Project

General

Profile

Bug #2798 ยป config-pfsense.bartellbartell.com-20130206111811.xml

Robert Staph, 02/06/2013 10:26 AM

 
1
<?xml version="1.0"?>
2
<pfsense>
3
	<version>9.2</version>
4
	<lastchange/>
5
	<theme>pfsense</theme>
6
	<system>
7
		<optimization>normal</optimization>
8
		<hostname>pfsense</hostname>
9
		<domain>***.com</domain>
10
		<timezone>EST5EDT</timezone>
11
		<time-update-interval/>
12
		<timeservers>pool.ntp.org</timeservers>
13
		<webgui>
14
			<protocol>http</protocol>
15
			<port/>
16
			<certificate/>
17
			<private-key/>
18
			<auth_method>session</auth_method>
19
			<backing_method>htpasswd</backing_method>
20
			<ssl-certref/>
21
			<max_procs>2</max_procs>
22
			<quietlogin/>
23
			<nodnsrebindcheck/>
24
		</webgui>
25
		<disablenatreflection>yes</disablenatreflection>
26
		<ssh>
27
			<authorizedkeys/>
28
		</ssh>
29
		<scrubnodf>enabled</scrubnodf>
30
		<maximumstates/>
31
		<shapertype/>
32
		<afterfilterchangeshellcmd/>
33
		<enablesshd>enabled</enablesshd>
34
		<group>
35
			<name>admins</name>
36
			<description><![CDATA[System Administrators]]></description>
37
			<scope>user</scope>
38
			<priv>page-all</priv>
39
			<home>index.php</home>
40
			<gid>2000</gid>
41
			<member>0</member>
42
		</group>
43
		<group>
44
			<name>all</name>
45
			<description><![CDATA[All Users]]></description>
46
			<scope>system</scope>
47
			<gid>1998</gid>
48
		</group>
49
		<user>
50
			<name>admin</name>
51
			<descr><![CDATA[System Administrator]]></descr>
52
			<scope>system</scope>
53
			<password>*</password>
54
			<uid>0</uid>
55
			<priv>user-shell-access</priv>
56
			<priv>user-copy-files</priv>
57
		</user>
58
		<user>
59
			<scope>user</scope>
60
			<password>*</password>
61
			<md5-hash>0ba9802db2338a5427359c0d87ef450f</md5-hash>
62
			<nt-hash>f210b75f9069f520bb43533b33d33f31</nt-hash>
63
			<name>fullbartell</name>
64
			<descr/>
65
			<expires/>
66
			<authorizedkeys/>
67
			<ipsecpsk/>
68
			<uid>2001</uid>
69
		</user>
70
		<nextuid>2002</nextuid>
71
		<nextgid>2001</nextgid>
72
		<disablesegmentationoffloading/>
73
		<disablelargereceiveoffloading/>
74
		<gitsync>
75
			<repositoryurl/>
76
			<branch/>
77
		</gitsync>
78
		<dns1gwint>none</dns1gwint>
79
		<dns2gwint>none</dns2gwint>
80
		<dns3gwint>none</dns3gwint>
81
		<dns4gwint>none</dns4gwint>
82
		<maximumtableentries>500000</maximumtableentries>
83
		<reflectiontimeout/>
84
		<dnsserver>8.8.8.8</dnsserver>
85
		<dnsserver>8.8.4.4</dnsserver>
86
		<firmware>
87
			<alturl>
88
				<enable/>
89
				<firmwareurl>http://snapshots.pfsense.org/FreeBSD_RELENG_8_3/i386/pfSense_HEAD/.updaters</firmwareurl>
90
			</alturl>
91
			<allowinvalidsig/>
92
		</firmware>
93
		<ipv6allow/>
94
	</system>
95
	<interfaces>
96
		<wan>
97
			<if>fxp1</if>
98
			<bandwidth>100</bandwidth>
99
			<bandwidthtype>Mb</bandwidthtype>
100
			<spoofmac/>
101
			<disableftpproxy/>
102
			<enable/>
103
			<descr><![CDATA[WAN]]></descr>
104
			<ipaddr>10.1.10.2</ipaddr>
105
			<subnet>24</subnet>
106
			<gateway>GW_WAN</gateway>
107
		</wan>
108
		<lan>
109
			<if>bge0</if>
110
			<bandwidth>100</bandwidth>
111
			<bandwidthtype>Mb</bandwidthtype>
112
			<bridge/>
113
			<enable/>
114
			<descr><![CDATA[LAN]]></descr>
115
			<spoofmac/>
116
			<ipaddr>10.0.0.1</ipaddr>
117
			<subnet>24</subnet>
118
		</lan>
119
		<opt3>
120
			<descr><![CDATA[CLIENTS]]></descr>
121
			<if>fxp0</if>
122
			<bridge/>
123
			<enable/>
124
			<ipaddr>10.10.10.1</ipaddr>
125
			<subnet>24</subnet>
126
			<gateway/>
127
			<spoofmac/>
128
			<mtu/>
129
		</opt3>
130
	</interfaces>
131
	<staticroutes/>
132
	<bigpond/>
133
	<dhcpd>
134
		<lan>
135
			<enable/>
136
			<range>
137
				<from>10.0.0.63</from>
138
				<to>10.0.0.94</to>
139
			</range>
140
			<defaultleasetime/>
141
			<maxleasetime/>
142
			<netmask/>
143
			<failover_peerip/>
144
			<gateway/>
145
			<ddnsdomain/>
146
			<next-server/>
147
			<filename/>
148
			<domain/>
149
			<domainsearchlist/>
150
			<tftp/>
151
			<ldap/>
152
			<rootpath/>
153
			<numberoptions/>
154
			<dnsserver>10.0.0.1</dnsserver>
155
			<ntpserver>10.0.0.1</ntpserver>
156
		</lan>
157
		<opt3>
158
			<range>
159
				<from>10.10.10.129</from>
160
				<to>10.10.10.254</to>
161
			</range>
162
			<defaultleasetime>7200</defaultleasetime>
163
			<maxleasetime>32400</maxleasetime>
164
			<netmask/>
165
			<failover_peerip/>
166
			<gateway/>
167
			<enable/>
168
			<ddnsdomain/>
169
			<next-server/>
170
			<filename/>
171
			<domain/>
172
			<domainsearchlist/>
173
			<tftp/>
174
			<ldap/>
175
			<rootpath/>
176
			<numberoptions/>
177
		</opt3>
178
		<wan>
179
			<range>
180
				<from/>
181
				<to/>
182
			</range>
183
			<defaultleasetime/>
184
			<maxleasetime/>
185
			<netmask/>
186
			<failover_peerip/>
187
			<gateway/>
188
			<domain/>
189
			<domainsearchlist/>
190
			<ddnsdomain/>
191
			<tftp/>
192
			<ldap/>
193
			<next-server/>
194
			<filename/>
195
			<rootpath/>
196
			<numberoptions/>
197
		</wan>
198
	</dhcpd>
199
	<pptpd>
200
		<redir/>
201
		<localip>10.0.0.47</localip>
202
		<remoteip>10.0.0.48</remoteip>
203
		<radius>
204
			<server>
205
				<ip/>
206
				<port/>
207
				<acctport/>
208
				<secret/>
209
			</server>
210
			<server2>
211
				<ip/>
212
				<port/>
213
				<acctport/>
214
				<secret2/>
215
			</server2>
216
			<nasip/>
217
			<acct_update/>
218
		</radius>
219
		<req128/>
220
		<wins/>
221
		<mode>server</mode>
222
		<n_pptp_units>6</n_pptp_units>
223
	</pptpd>
224
	<ovpn/>
225
	<dnsmasq>
226
		<custom_options/>
227
		<enable/>
228
	</dnsmasq>
229
	<diag>
230
		<ipv6nat/>
231
	</diag>
232
	<syslog>
233
		<reverse/>
234
		<nentries>200</nentries>
235
		<nologdefaultblock/>
236
		<rawfilter/>
237
	</syslog>
238
	<nat>
239
		<ipsecpassthru/>
240
		<advancedoutbound>
241
			<rule>
242
				<source>
243
					<network>10.0.0.0/24</network>
244
				</source>
245
				<sourceport/>
246
				<descr><![CDATA[Auto created rule for LAN]]></descr>
247
				<target/>
248
				<interface>wan</interface>
249
				<destination>
250
					<any/>
251
				</destination>
252
				<natport/>
253
				<dstport/>
254
			</rule>
255
			<rule>
256
				<source>
257
					<network>10.10.10.0/24</network>
258
				</source>
259
				<sourceport/>
260
				<descr/>
261
				<target/>
262
				<interface>wan</interface>
263
				<destination>
264
					<any/>
265
				</destination>
266
				<natport/>
267
				<dstport/>
268
			</rule>
269
			<enable/>
270
		</advancedoutbound>
271
	</nat>
272
	<filter>
273
		<rule>
274
			<type>match</type>
275
			<interface>wan</interface>
276
			<descr><![CDATA[Penalty Box]]></descr>
277
			<source>
278
				<any/>
279
				<address>penaltybox</address>
280
			</source>
281
			<defaultqueue>qOthersLow</defaultqueue>
282
			<destination>
283
				<any/>
284
			</destination>
285
			<floating>yes</floating>
286
			<wizard>yes</wizard>
287
			<enabled>on</enabled>
288
		</rule>
289
		<rule>
290
			<type>match</type>
291
			<interface>wan</interface>
292
			<defaultqueue>qOthersHigh</defaultqueue>
293
			<ackqueue>qACK</ackqueue>
294
			<source>
295
				<any/>
296
			</source>
297
			<destination>
298
				<any/>
299
				<port>3389-3389</port>
300
			</destination>
301
			<floating>yes</floating>
302
			<wizard>yes</wizard>
303
			<enabled>on</enabled>
304
			<descr><![CDATA[m_Other MSRDP outbound]]></descr>
305
			<protocol>tcp</protocol>
306
		</rule>
307
		<rule>
308
			<type>match</type>
309
			<interface>wan</interface>
310
			<defaultqueue>qOthersHigh</defaultqueue>
311
			<ackqueue>qACK</ackqueue>
312
			<source>
313
				<any/>
314
			</source>
315
			<destination>
316
				<any/>
317
				<port>5900-5930</port>
318
			</destination>
319
			<floating>yes</floating>
320
			<wizard>yes</wizard>
321
			<enabled>on</enabled>
322
			<descr><![CDATA[m_Other VNC outbound]]></descr>
323
			<protocol>tcp</protocol>
324
		</rule>
325
		<rule>
326
			<type>match</type>
327
			<interface>wan</interface>
328
			<defaultqueue>qOthersHigh</defaultqueue>
329
			<ackqueue>qACK</ackqueue>
330
			<source>
331
				<any/>
332
			</source>
333
			<destination>
334
				<any/>
335
				<port>3283-3283</port>
336
			</destination>
337
			<floating>yes</floating>
338
			<wizard>yes</wizard>
339
			<enabled>on</enabled>
340
			<descr><![CDATA[m_Other AppleRemoteDesktop1 outbound]]></descr>
341
			<protocol>tcp</protocol>
342
		</rule>
343
		<rule>
344
			<type>match</type>
345
			<interface>wan</interface>
346
			<defaultqueue>qOthersHigh</defaultqueue>
347
			<ackqueue>qACK</ackqueue>
348
			<source>
349
				<any/>
350
			</source>
351
			<destination>
352
				<any/>
353
				<port>5900-5900</port>
354
			</destination>
355
			<floating>yes</floating>
356
			<wizard>yes</wizard>
357
			<enabled>on</enabled>
358
			<descr><![CDATA[m_Other AppleRemoteDesktop2 outbound]]></descr>
359
			<protocol>tcp</protocol>
360
		</rule>
361
		<rule>
362
			<type>match</type>
363
			<interface>wan</interface>
364
			<defaultqueue>qOthersHigh</defaultqueue>
365
			<source>
366
				<any/>
367
			</source>
368
			<destination>
369
				<any/>
370
				<port>3283-3283</port>
371
			</destination>
372
			<floating>yes</floating>
373
			<wizard>yes</wizard>
374
			<enabled>on</enabled>
375
			<descr><![CDATA[m_Other AppleRemoteDesktop3 outbound]]></descr>
376
			<protocol>udp</protocol>
377
		</rule>
378
		<rule>
379
			<type>match</type>
380
			<interface>wan</interface>
381
			<defaultqueue>qOthersHigh</defaultqueue>
382
			<source>
383
				<any/>
384
			</source>
385
			<destination>
386
				<any/>
387
				<port>5900-5900</port>
388
			</destination>
389
			<floating>yes</floating>
390
			<wizard>yes</wizard>
391
			<enabled>on</enabled>
392
			<descr><![CDATA[m_Other AppleRemoteDesktop4 outbound]]></descr>
393
			<protocol>udp</protocol>
394
		</rule>
395
		<rule>
396
			<type>match</type>
397
			<interface>wan</interface>
398
			<defaultqueue>qOthersHigh</defaultqueue>
399
			<ackqueue>qACK</ackqueue>
400
			<source>
401
				<any/>
402
			</source>
403
			<destination>
404
				<any/>
405
				<port>53-53</port>
406
			</destination>
407
			<floating>yes</floating>
408
			<wizard>yes</wizard>
409
			<enabled>on</enabled>
410
			<descr><![CDATA[m_Other DNS1 outbound]]></descr>
411
			<protocol>tcp</protocol>
412
		</rule>
413
		<rule>
414
			<type>match</type>
415
			<interface>wan</interface>
416
			<defaultqueue>qOthersHigh</defaultqueue>
417
			<source>
418
				<any/>
419
			</source>
420
			<destination>
421
				<any/>
422
				<port>53-53</port>
423
			</destination>
424
			<floating>yes</floating>
425
			<wizard>yes</wizard>
426
			<enabled>on</enabled>
427
			<descr><![CDATA[m_Other DNS2 outbound]]></descr>
428
			<protocol>udp</protocol>
429
		</rule>
430
		<rule>
431
			<type>match</type>
432
			<interface>wan</interface>
433
			<defaultqueue>qOthersHigh</defaultqueue>
434
			<ackqueue>qACK</ackqueue>
435
			<source>
436
				<any/>
437
			</source>
438
			<destination>
439
				<any/>
440
				<port>3306-3306</port>
441
			</destination>
442
			<floating>yes</floating>
443
			<wizard>yes</wizard>
444
			<enabled>on</enabled>
445
			<descr><![CDATA[m_Other MySQL1 outbound]]></descr>
446
			<protocol>tcp</protocol>
447
		</rule>
448
		<rule>
449
			<type>pass</type>
450
			<interface>wan</interface>
451
			<protocol>icmp</protocol>
452
			<source>
453
				<any/>
454
			</source>
455
			<destination>
456
				<any/>
457
			</destination>
458
			<log/>
459
			<descr><![CDATA[WAN ICMP Passthrough]]></descr>
460
		</rule>
461
		<rule>
462
			<id/>
463
			<type>block</type>
464
			<interface>wan</interface>
465
			<tag/>
466
			<tagged/>
467
			<max/>
468
			<max-src-nodes/>
469
			<max-src-conn/>
470
			<max-src-states/>
471
			<statetimeout/>
472
			<statetype>keep state</statetype>
473
			<os/>
474
			<source>
475
				<address>pfBlockerTopSpammers</address>
476
			</source>
477
			<destination>
478
				<any/>
479
			</destination>
480
			<descr><![CDATA[Block SPAM]]></descr>
481
		</rule>
482
		<rule>
483
			<id/>
484
			<type>block</type>
485
			<interface>lan</interface>
486
			<tag/>
487
			<tagged/>
488
			<max/>
489
			<max-src-nodes/>
490
			<max-src-conn/>
491
			<max-src-states/>
492
			<statetimeout/>
493
			<statetype>keep state</statetype>
494
			<os/>
495
			<source>
496
				<any/>
497
			</source>
498
			<destination>
499
				<address>pfBlockerTopSpammers</address>
500
			</destination>
501
			<descr><![CDATA[Block SPAM]]></descr>
502
			<disabled/>
503
		</rule>
504
		<rule>
505
			<type>pass</type>
506
			<interface>lan</interface>
507
			<protocol>icmp</protocol>
508
			<source>
509
				<any/>
510
			</source>
511
			<destination>
512
				<any/>
513
			</destination>
514
			<descr><![CDATA[LAN ICMP Passthrough]]></descr>
515
		</rule>
516
		<rule>
517
			<type>pass</type>
518
			<interface>lan</interface>
519
			<source>
520
				<any/>
521
			</source>
522
			<destination>
523
				<network>lan</network>
524
			</destination>
525
			<descr><![CDATA[ANY -&gt; LAN]]></descr>
526
		</rule>
527
		<rule>
528
			<type>pass</type>
529
			<interface>lan</interface>
530
			<source>
531
				<network>lan</network>
532
			</source>
533
			<destination>
534
				<any/>
535
			</destination>
536
			<descr><![CDATA[LAN -&gt; ANY]]></descr>
537
		</rule>
538
		<rule>
539
			<id/>
540
			<type>pass</type>
541
			<interface>lan</interface>
542
			<ipprotocol>inet6</ipprotocol>
543
			<tag/>
544
			<tagged/>
545
			<max/>
546
			<max-src-nodes/>
547
			<max-src-conn/>
548
			<max-src-states/>
549
			<statetimeout/>
550
			<statetype>keep state</statetype>
551
			<os/>
552
			<source>
553
				<network>lan</network>
554
			</source>
555
			<destination>
556
				<any/>
557
			</destination>
558
			<descr><![CDATA[LAN -&gt; ANY]]></descr>
559
		</rule>
560
		<rule>
561
			<id/>
562
			<type>pass</type>
563
			<interface>opt3</interface>
564
			<tag/>
565
			<tagged/>
566
			<max/>
567
			<max-src-nodes/>
568
			<max-src-conn/>
569
			<max-src-states/>
570
			<statetimeout/>
571
			<statetype>keep state</statetype>
572
			<os/>
573
			<protocol>tcp/udp</protocol>
574
			<source>
575
				<network>opt3</network>
576
			</source>
577
			<destination>
578
				<network>opt3ip</network>
579
				<port>53</port>
580
			</destination>
581
			<descr/>
582
		</rule>
583
		<rule>
584
			<id/>
585
			<type>pass</type>
586
			<interface>opt3</interface>
587
			<tag/>
588
			<tagged/>
589
			<max/>
590
			<max-src-nodes/>
591
			<max-src-conn/>
592
			<max-src-states/>
593
			<statetimeout/>
594
			<statetype>keep state</statetype>
595
			<os/>
596
			<protocol>tcp/udp</protocol>
597
			<source>
598
				<network>opt3</network>
599
			</source>
600
			<destination>
601
				<network>lanip</network>
602
				<port>53</port>
603
			</destination>
604
			<descr/>
605
		</rule>
606
		<rule>
607
			<type>block</type>
608
			<interface>opt3</interface>
609
			<max-src-nodes/>
610
			<max-src-states/>
611
			<statetimeout/>
612
			<statetype>keep state</statetype>
613
			<os/>
614
			<source>
615
				<network>opt3</network>
616
			</source>
617
			<destination>
618
				<network>lan</network>
619
			</destination>
620
			<descr/>
621
		</rule>
622
		<rule>
623
			<type>block</type>
624
			<interface>opt3</interface>
625
			<max-src-nodes/>
626
			<max-src-states/>
627
			<statetimeout/>
628
			<statetype>keep state</statetype>
629
			<os/>
630
			<source>
631
				<network>opt3</network>
632
			</source>
633
			<destination>
634
				<network>pptp</network>
635
			</destination>
636
			<descr/>
637
		</rule>
638
		<rule>
639
			<id/>
640
			<type>block</type>
641
			<interface>opt3</interface>
642
			<tag/>
643
			<tagged/>
644
			<max/>
645
			<max-src-nodes/>
646
			<max-src-conn/>
647
			<max-src-states/>
648
			<statetimeout/>
649
			<statetype>keep state</statetype>
650
			<os/>
651
			<source>
652
				<any/>
653
			</source>
654
			<destination>
655
				<network>opt3</network>
656
			</destination>
657
			<descr/>
658
			<sched>weekdays21to06</sched>
659
		</rule>
660
		<rule>
661
			<id/>
662
			<type>block</type>
663
			<interface>opt3</interface>
664
			<tag/>
665
			<tagged/>
666
			<max/>
667
			<max-src-nodes/>
668
			<max-src-conn/>
669
			<max-src-states/>
670
			<statetimeout/>
671
			<statetype>keep state</statetype>
672
			<os/>
673
			<source>
674
				<network>opt3</network>
675
			</source>
676
			<destination>
677
				<any/>
678
			</destination>
679
			<descr/>
680
			<sched>weekdays21to06</sched>
681
		</rule>
682
		<rule>
683
			<id/>
684
			<type>block</type>
685
			<interface>opt3</interface>
686
			<tag/>
687
			<tagged/>
688
			<max/>
689
			<max-src-nodes/>
690
			<max-src-conn/>
691
			<max-src-states/>
692
			<statetimeout/>
693
			<statetype>keep state</statetype>
694
			<os/>
695
			<source>
696
				<any/>
697
			</source>
698
			<destination>
699
				<network>opt3</network>
700
			</destination>
701
			<descr/>
702
			<sched>weekends</sched>
703
		</rule>
704
		<rule>
705
			<id/>
706
			<type>block</type>
707
			<interface>opt3</interface>
708
			<tag/>
709
			<tagged/>
710
			<max/>
711
			<max-src-nodes/>
712
			<max-src-conn/>
713
			<max-src-states/>
714
			<statetimeout/>
715
			<statetype>keep state</statetype>
716
			<os/>
717
			<source>
718
				<network>opt3</network>
719
			</source>
720
			<destination>
721
				<any/>
722
			</destination>
723
			<descr/>
724
			<sched>weekends</sched>
725
		</rule>
726
		<rule>
727
			<type>pass</type>
728
			<interface>opt3</interface>
729
			<max-src-nodes/>
730
			<max-src-states/>
731
			<statetimeout/>
732
			<statetype>keep state</statetype>
733
			<os/>
734
			<source>
735
				<network>opt3</network>
736
			</source>
737
			<destination>
738
				<any/>
739
			</destination>
740
			<descr/>
741
		</rule>
742
		<rule>
743
			<type>pass</type>
744
			<interface>opt3</interface>
745
			<max-src-nodes/>
746
			<max-src-states/>
747
			<statetimeout/>
748
			<statetype>keep state</statetype>
749
			<os/>
750
			<source>
751
				<any/>
752
			</source>
753
			<destination>
754
				<network>opt3</network>
755
			</destination>
756
			<descr/>
757
		</rule>
758
		<rule>
759
			<type>pass</type>
760
			<interface>pptp</interface>
761
			<max-src-nodes/>
762
			<max-src-states/>
763
			<statetimeout/>
764
			<statetype>keep state</statetype>
765
			<os/>
766
			<protocol>icmp</protocol>
767
			<source>
768
				<any/>
769
			</source>
770
			<destination>
771
				<any/>
772
			</destination>
773
			<descr/>
774
		</rule>
775
		<rule>
776
			<type>pass</type>
777
			<interface>pptp</interface>
778
			<max-src-nodes/>
779
			<max-src-states/>
780
			<statetimeout/>
781
			<statetype>keep state</statetype>
782
			<os/>
783
			<source>
784
				<any/>
785
			</source>
786
			<destination>
787
				<network>pptp</network>
788
			</destination>
789
			<descr/>
790
		</rule>
791
		<rule>
792
			<type>pass</type>
793
			<interface>pptp</interface>
794
			<max-src-nodes/>
795
			<max-src-states/>
796
			<statetimeout/>
797
			<statetype>keep state</statetype>
798
			<os/>
799
			<source>
800
				<network>pptp</network>
801
			</source>
802
			<destination>
803
				<any/>
804
			</destination>
805
			<descr/>
806
		</rule>
807
		<tcpidletimeout>7200</tcpidletimeout>
808
	</filter>
809
	<ipsec>
810
		<preferredoldsa/>
811
	</ipsec>
812
	<aliases>
813
		<alias>
814
			<name>IT</name>
815
			<address>10.0.0.128/26</address>
816
			<descr><![CDATA[IT subnet alias]]></descr>
817
			<type>network</type>
818
			<detail><![CDATA[Entry added Wed, 10 Aug 2011 14:26:42 -0400]]></detail>
819
		</alias>
820
		<alias>
821
			<name>penaltybox</name>
822
			<address/>
823
			<descr/>
824
			<type>host</type>
825
			<detail/>
826
		</alias>
827
		<alias>
828
			<name>pfBlockerTopSpammers</name>
829
			<url>http://127.0.0.1:80/pfblocker.php?pfb=pfBlockerTopSpammers</url>
830
			<updatefreq>32</updatefreq>
831
			<address/>
832
			<descr><![CDATA[pfBlocker country list]]></descr>
833
			<type>urltable</type>
834
			<detail><![CDATA[DO NOT EDIT THIS ALIAS]]></detail>
835
		</alias>
836
	</aliases>
837
	<proxyarp/>
838
	<cron>
839
		<item>
840
			<minute>0</minute>
841
			<hour>*</hour>
842
			<mday>*</mday>
843
			<month>*</month>
844
			<wday>*</wday>
845
			<who>root</who>
846
			<command>/usr/bin/nice -n20 newsyslog</command>
847
		</item>
848
		<item>
849
			<minute>1,31</minute>
850
			<hour>0-5</hour>
851
			<mday>*</mday>
852
			<month>*</month>
853
			<wday>*</wday>
854
			<who>root</who>
855
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
856
		</item>
857
		<item>
858
			<minute>1</minute>
859
			<hour>3</hour>
860
			<mday>1</mday>
861
			<month>*</month>
862
			<wday>*</wday>
863
			<who>root</who>
864
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
865
		</item>
866
		<item>
867
			<minute>*/60</minute>
868
			<hour>*</hour>
869
			<mday>*</mday>
870
			<month>*</month>
871
			<wday>*</wday>
872
			<who>root</who>
873
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
874
		</item>
875
		<item>
876
			<minute>1</minute>
877
			<hour>1</hour>
878
			<mday>*</mday>
879
			<month>*</month>
880
			<wday>*</wday>
881
			<who>root</who>
882
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
883
		</item>
884
		<item>
885
			<minute>*/60</minute>
886
			<hour>*</hour>
887
			<mday>*</mday>
888
			<month>*</month>
889
			<wday>*</wday>
890
			<who>root</who>
891
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
892
		</item>
893
		<item>
894
			<minute>*/5</minute>
895
			<hour>*</hour>
896
			<mday>*</mday>
897
			<month>*</month>
898
			<wday>*</wday>
899
			<who>root</who>
900
			<command>/etc/ping_hosts.sh</command>
901
		</item>
902
		<item>
903
			<minute>*/300</minute>
904
			<hour>*</hour>
905
			<mday>*</mday>
906
			<month>*</month>
907
			<wday>*</wday>
908
			<who>root</who>
909
			<command>/usr/local/sbin/reset_slbd.sh</command>
910
		</item>
911
		<item>
912
			<minute>30</minute>
913
			<hour>12</hour>
914
			<mday>*</mday>
915
			<month>*</month>
916
			<wday>*</wday>
917
			<who>root</who>
918
			<command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
919
		</item>
920
		<item>
921
			<minute>0</minute>
922
			<hour>*</hour>
923
			<mday>*</mday>
924
			<month>*</month>
925
			<wday>*</wday>
926
			<who>root</who>
927
			<command>/usr/local/bin/php -q /usr/local/www/pfblocker.php cron</command>
928
		</item>
929
		<item>
930
			<minute>0,15,30,45</minute>
931
			<hour>*</hour>
932
			<mday>*</mday>
933
			<month>*</month>
934
			<wday>*</wday>
935
			<who>root</who>
936
			<command>/etc/rc.filter_configure_sync</command>
937
		</item>
938
	</cron>
939
	<wol/>
940
	<installedpackages>
941
		<bandwidthd>
942
			<config>
943
				<active_interface>lan</active_interface>
944
				<skipintervals/>
945
				<graphcutoff/>
946
				<promiscuous/>
947
				<outputcdf/>
948
				<recovercdf/>
949
				<filter/>
950
				<drawgraphs>on</drawgraphs>
951
				<meta_refresh/>
952
			</config>
953
		</bandwidthd>
954
		<phpsysinfo>
955
			<config>
956
				<hidepicklist/>
957
				<sensorprogram/>
958
				<showmountpoint>on</showmountpoint>
959
				<showinodes/>
960
				<loadbar/>
961
				<showerrors/>
962
			</config>
963
		</phpsysinfo>
964
		<miniupnpd>
965
			<config>
966
				<enable/>
967
				<enable_upnp/>
968
				<enable_natpmp/>
969
				<iface_array>lan</iface_array>
970
				<download/>
971
				<upload/>
972
				<overridewanip/>
973
				<upnpqueue/>
974
				<logpackets/>
975
				<sysuptime/>
976
				<permdefault/>
977
				<permuser1/>
978
				<permuser2/>
979
				<permuser3/>
980
				<permuser4/>
981
			</config>
982
		</miniupnpd>
983
		<service/>
984
		<carp/>
985
		<openntpd>
986
			<config>
987
				<enable>on</enable>
988
				<interface>lan</interface>
989
			</config>
990
		</openntpd>
991
		<menu/>
992
		<menu>
993
			<name>pfBlocker</name>
994
			<tooltiptext>Configure pfblocker</tooltiptext>
995
			<section>Firewall</section>
996
			<url>/pkg_edit.php?xml=pfblocker.xml</url>
997
		</menu>
998
		<pfblocker>
999
			<config>
1000
				<enable_cb/>
1001
				<enable_log/>
1002
				<inbound_interface>wan</inbound_interface>
1003
				<inbound_deny_action>block</inbound_deny_action>
1004
				<outbound_interface>lan</outbound_interface>
1005
				<outbound_deny_action>reject</outbound_deny_action>
1006
				<credits/>
1007
				<donation/>
1008
			</config>
1009
		</pfblocker>
1010
		<pfblockertopspammers>
1011
			<config>
1012
				<countries>KR,CN,IN,RU,TR,VN,UA,BR,VE,PK</countries>
1013
				<action>Alias_only</action>
1014
			</config>
1015
		</pfblockertopspammers>
1016
		<tab/>
1017
		<package>
1018
			<name>pfBlocker</name>
1019
			<website/>
1020
			<descr><![CDATA[Introduce Enhanced Aliastable Feature to pfsense.&lt;br /&gt;
1021
			Assign many IP urls lists from sites like I-blocklist to a single alias and then choose rule action to take.&lt;br /&gt;
1022
			This package also Block countries and IP ranges.&lt;br /&gt;
1023
			pfBlocker replaces Countryblock and IPblocklist.]]></descr>
1024
			<category>Firewall</category>
1025
			<pkginfolink>http://forum.pfsense.org/index.php/topic,42543.0.html</pkginfolink>
1026
			<config_file>http://pfsense.org/packages/config/pf-blocker/pfblocker.xml</config_file>
1027
			<depends_on_package_base_url>http://files.pfsense.org/packages/8/All/</depends_on_package_base_url>
1028
			<version>1.0.2</version>
1029
			<status>Release</status>
1030
			<required_version>2.0</required_version>
1031
			<maintainer>tom@tomschaefer.org marcellocoutinho@gmail.com</maintainer>
1032
			<configurationfile>pfblocker.xml</configurationfile>
1033
		</package>
1034
	</installedpackages>
1035
	<revision>
1036
		<description><![CDATA[admin@10.0.0.141: /services_router_advertisements.php made unknown change]]></description>
1037
		<time>1360167293</time>
1038
		<username>admin@10.0.0.141</username>
1039
	</revision>
1040
	<widgets>
1041
		<sequence>carp_status-container:col1:close,cpu_graphs-container:col1:close,installed_packages-container:col1:close,captive_portal_status-container:col1:show,system_information-container:col1:show,log-container:col1:close,ipsec-container:col2:close,load_balancer_status-container:col2:close,services_status-container:col2:close,interface_statistics-container:col2:close,gmirror_status-container:col2:none,openvpn-container:col2:none,snort_alerts-container:col2:none,gateways-container:col2:show,traffic_graphs-container:col2:show,interfaces-container:col2:show,picture-container:col2:none,rss-container:col2:none,wake_on_lan-container:col2:none,pfBlocker-container:col2:none,smart_status-container:col2:none</sequence>
1042
		<traffic_graphs-config>WAN_graph-config:show,LAN_graph-config:hide,DMZ_graph-config:hide,TWAN_graph-config:show,CLIENTS_graph-config:show,SPARE_graph-config:hide,WIRELESS_graph-config:hide,refreshInterval=1</traffic_graphs-config>
1043
		<log-config>10</log-config>
1044
		<trafficgraphs>
1045
			<shown>
1046
				<item>wan</item>
1047
				<item>opt3</item>
1048
			</shown>
1049
			<refreshinterval>2</refreshinterval>
1050
		</trafficgraphs>
1051
	</widgets>
1052
	<rrd>
1053
		<enable/>
1054
		<category>traffic</category>
1055
		<style>inverse</style>
1056
	</rrd>
1057
	<captiveportal>
1058
		<client>
1059
			<zone>Client</zone>
1060
			<descr><![CDATA[Client wired and wireless]]></descr>
1061
			<zoneid>8000</zoneid>
1062
			<interface>opt3</interface>
1063
			<maxproc/>
1064
			<timeout>540</timeout>
1065
			<idletimeout>539</idletimeout>
1066
			<freelogins_count/>
1067
			<freelogins_resettimeout/>
1068
			<enable/>
1069
			<auth_method>none</auth_method>
1070
			<reauthenticateacct/>
1071
			<httpsname/>
1072
			<preauthurl/>
1073
			<peruserbw/>
1074
			<bwdefaultdn>3162</bwdefaultdn>
1075
			<bwdefaultup>1581</bwdefaultup>
1076
			<certref/>
1077
			<nomacfilter/>
1078
			<radius_protocol/>
1079
			<redirurl/>
1080
			<radiusip/>
1081
			<radiusip2/>
1082
			<radiusip3/>
1083
			<radiusip4/>
1084
			<radiusport/>
1085
			<radiusport2/>
1086
			<radiusport3/>
1087
			<radiusport4/>
1088
			<radiusacctport/>
1089
			<radiuskey/>
1090
			<radiuskey2/>
1091
			<radiuskey3/>
1092
			<radiuskey4/>
1093
			<radiusvendor>default</radiusvendor>
1094
			<radiussrcip_attribute>wan</radiussrcip_attribute>
1095
			<radmac_format>default</radmac_format>
1096
			<page>
1097
				<htmltext>PEhUTUw+DQo8SEVBRD4NCjxUSVRMRT5CYXJ0ZWxsICYgQmFydGVsbCBDbGllbnQgSW50ZXJuZXQgQWNjZXNzPC9USVRMRT4NCjxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+DQogdGQuZXgxIHsgZm9udC1zaXplOjE2cHg7IGZvbnQtZmFtaWx5OiAiRHJvaWQgU2FucyIsICJIZWx2ZXRpY2EgTmV1ZSIsIGhlbHZldGljYSwgc2Fucy1zZXJpZjsgfQ0KIHAuZXgyIHsgZm9udC1zaXplOjE5cHg7IGZvbnQtZmFtaWx5OiAiRHJvaWQgU2FucyIsICJIZWx2ZXRpY2EgTmV1ZSIsIGhlbHZldGljYSwgc2Fucy1zZXJpZjsgfQ0KIHAuZGlzY2xhaW1lciB7IGZvbnQtc2l6ZTo5cHg7IGZvbnQtZmFtaWx5OiAiRHJvaWQgU2FucyIsICJIZWx2ZXRpY2EgTmV1ZSIsIGhlbHZldGljYSwgc2Fucy1zZXJpZjsgfQ0KIC5mc1N1Ym1pdEJ1dHRvbiB7DQoJYm9yZGVyLXRvcDoJCTJweCBzb2xpZCAjYTNhM2EzOw0KCWJvcmRlci1sZWZ0OgkJMnB4IHNvbGlkICNhM2EzYTM7DQoJYm9yZGVyLXJpZ2h0OgkJMnB4IHNvbGlkICM0ZjRmNGY7DQoJYm9yZGVyLWJvdHRvbToJCTJweCBzb2xpZCAjNGY0ZjRmOw0KCXBhZGRpbmc6CQkxMHB4IDMwcHggIWltcG9ydGFudDsNCglmb250LXNpemU6CQkxNnB4ICFpbXBvcnRhbnQ7DQoJYmFja2dyb3VuZC1jb2xvcjoJI2RkZGRkZDsNCglmb250LXdlaWdodDoJCWJvbGQ7DQoJY29sb3I6CQkJIzAwMDAwMDsNCgkta2h0bWwtYm9yZGVyLXJhZGl1czogOHB4Ow0KCS1tb3otYm9yZGVyLXJhZGl1czogOHB4Ow0KCS13ZWJraXQtYm9yZGVyLXJhZGl1czogOHB4Ow0KCWJvcmRlci1yYWRpdXM6IDhweDsNCgljdXJzb3I6cG9pbnRlcjsNCiB9DQo8L3N0eWxlPg0KPC9IRUFEPg0KPEJPRFkgYmdjb2xvcj0iI0ZGRkZGRiI+DQo8dGFibGUgIGJvcmRlcj0iMCIgYWxpZ249ImNlbnRlciI+PFRSPg0KPFREIGFsaWduPSJjZW50ZXIiIGNsYXNzPSJleDEiPg0KPHAgY2xhc3M9ImV4MiI+DQpUaGlzIHdpcmVsZXNzIGFjY2VzcyBwb2ludCBpcyBvbmx5IGZvciB1c2UgYnkgY2xpZW50cyBvZiBCYXJ0ZWxsICYgQmFydGVsbCBkdXJpbmcgdGhlaXIgdmlzaXQgdG8gb3VyIG9mZmljZS4NCklmIHlvdSBuZWVkIGZhc3RlciBpbnRlcm5ldCBhY2Nlc3MgdGhhbiBhbGxvd2VkIHRocm91Z2ggaGVyZSwgcGxlYXNlIHNlZSBvbmUgb2Ygb3VyIGhlbHBmdWwgZW1wbG95ZWVzLjxCUj48QlI+DQpQbGVhc2UgcmVhZCBhbmQgYWNjZXB0IHRoZSBXaXJlbGVzcyBBY2Nlc3MgRGlzY2xhaW1lciBiZWxvdywgYmVmb3JlIGFjY2VwdGluZyB3aXJlbGVzcyBpbnRlcm5ldCBhY2Nlc3MuDQo8L3A+PEJSPg0KPGZvcm0gbWV0aG9kPSJwb3N0IiBhY3Rpb249IiRQT1JUQUxfQUNUSU9OJCI+DQogICAgIDxpbnB1dCBuYW1lPSJhdXRoX3VzZXIiIHR5cGU9ImhpZGRlbiI+DQogICAgIDxpbnB1dCBuYW1lPSJhdXRoX3Bhc3MiIHR5cGU9ImhpZGRlbiI+DQogICAgIDxpbnB1dCBuYW1lPSJyZWRpcnVybCIgdHlwZT0iaGlkZGVuIiB2YWx1ZT0iJFBPUlRBTF9SRURJUlVSTCQiPg0KICA8aW5wdXQgY2xhc3M9ImZzU3VibWl0QnV0dG9uIiBuYW1lPSJhY2NlcHQiIHR5cGU9InN1Ym1pdCIgdmFsdWU9IkNvbnRpdWUiPg0KPC9mb3JtPg0KPC9URD48L1RSPjxUUj48VEQ+PEJSPjxwIGNsYXNzPSJkaXNjbGFpbWVyIj4NCg0KVGhpcyB3aXJlbGVzcyBuZXR3b3JrICgiV2lGaSIpIGlzIHByb3ZpZGVkIGFzIGEgZnJlZSBzZXJ2aWNlIGJ5IEJhcnRlbGwgJiBCYXJ0ZWxsIEx0ZC4gDQpUaGlzIHB1YmxpYyBXaUZpICJob3RzcG90IiBpcyBpbnRlbmRlZCBmb3IgdGhlIGxpbWl0ZWQgcGVyc29uYWwsIG5vbi1jb21tZXJjaWFsIHVzZSBvZiB2aXNpdG9ycy9jbGllbnRzIGF0IA0KQmFydGVsbCAmIEJhcnRlbGwuIEluIHByb3ZpZGluZyB0aGlzIGZyZWUgV2lGaSwgQmFydGVsbCAmIEJhcnRlbGwgbWF5IHJlc3RyaWN0IGFjY2VzcyB0byBjZXJ0YWluIHNpdGVzIA0KY29uc2lkZXJlZCBieSBCYXJ0ZWxsICYgQmFydGVsbCB0byBiZSBpbGxlZ2FsLCBtYWxpY2lvdXMgb3IgaW5hcHByb3ByaWF0ZSwgYW5kIHdpbGwgdGVybWluYXRlIHlvdXIgYWNjZXNzIHRvIHRoaXMgDQpzZXJ2aWNlIGlmIHlvdSB1c2UgaXQgaW4gdmlvbGF0aW9uIG9mIHRoaXMgQWdyZWVtZW50LiBCYXJ0ZWxsICYgQmFydGVsbCBtYXkgDQpyZXZpc2UgdGhpcyBBZ3JlZW1lbnQgYXQgYW55IHRpbWUgYW5kIGl0IGlzIHlvdXIgcmVzcG9uc2liaWxpdHkgdG8gcmV2aWV3IGl0IGZvciBhbnkgY2hhbmdlcyBlYWNoIHRpbWUuIA0KQmFydGVsbCAmIEJhcnRlbGwgZG9lcyBub3QgZXhlcmNpc2UgY29udHJvbCBvdmVyIHRoZSBzaXRlcyB5b3UgbWF5IHZpc2l0IGFuZCBwcm9kdWN0cyB5b3UgbWF5IHVzZSB3aGlsZSB1c2luZyB0aGlzIA0KV2lGaS4gWW91IHVzZSB0aGlzIFdpRmkgYXQgeW91ciBvd24gcmlzay48QlI+PEJSPg0KDQpZb3UgYWdyZWUgdGhhdCB0aGlzIFdpRmkgbWF5IG5vdCBiZSB1bmludGVycnVwdGVkIG9yIGVycm9yLWZyZWUsIHZpcnVzZXMgb3Igb3RoZXIgaGFybWZ1bCBhcHBsaWNhdGlvbnMgDQptYXkgYmUgYXZhaWxhYmxlIHRocm91Z2ggdGhpcyBXaUZpLCBCYXJ0ZWxsICYgQmFydGVsbCBkb2VzIG5vdCBndWFyYW50ZWUgdGhlIHNlY3VyaXR5IG9mIHRoaXMgV2lGaSBhbmQgdW5hdXRob3JpemVkIA0KdGhpcmQgcGFydGllcyBtYXkgYWNjZXNzIHlvdXIgY29tcHV0ZXIgb3IgZmlsZXMgb3IgbW9uaXRvciB5b3VyIGNvbm5lY3Rpb24uIFRoaXMgV2lGaSBpcyBwcm92aWRlZCBvbiBhbiANCiJhcyBpcyIsICJhcyBhdmFpbGFibGUiIGJhc2lzIHdpdGhvdXQgd2FycmFudGllcyBvZiBhbnkga2luZC48QlI+PEJSPg0KDQpCeSBsb2dnaW5nIGluIHRvIHRoaXMgV2lGaSwgeW91IGFjY2VwdCB0aGVzZSB0ZXJtcyBhbmQgY29uZGl0aW9ucyBhbmQgYWdyZWUgeW91ciBhY2Nlc3MgdG8gdGhpcyBXaUZpIA0KaXMgYXQgeW91ciBvd24gcmlzayBhbmQgaXMgYXQgdGhlIHNvbGUgZGlzY3JldGlvbiBvZiBCYXJ0ZWxsICYgQmFydGVsbCBhbmQgbWF5IGJlIG1vbml0b3JlZCwgc3VzcGVuZGVkIG9yIA0KdGVybWluYXRlZCBhdCBhbnkgdGltZSBmb3IgYW55IHJlYXNvbiwgaW5jbHVkaW5nIGJ1dCBub3QgbGltaXRlZCB0bywgdmlvbGF0aW9uIG9mIGludGVybmV0IHVzZSBndWlkZWxpbmVzLCANCnZpb2xhdGlvbiBvZiB0aGlzIEFncmVlbWVudCwgYWN0aW9ucyBieSB5b3UgdGhhdCBtYXkgbGVhZCB0byBsaWFiaWxpdHkgZm9yIEJhcnRlbGwgJiBCYXJ0ZWxsLCBkaXNydXB0aW9uIGJ5IHlvdSANCm9mIGFub3RoZXLigJlzIGFjY2VzcyB0byB0aGlzIFdpRmksIGFjdGlvbnMgYnkgeW91IHdoaWNoIHZpb2xhdGUgdGhlIHJpZ2h0cyBvZiBCYXJ0ZWxsICYgQmFydGVsbCBvciBvZiBhbnkgDQp0aGlyZCBwYXJ0eSwgb3IgYWN0aW9ucyBieSB5b3Ugd2hpY2ggdmlvbGF0ZSBhbnkgZmVkZXJhbCwgc3RhdGUgb3IgbG9jYWwgbGF3LiBZb3UgYWxzbyBhZ3JlZSBub3QgdG8gdXRpbGl6ZSANCnRoaXMgV2lGaSBpbiBhbnkgdW5hdXRob3JpemVkIG1hbm5lciB0byB1cGxvYWQgb3IgZG93bmxvYWQgYW55IGNvcHlyaWdodGVkIG1hdHRlciwgaW4gYW55IGZvcm1hdCwgbm9yIHRvIA0KdXBsb2FkIG9yIGRvd25sb2FkIGFueSBwb3Jub2dyYXBoaWMsIGFkdWx0LW9yaWVudGVkLCBoYXRlIG9yIHNwYW0gbWF0dGVyLCBpbiBhbnkgZm9ybWF0PC9wPg0KPC9URD48L1RSPjwvVEFCTEU+DQo8L0JPRFk+</htmltext>
1098
			</page>
1099
			<allowedip>
1100
				<ip>10.0.0.1</ip>
1101
				<sn>32</sn>
1102
				<descr/>
1103
			</allowedip>
1104
		</client>
1105
	</captiveportal>
1106
	<sysctl>
1107
		<item>
1108
			<tunable>net.inet.tcp.blackhole</tunable>
1109
			<descr><![CDATA[Drop packets to closed TCP ports without returning a RST]]></descr>
1110
			<value>default</value>
1111
		</item>
1112
		<item>
1113
			<tunable>net.inet.udp.blackhole</tunable>
1114
			<descr><![CDATA[Do not send ICMP port unreachable messages for closed UDP ports]]></descr>
1115
			<value>default</value>
1116
		</item>
1117
		<item>
1118
			<tunable>net.inet.ip.random_id</tunable>
1119
			<descr><![CDATA[Randomize the ID field in IP packets (default is 0: sequential IP IDs)]]></descr>
1120
			<value>default</value>
1121
		</item>
1122
		<item>
1123
			<tunable>net.inet.tcp.drop_synfin</tunable>
1124
			<descr><![CDATA[Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)]]></descr>
1125
			<value>default</value>
1126
		</item>
1127
		<item>
1128
			<tunable>net.inet.ip.redirect</tunable>
1129
			<descr><![CDATA[Sending of IPv4 ICMP redirects]]></descr>
1130
			<value>default</value>
1131
		</item>
1132
		<item>
1133
			<tunable>net.inet6.ip6.redirect</tunable>
1134
			<descr><![CDATA[Sending of IPv6 ICMP redirects]]></descr>
1135
			<value>default</value>
1136
		</item>
1137
		<item>
1138
			<tunable>net.inet.tcp.syncookies</tunable>
1139
			<descr><![CDATA[Generate SYN cookies for outbound SYN-ACK packets]]></descr>
1140
			<value>default</value>
1141
		</item>
1142
		<item>
1143
			<tunable>net.inet.tcp.recvspace</tunable>
1144
			<descr><![CDATA[Maximum incoming TCP datagram size]]></descr>
1145
			<value>default</value>
1146
		</item>
1147
		<item>
1148
			<tunable>net.inet.tcp.sendspace</tunable>
1149
			<descr><![CDATA[Maximum outgoing TCP datagram size]]></descr>
1150
			<value>default</value>
1151
		</item>
1152
		<item>
1153
			<tunable>net.inet.ip.fastforwarding</tunable>
1154
			<descr><![CDATA[Fastforwarding (see http://lists.freebsd.org/pipermail/freebsd-net/2004-January/002534.html)]]></descr>
1155
			<value>default</value>
1156
		</item>
1157
		<item>
1158
			<tunable>net.inet.tcp.delayed_ack</tunable>
1159
			<descr><![CDATA[Do not delay ACK to try and piggyback it onto a data packet]]></descr>
1160
			<value>default</value>
1161
		</item>
1162
		<item>
1163
			<tunable>net.inet.udp.maxdgram</tunable>
1164
			<descr><![CDATA[Maximum outgoing UDP datagram size]]></descr>
1165
			<value>default</value>
1166
		</item>
1167
		<item>
1168
			<tunable>net.link.bridge.pfil_onlyip</tunable>
1169
			<descr><![CDATA[Handling of non-IP packets which are not passed to pfil (see if_bridge(4))]]></descr>
1170
			<value>default</value>
1171
		</item>
1172
		<item>
1173
			<tunable>net.link.tap.user_open</tunable>
1174
			<descr><![CDATA[Allow unprivileged access to tap(4) device nodes]]></descr>
1175
			<value>default</value>
1176
		</item>
1177
		<item>
1178
			<tunable>kern.randompid</tunable>
1179
			<descr><![CDATA[Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())]]></descr>
1180
			<value>default</value>
1181
		</item>
1182
		<item>
1183
			<tunable>net.inet.tcp.inflight.enable</tunable>
1184
			<descr><![CDATA[The system will attempt to calculate the bandwidth delay product for each connection and limit the amount of data queued to the network to just the amount required to maintain optimum throughput. ]]></descr>
1185
			<value>default</value>
1186
		</item>
1187
		<item>
1188
			<tunable>net.inet.icmp.icmplim</tunable>
1189
			<descr><![CDATA[Set ICMP Limits]]></descr>
1190
			<value>default</value>
1191
		</item>
1192
		<item>
1193
			<tunable>net.inet.tcp.tso</tunable>
1194
			<descr><![CDATA[TCP Offload engine]]></descr>
1195
			<value>default</value>
1196
		</item>
1197
		<item>
1198
			<tunable>net.inet.ip.portrange.first</tunable>
1199
			<descr><![CDATA[Set the ephemeral port range starting port]]></descr>
1200
			<value>default</value>
1201
		</item>
1202
		<item>
1203
			<tunable>hw.syscons.kbd_reboot</tunable>
1204
			<descr><![CDATA[Enables ctrl+alt+delete]]></descr>
1205
			<value>default</value>
1206
		</item>
1207
		<item>
1208
			<tunable>kern.ipc.maxsockbuf</tunable>
1209
			<descr><![CDATA[Maximum socket buffer size]]></descr>
1210
			<value>default</value>
1211
		</item>
1212
		<item>
1213
			<descr><![CDATA[Set to 0 to disable filtering on the incoming and outgoing member interfaces.]]></descr>
1214
			<tunable>net.link.bridge.pfil_member</tunable>
1215
			<value>1</value>
1216
		</item>
1217
		<item>
1218
			<descr><![CDATA[Set to 1 to enable filtering on the bridge interface]]></descr>
1219
			<tunable>net.link.bridge.pfil_bridge</tunable>
1220
			<value>0</value>
1221
		</item>
1222
		<item>
1223
			<tunable>net.link.ether.ipfw</tunable>
1224
			<value>1</value>
1225
			<descr/>
1226
		</item>
1227
		<item>
1228
			<tunable>net.inet.ip.fw.one_pass</tunable>
1229
			<value>1</value>
1230
			<descr/>
1231
		</item>
1232
	</sysctl>
1233
	<gateways>
1234
		<gateway_item>
1235
			<interface>wan</interface>
1236
			<gateway>10.1.10.1</gateway>
1237
			<name>GW_WAN</name>
1238
			<weight>1</weight>
1239
			<interval>5</interval>
1240
			<descr><![CDATA[Interface wan Static Gateway]]></descr>
1241
			<monitor>68.85.46.49</monitor>
1242
			<defaultgw/>
1243
			<down>120</down>
1244
			<ipprotocol>inet</ipprotocol>
1245
		</gateway_item>
1246
		<gateway_item>
1247
			<interface>opt1</interface>
1248
			<gateway>*</gateway>
1249
			<name>GWv6</name>
1250
			<weight>1</weight>
1251
			<ipprotocol>inet6</ipprotocol>
1252
			<interval/>
1253
			<descr/>
1254
			<defaultgw/>
1255
		</gateway_item>
1256
	</gateways>
1257
	<dyndnses>
1258
		<dyndns>
1259
			<type>dyndns</type>
1260
			<username/>
1261
			<password/>
1262
			<host/>
1263
			<mx/>
1264
			<interface>wan</interface>
1265
			<descr><![CDATA[Upgraded Dyndns dyndns]]></descr>
1266
		</dyndns>
1267
	</dyndnses>
1268
	<openvpn/>
1269
	<shaper>
1270
		<queue>
1271
			<interface>lan</interface>
1272
			<name>lan</name>
1273
			<scheduler>HFSC</scheduler>
1274
			<bandwidth/>
1275
			<bandwidthtype/>
1276
			<enabled>on</enabled>
1277
			<queue>
1278
				<name>qLink</name>
1279
				<interface>lan</interface>
1280
				<qlimit>1000</qlimit>
1281
				<priority>2</priority>
1282
				<bandwidth>20</bandwidth>
1283
				<bandwidthtype>%</bandwidthtype>
1284
				<enabled>on</enabled>
1285
				<default>on</default>
1286
				<ecn>on</ecn>
1287
			</queue>
1288
			<queue>
1289
				<name>qInternet</name>
1290
				<interface>lan</interface>
1291
				<bandwidth>16</bandwidth>
1292
				<bandwidthtype>Mb</bandwidthtype>
1293
				<enabled>on</enabled>
1294
				<ecn>on</ecn>
1295
				<linkshare3>16Mb</linkshare3>
1296
				<linkshare>on</linkshare>
1297
				<upperlimit3>16Mb</upperlimit3>
1298
				<upperlimit>on</upperlimit>
1299
				<queue>
1300
					<name>qACK</name>
1301
					<interface>lan</interface>
1302
					<priority>6</priority>
1303
					<bandwidth>18</bandwidth>
1304
					<bandwidthtype>%</bandwidthtype>
1305
					<enabled>on</enabled>
1306
					<ecn>on</ecn>
1307
					<linkshare3>18%</linkshare3>
1308
					<linkshare>on</linkshare>
1309
				</queue>
1310
				<queue>
1311
					<name>qOthersHigh</name>
1312
					<interface>lan</interface>
1313
					<priority>4</priority>
1314
					<bandwidth>9</bandwidth>
1315
					<bandwidthtype>%</bandwidthtype>
1316
					<enabled>on</enabled>
1317
					<ecn>on</ecn>
1318
					<linkshare3>9%</linkshare3>
1319
					<linkshare>on</linkshare>
1320
				</queue>
1321
				<queue>
1322
					<name>qOthersLow</name>
1323
					<interface>lan</interface>
1324
					<priority>3</priority>
1325
					<bandwidth>10</bandwidth>
1326
					<bandwidthtype>%</bandwidthtype>
1327
					<enabled>on</enabled>
1328
					<ecn>on</ecn>
1329
					<linkshare3>10%</linkshare3>
1330
					<linkshare>on</linkshare>
1331
				</queue>
1332
			</queue>
1333
		</queue>
1334
		<queue>
1335
			<interface>opt3</interface>
1336
			<name>opt3</name>
1337
			<scheduler>HFSC</scheduler>
1338
			<bandwidth/>
1339
			<bandwidthtype>Kb</bandwidthtype>
1340
			<queue>
1341
				<name>qLink</name>
1342
				<interface>opt3</interface>
1343
				<qlimit>500</qlimit>
1344
				<priority>2</priority>
1345
				<bandwidth>20</bandwidth>
1346
				<bandwidthtype>%</bandwidthtype>
1347
				<enabled>on</enabled>
1348
				<default>on</default>
1349
				<ecn>on</ecn>
1350
			</queue>
1351
			<queue>
1352
				<name>qInternet</name>
1353
				<interface>opt3</interface>
1354
				<bandwidth>16</bandwidth>
1355
				<bandwidthtype>Mb</bandwidthtype>
1356
				<enabled>on</enabled>
1357
				<ecn>on</ecn>
1358
				<linkshare3>16Mb</linkshare3>
1359
				<linkshare>on</linkshare>
1360
				<upperlimit3>16Mb</upperlimit3>
1361
				<upperlimit>on</upperlimit>
1362
				<queue>
1363
					<name>qACK</name>
1364
					<interface>opt3</interface>
1365
					<priority>6</priority>
1366
					<bandwidth>18</bandwidth>
1367
					<bandwidthtype>%</bandwidthtype>
1368
					<enabled>on</enabled>
1369
					<ecn>on</ecn>
1370
					<linkshare3>18%</linkshare3>
1371
					<linkshare>on</linkshare>
1372
				</queue>
1373
				<queue>
1374
					<name>qOthersHigh</name>
1375
					<interface>opt3</interface>
1376
					<priority>4</priority>
1377
					<bandwidth>9</bandwidth>
1378
					<bandwidthtype>%</bandwidthtype>
1379
					<enabled>on</enabled>
1380
					<ecn>on</ecn>
1381
					<linkshare3>9%</linkshare3>
1382
					<linkshare>on</linkshare>
1383
				</queue>
1384
				<queue>
1385
					<name>qOthersLow</name>
1386
					<interface>opt3</interface>
1387
					<priority>3</priority>
1388
					<bandwidth>10</bandwidth>
1389
					<bandwidthtype>%</bandwidthtype>
1390
					<enabled>on</enabled>
1391
					<ecn>on</ecn>
1392
					<linkshare3>10%</linkshare3>
1393
					<linkshare>on</linkshare>
1394
				</queue>
1395
			</queue>
1396
		</queue>
1397
		<queue>
1398
			<interface>wan</interface>
1399
			<name>wan</name>
1400
			<scheduler>HFSC</scheduler>
1401
			<bandwidth>3</bandwidth>
1402
			<bandwidthtype>Mb</bandwidthtype>
1403
			<enabled>on</enabled>
1404
			<queue>
1405
				<name>qACK</name>
1406
				<interface>wan</interface>
1407
				<priority>6</priority>
1408
				<bandwidth>18</bandwidth>
1409
				<bandwidthtype>%</bandwidthtype>
1410
				<enabled>on</enabled>
1411
				<ecn>on</ecn>
1412
				<linkshare3>18%</linkshare3>
1413
				<linkshare>on</linkshare>
1414
			</queue>
1415
			<queue>
1416
				<name>qDefault</name>
1417
				<interface>wan</interface>
1418
				<priority>3</priority>
1419
				<bandwidth>9</bandwidth>
1420
				<bandwidthtype>%</bandwidthtype>
1421
				<enabled>on</enabled>
1422
				<default>on</default>
1423
				<ecn>on</ecn>
1424
			</queue>
1425
			<queue>
1426
				<name>qOthersHigh</name>
1427
				<interface>wan</interface>
1428
				<priority>4</priority>
1429
				<bandwidth>9</bandwidth>
1430
				<bandwidthtype>%</bandwidthtype>
1431
				<enabled>on</enabled>
1432
				<ecn>on</ecn>
1433
				<linkshare3>9%</linkshare3>
1434
				<linkshare>on</linkshare>
1435
			</queue>
1436
			<queue>
1437
				<name>qOthersLow</name>
1438
				<interface>wan</interface>
1439
				<priority>2</priority>
1440
				<bandwidth>10</bandwidth>
1441
				<bandwidthtype>%</bandwidthtype>
1442
				<enabled>on</enabled>
1443
				<ecn>on</ecn>
1444
				<linkshare3>10%</linkshare3>
1445
				<linkshare>on</linkshare>
1446
			</queue>
1447
		</queue>
1448
	</shaper>
1449
	<ppps/>
1450
	<dhcrelay/>
1451
	<l7shaper>
1452
		<container/>
1453
	</l7shaper>
1454
	<dnshaper/>
1455
	<ezshaper>
1456
		<step1>
1457
			<numberofconnections>2</numberofconnections>
1458
			<numberoflocalinterfaces>4</numberoflocalinterfaces>
1459
		</step1>
1460
		<step4>
1461
			<enable>on</enable>
1462
			<bandwidthunit>%</bandwidthunit>
1463
			<address>penaltybox</address>
1464
			<bandwidth>10</bandwidth>
1465
		</step4>
1466
		<step7>
1467
			<enable>on</enable>
1468
			<msrdp>H</msrdp>
1469
			<vnc>H</vnc>
1470
			<appleremotedesktop>H</appleremotedesktop>
1471
			<pcanywhere>D</pcanywhere>
1472
			<irc>D</irc>
1473
			<jabber>D</jabber>
1474
			<icq>D</icq>
1475
			<aolinstantmessenger>D</aolinstantmessenger>
1476
			<msnmessenger>D</msnmessenger>
1477
			<teamspeak>D</teamspeak>
1478
			<pptp>D</pptp>
1479
			<ipsec>D</ipsec>
1480
			<streamingmp3>D</streamingmp3>
1481
			<rtsp>D</rtsp>
1482
			<http>D</http>
1483
			<smtp>D</smtp>
1484
			<pop3>D</pop3>
1485
			<imap>D</imap>
1486
			<lotusnotes>D</lotusnotes>
1487
			<dns>H</dns>
1488
			<icmp>D</icmp>
1489
			<smb>D</smb>
1490
			<snmp>D</snmp>
1491
			<mysqlserver>H</mysqlserver>
1492
			<nntp>D</nntp>
1493
			<cvsup>D</cvsup>
1494
			<slingbox>D</slingbox>
1495
			<hbci>D</hbci>
1496
		</step7>
1497
		<step3>
1498
			<local0download>256</local0download>
1499
			<local0downloadspeed>Kb</local0downloadspeed>
1500
			<local1download>0</local1download>
1501
			<local1downloadspeed>Kb</local1downloadspeed>
1502
			<local2download>0</local2download>
1503
			<local2downloadspeed>Kb</local2downloadspeed>
1504
			<local3download>0</local3download>
1505
			<local3downloadspeed>Kb</local3downloadspeed>
1506
			<conn0upload>256</conn0upload>
1507
			<conn0uploadspeed>Kb</conn0uploadspeed>
1508
			<conn1upload>0</conn1upload>
1509
			<conn1uploadspeed>Kb</conn1uploadspeed>
1510
			<connuploadspeed>%</connuploadspeed>
1511
			<conndownloadspeed>%</conndownloadspeed>
1512
		</step3>
1513
		<step2>
1514
			<uploadscheduler>HFSC</uploadscheduler>
1515
			<connupload>3</connupload>
1516
			<connuploadspeed>Mb</connuploadspeed>
1517
			<conndownload>16</conndownload>
1518
			<conndownloadspeed>Mb</conndownloadspeed>
1519
			<conn0downloadscheduler>HFSC</conn0downloadscheduler>
1520
			<conn0interface>lan</conn0interface>
1521
			<conn1downloadscheduler>HFSC</conn1downloadscheduler>
1522
			<conn1interface>opt3</conn1interface>
1523
		</step2>
1524
	</ezshaper>
1525
	<voucher/>
1526
	<wireless/>
1527
	<bridges/>
1528
	<cert/>
1529
	<schedules>
1530
		<schedule>
1531
			<name>weekdays21to06</name>
1532
			<descr/>
1533
			<timerange>
1534
				<position>1,2,3,4,5</position>
1535
				<hour>0:00-6:00</hour>
1536
				<rangedescr>0:00 to 06:00</rangedescr>
1537
			</timerange>
1538
			<timerange>
1539
				<position>1,2,3,4,5</position>
1540
				<hour>20:00-23:59</hour>
1541
				<rangedescr>20:00 to 23:59</rangedescr>
1542
			</timerange>
1543
			<schedlabel>50b6e283d9f2a</schedlabel>
1544
		</schedule>
1545
		<schedule>
1546
			<name>weekends</name>
1547
			<descr/>
1548
			<timerange>
1549
				<position>6,7</position>
1550
				<hour>0:00-23:59</hour>
1551
				<rangedescr/>
1552
			</timerange>
1553
			<schedlabel>50b6e29ee6cc9</schedlabel>
1554
		</schedule>
1555
	</schedules>
1556
	<l2tp>
1557
		<radius>
1558
			<server/>
1559
			<secret/>
1560
		</radius>
1561
		<remoteip>10.0.0.0</remoteip>
1562
		<localip>10.0.0.56</localip>
1563
		<l2tp_subnet>24</l2tp_subnet>
1564
		<mode>off</mode>
1565
		<interface>wan</interface>
1566
		<n_l2tp_units>6</n_l2tp_units>
1567
		<secret>bartellvpn</secret>
1568
		<paporchap>chap</paporchap>
1569
		<dns1>10.0.0.1</dns1>
1570
		<user>
1571
			<name>rstaph</name>
1572
			<ip/>
1573
			<password>sceptre</password>
1574
		</user>
1575
	</l2tp>
1576
	<virtualip/>
1577
	<rrddata/>
1578
	<dhcpdv6>
1579
		<lan>
1580
			<range>
1581
				<from>8</from>
1582
				<to>8</to>
1583
			</range>
1584
			<prefixrange>
1585
				<from/>
1586
				<to/>
1587
				<prefixlength>48</prefixlength>
1588
			</prefixrange>
1589
			<defaultleasetime/>
1590
			<maxleasetime/>
1591
			<netmask/>
1592
			<failover_peerip/>
1593
			<domain/>
1594
			<domainsearchlist/>
1595
			<enable/>
1596
			<ddnsdomain/>
1597
			<tftp/>
1598
			<ldap/>
1599
			<nextserver/>
1600
			<filename/>
1601
			<rootpath/>
1602
			<dhcpv6leaseinlocaltime/>
1603
			<numberoptions/>
1604
			<ramode>managed</ramode>
1605
			<rapriority>medium</rapriority>
1606
			<rainterface></rainterface>
1607
			<radomainsearchlist/>
1608
		</lan>
1609
	</dhcpdv6>
1610
	<gifs>
1611
		<gif>
1612
			<ipaddr/>
1613
			<if>wan</if>
1614
			<tunnel-local-addr>8</tunnel-local-addr>
1615
			<tunnel-remote-addr>8</tunnel-remote-addr>
1616
			<tunnel-remote-net>64</tunnel-remote-net>
1617
			<remote-addr>216.66.22.2</remote-addr>
1618
			<descr><![CDATA[he.net V6]]></descr>
1619
			<gifif>gif0</gifif>
1620
		</gif>
1621
	</gifs>
1622
</pfsense>
    (1-1/1)