Project

General

Profile

Download (10.4 KB) Statistics
| Branch: | Tag: | Revision:
1
<?xml version="1.0"?>
2
<!-- pfSense default system configuration -->
3
<pfsense>
4
	<version>2.0</version>
5
	<lastchange></lastchange>
6
	<theme>metallic</theme>
7
	<system>
8
		<enablesshd/>
9
		<optimization>normal</optimization>
10
		<schedulertype>priq</schedulertype>
11
		<hostname>pfSense</hostname>
12
		<domain>local</domain>
13
		<dnsserver></dnsserver>
14
		<dnsallowoverride/>
15
		<username>admin</username>
16
		<password>$1$dSJImFph$GvZ7.1UbuWu.Yb8etC0re.</password>
17
		<timezone>Etc/UTC</timezone>
18
		<time-update-interval>300</time-update-interval>
19
		<timeservers>pool.ntp.org</timeservers>
20
		<webgui>
21
			<protocol>http</protocol>
22
			<!--
23
			<port></port>
24
			<certificate></certificate>
25
			<private-key></private-key>
26
			<noassigninterfaces/>
27
			<expanddiags/>
28
			<noantilockout></noantilockout>
29
			-->
30
		</webgui>
31
		<!-- <disableconsolemenu/> -->
32
		<!-- <disablefirmwarecheck/> -->
33
		<!-- <shellcmd></shellcmd> -->
34
		<!-- <earlyshellcmd></earlyshellcmd> -->
35
		<!-- <harddiskstandby></harddiskstandby> -->
36
	</system>
37
	<interfaces>
38
		<lan>
39
			<if>sis0</if>
40
			<ipaddr>192.168.1.1</ipaddr>
41
			<subnet>24</subnet>
42
			<media></media>
43
			<mediaopt></mediaopt>
44
			<bandwidth>100</bandwidth>
45
			<bandwidthtype>Mb</bandwidthtype>
46
			<!--
47
			<wireless>
48
				*see below (opt[n])*
49
			</wireless>
50
			-->
51
		</lan>
52
		<wan>
53
			<if>sis1</if>
54
			<mtu></mtu>
55
			<ipaddr>dhcp</ipaddr>
56
			<!-- *or* ipv4-address *or* 'pppoe' *or* 'pptp' *or* 'bigpond' -->
57
			<subnet></subnet>
58
			<gateway></gateway>
59
			<blockpriv/>
60
			<disableftpproxy/>
61
			<dhcphostname></dhcphostname>
62
			<media></media>
63
			<mediaopt></mediaopt>
64
			<bandwidth>100</bandwidth>
65
			<bandwidthtype>Mb</bandwidthtype>
66
			<!--
67
			<wireless>
68
				*see below (opt[n])*
69
			</wireless>
70
			-->
71
		</wan>
72
		<!--
73
		<opt[n]>
74
			<enable/>
75
			<descr></descr>
76
			<if></if>
77
			<ipaddr></ipaddr>
78
			<subnet></subnet>
79
			<media></media>
80
			<mediaopt></mediaopt>
81
			<bridge>lan|wan|opt[n]</bridge>
82
			<wireless>
83
				<mode>hostap *or* bss *or* ibss</mode>
84
				<ssid></ssid>
85
				<channel></channel>
86
				<wep>
87
					<enable/>
88
					<key>
89
						<txkey/>
90
						<value></value>
91
					</key>
92
				</wep>
93
			</wireless>
94
		</opt[n]>
95
		-->
96
	</interfaces>
97
	<!--
98
	<vlans>
99
		<vlan>
100
			<tag></tag>
101
			<if></if>
102
			<descr></descr>
103
		</vlan>
104
	</vlans>
105
	-->
106
	<staticroutes>
107
		<!--
108
		<route>
109
			<interface>lan|opt[n]|pptp</interface>
110
			<network>xxx.xxx.xxx.xxx/xx</network>
111
			<gateway>xxx.xxx.xxx.xxx</gateway>
112
			<descr></descr>
113
		</route>
114
		-->
115
	</staticroutes>
116
	<pppoe>
117
		<username></username>
118
		<password></password>
119
		<provider></provider>
120
		<!--
121
		<ondemand/>
122
		<timeout></timeout>
123
		-->
124
	</pppoe>
125
	<pptp>
126
		<username></username>
127
		<password></password>
128
		<local></local>
129
		<subnet></subnet>
130
		<remote></remote>
131
		<!--
132
		<ondemand/>
133
		<timeout></timeout>
134
		-->
135
	</pptp>
136
	<bigpond>
137
		<username></username>
138
		<password></password>
139
		<authserver></authserver>
140
		<authdomain></authdomain>
141
		<minheartbeatinterval></minheartbeatinterval>
142
	</bigpond>
143
	<dyndns>
144
		<!-- <enable/> -->
145
		<type>dyndns</type>
146
		<username></username>
147
		<password></password>
148
		<host></host>
149
		<mx></mx>
150
		<!-- <wildcard/> -->
151
	</dyndns>
152
	<dhcpd>
153
		<lan>
154
			<enable/>
155
			<range>
156
				<from>192.168.1.100</from>
157
				<to>192.168.1.199</to>
158
			</range>
159
			<!--
160
			<winsserver>xxx.xxx.xxx.xxx</winsserver>
161
			<defaultleasetime></defaultleasetime>
162
			<maxleasetime></maxleasetime>
163
			<gateway>xxx.xxx.xxx.xxx</gateway>
164
			<domain></domain>
165
			<dnsserver></dnsserver>
166
			<next-server></next-server>
167
			<filename></filename>
168
			-->
169
		</lan>
170
		<!--
171
		<opt[n]>
172
			...
173
		</opt[n]>
174
		-->
175
		<!--
176
		<staticmap>
177
			<mac>xx:xx:xx:xx:xx:xx</mac>
178
			<ipaddr>xxx.xxx.xxx.xxx</ipaddr>
179
			<descr></descr>
180
		</staticmap>
181
		-->
182
	</dhcpd>
183
	<pptpd>
184
		<mode><!-- off *or* server *or* redir --></mode>
185
		<redir></redir>
186
		<localip></localip>
187
		<remoteip></remoteip>
188
		<!-- <accounting/> -->
189
		<!--
190
		<user>
191
			<name></name>
192
			<password></password>
193
		</user>
194
		-->
195
	</pptpd>
196
	<ovpn>
197
		<!--
198
		<server>
199
			<enable/>
200
			<ca_cert></ca_cert>
201
			<srv_cert></srv_cert>
202
			<srv_key></srv_key>
203
			<dh_param></dh_param>
204
			<verb></verb>
205
			<tun_iface></tun_iface>
206
			<port></port>
207
			<bind_iface></bind_iface>
208
			<cli2cli/>
209
			<maxcli></maxcli>
210
			<prefix></prefix>
211
			<ipblock></ipblock>
212
			<crypto></crypto>
213
			<dupcn/>
214
			<psh_options>
215
				<redir></redir>
216
				<redir_loc></redir_loc>
217
				<rte_delay></rte_delay>
218
				<ping></ping>
219
				<pingrst></pingrst>
220
				<pingexit></pingexit>
221
				<inact></inact>
222
			</psh_options>
223
		</server>
224
		<client>
225
			<tunnel></tunnel>
226
			<ca_cert></ca_cert>
227
			<cli_cert></cli_cert>
228
			<cli_key></cli_key>
229
			<type></type>
230
			<tunnel>
231
				<if></if>
232
				<proto></proto>
233
				<cport></cport>
234
				<saddr></saddr>
235
				<sport></sport>
236
				<crypto></crypto>
237
			</tunnel>
238
		</client>
239
		-->
240
	</ovpn>
241
	<dnsmasq>
242
		<enable/>
243
		<!--
244
		<hosts>
245
			<host></host>
246
			<domain></domain>
247
			<ip></ip>
248
			<descr></descr>
249
		</hosts>
250
		-->
251
	</dnsmasq>
252
	<snmpd>
253
		<!-- <enable/> -->
254
		<syslocation></syslocation>
255
		<syscontact></syscontact>
256
		<rocommunity>public</rocommunity>
257
	</snmpd>
258
	<diag>
259
		<ipv6nat>
260
			<!-- <enable/> -->
261
			<ipaddr></ipaddr>
262
		</ipv6nat>
263
	</diag>
264
	<bridge>
265
		<!-- <filteringbridge/> -->
266
	</bridge>
267
	<syslog>
268
		<!--
269
		<reverse/>
270
		<enable/>
271
		<remoteserver>xxx.xxx.xxx.xxx</remoteserver>
272
		<filter/>
273
		<dhcp/>
274
		<system/>
275
		<nologdefaultblock/>
276
		-->
277
	</syslog>
278
	<!--
279
	<captiveportal>
280
		<enable/>
281
		<interface>lan|opt[n]</interface>
282
		<idletimeout>minutes</idletimeout>
283
		<timeout>minutes</timeout>
284
		<page>
285
			<htmltext></htmltext>
286
			<errtext></errtext>
287
		</page>
288
		<httpslogin/>
289
		<httpsname></httpsname>
290
		<certificate></certificate>
291
		<private-key></private-key>
292
		<redirurl></redirurl>
293
		<radiusip></radiusip>
294
		<radiusport></radiusport>
295
		<radiuskey></radiuskey>
296
		<nomacfilter/>
297
	</captiveportal>
298
	-->
299
	<nat>
300
		<ipsecpassthru>
301
			<enable/>
302
		</ipsecpassthru>
303
		<!--
304
		<rule>
305
			<interface></interface>
306
			<external-address></external-address>
307
			<protocol></protocol>
308
			<external-port></external-port>
309
			<target></target>
310
			<local-port></local-port>
311
			<descr></descr>
312
		</rule>
313
		-->
314
		<!--
315
		<onetoone>
316
			<interface></interface>
317
			<external>xxx.xxx.xxx.xxx</external>
318
			<internal>xxx.xxx.xxx.xxx</internal>
319
			<subnet></subnet>
320
			<descr></descr>
321
		</onetoone>
322
		-->
323
		<!--
324
		<advancedoutbound>
325
			<enable/>
326
			<rule>
327
				<interface></interface>
328
				<source>
329
					<network>xxx.xxx.xxx.xxx/xx</network>
330
				</source>
331
				<destination>
332
					<not/>
333
					<any/>
334
					*or*
335
					<network>xxx.xxx.xxx.xxx/xx</network>
336
				</destination>
337
				<target>xxx.xxx.xxx.xxx</target>
338
				<descr></descr>
339
			</rule>
340
		</advancedoutbound>
341
		-->
342
		<!--
343
		<servernat>
344
			<ipaddr></ipaddr>
345
			<descr></descr>
346
		</servernat>
347
		-->
348
	</nat>
349
	<filter>
350
		<!-- <tcpidletimeout></tcpidletimeout> -->
351
		<rule>
352
			<type>pass</type>
353
			<descr>Default LAN -&gt; any</descr>
354
			<interface>lan</interface>
355
			<source>
356
				<network>lan</network>
357
			</source>
358
			<destination>
359
				<any/>
360
			</destination>
361
		</rule>
362
		<!-- rule syntax:
363
		<rule>
364
			<disabled/>
365
			<type>pass|block|reject</type>
366
			<descr>...</descr>
367
			<interface>lan|opt[n]|wan|pptp</interface>
368
			<protocol>tcp|udp|tcp/udp|...</protocol>
369
			<icmptype></icmptype>
370
			<source>
371
				<not/>
372

    
373
				<address>xxx.xxx.xxx.xxx(/xx) or alias</address>
374
				*or*
375
				<network>lan|opt[n]|pptp</network>
376
				*or*
377
				<any/>
378

    
379
				<port>a[-b]</port>
380
			</source>
381
			<destination>
382
				*same as for source*
383
			</destination>
384
			<frags/>
385
			<log/>
386
		</rule>
387
		-->
388
	</filter>
389
	<shaper>
390
		<!-- <enable/> -->
391
		<!-- rule syntax:
392
		<rule>
393
			<disabled/>
394
			<descr></descr>
395

    
396
			<targetpipe>number (zero based)</targetpipe>
397
			*or*
398
			<targetqueue>number (zero based)</targetqueue>
399

    
400
			<interface>lan|wan|opt[n]|pptp</interface>
401
			<protocol>tcp|udp</protocol>
402
			<direction>in|out</direction>
403
			<source>
404
				<not/>
405

    
406
				<address>xxx.xxx.xxx.xxx(/xx)</address>
407
				*or*
408
				<network>lan|opt[n]|pptp</network>
409
				*or*
410
				<any/>
411

    
412
				<port>a[-b]</port>
413
			</source>
414
			<destination>
415
				*same as for source*
416
			</destination>
417

    
418
			<iplen>from[-to]</iplen>
419
			<iptos>(!)lowdelay,throughput,reliability,mincost,congestion</iptos>
420
			<tcpflags>(!)fin,syn,rst,psh,ack,urg</tcpflags>
421
		</rule>
422
		<pipe>
423
			<descr></descr>
424
			<bandwidth></bandwidth>
425
			<delay></delay>
426
			<mask>source|destination</mask>
427
		</pipe>
428
		<queue>
429
			<descr></descr>
430
			<targetpipe>number (zero based)</targetpipe>
431
			<weight></weight>
432
			<mask>source|destination</mask>
433
		</queue>
434
		-->
435
	</shaper>
436
	<ipsec>
437
                <preferredoldsa/>
438
		<!-- <enable/> -->
439
		<!-- syntax:    
440
		<tunnel>
441
			<disabled/>
442
			<auto/>
443
			<descr></descr>
444
			<interface>lan|wan|opt[n]</interface>
445
			<local-subnet>
446
				<address>xxx.xxx.xxx.xxx(/xx)</address>
447
				*or*
448
				<network>lan|opt[n]</network>
449
			</local-subnet>
450
			<remote-subnet>xxx.xxx.xxx.xxx/xx</remote-subnet>
451
			<remote-gateway></remote-gateway>
452
			<p1>
453
				<mode></mode>
454
				<myident>
455
					<myaddress/>
456
					*or*
457
					<address>xxx.xxx.xxx.xxx</address>
458
					*or*
459
					<fqdn>the.fq.dn</fqdn>
460
				</myident>
461
				<encryption-algorithm></encryption-algorithm>
462
				<hash-algorithm></hash-algorithm>
463
				<dhgroup></dhgroup>
464
				<lifetime></lifetime>
465
				<pre-shared-key></pre-shared-key>
466
			</p1>
467
			<p2>
468
				<protocol></protocol>
469
				<encryption-algorithm-option></encryption-algorithm-option>
470
				<hash-algorithm-option></hash-algorithm-option>
471
				<pfsgroup></pfsgroup>
472
				<lifetime></lifetime>
473
			</p2>
474
		</tunnel>
475
		<mobileclients>
476
			<enable/>
477
			<p1>
478
				<mode></mode>
479
				<myident>
480
					<myaddress/>
481
					*or*
482
					<address>xxx.xxx.xxx.xxx</address>
483
					*or*
484
					<fqdn>the.fq.dn</fqdn>
485
				</myident>
486
				<encryption-algorithm></encryption-algorithm>
487
				<hash-algorithm></hash-algorithm>
488
				<dhgroup></dhgroup>
489
				<lifetime></lifetime>
490
			</p1>
491
			<p2>
492
				<protocol></protocol>
493
				<encryption-algorithm-option></encryption-algorithm-option>
494
				<hash-algorithm-option></hash-algorithm-option>
495
				<pfsgroup></pfsgroup>
496
				<lifetime></lifetime>
497
			</p2>
498
		</mobileclients>
499
		<mobilekey>
500
			<ident></ident>
501
			<pre-shared-key></pre-shared-key>
502
		</mobilekey>
503
		-->
504
	</ipsec>
505
	<aliases>
506
		<!--
507
		<alias>
508
			<name></name>
509
			<address>xxx.xxx.xxx.xxx(/xx)</address>
510
			<descr></descr>
511
		</alias>
512
		-->
513
	</aliases>
514
	<proxyarp>
515
		<!--
516
		<proxyarpnet>
517
			<network>xxx.xxx.xxx.xxx/xx</network>
518
			*or*
519
			<range>
520
				<from>xxx.xxx.xxx.xxx</from>
521
				<to>xxx.xxx.xxx.xxx</to>
522
			</range>
523
		</proxyarpnet>
524
		-->
525
	</proxyarp>
526
	<wol>
527
		<!--
528
		<wolentry>
529
			<interface>lan|opt[n]</interface>
530
			<mac>xx:xx:xx:xx:xx:xx</mac>
531
			<descr></descr>
532
		</wolentry>
533
		-->
534
	</wol>
535
	<installedpackages>
536
	</installedpackages>
537
</pfsense>
(1-1/2)