forked from NationTech/harmony
		
	
		
			
				
	
	
		
			941 lines
		
	
	
		
			36 KiB
		
	
	
	
		
			XML
		
	
	
	
	
	
			
		
		
	
	
			941 lines
		
	
	
		
			36 KiB
		
	
	
	
		
			XML
		
	
	
	
	
	
| <?xml version="1.0"?>
 | |
| <opnsense>
 | |
|   <theme>opnsense</theme>
 | |
|   <sysctl version="1.0.0">
 | |
|     <item uuid="81d201fc-5b0e-44d5-9feb-aad8d5eb5c58">
 | |
|       <tunable>vfs.read_max</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Increase UFS read-ahead speeds to match the state of hard drives and NCQ.</descr>
 | |
|     </item>
 | |
|     <item uuid="1d4d8672-d740-4274-8729-2bbd9a0c1ee3">
 | |
|       <tunable>net.inet.ip.portrange.first</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Set the ephemeral port range to be lower.</descr>
 | |
|     </item>
 | |
|     <item uuid="c9c2b79d-6825-44e2-9c57-58a76a3cdda1">
 | |
|       <tunable>net.inet.tcp.blackhole</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Drop packets to closed TCP ports without returning a RST</descr>
 | |
|     </item>
 | |
|     <item uuid="2bb189ec-368b-4be3-ad06-3eb67a599687">
 | |
|       <tunable>net.inet.udp.blackhole</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Do not send ICMP port unreachable messages for closed UDP ports</descr>
 | |
|     </item>
 | |
|     <item uuid="ba255494-ae47-48ad-bc35-ce6b76441879">
 | |
|       <tunable>net.inet.ip.random_id</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Randomize the ID field in IP packets</descr>
 | |
|     </item>
 | |
|     <item uuid="b6b18051-830f-4b27-81ec-f772b14681e2">
 | |
|       <tunable>net.inet.ip.sourceroute</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>
 | |
|         Source routing is another way for an attacker to try to reach non-routable addresses behind your box.
 | |
|         It can also be used to probe for information about your internal networks. These functions come enabled
 | |
|         as part of the standard FreeBSD core system.
 | |
|       </descr>
 | |
|     </item>
 | |
|     <item uuid="ea21409c-62d6-4040-aa2b-36bd01af5578">
 | |
|       <tunable>net.inet.ip.accept_sourceroute</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>
 | |
|         Source routing is another way for an attacker to try to reach non-routable addresses behind your box.
 | |
|         It can also be used to probe for information about your internal networks. These functions come enabled
 | |
|         as part of the standard FreeBSD core system.
 | |
|       </descr>
 | |
|     </item>
 | |
|     <item uuid="1613256c-ef7e-4b53-a44c-234440046293">
 | |
|       <tunable>net.inet.icmp.log_redirect</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>
 | |
|         This option turns off the logging of redirect packets because there is no limit and this could fill
 | |
|         up your logs consuming your whole hard drive.
 | |
|       </descr>
 | |
|     </item>
 | |
|     <item uuid="1ba88c72-6e5b-4f19-abba-351c2b76d5dc">
 | |
|       <tunable>net.inet.tcp.drop_synfin</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)</descr>
 | |
|     </item>
 | |
|     <item uuid="6f99f7f4-6824-44eb-986e-bc40c6db07a9">
 | |
|       <tunable>net.inet6.ip6.redirect</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Enable sending IPv6 redirects</descr>
 | |
|     </item>
 | |
|     <item uuid="ec76b735-42a4-43b2-adce-98451f21f06d">
 | |
|       <tunable>net.inet6.ip6.use_tempaddr</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Enable privacy settings for IPv6 (RFC 4941)</descr>
 | |
|     </item>
 | |
|     <item uuid="15077673-4e46-476d-8a10-637217fff1ea">
 | |
|       <tunable>net.inet6.ip6.prefer_tempaddr</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Prefer privacy addresses and use them over the normal addresses</descr>
 | |
|     </item>
 | |
|     <item uuid="713f8cd7-8436-477b-937b-5839033b75cf">
 | |
|       <tunable>net.inet.tcp.syncookies</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Generate SYN cookies for outbound SYN-ACK packets</descr>
 | |
|     </item>
 | |
|     <item uuid="9efc9598-4a5d-4221-9224-6b3a50332a88">
 | |
|       <tunable>net.inet.tcp.recvspace</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Maximum incoming/outgoing TCP datagram size (receive)</descr>
 | |
|     </item>
 | |
|     <item uuid="c1b7ce2b-1fc2-45ee-a017-eb9c31dc2f9e">
 | |
|       <tunable>net.inet.tcp.sendspace</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Maximum incoming/outgoing TCP datagram size (send)</descr>
 | |
|     </item>
 | |
|     <item uuid="f640420a-ecee-4de7-bfbf-35923dfab83f">
 | |
|       <tunable>net.inet.tcp.delayed_ack</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Do not delay ACK to try and piggyback it onto a data packet</descr>
 | |
|     </item>
 | |
|     <item uuid="e7ffaf90-54eb-4570-9d6f-539ddbc03837">
 | |
|       <tunable>net.inet.udp.maxdgram</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Maximum outgoing UDP datagram size</descr>
 | |
|     </item>
 | |
|     <item uuid="b9877f9c-94d3-4752-8e9d-4a0b5cb27d22">
 | |
|       <tunable>net.link.bridge.pfil_onlyip</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Handling of non-IP packets which are not passed to pfil (see if_bridge(4))</descr>
 | |
|     </item>
 | |
|     <item uuid="966794d5-8a54-4555-81c4-2eee0dc32af0">
 | |
|       <tunable>net.link.bridge.pfil_local_phys</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Set to 1 to additionally filter on the physical interface for locally destined packets</descr>
 | |
|     </item>
 | |
|     <item uuid="d586dd8f-99fa-4001-8dcf-833ee141347e">
 | |
|       <tunable>net.link.bridge.pfil_member</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Set to 0 to disable filtering on the incoming and outgoing member interfaces.</descr>
 | |
|     </item>
 | |
|     <item uuid="082b7cd2-f519-4dcd-8b5a-006e318b300b">
 | |
|       <tunable>net.link.bridge.pfil_bridge</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Set to 1 to enable filtering on the bridge interface</descr>
 | |
|     </item>
 | |
|     <item uuid="5dcfe7bf-e415-4d6b-bda1-c86d0c064a51">
 | |
|       <tunable>net.link.tap.user_open</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Allow unprivileged access to tap(4) device nodes</descr>
 | |
|     </item>
 | |
|     <item uuid="90a7d4bc-5a1d-4d77-9170-e85eb0155e3c">
 | |
|       <tunable>kern.randompid</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())</descr>
 | |
|     </item>
 | |
|     <item uuid="0991a997-640b-4516-8aa9-4fd8277b6408">
 | |
|       <tunable>hw.syscons.kbd_reboot</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Disable CTRL+ALT+Delete reboot from keyboard.</descr>
 | |
|     </item>
 | |
|     <item uuid="5a14cf5c-1648-4b72-9f4f-41192bb1c313">
 | |
|       <tunable>net.inet.tcp.log_debug</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Enable TCP extended debugging</descr>
 | |
|     </item>
 | |
|     <item uuid="6c1ec6b6-1d5d-4928-aec1-408db79ffd4d">
 | |
|       <tunable>net.inet.icmp.icmplim</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Set ICMP Limits</descr>
 | |
|     </item>
 | |
|     <item uuid="ce69c48a-1edf-4a9c-958c-fba9a99fbf5a">
 | |
|       <tunable>net.inet.tcp.tso</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>TCP Offload Engine</descr>
 | |
|     </item>
 | |
|     <item uuid="b5b9598d-c2c6-45c7-be1d-7a57102be6bd">
 | |
|       <tunable>net.inet.udp.checksum</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>UDP Checksums</descr>
 | |
|     </item>
 | |
|     <item uuid="027c1a3f-93e7-48dd-877b-965fd28e858a">
 | |
|       <tunable>kern.ipc.maxsockbuf</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Maximum socket buffer size</descr>
 | |
|     </item>
 | |
|     <item uuid="41eac5bb-e6f5-4595-8a39-25da91e766ab">
 | |
|       <tunable>vm.pmap.pti</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Page Table Isolation (Meltdown mitigation, requires reboot.)</descr>
 | |
|     </item>
 | |
|     <item uuid="92e7d557-cc9d-4840-b769-61334650fda2">
 | |
|       <tunable>hw.ibrs_disable</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Disable Indirect Branch Restricted Speculation (Spectre V2 mitigation)</descr>
 | |
|     </item>
 | |
|     <item uuid="02e66e20-4941-4082-a341-9ba61d25dfe7">
 | |
|       <tunable>security.bsd.see_other_gids</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Hide processes running as other groups</descr>
 | |
|     </item>
 | |
|     <item uuid="17499af0-d726-4c00-8f0a-d6da6131d7d5">
 | |
|       <tunable>security.bsd.see_other_uids</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Hide processes running as other users</descr>
 | |
|     </item>
 | |
|     <item uuid="2c42ae2f-a7bc-48cb-b27d-db72e738e80b">
 | |
|       <tunable>net.inet.ip.redirect</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Enable/disable sending of ICMP redirects in response to IP packets for which a better,
 | |
|         and for the sender directly reachable, route and next hop is known.
 | |
|       </descr>
 | |
|     </item>
 | |
|     <item uuid="7d315fb1-c638-4b79-9f6c-240b41e6d643">
 | |
|       <tunable>net.local.dgram.maxdgram</tunable>
 | |
|       <value>default</value>
 | |
|       <descr>Maximum outgoing UDP datagram size</descr>
 | |
|     </item>
 | |
|   </sysctl>
 | |
|   <system>
 | |
|     <optimization>normal</optimization>
 | |
|     <hostname>fw0</hostname>
 | |
|     <domain>harmony.mcd</domain>
 | |
|     <dnsallowoverride>1</dnsallowoverride>
 | |
|     <group uuid="ddd7a994-e053-46d9-84cf-032b86889d81">
 | |
|       <gid>1999</gid>
 | |
|       <name>admins</name>
 | |
|       <scope>system</scope>
 | |
|       <description>System Administrators</description>
 | |
|       <priv>page-all</priv>
 | |
|       <member>0</member>
 | |
|     </group>
 | |
|     <user uuid="a7114dcd-e6fe-483c-ab49-0638ec8466d5">
 | |
|       <uid>0</uid>
 | |
|       <name>root</name>
 | |
|       <disabled>0</disabled>
 | |
|       <scope>system</scope>
 | |
|       <expires/>
 | |
|       <authorizedkeys/>
 | |
|       <otp_seed/>
 | |
|       <shell/>
 | |
|       <password>$2y$10$YRVoF4SkuhasdkjhasdkjhasdkjhasdkjhasdkjhasdkjhdsTwBfS</password>
 | |
|       <landing_page/>
 | |
|       <comment/>
 | |
|       <email/>
 | |
|       <apikeys/>
 | |
|       <priv/>
 | |
|       <language/>
 | |
|       <descr>System Administrator</descr>
 | |
|       <dashboard/>
 | |
|     </user>
 | |
|     <nextuid>2000</nextuid>
 | |
|     <nextgid>2000</nextgid>
 | |
|     <timezone>America/Toronto</timezone>
 | |
|     <timeservers>0.opnsense.pool.ntp.org 1.opnsense.pool.ntp.org 2.opnsense.pool.ntp.org 3.opnsense.pool.ntp.org</timeservers>
 | |
|     <webgui>
 | |
|       <protocol>https</protocol>
 | |
|       <ssl-certref>6796970f3b58c</ssl-certref>
 | |
|       <port/>
 | |
|       <ssl-ciphers/>
 | |
|       <interfaces/>
 | |
|       <compression/>
 | |
|     </webgui>
 | |
|     <disablenatreflection>yes</disablenatreflection>
 | |
|     <usevirtualterminal>1</usevirtualterminal>
 | |
|     <disableconsolemenu>1</disableconsolemenu>
 | |
|     <disablevlanhwfilter>1</disablevlanhwfilter>
 | |
|     <disablechecksumoffloading>1</disablechecksumoffloading>
 | |
|     <disablesegmentationoffloading>1</disablesegmentationoffloading>
 | |
|     <disablelargereceiveoffloading>1</disablelargereceiveoffloading>
 | |
|     <ipv6allow>1</ipv6allow>
 | |
|     <powerd_ac_mode>hadp</powerd_ac_mode>
 | |
|     <powerd_battery_mode>hadp</powerd_battery_mode>
 | |
|     <powerd_normal_mode>hadp</powerd_normal_mode>
 | |
|     <bogons>
 | |
|       <interval>monthly</interval>
 | |
|     </bogons>
 | |
|     <pf_share_forward>1</pf_share_forward>
 | |
|     <lb_use_sticky>1</lb_use_sticky>
 | |
|     <ssh>
 | |
|       <group>admins</group>
 | |
|       <noauto>1</noauto>
 | |
|       <interfaces/>
 | |
|       <kex/>
 | |
|       <ciphers/>
 | |
|       <macs/>
 | |
|       <keys/>
 | |
|       <keysig/>
 | |
|       <enabled>enabled</enabled>
 | |
|       <passwordauth>1</passwordauth>
 | |
|       <permitrootlogin>1</permitrootlogin>
 | |
|     </ssh>
 | |
|     <rrdbackup>-1</rrdbackup>
 | |
|     <netflowbackup>-1</netflowbackup>
 | |
|     <firmware version="1.0.1">
 | |
|       <mirror/>
 | |
|       <flavour/>
 | |
|       <plugins/>
 | |
|       <type/>
 | |
|       <subscription/>
 | |
|       <reboot/>
 | |
|     </firmware>
 | |
|     <language>en_US</language>
 | |
|     <serialspeed>115200</serialspeed>
 | |
|     <primaryconsole>video</primaryconsole>
 | |
|   </system>
 | |
|   <interfaces>
 | |
|     <wan>
 | |
|       <enable>1</enable>
 | |
|       <if>igc3</if>
 | |
|       <ipaddr>dhcp</ipaddr>
 | |
|       <ipaddrv6>dhcp6</ipaddrv6>
 | |
|       <gateway>WAN_GW</gateway>
 | |
|       <media/>
 | |
|       <mediaopt/>
 | |
|       <dhcp6-ia-pd-len>0</dhcp6-ia-pd-len>
 | |
|     </wan>
 | |
|     <lan>
 | |
|       <enable>1</enable>
 | |
|       <if>igc0</if>
 | |
|       <ipaddr>192.168.33.1</ipaddr>
 | |
|       <subnet>24</subnet>
 | |
|       <ipaddrv6/>
 | |
|       <subnetv6/>
 | |
|       <media/>
 | |
|       <mediaopt/>
 | |
|       <gateway/>
 | |
|       <gatewayv6/>
 | |
|     </lan>
 | |
|     <lo0>
 | |
|       <internal_dynamic>1</internal_dynamic>
 | |
|       <descr>Loopback</descr>
 | |
|       <enable>1</enable>
 | |
|       <if>lo0</if>
 | |
|       <ipaddr>127.0.0.1</ipaddr>
 | |
|       <ipaddrv6>::1</ipaddrv6>
 | |
|       <subnet>8</subnet>
 | |
|       <subnetv6>128</subnetv6>
 | |
|       <type>none</type>
 | |
|       <virtual>1</virtual>
 | |
|     </lo0>
 | |
|   </interfaces>
 | |
|   <dhcpd>
 | |
|     <lan>
 | |
|       <enable>1</enable>
 | |
|       <range>
 | |
|         <from>192.168.33.10</from>
 | |
|         <to>192.168.33.245</to>
 | |
|       </range>
 | |
|     </lan>
 | |
|   </dhcpd>
 | |
|   <snmpd>
 | |
|     <syslocation/>
 | |
|     <syscontact/>
 | |
|     <rocommunity>public</rocommunity>
 | |
|   </snmpd>
 | |
|   <nat>
 | |
|     <outbound>
 | |
|       <mode>automatic</mode>
 | |
|     </outbound>
 | |
|   </nat>
 | |
|   <filter>
 | |
|     <rule>
 | |
|       <type>pass</type>
 | |
|       <ipprotocol>inet</ipprotocol>
 | |
|       <descr>Default allow LAN to any rule</descr>
 | |
|       <interface>lan</interface>
 | |
|       <source>
 | |
|         <network>lan</network>
 | |
|       </source>
 | |
|       <destination>
 | |
|         <any/>
 | |
|       </destination>
 | |
|     </rule>
 | |
|     <rule>
 | |
|       <type>pass</type>
 | |
|       <ipprotocol>inet6</ipprotocol>
 | |
|       <descr>Default allow LAN IPv6 to any rule</descr>
 | |
|       <interface>lan</interface>
 | |
|       <source>
 | |
|         <network>lan</network>
 | |
|       </source>
 | |
|       <destination>
 | |
|         <any/>
 | |
|       </destination>
 | |
|     </rule>
 | |
|   </filter>
 | |
|   <rrd>
 | |
|     <enable/>
 | |
|   </rrd>
 | |
|   <ntpd>
 | |
|     <prefer>0.opnsense.pool.ntp.org</prefer>
 | |
|   </ntpd>
 | |
|   <widgets>
 | |
|     <sequence>system_information-container:00000000-col3:show,services_status-container:00000001-col4:show,gateways-container:00000002-col4:show,interface_list-container:00000003-col4:show</sequence>
 | |
|     <column_count>2</column_count>
 | |
|   </widgets>
 | |
|   <revision>
 | |
|     <username>(system)</username>
 | |
|     <description>/usr/local/opnsense/mvc/script/run_migrations.php made changes</description>
 | |
|     <time>1738511129.2333</time>
 | |
|   </revision>
 | |
|   <OPNsense>
 | |
|     <DHCRelay version="1.0.1"/>
 | |
|     <wireguard>
 | |
|       <client version="1.0.0">
 | |
|         <clients/>
 | |
|       </client>
 | |
|       <general version="0.0.1">
 | |
|         <enabled>0</enabled>
 | |
|       </general>
 | |
|       <server version="1.0.0">
 | |
|         <servers/>
 | |
|       </server>
 | |
|     </wireguard>
 | |
|     <IPsec version="1.0.3">
 | |
|       <general>
 | |
|         <enabled/>
 | |
|         <preferred_oldsa>0</preferred_oldsa>
 | |
|         <disablevpnrules>0</disablevpnrules>
 | |
|         <passthrough_networks/>
 | |
|       </general>
 | |
|       <charon>
 | |
|         <max_ikev1_exchanges/>
 | |
|         <threads>16</threads>
 | |
|         <ikesa_table_size>32</ikesa_table_size>
 | |
|         <ikesa_table_segments>4</ikesa_table_segments>
 | |
|         <init_limit_half_open>1000</init_limit_half_open>
 | |
|         <ignore_acquire_ts>1</ignore_acquire_ts>
 | |
|         <make_before_break/>
 | |
|         <retransmit_tries/>
 | |
|         <retransmit_timeout/>
 | |
|         <retransmit_base/>
 | |
|         <retransmit_jitter/>
 | |
|         <retransmit_limit/>
 | |
|         <syslog>
 | |
|           <daemon>
 | |
|             <ike_name>1</ike_name>
 | |
|             <log_level>0</log_level>
 | |
|             <app>1</app>
 | |
|             <asn>1</asn>
 | |
|             <cfg>1</cfg>
 | |
|             <chd>1</chd>
 | |
|             <dmn>1</dmn>
 | |
|             <enc>1</enc>
 | |
|             <esp>1</esp>
 | |
|             <ike>1</ike>
 | |
|             <imc>1</imc>
 | |
|             <imv>1</imv>
 | |
|             <job>1</job>
 | |
|             <knl>1</knl>
 | |
|             <lib>1</lib>
 | |
|             <mgr>1</mgr>
 | |
|             <net>1</net>
 | |
|             <pts>1</pts>
 | |
|             <tls>1</tls>
 | |
|             <tnc>1</tnc>
 | |
|           </daemon>
 | |
|         </syslog>
 | |
|       </charon>
 | |
|       <keyPairs/>
 | |
|       <preSharedKeys/>
 | |
|     </IPsec>
 | |
|     <Swanctl version="1.0.0">
 | |
|       <Connections/>
 | |
|       <locals/>
 | |
|       <remotes/>
 | |
|       <children/>
 | |
|       <Pools/>
 | |
|       <VTIs/>
 | |
|       <SPDs/>
 | |
|     </Swanctl>
 | |
|     <OpenVPNExport version="0.0.1">
 | |
|       <servers/>
 | |
|     </OpenVPNExport>
 | |
|     <OpenVPN version="1.0.1">
 | |
|       <Overwrites/>
 | |
|       <Instances/>
 | |
|       <StaticKeys/>
 | |
|     </OpenVPN>
 | |
|     <captiveportal version="1.0.2">
 | |
|       <zones/>
 | |
|       <templates/>
 | |
|     </captiveportal>
 | |
|     <cron version="1.0.4">
 | |
|       <jobs/>
 | |
|     </cron>
 | |
|     <Firewall>
 | |
|       <Lvtemplate version="0.0.1">
 | |
|         <templates/>
 | |
|       </Lvtemplate>
 | |
|       <Alias version="1.0.1">
 | |
|         <geoip>
 | |
|           <url/>
 | |
|         </geoip>
 | |
|         <aliases/>
 | |
|       </Alias>
 | |
|       <Category version="1.0.0">
 | |
|         <categories/>
 | |
|       </Category>
 | |
|       <Filter version="1.0.4">
 | |
|         <rules/>
 | |
|         <snatrules/>
 | |
|         <npt/>
 | |
|         <onetoone/>
 | |
|       </Filter>
 | |
|     </Firewall>
 | |
|     <Netflow version="1.0.1">
 | |
|       <capture>
 | |
|         <interfaces/>
 | |
|         <egress_only/>
 | |
|         <version>v9</version>
 | |
|         <targets/>
 | |
|       </capture>
 | |
|       <collect>
 | |
|         <enable>0</enable>
 | |
|       </collect>
 | |
|       <activeTimeout>1800</activeTimeout>
 | |
|       <inactiveTimeout>15</inactiveTimeout>
 | |
|     </Netflow>
 | |
|     <IDS version="1.1.0">
 | |
|       <rules/>
 | |
|       <policies/>
 | |
|       <userDefinedRules/>
 | |
|       <files/>
 | |
|       <fileTags/>
 | |
|       <general>
 | |
|         <enabled>0</enabled>
 | |
|         <ips>0</ips>
 | |
|         <promisc>0</promisc>
 | |
|         <interfaces>wan</interfaces>
 | |
|         <homenet>192.168.0.0/16,10.0.0.0/8,172.16.0.0/12</homenet>
 | |
|         <defaultPacketSize/>
 | |
|         <UpdateCron/>
 | |
|         <AlertLogrotate>W0D23</AlertLogrotate>
 | |
|         <AlertSaveLogs>4</AlertSaveLogs>
 | |
|         <MPMAlgo/>
 | |
|         <detect>
 | |
|           <Profile/>
 | |
|           <toclient_groups/>
 | |
|           <toserver_groups/>
 | |
|         </detect>
 | |
|         <syslog>0</syslog>
 | |
|         <syslog_eve>0</syslog_eve>
 | |
|         <LogPayload>0</LogPayload>
 | |
|         <verbosity/>
 | |
|         <eveLog>
 | |
|           <http>
 | |
|             <enable>0</enable>
 | |
|             <extended>0</extended>
 | |
|             <dumpAllHeaders/>
 | |
|           </http>
 | |
|           <tls>
 | |
|             <enable>0</enable>
 | |
|             <extended>0</extended>
 | |
|             <sessionResumption>0</sessionResumption>
 | |
|             <custom/>
 | |
|           </tls>
 | |
|         </eveLog>
 | |
|       </general>
 | |
|     </IDS>
 | |
|     <Interfaces>
 | |
|       <loopbacks version="1.0.0"/>
 | |
|       <neighbors version="1.0.0"/>
 | |
|       <vxlans version="1.0.2"/>
 | |
|     </Interfaces>
 | |
|     <Kea>
 | |
|       <ctrl_agent version="0.0.1">
 | |
|         <general>
 | |
|           <enabled>0</enabled>
 | |
|           <http_host>127.0.0.1</http_host>
 | |
|           <http_port>8000</http_port>
 | |
|         </general>
 | |
|       </ctrl_agent>
 | |
|       <dhcp4 version="1.0.3">
 | |
|         <general>
 | |
|           <enabled>0</enabled>
 | |
|           <interfaces/>
 | |
|           <valid_lifetime>4000</valid_lifetime>
 | |
|           <fwrules>1</fwrules>
 | |
|           <dhcp_socket_type>raw</dhcp_socket_type>
 | |
|         </general>
 | |
|         <ha>
 | |
|           <enabled>0</enabled>
 | |
|           <this_server_name/>
 | |
|           <max_unacked_clients>2</max_unacked_clients>
 | |
|         </ha>
 | |
|         <subnets/>
 | |
|         <reservations/>
 | |
|         <ha_peers/>
 | |
|       </dhcp4>
 | |
|     </Kea>
 | |
|     <monit version="1.0.13">
 | |
|       <general>
 | |
|         <enabled>0</enabled>
 | |
|         <interval>120</interval>
 | |
|         <startdelay>120</startdelay>
 | |
|         <mailserver>127.0.0.1</mailserver>
 | |
|         <port>25</port>
 | |
|         <username/>
 | |
|         <password/>
 | |
|         <ssl>0</ssl>
 | |
|         <sslversion>auto</sslversion>
 | |
|         <sslverify>1</sslverify>
 | |
|         <logfile/>
 | |
|         <statefile/>
 | |
|         <eventqueuePath/>
 | |
|         <eventqueueSlots/>
 | |
|         <httpdEnabled>0</httpdEnabled>
 | |
|         <httpdUsername>root</httpdUsername>
 | |
|         <httpdPassword/>
 | |
|         <httpdPort>2812</httpdPort>
 | |
|         <httpdAllow/>
 | |
|         <mmonitUrl/>
 | |
|         <mmonitTimeout>5</mmonitTimeout>
 | |
|         <mmonitRegisterCredentials>1</mmonitRegisterCredentials>
 | |
|       </general>
 | |
|       <alert uuid="8e3719e1-dd47-467e-bfed-55787df3a8e7">
 | |
|         <enabled>0</enabled>
 | |
|         <recipient>root@localhost.local</recipient>
 | |
|         <noton>0</noton>
 | |
|         <events/>
 | |
|         <format/>
 | |
|         <reminder/>
 | |
|         <description/>
 | |
|       </alert>
 | |
|       <service uuid="68d541ef-8edb-42cc-8a24-2d8c62ac8439">
 | |
|         <enabled>1</enabled>
 | |
|         <name>$HOST</name>
 | |
|         <description/>
 | |
|         <type>system</type>
 | |
|         <pidfile/>
 | |
|         <match/>
 | |
|         <path/>
 | |
|         <timeout>300</timeout>
 | |
|         <starttimeout>30</starttimeout>
 | |
|         <address/>
 | |
|         <interface/>
 | |
|         <start/>
 | |
|         <stop/>
 | |
|         <tests>b9a4410c-bc95-4de6-ac83-567dd8cf60c0,c1ec5aac-2fda-45f5-a0d8-9bea7db470d6,f1a4fa3a-65a2-43da-b6e0-18b0361ac43b,76c03880-d148-413e-8097-3ee0aa33cb2c</tests>
 | |
|         <depends/>
 | |
|         <polltime/>
 | |
|       </service>
 | |
|       <service uuid="ebf7ab21-6712-45d4-981c-d459ad8ae284">
 | |
|         <enabled>1</enabled>
 | |
|         <name>RootFs</name>
 | |
|         <description/>
 | |
|         <type>filesystem</type>
 | |
|         <pidfile/>
 | |
|         <match/>
 | |
|         <path>/</path>
 | |
|         <timeout>300</timeout>
 | |
|         <starttimeout>30</starttimeout>
 | |
|         <address/>
 | |
|         <interface/>
 | |
|         <start/>
 | |
|         <stop/>
 | |
|         <tests>f24e0d56-0445-4e5f-9b58-3af0f246b80d</tests>
 | |
|         <depends/>
 | |
|         <polltime/>
 | |
|       </service>
 | |
|       <service uuid="ca9f44d4-b52e-42e9-998a-bbfb64dca7a9">
 | |
|         <enabled>0</enabled>
 | |
|         <name>carp_status_change</name>
 | |
|         <description/>
 | |
|         <type>custom</type>
 | |
|         <pidfile/>
 | |
|         <match/>
 | |
|         <path>/usr/local/opnsense/scripts/OPNsense/Monit/carp_status</path>
 | |
|         <timeout>300</timeout>
 | |
|         <starttimeout>30</starttimeout>
 | |
|         <address/>
 | |
|         <interface/>
 | |
|         <start/>
 | |
|         <stop/>
 | |
|         <tests>f48cfab6-de1e-4006-bcd7-c8f8990d25d6</tests>
 | |
|         <depends/>
 | |
|         <polltime/>
 | |
|       </service>
 | |
|       <service uuid="39ef4972-9370-4d92-b374-b52d2ebbd75b">
 | |
|         <enabled>0</enabled>
 | |
|         <name>gateway_alert</name>
 | |
|         <description/>
 | |
|         <type>custom</type>
 | |
|         <pidfile/>
 | |
|         <match/>
 | |
|         <path>/usr/local/opnsense/scripts/OPNsense/Monit/gateway_alert</path>
 | |
|         <timeout>300</timeout>
 | |
|         <starttimeout>30</starttimeout>
 | |
|         <address/>
 | |
|         <interface/>
 | |
|         <start/>
 | |
|         <stop/>
 | |
|         <tests>5e0dc1c7-90ac-48cc-944e-e0b20c482656</tests>
 | |
|         <depends/>
 | |
|         <polltime/>
 | |
|       </service>
 | |
|       <test uuid="2a8b1b91-4518-45a8-bc5c-cf80501752a0">
 | |
|         <name>Ping</name>
 | |
|         <type>NetworkPing</type>
 | |
|         <condition>failed ping</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="7aa46fcf-93b0-4d50-b680-7987d79986cb">
 | |
|         <name>NetworkLink</name>
 | |
|         <type>NetworkInterface</type>
 | |
|         <condition>failed link</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="3b123130-ce2f-4796-941d-10f2d75f9237">
 | |
|         <name>NetworkSaturation</name>
 | |
|         <type>NetworkInterface</type>
 | |
|         <condition>saturation is greater than 75%</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="b9a4410c-bc95-4de6-ac83-567dd8cf60c0">
 | |
|         <name>MemoryUsage</name>
 | |
|         <type>SystemResource</type>
 | |
|         <condition>memory usage is greater than 75%</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="c1ec5aac-2fda-45f5-a0d8-9bea7db470d6">
 | |
|         <name>CPUUsage</name>
 | |
|         <type>SystemResource</type>
 | |
|         <condition>cpu usage is greater than 75%</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="f1a4fa3a-65a2-43da-b6e0-18b0361ac43b">
 | |
|         <name>LoadAvg1</name>
 | |
|         <type>SystemResource</type>
 | |
|         <condition>loadavg (1min) is greater than 8</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="76c03880-d148-413e-8097-3ee0aa33cb2c">
 | |
|         <name>LoadAvg5</name>
 | |
|         <type>SystemResource</type>
 | |
|         <condition>loadavg (5min) is greater than 6</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="e89b68a9-503a-474f-afde-ce39a4264494">
 | |
|         <name>LoadAvg15</name>
 | |
|         <type>SystemResource</type>
 | |
|         <condition>loadavg (15min) is greater than 4</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="f24e0d56-0445-4e5f-9b58-3af0f246b80d">
 | |
|         <name>SpaceUsage</name>
 | |
|         <type>SpaceUsage</type>
 | |
|         <condition>space usage is greater than 75%</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="f48cfab6-de1e-4006-bcd7-c8f8990d25d6">
 | |
|         <name>ChangedStatus</name>
 | |
|         <type>ProgramStatus</type>
 | |
|         <condition>changed status</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|       <test uuid="5e0dc1c7-90ac-48cc-944e-e0b20c482656">
 | |
|         <name>NonZeroStatus</name>
 | |
|         <type>ProgramStatus</type>
 | |
|         <condition>status != 0</condition>
 | |
|         <action>alert</action>
 | |
|         <path/>
 | |
|       </test>
 | |
|     </monit>
 | |
|     <Gateways version="1.0.0">
 | |
|       <gateway_item uuid="b5f483d7-8a2f-402a-b169-d955156f2cdb">
 | |
|         <disabled>0</disabled>
 | |
|         <name>WAN_GW</name>
 | |
|         <descr>WAN Gateway</descr>
 | |
|         <interface>wan</interface>
 | |
|         <ipprotocol>inet</ipprotocol>
 | |
|         <gateway/>
 | |
|         <defaultgw>1</defaultgw>
 | |
|         <fargw/>
 | |
|         <monitor_disable>1</monitor_disable>
 | |
|         <monitor_noroute/>
 | |
|         <monitor/>
 | |
|         <force_down/>
 | |
|         <priority>255</priority>
 | |
|         <weight>1</weight>
 | |
|         <latencylow/>
 | |
|         <latencyhigh/>
 | |
|         <losslow/>
 | |
|         <losshigh/>
 | |
|         <interval/>
 | |
|         <time_period/>
 | |
|         <loss_interval/>
 | |
|         <data_length/>
 | |
|       </gateway_item>
 | |
|     </Gateways>
 | |
|     <Syslog version="1.0.2">
 | |
|       <general>
 | |
|         <enabled>1</enabled>
 | |
|         <loglocal>1</loglocal>
 | |
|         <maxpreserve>31</maxpreserve>
 | |
|         <maxfilesize/>
 | |
|       </general>
 | |
|       <destinations/>
 | |
|     </Syslog>
 | |
|     <TrafficShaper version="1.0.3">
 | |
|       <pipes/>
 | |
|       <queues/>
 | |
|       <rules/>
 | |
|     </TrafficShaper>
 | |
|     <unboundplus version="1.0.11">
 | |
|       <general>
 | |
|         <enabled>1</enabled>
 | |
|         <port>53</port>
 | |
|         <stats/>
 | |
|         <active_interface/>
 | |
|         <dnssec/>
 | |
|         <dns64/>
 | |
|         <dns64prefix/>
 | |
|         <noarecords/>
 | |
|         <regdhcp/>
 | |
|         <regdhcpdomain/>
 | |
|         <regdhcpstatic/>
 | |
|         <noreglladdr6/>
 | |
|         <noregrecords/>
 | |
|         <txtsupport/>
 | |
|         <cacheflush/>
 | |
|         <local_zone_type>transparent</local_zone_type>
 | |
|         <outgoing_interface/>
 | |
|         <enable_wpad/>
 | |
|       </general>
 | |
|       <advanced>
 | |
|         <hideidentity/>
 | |
|         <hideversion/>
 | |
|         <prefetch/>
 | |
|         <prefetchkey/>
 | |
|         <dnssecstripped/>
 | |
|         <aggressivensec>1</aggressivensec>
 | |
|         <serveexpired/>
 | |
|         <serveexpiredreplyttl/>
 | |
|         <serveexpiredttl/>
 | |
|         <serveexpiredttlreset/>
 | |
|         <serveexpiredclienttimeout/>
 | |
|         <qnameminstrict/>
 | |
|         <extendedstatistics/>
 | |
|         <logqueries/>
 | |
|         <logreplies/>
 | |
|         <logtagqueryreply/>
 | |
|         <logservfail/>
 | |
|         <loglocalactions/>
 | |
|         <logverbosity>1</logverbosity>
 | |
|         <valloglevel>0</valloglevel>
 | |
|         <privatedomain/>
 | |
|         <privateaddress>0.0.0.0/8,10.0.0.0/8,100.64.0.0/10,169.254.0.0/16,172.16.0.0/12,192.0.2.0/24,192.168.0.0/16,198.18.0.0/15,198.51.100.0/24,203.0.113.0/24,233.252.0.0/24,::1/128,2001:db8::/32,fc00::/8,fd00::/8,fe80::/10</privateaddress>
 | |
|         <insecuredomain/>
 | |
|         <msgcachesize/>
 | |
|         <rrsetcachesize/>
 | |
|         <outgoingnumtcp/>
 | |
|         <incomingnumtcp/>
 | |
|         <numqueriesperthread/>
 | |
|         <outgoingrange/>
 | |
|         <jostletimeout/>
 | |
|         <discardtimeout/>
 | |
|         <cachemaxttl/>
 | |
|         <cachemaxnegativettl/>
 | |
|         <cacheminttl/>
 | |
|         <infrahostttl/>
 | |
|         <infrakeepprobing/>
 | |
|         <infracachenumhosts/>
 | |
|         <unwantedreplythreshold/>
 | |
|       </advanced>
 | |
|       <acls>
 | |
|         <default_action>allow</default_action>
 | |
|       </acls>
 | |
|       <dnsbl>
 | |
|         <enabled>0</enabled>
 | |
|         <safesearch/>
 | |
|         <type/>
 | |
|         <lists/>
 | |
|         <whitelists/>
 | |
|         <blocklists/>
 | |
|         <wildcards/>
 | |
|         <address/>
 | |
|         <nxdomain/>
 | |
|       </dnsbl>
 | |
|       <forwarding>
 | |
|         <enabled/>
 | |
|       </forwarding>
 | |
|       <dots/>
 | |
|       <hosts/>
 | |
|       <aliases/>
 | |
|     </unboundplus>
 | |
|     <trust>
 | |
|       <general version="1.0.1">
 | |
|         <store_intermediate_certs>0</store_intermediate_certs>
 | |
|         <install_crls>0</install_crls>
 | |
|         <fetch_crls>0</fetch_crls>
 | |
|         <enable_legacy_sect>1</enable_legacy_sect>
 | |
|         <enable_config_constraints>0</enable_config_constraints>
 | |
|         <CipherString/>
 | |
|         <Ciphersuites/>
 | |
|         <SignatureAlgorithms/>
 | |
|         <groups/>
 | |
|         <MinProtocol/>
 | |
|         <MinProtocol_DTLS/>
 | |
|       </general>
 | |
|     </trust>
 | |
|   </OPNsense>
 | |
|   <hasync version="1.0.2">
 | |
|     <disablepreempt>0</disablepreempt>
 | |
|     <disconnectppps>0</disconnectppps>
 | |
|     <pfsyncinterface/>
 | |
|     <pfsyncpeerip/>
 | |
|     <pfsyncversion>1400</pfsyncversion>
 | |
|     <synchronizetoip/>
 | |
|     <verifypeer>0</verifypeer>
 | |
|     <username/>
 | |
|     <password/>
 | |
|     <syncitems/>
 | |
|   </hasync>
 | |
|   <openvpn/>
 | |
|   <ifgroups version="1.0.0"/>
 | |
|   <gifs version="1.0.0">
 | |
|     <gif/>
 | |
|   </gifs>
 | |
|   <gres version="1.0.0">
 | |
|     <gre/>
 | |
|   </gres>
 | |
|   <laggs version="1.0.0">
 | |
|     <lagg/>
 | |
|   </laggs>
 | |
|   <virtualip version="1.0.0">
 | |
|     <vip/>
 | |
|   </virtualip>
 | |
|   <vlans version="1.0.0">
 | |
|     <vlan/>
 | |
|   </vlans>
 | |
|   <staticroutes version="1.0.0"/>
 | |
|   <bridges>
 | |
|     <bridged/>
 | |
|   </bridges>
 | |
|   <ppps>
 | |
|     <ppp/>
 | |
|   </ppps>
 | |
|   <wireless>
 | |
|     <clone/>
 | |
|   </wireless>
 | |
|   <ca/>
 | |
|   <dhcpdv6/>
 | |
|   <cert uuid="c1f73db9-f01b-46ba-b866-f8b911e83f96">
 | |
|     <refid>6796970f3b58c</refid>
 | |
|     <descr>Web GUI TLS certificate</descr>
 | |
|     <caref/>
 | |
|     <crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUhIakNDQlFhZ0F3SUJBZ0lVR3B1ZFZqRzR5a0JVYS9NUWxyU2ZBcWs5VCtRd0RRWUpLb1pJaHZjTkFRRUwKQlFBd2dZa3hIVEFiQmdOVkJBTU1GRTlRVG5ObGJuTmxMbXh2WTJGc1pHOXRZV2x1TVFzd0NRWURWUVFHRXdKTwpUREVWTUJNR0ExVUVDQXdNV25WcFpDMUliMnhzWVc1a01SVXdFd1lEVlFRSERBeE5hV1JrWld4b1lYSnVhWE14CkxUQXJCZ05WQkFvTUpFOVFUbk5sYm5ObElITmxiR1l0YzJsbmJtVmtJSGRsWWlCalpYSjBhV1pwWTJGMFpUQWUKRncweU5UQXhNall5TURFeU1EWmFGdzB5TmpBeU1qY3lNREV5TURaYU1JR0pNUjB3R3dZRFZRUUREQlJQVUU1egpaVzV6WlM1c2IyTmhiR1J2YldGcGJqRUxNQWtHQTFVRUJoTUNUa3d4RlRBVEJnTlZCQWdNREZwMWFXUXRTRzlzCmJHRnVaREVWTUJNR0ExVUVCd3dNVFdsa1pHVnNhR0Z5Ym1sek1TMHdLd1lEVlFRS0RDUlBVRTV6Wlc1elpTQnoKWld4bUxYTnBaMjVsWkNCM1pXSWdZMlZ5ZEdsbWFXTmhkR1V3Z2dJaU1BMEdDU3FHU0liM0RRRUJBUVVBQTRJQwpEd0F3Z2dJS0FvSUNBUUM0alhjOXE4VENxMmZzc05zRU94dktuZm1FVjRNTzFRWDZNdmRReVN2QXIzNmRlNXVMCmZ3bkJSRnVkRC9zQ1B0ZzhXajVCaCtiNGF3WC9mOUdnQnNJbnhKNVB2SWFXMlBtWThpS0Q1Q01WQXhxUE1lMlQKT0VxaEYvWkJxZlNNUWk2RkVhTTRFS0J6bllMbzhnMlAyTW93VjBDbmI3aXVJVWlKRFF3a2JWOVZESG55VkhGaApkVVlONjlpTXRYMEZiSHVtY2tKWHJwQTVQcGFSdVdsaUNnNHl4dWxEOGRsL3dJOXAzZENQY2tNaXgvYjQ1aWdJCjZHbC9GUmhhZmx5VWJ2WWxSMEw5d1pVMmNpcHFQemJJR0tlZ2pkRVdIcGRzVW5sTnJiR1I0azZieWQ4ZGd1a0YKWlNVNUlUSkZRSFdNN3ZNNkZuMTloUE51NG94TEtVUTc1b1YwZDdHV2RaQ1RIYnU3R1hqekhhVHJKYnhTTjMyVApIcDFEMlhUQ1BPTEs1NjNMc2YrNm12Ty9BQSt5SWQyZ0tvWllsdG9GUDdGcHNwWmIwYnhqeWt1amxvOUg0TW1iCmpDeCtWTVkwWUozelVTU3NCOE5IdHpyS0hyVW9oMG9oNTZPNzBNQjZpUWt5dTNaZzNlL1lTUnJwOVJwMTFMMWwKU2F3NmIzMEtFOUh6VHkxWDVXczJlQmxYajFvS2FBVktlTEN4dzlnRDJuSFdqaHViTlFwSmhmdFY2S3F0TjFVeQp4NXBWUTRrL0l1VUNTRlRMK3JOTThWOEc1NCsxTlFTaWZlWVpLdzF4bGRIMlpDbjA1QURrWUhEaFI3VUtkSGhCCncycjkrTjNjdENSaVM1V1BlRTBhQzJ5bFU2czdtU0RwWGM1cy84SnA2QlN5c1ZYL3dpZGRFMWl4N1FJREFRQUIKbzRJQmVqQ0NBWFl3Q1FZRFZSMFRCQUl3QURBUkJnbGdoa2dCaHZoQ0FRRUVCQU1DQmtBd05BWUpZSVpJQVliNApRZ0VOQkNjV0pVOVFUbk5sYm5ObElFZGxibVZ5WVhSbFpDQlRaWEoyWlhJZ1EyVnlkR2xtYVdOaGRHVXdIUVlEClZSME9CQllFRkhIMGNpYU9qNXdrKzBLeFlYUFNtL1pveFpHT01JR3pCZ05WSFNNRWdhc3dnYWloZ1kra2dZd3cKZ1lreEhUQWJCZ05WQkFNTUZFOVFUbk5sYm5ObExteHZZMkZzWkc5dFlXbHVNUXN3Q1FZRFZRUUdFd0pPVERFVgpNQk1HQTFVRUNBd01XblZwWkMxSWIyeHNZVzVrTVJVd0V3WURWUVFIREF4TmFXUmtaV3hvWVhKdWFYTXhMVEFyCkJnTlZCQW9NSkU5UVRuTmxibk5sSUhObGJHWXRjMmxuYm1Wa0lIZGxZaUJqWlhKMGFXWnBZMkYwWllJVUdwdWQKVmpHNHlrQlVhL01RbHJTZkFxazlUK1F3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQ0FJQwpNQXNHQTFVZER3UUVBd0lGb0RBZkJnTlZIUkVFR0RBV2doUlBVRTV6Wlc1elpTNXNiMk5oYkdSdmJXRnBiakFOCkJna3Foa2lHOXcwQkFRc0ZBQU9DQWdFQUhwcjZXQ2RmMzFWblR2RlMwUjA4RTUySHJvZHc3TjVJMGpwNkYrdHMKR2xsdGxaMDdvOWxvN2E5VFNBK1FnSGFQK1VOMkZUZmlFeHZ0RG0vdDZEQjhSald4ZnV4eloyOTMxeE8wWEhUNwp1Vll3OGpaYnlhOVQyU1VjTGR2ZFpyUHZFajJscnExYXRnc2UwMmhUUTdOSGhpd0hrbEdWTHR5K0FpaVc1STBPCkpPNGFiUHdBU3Z0SEtTU2hYTEhJY1NqWTIwLzF0TjUvdFRMTTFKUUFHZFM1NWU4YVpkdWRHWkVJdHlTZk0ya3kKY21zVnNMS0ZsL1ZLRmUrQnQySmd0d0FPUk0xbzM5WTZLQ2RHTkJPYThGUS9GQWhqZ2JrM1IwYVk3MEFBRDlyNQpXT0dPeEFxS0g5YmdhUUhrY05zSnNWekJlTFZzd3NPYnI2dktqUkUzSm1jTC9COGsxNVJaeXdMV2YxV2N6QzhwCjd5VDNUcW5vRXhQUlZZa3AzSmFQRkNncDN1YzQ0S01UZ1laQW4xeHJLS3hQdUV3NE0rSisyNzBGRzhqckJPN1UKdENMajVPMVpVMXBoVDBEckswVGloOHJlbkgrWDZkVUY4UmY4WDA0QXd5a3MzbjYramNoT3E2azFaaWVYT0NVYwppclM5eTFnNnZCM25YdW1kU05JdEZvQVhTWXRtOE5KaVUxN3kyanlnOWRHK3B4K1FpZTV2YjBMNE5xdzVoMFZhCldiWVpsMjA2cVpFenpFVEJtTHNuaWYydHB0aUlkbWh0UEZPYXBvT3hTL1ByV0V3VXc4NXdNQ0ZLcW1tZ3QzeVYKRUVlRXVRVTJIMFE5NS8wWGJOZnhKcVJSUXltOTBHeTlmTTUzU2VGbnpwVlU2VzJ6WTQyd3AwQktBZGxDdW9CdAplTjg9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K</crt>
 | |
|     <csr/>
 | |
|     <prv>LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUpRd0lCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQ1Mwd2dna3BBZ0VBQW9JQ0FRQzRqWGM5cThUQ3EyZnMKc05zRU94dktuZm1FVjRNTzFRWDZNdmRReVN2QXIzNmRlNXVMZnduQlJGdWREL3NDUHRnOFdqNUJoK2I0YXdYLwpmOUdnQnNJbnhKNVB2SWFXMlBtWThpS0Q1Q01WQXhxUE1lMlRPRXFoRi9aQnFmU01RaTZGRWFNNEVLQnpuWUxvCjhnMlAyTW93VjBDbmI3aXVJVWlKRFF3a2JWOVZESG55VkhGaGRVWU42OWlNdFgwRmJIdW1ja0pYcnBBNVBwYVIKdVdsaUNnNHl4dWxEOGRsL3dJOXAzZENQY2tNaXgvYjQ1aWdJNkdsL0ZSaGFmbHlVYnZZbFIwTDl3WlUyY2lwcQpQemJJR0tlZ2pkRVdIcGRzVW5sTnJiR1I0azZieWQ4ZGd1a0ZaU1U1SVRKRlFIV003dk02Rm4xOWhQTnU0b3hMCktVUTc1b1YwZDdHV2RaQ1RIYnU3R1hqekhhVHJKYnhTTjMyVEhwMUQyWFRDUE9MSzU2M0xzZis2bXZPL0FBK3kKSWQyZ0tvWllsdG9GUDdGcHNwWmIwYnhqeWt1amxvOUg0TW1iakN4K1ZNWTBZSjN6VVNTc0I4Tkh0enJLSHJVbwpoMG9oNTZPNzBNQjZpUWt5dTNaZzNlL1lTUnJwOVJwMTFMMWxTYXc2YjMwS0U5SHpUeTFYNVdzMmVCbFhqMW9LCmFBVktlTEN4dzlnRDJuSFdqaHViTlFwSmhmdFY2S3F0TjFVeXg1cFZRNGsvSXVVQ1NGVEwrck5NOFY4RzU0KzEKTlFTaWZlWVpLdzF4bGRIMlpDbjA1QURrWUhEaFI3VUtkSGhCdzJyOStOM2N0Q1JpUzVXUGVFMGFDMnlsVTZzNwptU0RwWGM1cy84SnA2QlN5c1ZYL3dpZGRFMWl4N1FJREFRQUJBb0lDQUJ4UldLS1Y0TE1lS2V3Zmx2dW5OalI0CjJQaDlsUmFKaVVsQzJNQUVuam9LczVybWhJOTdCcndwQ1FXb2xoTmFJVVBoZFB3SkpsK256RnZQK1JKYzl4MnoKQmJlbWJlQm5tcVRsUW5hS1l2ZXVhanplcEYyYW5aanFYRmJuQlNjZ1lKTDZpZGpvZERaSlRQVUJieU5MV0hyaQphSUZJbTBYY3hZeUIvQUw2NVUzZmhEYXl6bEx0ODduZkhuTTR4ZDQzTHlIekZrcnQ5aU5TZnpnTkF5YVA5RzNHCko3VE5QMXBpNlo2TThwdVFKTTBKY2RQdlBPVmhCQThENWFDOUV1ZVR2eUVwTmhaSnhlTjgwUlZNYmROMk5RSmwKd0Zkc2lqK015Q0FyTHJ2N3hhUVI3YkpSaS8vUDdVNCswYi9lakNyNzMwWmlmUTd0ZjR6Y0pqckNNajRldVF0SwowSHdmYll0L2NLVWc0aTlTd0hCRlg4QUxva2M1WkNkOXkxVEQzSU1LVlpDS0pFY24rT2gvMGRTT0pDWlFoTDdKClN1czBtUU1BVDYwTGkwZXhyMC92NjZ2dWJqTWpNcHhQVjlIY2RDbTRSbVU3aFMvQlJpaGpBc0ZqelhOVlFXQzMKSUVWVTNNRC92Q1hQRzZKb284bi9UOGhQWHc0T3U0NkE5RXF5dnR4VzFlWDgrMERFVFBreCtkbzJ2R0ZWRGtRMQpoNmNLSGVmMFFGSUViaHV2V1FKRTRWNE9VdEYyRlp6VjliS3laWE5jQnNTNWdkTlFKRmt1ZkYvOFV2SlFLT0tHCi9VeVYvejZrY01xMHNUc2JSRjNVSzM2QnUxSENudldoVlVvV3NBb2JKV3pBemRpRkt0V1BpclBJNW9TUWFob24Kc2JqejAwdUJJQkFhdk5rUVhiY0JBb0lCQVFEemF5bHc1VEFWYnBza3A1WUpnaWppTzVhRUNPQlNka1FwZ1Jodwo1Y0VWenZhbUlZZ2NDMVBjSE1DeUUvMjFITFF3OUtpcVRqSGJrTWhOMEs0TW1HeWJwM1hKL2hHYkd6UzRVSGFKClQrdyt4NDRWTUxxN2l4Q2dmc3JXRHNOU2RhOUFGYnEzYWg4REpaVjNIcHplRVlOR3BIZ2hzM041STNNckR2Q2QKeXowWjhNOStWdUpIVDBjYXVqa0JlTWtZbEhYVEdabnFtYzBoaFlUdDlZVGxTTXNMV1JEdUpkdDNoQjkyTDZLOApOa082Z2lxeURteWswbHZWejhSdFZBdUQ2TWtJaDEwT3lCRksyaEpCaVhQa0R5dmM4b1JSa2xpSmxaR3UzN2VXCmVacENYSmJ4MU5meGhnckhBbnhtbU91N3dVUG5oUUNGRW1RMmZicnNZcVkxZGVrMUFvSUJBUURDRjJoV0YwQjgKc0dUMVBoek0zR3RiVkpyVFh3bXFxb3BVYjlTVi9IU1JGMkJiWUUxNWFFMy9vMmVQVmovNDVoaUlyYVhweklVeQpaWkV4Yml4WkhoZy9Qa2NqeG1oTllmTUJrdFdQZHBvMFh6ZVBWQ1hFV0J2VXNBclc4RDI1ZzlkbHEzTlEyd0hqCktDQUtoZGJudU9OeUllT25DZ0tTTEdNbjJMbGJ0dWFJcmcxUnFkOU5KOCszOVQrUXZmNHVvWmxTenpPRHgwaTEKRlFMUEgxcitRdVZYMUVqL08va3kvSzJxcWRZSXlyUHRGTXpjSVdTZ3EyTWErZ1c5T29CK3NhL2JwNWZOMEl4cAp4WjlKa2grNDRjaFgvVkE4dDJORk9HVW5TOXNXRTlsNE9wcEdxSDNtZmtLMk12SnRpS3FSTG43S0k3dnVhRnRtCnk1eFdXdXNURW5UWkFvSUJBQUYxcmd6d1F1YU9BRDRyQnhwTmZvTkV5alZHZkZuaVBheG1Dc2g2aURyaVA5WmwKTXhTLytLUEVSRitOQVNONTVaYTVrTjFjbEszMVkwNGNKejhLRnZTai8yL1RwelZmNTJRSGozNXBUVWhmRi9vRwpqY2djSUdCbUFqOWdYVWw4VFMyOE01OXY4bm1wV3drWTFPWDhBdWFFaS9mZnhKeUFXdXR5TG4wenY4ME5CYUdEClVkNE5tcWFOWVZRaDdrckljU0J2OGQxWFNNU2ZzVmxmOUlrUGM3QkF1M3BDSGR2TW5nZXVaM0pyZk9KOGIxY2MKQVFqSC9pYjlGUGQyM283TzhZMnNpaUZSajlEOEY4bnUwaFFYQnpOTy9QNGtPNFd2c096MGlIeE5oR0JMZjlnNQpaNFlhUUt4SzFvWWkrcDdvbk1paG9vd3B2UklhbE9sZitoRXVBTlVDZ2dFQkFMcWJpc01MQkFOZURSTUZMdWVBCkhPL29maHN2U3JuOTBaV3hGM0ZGRWtYVmRkMGswQmdrUXFuQVQzY3VjNzg0YXVvdUdsQ1pSSTdadkNrTVJqTkEKamd0d016R2dOdlAvY29aV3lHRndwSDRwOWQ4bUJsR3FiTWVtb2lWWlFkODFkVWpZK0x3S2ROd1QzZ3AvOThrKwpwOTg1MmdqbHhPY0pLaVJMYUp0WFZIcWc3VWxReTlNQXJlT3VOZmxSMGlxL1VBeWdEbVZxbXVzUFVtNFZOWVUwCmlCQlRtQU5kaEJDVGc5Mk1BSzdmUlBKeWh5dzJKdXViSEdQNWNyOG1taGcxZW1EejF5NFlqb2U3YTVSdW0zVkUKRHowWjNhVWlwSjBPeGFKc2VpM1YwOGFXZ1hIaDJYcGNkb042cEQ3UG9UNkl0M3BkdFBoWStWZng5MVBIZ2pBSwpGTEVDZ2dFQkFLeVVmRjBqK09TZWFSV3JtdnhCdSs2czF0Y3hFNG1IYzNtaTZuenp3WGxPRTFuSGR2b2lyNmtVCldscVRVcU5kbFF3NU9oUUlOeHMxWXpyNWdvVmlSZlhsSUd3VVFJOTRuY09XSWhNNXY5SXU4RUV4alY2TnNjUUoKRGIzNjdFamV2NWJnbFJ5ejExcmdQZTlBVzlWcXpzZHNMcjdJUVcybHlaRWR6VmEzRUVCbXpaTW00T1V6a1dkVQo5TVd4N2kyRFlWNVF2b1BSMzcwNzR2elNNeFYrZDhYZmp4MFcwbzl2WWU1UHNVMVRTaEp3SkVtWXc0bmNmL3h1CitBVzRNQWtISlRONm1FYXg4SUlpV2VIN3VZT3UveDZtazZBejVIK3UyK2ZRcHpyZEtVVm02SWFLT2I1THlLQzcKTnFrZnpXeXdTNXlUWmorN3FibVZ2b3ZLYjZubXczRT0KLS0tLS1FTkQgUFJJVkFURSBLRVktLS0tLQo=</prv>
 | |
|   </cert>
 | |
|   <syslog/>
 | |
| </opnsense>
 | |
| 
 |