Project

General

Profile

Download (14.9 KB) Statistics
| Branch: | Tag: | Revision:
1
<?xml version="1.0"?>
2
<!-- pfSense default system configuration -->
3
<pfsense>
4
	<version>2.9</version>
5
	<lastchange></lastchange>
6
	<theme>nervecenter</theme>
7
	<sysctl>
8
		<item>
9
			<desc>Drop packets to closed TCP ports without returning a RST</desc>
10
			<tunable>net.inet.tcp.blackhole</tunable>
11
			<value>2</value>
12
		</item>
13
		<item>
14
			<desc>Do not send ICMP port unreachable messages for closed UDP ports</desc>
15
			<tunable>net.inet.udp.blackhole</tunable>
16
			<value>1</value>
17
		</item>
18
		<item>
19
			<desc>Randomize the ID field in IP packets (default is 0: sequential IP IDs)</desc>
20
			<tunable>net.inet.ip.random_id</tunable>
21
			<value>1</value>
22
		</item>
23
		<item>
24
			<desc>Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)</desc>
25
			<tunable>net.inet.tcp.drop_synfin</tunable>
26
			<value>1</value>
27
		</item>
28
		<item>
29
			<desc>Disable sending IPv4 redirects</desc>
30
			<tunable>net.inet.ip.redirect</tunable>
31
			<value>0</value>
32
		</item>
33
		<item>
34
			<desc>Disable sending IPv6 redirects</desc>
35
			<tunable>net.inet6.ip6.redirect</tunable>
36
			<value>0</value>
37
		</item>
38
		<item>
39
			<desc>Generate SYN cookies for outbound SYN-ACK packets</desc>
40
			<tunable>net.inet.tcp.syncookies</tunable>
41
			<value>1</value>
42
		</item>
43
		<item>
44
			<desc>Maximum incoming/outgoing TCP datagram size (receive)</desc>
45
			<tunable>net.inet.tcp.recvspace</tunable>
46
			<value>65228</value>
47
		</item>
48
		<item>
49
			<desc>Maximum incoming/outgoing TCP datagram size (send)</desc>
50
			<tunable>net.inet.tcp.sendspace</tunable>
51
			<value>65228</value>
52
		</item>
53
		<item>
54
			<desc>IP Fastforwarding</desc>
55
			<tunable>net.inet.ip.fastforwarding</tunable>
56
			<value>1</value>
57
		</item>
58
		<item>
59
			<desc>Do not delay ACK to try and piggyback it onto a data packet</desc>
60
			<tunable>net.inet.tcp.delayed_ack</tunable>
61
			<value>0</value>
62
		</item>
63
		<item>
64
			<desc>Maximum outgoing UDP datagram size</desc>
65
			<tunable>net.inet.udp.maxdgram</tunable>
66
			<value>57344</value>
67
		</item>
68
		<item>
69
			<desc>Handling of non-IP packets which are not passed to pfil (see if_bridge(4))</desc>
70
			<tunable>net.link.bridge.pfil_onlyip</tunable>
71
			<value>0</value>
72
		</item>
73
		<item>
74
			<desc>Allow unprivileged access to tap(4) device nodes</desc>
75
			<tunable>net.link.tap.user_open</tunable>
76
			<value>1</value>
77
		</item>
78
		<item>
79
			<desc>Verbosity of the rndtest driver (0: do not display results on console)</desc>
80
			<tunable>kern.rndtest.verbose</tunable>
81
			<value>0</value>
82
		</item>
83
		<item>
84
			<desc>Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())</desc>
85
			<tunable>kern.randompid</tunable>
86
			<value>347</value>
87
		</item>
88
	</sysctl>
89
	<system>
90
		<optimization>normal</optimization>
91
		<hostname>pfSense</hostname>
92
		<domain>local</domain>
93
		<dnsserver></dnsserver>
94
		<dnsallowoverride/>
95
		<username>admin</username>
96
		<password>$1$dSJImFph$GvZ7.1UbuWu.Yb8etC0re.</password>
97
		<timezone>Etc/UTC</timezone>
98
		<time-update-interval>300</time-update-interval>
99
		<timeservers>pool.ntp.org</timeservers>
100
		<webgui>
101
			<protocol>http</protocol>
102
			<!--
103
			<port></port>
104
			<certificate></certificate>
105
			<private-key></private-key>
106
			<noassigninterfaces/>
107
			<expanddiags/>
108
			<noantilockout></noantilockout>
109
			-->
110
		</webgui>
111
                <disablenatreflection>yes</disablenatreflection>
112
		<!-- <disableconsolemenu/> -->
113
		<!-- <disablefirmwarecheck/> -->
114
		<!-- <shellcmd></shellcmd> -->
115
		<!-- <earlyshellcmd></earlyshellcmd> -->
116
		<!-- <harddiskstandby></harddiskstandby> -->
117
	</system>
118
	<interfaces>
119
		<lan>
120
			<if>sis0</if>
121
			<ipaddr>192.168.1.1</ipaddr>
122
			<subnet>24</subnet>
123
			<media></media>
124
			<mediaopt></mediaopt>
125
			<bandwidth>100</bandwidth>
126
			<bandwidthtype>Mb</bandwidthtype>
127
			<!--
128
			<wireless>
129
				*see below (opt[n])*
130
			</wireless>
131
			-->
132
		</lan>
133
		<wan>
134
			<if>sis1</if>
135
			<mtu></mtu>
136
			<ipaddr>dhcp</ipaddr>
137
			<!-- *or* ipv4-address *or* 'pppoe' *or* 'pptp' *or* 'bigpond' -->
138
			<subnet></subnet>
139
			<gateway></gateway>
140
			<blockpriv/>
141
                        <disableftpproxy/>
142
			<dhcphostname></dhcphostname>
143
			<media></media>
144
			<mediaopt></mediaopt>
145
			<bandwidth>100</bandwidth>
146
			<bandwidthtype>Mb</bandwidthtype>
147
			<!--
148
			<wireless>
149
				*see below (opt[n])*
150
			</wireless>
151
			-->
152
		</wan>
153
		<!--
154
		<opt[n]>
155
			<enable/>
156
			<descr></descr>
157
			<if></if>
158
			<ipaddr></ipaddr>
159
			<subnet></subnet>
160
			<media></media>
161
			<mediaopt></mediaopt>
162
			<bridge>lan|wan|opt[n]</bridge>
163
			<wireless>
164
				<mode>hostap *or* bss *or* ibss</mode>
165
				<ssid></ssid>
166
				<channel></channel>
167
				<wep>
168
					<enable/>
169
					<key>
170
						<txkey/>
171
						<value></value>
172
					</key>
173
				</wep>
174
			</wireless>
175
		</opt[n]>
176
		-->
177
	</interfaces>
178
	<!--
179
	<vlans>
180
		<vlan>
181
			<tag></tag>
182
			<if></if>
183
			<descr></descr>
184
		</vlan>
185
	</vlans>
186
	-->
187
	<staticroutes>
188
		<!--
189
		<route>
190
			<interface>lan|opt[n]|pptp</interface>
191
			<network>xxx.xxx.xxx.xxx/xx</network>
192
			<gateway>xxx.xxx.xxx.xxx</gateway>
193
			<descr></descr>
194
		</route>
195
		-->
196
	</staticroutes>
197
	<pppoe>
198
		<username></username>
199
		<password></password>
200
		<provider></provider>
201
		<!--
202
		<ondemand/>
203
		<timeout></timeout>
204
		-->
205
	</pppoe>
206
	<pptp>
207
		<username></username>
208
		<password></password>
209
		<local></local>
210
		<subnet></subnet>
211
		<remote></remote>
212
		<!--
213
		<ondemand/>
214
		<timeout></timeout>
215
		-->
216
	</pptp>
217
	<bigpond>
218
		<username></username>
219
		<password></password>
220
		<authserver></authserver>
221
		<authdomain></authdomain>
222
		<minheartbeatinterval></minheartbeatinterval>
223
	</bigpond>
224
	<dyndns>
225
		<!-- <enable/> -->
226
		<type>dyndns</type>
227
		<username></username>
228
		<password></password>
229
		<host></host>
230
		<mx></mx>
231
		<!-- <wildcard/> -->
232
	</dyndns>
233
	<dhcpd>
234
		<lan>
235
			<enable/>
236
			<range>
237
				<from>192.168.1.100</from>
238
				<to>192.168.1.199</to>
239
			</range>
240
			<!--
241
			<winsserver>xxx.xxx.xxx.xxx</winsserver>
242
			<defaultleasetime></defaultleasetime>
243
			<maxleasetime></maxleasetime>
244
			<gateway>xxx.xxx.xxx.xxx</gateway>
245
			<domain></domain>
246
			<dnsserver></dnsserver>
247
			<ntpserver>xxx.xxx.xxx.xxx</ntpserver>
248
			<next-server></next-server>
249
			<filename></filename>
250
			-->
251
		</lan>
252
		<!--
253
		<opt[n]>
254
			...
255
		</opt[n]>
256
		-->
257
		<!--
258
		<staticmap>
259
			<mac>xx:xx:xx:xx:xx:xx</mac>
260
			<ipaddr>xxx.xxx.xxx.xxx</ipaddr>
261
			<descr></descr>
262
		</staticmap>
263
		-->
264
	</dhcpd>
265
	<pptpd>
266
		<mode><!-- off *or* server *or* redir --></mode>
267
		<redir></redir>
268
		<localip></localip>
269
		<remoteip></remoteip>
270
		<!-- <accounting/> -->
271
		<!--
272
		<user>
273
			<name></name>
274
			<password></password>
275
		</user>
276
		-->
277
	</pptpd>
278
	<ovpn>
279
		<!--
280
		<server>
281
			<enable/>
282
			<ca_cert></ca_cert>
283
			<srv_cert></srv_cert>
284
			<srv_key></srv_key>
285
			<dh_param></dh_param>
286
			<verb></verb>
287
			<tun_iface></tun_iface>
288
			<port></port>
289
			<bind_iface></bind_iface>
290
			<cli2cli/>
291
			<maxcli></maxcli>
292
			<prefix></prefix>
293
			<ipblock></ipblock>
294
			<crypto></crypto>
295
			<dupcn/>
296
			<psh_options>
297
				<redir></redir>
298
				<redir_loc></redir_loc>
299
				<rte_delay></rte_delay>
300
				<ping></ping>
301
				<pingrst></pingrst>
302
				<pingexit></pingexit>
303
				<inact></inact>
304
			</psh_options>
305
		</server>
306
		<client>
307
			<tunnel></tunnel>
308
			<ca_cert></ca_cert>
309
			<cli_cert></cli_cert>
310
			<cli_key></cli_key>
311
			<type></type>
312
			<tunnel>
313
				<if></if>
314
				<proto></proto>
315
				<cport></cport>
316
				<saddr></saddr>
317
				<sport></sport>
318
				<crypto></crypto>
319
			</tunnel>
320
		</client>
321
		-->
322
	</ovpn>
323
	<dnsmasq>
324
		<enable/>
325
		<!--
326
		<hosts>
327
			<host></host>
328
			<domain></domain>
329
			<ip></ip>
330
			<descr></descr>
331
		</hosts>
332
		-->
333
	</dnsmasq>
334
	<snmpd>
335
		<!-- <enable/> -->
336
		<syslocation></syslocation>
337
		<syscontact></syscontact>
338
		<rocommunity>public</rocommunity>
339
	</snmpd>
340
	<diag>
341
		<ipv6nat>
342
			<!-- <enable/> -->
343
			<ipaddr></ipaddr>
344
		</ipv6nat>
345
	</diag>
346
	<bridge>
347
		<!-- <filteringbridge/> -->
348
	</bridge>
349
	<syslog>
350
		<!--
351
		<reverse/>
352
		<enable/>
353
		<remoteserver>xxx.xxx.xxx.xxx</remoteserver>
354
		<filter/>
355
		<dhcp/>
356
		<system/>
357
		<nologdefaultblock/>
358
		-->
359
	</syslog>
360
	<!--
361
	<captiveportal>
362
		<enable/>
363
		<interface>lan|opt[n]</interface>
364
		<idletimeout>minutes</idletimeout>
365
		<timeout>minutes</timeout>
366
		<page>
367
			<htmltext></htmltext>
368
			<errtext></errtext>
369
		</page>
370
		<httpslogin/>
371
		<httpsname></httpsname>
372
		<certificate></certificate>
373
		<private-key></private-key>
374
		<redirurl></redirurl>
375
		<radiusip></radiusip>
376
		<radiusport></radiusport>
377
		<radiuskey></radiuskey>
378
		<nomacfilter/>
379
	</captiveportal>
380
	-->
381
	<nat>
382
		<ipsecpassthru>
383
			<enable/>
384
		</ipsecpassthru>
385
		<!--
386
		<rule>
387
			<interface></interface>
388
			<external-address></external-address>
389
			<protocol></protocol>
390
			<external-port></external-port>
391
			<target></target>
392
			<local-port></local-port>
393
			<descr></descr>
394
		</rule>
395
		-->
396
		<!--
397
		<onetoone>
398
			<interface></interface>
399
			<external>xxx.xxx.xxx.xxx</external>
400
			<internal>xxx.xxx.xxx.xxx</internal>
401
			<subnet></subnet>
402
			<descr></descr>
403
		</onetoone>
404
		-->
405
		<!--
406
		<advancedoutbound>
407
			<enable/>
408
			<rule>
409
				<interface></interface>
410
				<source>
411
					<network>xxx.xxx.xxx.xxx/xx</network>
412
				</source>
413
				<destination>
414
					<not/>
415
					<any/>
416
					*or*
417
					<network>xxx.xxx.xxx.xxx/xx</network>
418
				</destination>
419
				<target>xxx.xxx.xxx.xxx</target>
420
				<descr></descr>
421
			</rule>
422
		</advancedoutbound>
423
		-->
424
		<!--
425
		<servernat>
426
			<ipaddr></ipaddr>
427
			<descr></descr>
428
		</servernat>
429
		-->
430
	</nat>
431
	<filter>
432
		<!-- <tcpidletimeout></tcpidletimeout> -->
433
		<rule>
434
			<type>pass</type>
435
			<descr>Default LAN -&gt; any</descr>
436
			<interface>lan</interface>
437
			<source>
438
				<network>lan</network>
439
			</source>
440
			<destination>
441
				<any/>
442
			</destination>
443
		</rule>
444
		<!-- rule syntax:
445
		<rule>
446
			<disabled/>
447
			<type>pass|block|reject</type>
448
			<descr>...</descr>
449
			<interface>lan|opt[n]|wan|pptp</interface>
450
			<protocol>tcp|udp|tcp/udp|...</protocol>
451
			<icmptype></icmptype>
452
			<source>
453
				<not/>
454

    
455
				<address>xxx.xxx.xxx.xxx(/xx) or alias</address>
456
				*or*
457
				<network>lan|opt[n]|pptp</network>
458
				*or*
459
				<any/>
460

    
461
				<port>a[-b]</port>
462
			</source>
463
			<destination>
464
				*same as for source*
465
			</destination>
466
			<frags/>
467
			<log/>
468
		</rule>
469
		-->
470
	</filter>
471
	<shaper>
472
		<!-- <enable/> -->
473
		<!-- <schedulertype>hfsc</schedulertype> -->
474
		<!-- rule syntax:
475
		<rule>
476
			<disabled/>
477
			<descr></descr>
478

    
479
			<targetpipe>number (zero based)</targetpipe>
480
			*or*
481
			<targetqueue>number (zero based)</targetqueue>
482

    
483
			<interface>lan|wan|opt[n]|pptp</interface>
484
			<protocol>tcp|udp</protocol>
485
			<direction>in|out</direction>
486
			<source>
487
				<not/>
488

    
489
				<address>xxx.xxx.xxx.xxx(/xx)</address>
490
				*or*
491
				<network>lan|opt[n]|pptp</network>
492
				*or*
493
				<any/>
494

    
495
				<port>a[-b]</port>
496
			</source>
497
			<destination>
498
				*same as for source*
499
			</destination>
500

    
501
			<iplen>from[-to]</iplen>
502
			<iptos>(!)lowdelay,throughput,reliability,mincost,congestion</iptos>
503
			<tcpflags>(!)fin,syn,rst,psh,ack,urg</tcpflags>
504
		</rule>
505
		<pipe>
506
			<descr></descr>
507
			<bandwidth></bandwidth>
508
			<delay></delay>
509
			<mask>source|destination</mask>
510
		</pipe>
511
		<queue>
512
			<descr></descr>
513
			<targetpipe>number (zero based)</targetpipe>
514
			<weight></weight>
515
			<mask>source|destination</mask>
516
		</queue>
517
		-->
518
	</shaper>
519
	<ipsec>
520
                <preferredoldsa/>
521
		<!-- <enable/> -->
522
		<!-- syntax:
523
		<tunnel>
524
			<disabled/>
525
			<auto/>
526
			<descr></descr>
527
			<interface>lan|wan|opt[n]</interface>
528
			<local-subnet>
529
				<address>xxx.xxx.xxx.xxx(/xx)</address>
530
				*or*
531
				<network>lan|opt[n]</network>
532
			</local-subnet>
533
			<remote-subnet>xxx.xxx.xxx.xxx/xx</remote-subnet>
534
			<remote-gateway></remote-gateway>
535
			<p1>
536
				<mode></mode>
537
				<myident>
538
					<myaddress/>
539
					*or*
540
					<address>xxx.xxx.xxx.xxx</address>
541
					*or*
542
					<fqdn>the.fq.dn</fqdn>
543
				</myident>
544
				<encryption-algorithm></encryption-algorithm>
545
				<hash-algorithm></hash-algorithm>
546
				<dhgroup></dhgroup>
547
				<lifetime></lifetime>
548
				<pre-shared-key></pre-shared-key>
549
			</p1>
550
			<p2>
551
				<protocol></protocol>
552
				<encryption-algorithm-option></encryption-algorithm-option>
553
				<hash-algorithm-option></hash-algorithm-option>
554
				<pfsgroup></pfsgroup>
555
				<lifetime></lifetime>
556
			</p2>
557
		</tunnel>
558
		<mobileclients>
559
			<enable/>
560
			<p1>
561
				<mode></mode>
562
				<myident>
563
					<myaddress/>
564
					*or*
565
					<address>xxx.xxx.xxx.xxx</address>
566
					*or*
567
					<fqdn>the.fq.dn</fqdn>
568
				</myident>
569
				<encryption-algorithm></encryption-algorithm>
570
				<hash-algorithm></hash-algorithm>
571
				<dhgroup></dhgroup>
572
				<lifetime></lifetime>
573
			</p1>
574
			<p2>
575
				<protocol></protocol>
576
				<encryption-algorithm-option></encryption-algorithm-option>
577
				<hash-algorithm-option></hash-algorithm-option>
578
				<pfsgroup></pfsgroup>
579
				<lifetime></lifetime>
580
			</p2>
581
		</mobileclients>
582
		<mobilekey>
583
			<ident></ident>
584
			<pre-shared-key></pre-shared-key>
585
		</mobilekey>
586
		-->
587
	</ipsec>
588
	<aliases>
589
		<!--
590
		<alias>
591
			<name></name>
592
			<address>xxx.xxx.xxx.xxx(/xx)</address>
593
			<descr></descr>
594
		</alias>
595
		-->
596
	</aliases>
597
	<proxyarp>
598
		<!--
599
		<proxyarpnet>
600
			<network>xxx.xxx.xxx.xxx/xx</network>
601
			*or*
602
			<range>
603
				<from>xxx.xxx.xxx.xxx</from>
604
				<to>xxx.xxx.xxx.xxx</to>
605
			</range>
606
		</proxyarpnet>
607
		-->
608
	</proxyarp>
609
	<cron>
610
		<item>
611
			<minute>0</minute>
612
			<hour>*</hour>
613
			<mday>*</mday>
614
			<month>*</month>
615
			<wday>*</wday>
616
			<who>root</who>
617
			<command>/usr/bin/nice -n20 newsyslog</command>
618
		</item>
619
		<item>
620
			<minute>1,31</minute>
621
			<hour>0-5</hour>
622
			<mday>*</mday>
623
			<month>*</month>
624
			<wday>*</wday>
625
			<who>root</who>
626
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
627
		</item>
628
		<item>
629
			<minute>1</minute>
630
			<hour>*</hour>
631
			<mday>1</mday>
632
			<month>*</month>
633
			<wday>*</wday>
634
			<who>root</who>
635
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
636
		</item>
637
		<item>
638
			<minute>*/60</minute>
639
			<hour>*</hour>
640
			<mday>*</mday>
641
			<month>*</month>
642
			<wday>*</wday>
643
			<who>root</who>
644
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
645
		</item>
646
		<item>
647
			<minute>1</minute>
648
			<hour>1</hour>
649
			<mday>*</mday>
650
			<month>*</month>
651
			<wday>*</wday>
652
			<who>root</who>
653
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
654
		</item>
655
		<item>
656
			<minute>*/60</minute>
657
			<hour>*</hour>
658
			<mday>*</mday>
659
			<month>*</month>
660
			<wday>*</wday>
661
			<who>root</who>
662
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
663
		</item>
664
		<item>
665
			<minute>*/60</minute>
666
			<hour>*</hour>
667
			<mday>*</mday>
668
			<month>*</month>
669
			<wday>*</wday>
670
			<who>root</who>
671
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 3600 snort2c</command>
672
		</item>
673
		<item>
674
			<minute>*/5</minute>
675
			<hour>*</hour>
676
			<mday>*</mday>
677
			<month>*</month>
678
			<wday>*</wday>
679
			<who>root</who>
680
			<command>/usr/local/bin/checkreload.sh</command>
681
		</item>
682
		<item>
683
			<minute>*/5</minute>
684
			<hour>*</hour>
685
			<mday>*</mday>
686
			<month>*</month>
687
			<wday>*</wday>
688
			<who>root</who>
689
			<command>/etc/ping_hosts.sh</command>
690
		</item>
691
		<item>
692
			<minute>*/300</minute>
693
			<hour>*</hour>
694
			<mday>*</mday>
695
			<month>*</month>
696
			<wday>*</wday>
697
			<who>root</who>
698
			<command>/usr/local/sbin/reset_slbd.sh</command>
699
		</item>
700
	</cron>
701
	<wol>
702
		<!--
703
		<wolentry>
704
			<interface>lan|opt[n]</interface>
705
			<mac>xx:xx:xx:xx:xx:xx</mac>
706
			<descr></descr>
707
		</wolentry>
708
		-->
709
	</wol>
710
	<installedpackages>
711
	</installedpackages>
712
</pfsense>
    (1-1/1)