable>
45
			<value>default</value>
46
		</item>
47
		<item>
48
			<desc>Maximum incoming/outgoing TCP datagram size (receive)</desc>
49
			<tunable>net.inet.tcp.recvspace</tunable>
50
			<value>default</value>
51
		</item>
52
		<item>
53
			<desc>Maximum incoming/outgoing TCP datagram size (send)</desc>
54
			<tunable>net.inet.tcp.sendspace</tunable>
55
			<value>default</value>
56
		</item>
57
		<item>
58
			<desc>IP Fastforwarding</desc>
59
			<tunable>net.inet.ip.fastforwarding</tunable>
60
			<value>default</value>
61
		</item>
62
		<item>
63
			<desc>Do not delay ACK to try and piggyback it onto a data packet</desc>
64
			<tunable>net.inet.tcp.delayed_ack</tunable>
65
			<value>default</value>
66
		</item>
67
		<item>
68
			<desc>Maximum outgoing UDP datagram size</desc>
69
			<tunable>net.inet.udp.maxdgram</tunable>
70
			<value>default</value>
71
		</item>
72
		<item>
73
			<desc>Handling of non-IP packets which are not passed to pfil (see if_bridge(4))</desc>
74
			<tunable>net.link.bridge.pfil_onlyip</tunable>
75
			<value>default</value>
76
		</item>
77
		<item>
78
			<desc>Set to 0 to disable filtering on the incoming and outgoing member interfaces.</desc>
79
			<tunable>net.link.bridge.pfil_member</tunable>
80
			<value>default</value>
81
		</item>
82
		<item>
83
			<desc>Set to 1 to enable filtering on the bridge interface</desc>
84
			<tunable>net.link.bridge.pfil_bridge</tunable>
85
			<value>default</value>
86
		</item>
87
		<item>
88
			<desc>Allow unprivileged access to tap(4) device nodes</desc>
89
			<tunable>net.link.tap.user_open</tunable>
90
			<value>default</value>
91
		</item>
92
		<item>
93
			<desc>Verbosity of the rndtest driver (0: do not display results on console)</desc>
94
			<tunable>kern.rndtest.verbose</tunable>
95
			<value>default</value>
96
		</item>
97
		<item>
98
			<desc>Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())</desc>
99
			<tunable>kern.randompid</tunable>
100
			<value>default</value>
101
		</item>
102
		<item>
103
			<desc>Maximum size of the IP input queue</desc>
104
			<tunable>net.inet.ip.intr_queue_maxlen</tunable>
105
			<value>default</value>
106
		</item>
107
		<item>
108
			<desc>Disable CTRL+ALT+Delete reboot from keyboard.</desc>
109
			<tunable>hw.syscons.kbd_reboot</tunable>
110
			<value>default</value>
111
		</item>
112
		<item>
113
			<desc>Enable TCP Inflight mode</desc>
114
			<tunable>net.inet.tcp.inflight.enable</tunable>
115
			<value>default</value>
116
		</item>
117
		<item>
118
			<desc>Enable TCP extended debugging</desc>
119
			<tunable>net.inet.tcp.log_debug</tunable>
120
			<value>default</value>
121
		</item>
122
		<item>
123
			<desc>Set ICMP Limits</desc>
124
			<tunable>net.inet.icmp.icmplim</tunable>
125
			<value>default</value>
126
		</item>
127
		<item>
128
			<desc>TCP Offload Engine</desc>
129
			<tunable>net.inet.tcp.tso</tunable>
130
			<value>default</value>
131
		</item>
132
		<item>
133
			<desc>TCP Offload Engine - BCE</desc>
134
			<tunable>hw.bce.tso_enable</tunable>
135
			<value>default</value>
136
		</item>
137
	</sysctl>
138
	<system>
139
		<optimization>normal</optimization>
140
		<hostname>pfSense</hostname>
141
		<domain>local</domain>
142
		<dnsallowoverride/>
143
		<group>
144
			<name>all</name>
145
			<description>All Users</description>
146
			<scope>system</scope>
147
			<gid>1998</gid>
148
			<member>0</member>
149
		</group>
150
		<group>
151
			<name>admins</name>
152
			<description>System Administrators</description>
153
			<scope>system</scope>
154
			<gid>1999</gid>
155
			<member>0</member>
156
			<priv>page-all</priv>
157
		</group>
158
		<user>
159
			<name>admin</name>
160
			<fullname>System Administrator</fullname>
161
			<scope>system</scope>
162
			<groupname>admins</groupname>
163
			<password>$1$dSJImFph$GvZ7.1UbuWu.Yb8etC0re.</password>
164
			<uid>0</uid>
165
			<priv>user-shell-access</priv>
166
		</user>
167
		<nextuid>2000</nextuid>
168
		<nextgid>2000</nextgid>
169
		<timezone>Etc/UTC</timezone>
170
		<time-update-interval>300</time-update-interval>
171
		<timeservers>0.pfsense.pool.ntp.org</timeservers>
172
		<webgui>
173
			<protocol>https</protocol>
174
			<ssl-certref>4b779a647f67e</ssl-certref>
175
		</webgui>
176
		<disablenatreflection>yes</disablenatreflection>
177
		<cert>
178
			<refid>4b779a647f67e</refid>
179
			<name>webConfigurator default</name>
180
			<crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUVLRENDQTVHZ0F3SUJBZ0lKQU53dFBwU20wVGc0TUEwR0NTcUdTSWIzRFFFQkJRVUFNSUcvTVFzd0NRWUQKVlFRR0V3SlZVekVTTUJBR0ExVUVDQk1KVTI5dFpYZG9aWEpsTVJFd0R3WURWUVFIRXdoVGIyMWxZMmwwZVRFVQpNQklHQTFVRUNoTUxRMjl0Y0dGdWVVNWhiV1V4THpBdEJnTlZCQXNUSms5eVoyRnVhWHBoZEdsdmJtRnNJRlZ1CmFYUWdUbUZ0WlNBb1pXY3NJSE5sWTNScGIyNHBNU1F3SWdZRFZRUURFeHREYjIxdGIyNGdUbUZ0WlNBb1pXY3MKSUZsUFZWSWdibUZ0WlNreEhEQWFCZ2txaGtpRzl3MEJDUUVXRFVWdFlXbHNJRUZrWkhKbGMzTXdIaGNOTVRBdwpNakUwTURZek9ESTRXaGNOTVRVd09EQTNNRFl6T0RJNFdqQ0J2ekVMTUFrR0ExVUVCaE1DVlZNeEVqQVFCZ05WCkJBZ1RDVk52YldWM2FHVnlaVEVSTUE4R0ExVUVCeE1JVTI5dFpXTnBkSGt4RkRBU0JnTlZCQW9UQzBOdmJYQmgKYm5sT1lXMWxNUzh3TFFZRFZRUUxFeVpQY21kaGJtbDZZWFJwYjI1aGJDQlZibWwwSUU1aGJXVWdLR1ZuTENCegpaV04wYVc5dUtURWtNQ0lHQTFVRUF4TWJRMjl0Ylc5dUlFNWhiV1VnS0dWbkxDQlpUMVZTSUc1aGJXVXBNUnd3CkdnWUpLb1pJaHZjTkFRa0JGZzFGYldGcGJDQkJaR1J5WlhOek1JR2ZNQTBHQ1NxR1NJYjNEUUVCQVFVQUE0R04KQURDQmlRS0JnUURQSkJYVnVMUjVhSmFreE5yOFNkNHM3M2RCdXdkVlhGcmhHSmZDcTBvSk85LzRKS2VWTC8zcwpXK2RaK2MyZ1JMQmcrZG1IeUtHZWFJNzFSSVBlZTFteHZHSWFTUlF0RE04Ym1sZjBtVDFZc29GSEVPV2VFZHRYCkhPK0pqT2NMNnhUSGxMOWVQL1pHd3dtTkNXVXdLaGVac2RRV1FqYW1tOXE0QytxaHRFMnUwUUlEQVFBQm80SUIKS0RDQ0FTUXdIUVlEVlIwT0JCWUVGQll2UGF1R3BnRWV0bjQ1a3lkT2h1ZUlNZ25WTUlIMEJnTlZIU01FZ2V3dwpnZW1BRkJZdlBhdUdwZ0VldG40NWt5ZE9odWVJTWduVm9ZSEZwSUhDTUlHL01Rc3dDUVlEVlFRR0V3SlZVekVTCk1CQUdBMVVFQ0JNSlUyOXRaWGRvWlhKbE1SRXdEd1lEVlFRSEV3aFRiMjFsWTJsMGVURVVNQklHQTFVRUNoTUwKUTI5dGNHRnVlVTVoYldVeEx6QXRCZ05WQkFzVEprOXlaMkZ1YVhwaGRHbHZibUZzSUZWdWFYUWdUbUZ0WlNBbwpaV2NzSUhObFkzUnBiMjRwTVNRd0lnWURWUVFERXh0RGIyMXRiMjRnVG1GdFpTQW9aV2NzSUZsUFZWSWdibUZ0ClpTa3hIREFhQmdrcWhraUc5dzBCQ1FFV0RVVnRZV2xzSUVGa1pISmxjM09DQ1FEY0xUNlVwdEU0T0RBTUJnTlYKSFJNRUJUQURBUUgvTUEwR0NTcUdTSWIzRFFFQkJRVUFBNEdCQUFQYmNEZkFSbFR5cXNwMVA2eFBOMklpRGl3NgpRRmtpSk5xNURKQUo1dit2eEhEK0pxYzNTY0hkMnBDeFcvRVFBRUtid0IzenZkMW9yeTE2ZEpRcE1PeHZWdHIyCkl6MHl4SnZhT0lYVEQ5eThPckt4OVNEeDEwWUpLSGE2eUZmRE56bnRkc2E2bExCbkF5eXlrN20ySHhlclRTejcKbHlDWHNBMlVOZXA4VEZORQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==</crt>
181
			<prv>R2VuZXJhdGluZyBSU0EgcHJpdmF0ZSBrZXksIDEwMjQgYml0IGxvbmcgbW9kdWx1cwouLi4uLi4uLi4uKysrKysrCi4uLi4uLi4rKysrKysKZSBpcyA2NTUzNyAoMHgxMDAwMSkKLS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlDWGdJQkFBS0JnUURQSkJYVnVMUjVhSmFreE5yOFNkNHM3M2RCdXdkVlhGcmhHSmZDcTBvSk85LzRKS2VWCkwvM3NXK2RaK2MyZ1JMQmcrZG1IeUtHZWFJNzFSSVBlZTFteHZHSWFTUlF0RE04Ym1sZjBtVDFZc29GSEVPV2UKRWR0WEhPK0pqT2NMNnhUSGxMOWVQL1pHd3dtTkNXVXdLaGVac2RRV1FqYW1tOXE0QytxaHRFMnUwUUlEQVFBQgpBb0dCQUpTS3h4RzFXODU0bnhiWGlFWkZYb3NReW8rYlpIM2xOZEtYeFRTM2l1Y21SYzEzMDZsYmVoZEdMSmpNClY1WG56Q2d1NDd6SXRvV1hhM1VkUmdlRW8yTlRZOXl3TUUxczBVV2lERWY5Y3NNaTNReHYrZDFxMFFQbHhBc1oKVENjancxdEV4KzNleEpNN0JPSHNMRFdFemZEeGw5SWlTbjZvRzdRZ0s1RWI4TjJ4QWtFQStYNUpCVU5NSFp6Qgo4dTBJVmxmN3dsMGJCTnQ2UGlaTm50cDd1NzY3a1RodHJxZmdRYW1jOVdOSCt3R0VuTzJ2WkJPQWJWRGdqRm5lCnkzQVV4UTVZdFFKQkFOU0xDZzBkbXB4bFoybG9YNWh0dFNhK0dnTG9sVlREcUtkMjhLcmMweVlLREJSNUpTM2IKTFdCS3NVWkpqdUlKNzdXM3psTFBndTB3a1RLVVNXelpHeTBDUVFDVyttZmZ5bkRHUHJWVGQwTWpWUXpoK291KwpMYjdVMjBML2pVRnhSS09tNXBuaEptL2I3SE15UDhrd1NTUGgveWV6RE9ZYndPU1JxbFRia1ZEUVNyVTlBa0VBCnpTWWJJSWUzaVVlVFpqbVpNODZJc0ltREg5V1E5YzBaQi9NVTMwYmdBM0psTUlteUtpM0pBWTEyeUtvTllQNUkKUW5UVWtEZTlYdVdtOEZRUy94NGJUUUpBTjNLUjFXZ2NOdFdHRjU1czgwTCszUEVzNmg3RWc5NjhzU0pqK2xhZQpTYTJqcWFVRDIrR2hVVjZEUzdvajEzZUNQcnd5bENHeG1jR0IxbXFpeUFTVjRnPT0KLS0tLS1FTkQgUlNBIFBSSVZBVEUgS0VZLS0tLS0K</prv>
182
		</cert>
183
		<enablesshd/>
184
		<dnsserver/>
185
		<dnsserver/>
186
	</system>
187
	<interfaces>
188
		<wan>
189
			<if>em0</if>
190
			<mtu/>
191
			<ipaddr>dhcp</ipaddr>
192
			<subnet/>
193
			<gateway/>
194
			<blockbogons>on</blockbogons>
195
			<dhcphostname/>
196
			<media/>
197
			<mediaopt/>
198
			<bandwidth>100</bandwidth>
199
			<bandwidthtype>Mb</bandwidthtype>
200
			<spoofmac/>
201
			<pppoe_username/>
202
			<pppoe_password/>
203
			<pptp_username/>
204
			<pptp_password/>
205
		</wan>
206
		<lan>
207
			<if>em1</if>
208
			<ipaddr>192.168.1.1</ipaddr>
209
			<subnet>24</subnet>
210
			<media/>
211
			<mediaopt/>
212
			<bandwidth>100</bandwidth>
213
			<bandwidthtype>Mb</bandwidthtype>
214
		</lan>
215
		<opt1>
216
			<if>em2</if>
217
			<descr>OPT1</descr>
218
			<enable/>
219
			<ipaddr>192.168.91.1</ipaddr>
220
			<subnet>24</subnet>
221
			<gateway>OPT1GW</gateway>
222
			<spoofmac/>
223
		</opt1>
224
	</interfaces>
225
	<staticroutes/>
226
	<pppoe>
227
		<username/>
228
		<password/>
229
		<provider/>
230
	</pppoe>
231
	<pptp>
232
		<username/>
233
		<password/>
234
		<local/>
235
		<subnet/>
236
		<remote/>
237
		<timeout/>
238
	</pptp>
239
	<dhcpd>
240
		<lan>
241
			<enable/>
242
			<range>
243
				<from>192.168.1.10</from>
244
				<to>192.168.1.245</to>
245
			</range>
246
		</lan>
247
	</dhcpd>
248
	<pptpd>
249
		<mode/>
250
		<redir/>
251
		<localip/>
252
		<remoteip/>
253
	</pptpd>
254
	<ovpn/>
255
	<dnsmasq>
256
		<enable/>
257
	</dnsmasq>
258
	<snmpd>
259
		<syslocation/>
260
		<syscontact/>
261
		<rocommunity>public</rocommunity>
262
	</snmpd>
263
	<diag>
264
		<ipv6nat>
265
			<ipaddr/>
266
		</ipv6nat>
267
	</diag>
268
	<bridge/>
269
	<syslog/>
270
	<nat>
271
		<ipsecpassthru>
272
			<enable/>
273
		</ipsecpassthru>
274
	</nat>
275
	<filter>
276
		<rule>
277
			<type>pass</type>
278
			<descr>Default allow LAN to any rule</descr>
279
			<interface>lan</interface>
280
			<source>
281
				<network>lan</network>
282
			</source>
283
			<destination>
284
				<any/>
285
			</destination>
286
			<associated-rule-id/>
287
		</rule>
288
		<rule>
289
			<type>pass</type>
290
			<interface>wan</interface>
291
			<source>
292
				<any/>
293
			</source>
294
			<destination>
295
				<any/>
296
			</destination>
297
			<statetype>keep state</statetype>
298
			<os/>
299
			<descr>Allow all via pfSsh.php</descr>
300
		</rule>
301
	</filter>
302
	<shaper/>
303
	<ipsec>
304
		<preferredoldsa/>
305
	</ipsec>
306
	<aliases/>
307
	<proxyarp/>
308
	<cron>
309
		<item>
310
			<minute>0</minute>
311
			<hour>*</hour>
312
			<mday>*</mday>
313
			<month>*</month>
314
			<wday>*</wday>
315
			<who>root</who>
316
			<command>/usr/bin/nice -n20 newsyslog</command>
317
		</item>
318
		<item>
319
			<minute>1,31</minute>
320
			<hour>0-5</hour>
321
			<mday>*</mday>
322
			<month>*</month>
323
			<wday>*</wday>
324
			<who>root</who>
325
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
326
		</item>
327
		<item>
328
			<minute>1</minute>
329
			<hour>3</hour>
330
			<mday>1</mday>
331
			<month>*</month>
332
			<wday>*</wday>
333
			<who>root</who>
334
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
335
		</item>
336
		<item>
337
			<minute>*/60</minute>
338
			<hour>*</hour>
339
			<mday>*</mday>
340
			<month>*</month>
341
			<wday>*</wday>
342
			<who>root</who>
343
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
344
		</item>
345
		<item>
346
			<minute>1</minute>
347
			<hour>1</hour>
348
			<mday>*</mday>
349
			<month>*</month>
350
			<wday>*</wday>
351
			<who>root</who>
352
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
353
		</item>
354
		<item>
355
			<minute>*/60</minute>
356
			<hour>*</hour>
357
			<mday>*</mday>
358
			<month>*</month>
359
			<wday>*</wday>
360
			<who>root</who>
361
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
362
		</item>
363
		<item>
364
			<minute>*/5</minute>
365
			<hour>*</hour>
366
			<mday>*</mday>
367
			<month>*</month>
368
			<wday>*</wday>
369
			<who>root</who>
370
			<command>/usr/bin/nice -n20 /usr/local/bin/checkreload.sh</command>
371
		</item>
372
	</cron>
373
	<wol/>
374
	<rrd>
375
		<enable/>
376
	</rrd>
377
	<load_balancer>
378
		<monitor_type>
379
			<name>ICMP</name>
380
			<type>icmp</type>
381
			<desc>ICMP</desc>
382
			<options/>
383
		</monitor_type>
384
		<monitor_type>
385
			<name>TCP</name>
386
			<type>tcp</type>
387
			<desc>Generic TCP</desc>
388
			<options/>
389
		</monitor_type>
390
		<monitor_type>
391
			<name>HTTP</name>
392
			<type>http</type>
393
			<desc>Generic HTTP</desc>
394
			<options>
395
				<path>/</path>
396
				<host/>
397
				<code>200</code>
398
			</options>
399
		</monitor_type>
400
		<monitor_type>
401
			<name>HTTPS</name>
402
			<type>https</type>
403
			<desc>Generic HTTPS</desc>
404
			<options>
405
				<path>/</path>
406
				<host/>
407
				<code>200</code>
408
			</options>
409
		</monitor_type>
410
		<monitor_type>
411
			<name>SMTP</name>
412
			<type>send</type>
413
			<desc>Generic SMTP</desc>
414
			<options>
415
				<send>EHLO nosuchhost</send>
416
				<expect>250-</expect>
417
			</options>
418
		</monitor_type>
419
	</load_balancer>
420
	<widgets>
421
		<sequence>system_information-container:col1:show,captive_portal_status-container:col1:close,carp_status-container:col1:close,cpu_graphs-container:col1:close,gateways-container:col1:close,gmirror_status-container:col1:close,installed_packages-container:col1:close,interface_statistics-container:col1:close,interfaces-container:col2:show,ipsec-container:col2:close,load_balancer_status-container:col2:close,log-container:col2:close,picture-container:col2:close,rss-container:col2:close,services_status-container:col2:close,traffic_graphs-container:col2:close</sequence>
422
	</widgets>
423
	<vlans/>
424
	<revision>
425
		<description>/interfaces.php made unknown change</description>
426
		<time>1266130102</time>
427
	</revision>
428
	<l7shaper>
429
		<container/>
430
	</l7shaper>
431
	<dnshaper/>
432
	<gateways>
433
		<gateway_item>
434
			<interface>opt1</interface>
435
			<name>OPT1GW</name>
436
			<gateway>192.168.91.254</gateway>
437
			<descr/>
438
		</gateway_item>
439
	</gateways>
440
	<openvpn/>
441
</pfsense>
    (1-1/1)