1
|
<?php
|
2
|
/* $Id$ */
|
3
|
/*
|
4
|
globals.inc
|
5
|
part of pfSense (https://www.pfsense.org)
|
6
|
Copyright (C) 2004-2010 Scott Ullrich
|
7
|
|
8
|
Originally Part of m0n0wall
|
9
|
Copyright (C) 2003-2004 Manuel Kasper <mk@neon1.net>.
|
10
|
All rights reserved.
|
11
|
|
12
|
Redistribution and use in source and binary forms, with or without
|
13
|
modification, are permitted provided that the following conditions are met:
|
14
|
|
15
|
1. Redistributions of source code must retain the above copyright notice,
|
16
|
this list of conditions and the following disclaimer.
|
17
|
|
18
|
2. Redistributions in binary form must reproduce the above copyright
|
19
|
notice, this list of conditions and the following disclaimer in the
|
20
|
documentation and/or other materials provided with the distribution.
|
21
|
|
22
|
THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
|
23
|
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY
|
24
|
AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
25
|
AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY,
|
26
|
OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
27
|
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
28
|
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
29
|
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
30
|
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
31
|
POSSIBILITY OF SUCH DAMAGE.
|
32
|
|
33
|
pfSense_MODULE: utils
|
34
|
|
35
|
*/
|
36
|
|
37
|
global $g;
|
38
|
$g = array(
|
39
|
"base_packages" => "siproxd",
|
40
|
"event_address" => "unix:///var/run/check_reload_status",
|
41
|
"factory_shipped_username" => "admin",
|
42
|
"factory_shipped_password" => "pfsense",
|
43
|
"upload_path" => "/root",
|
44
|
"dhcpd_chroot_path" => "/var/dhcpd",
|
45
|
"unbound_chroot_path" => "/var/unbound",
|
46
|
"varrun_path" => "/var/run",
|
47
|
"varetc_path" => "/var/etc",
|
48
|
"vardb_path" => "/var/db",
|
49
|
"varlog_path" => "/var/log",
|
50
|
"etc_path" => "/etc",
|
51
|
"tmp_path" => "/tmp",
|
52
|
"conf_path" => "/conf",
|
53
|
"ftmp_path" => "/ftmp",
|
54
|
"conf_default_path" => "/conf.default",
|
55
|
"cf_path" => "/cf",
|
56
|
"cf_conf_path" => "/cf/conf",
|
57
|
"www_path" => "/usr/local/www",
|
58
|
"xml_rootobj" => "pfsense",
|
59
|
"admin_group" => "admins",
|
60
|
"product_name" => "pfSense",
|
61
|
"product_copyright" => "Electric Sheep Fencing LLC",
|
62
|
"product_copyright_url" => "http://www.electricsheepfencing.com",
|
63
|
"product_copyright_years" => "2004 - ".date("Y"),
|
64
|
"product_website" => "www.pfsense.org",
|
65
|
"product_website_footer" => "https://www.pfsense.org/?gui22",
|
66
|
"product_email" => "coreteam@pfsense.org",
|
67
|
"hideplatform" => false,
|
68
|
"hidedownloadbackup" => false,
|
69
|
"hidebackupbeforeupgrade" => false,
|
70
|
"disablethemeselection" => false,
|
71
|
"disablehelpmenu" => false,
|
72
|
"disablehelpicon" => false,
|
73
|
"disablecrashreporter" => false,
|
74
|
"crashreporterurl" => "https://crashreporter.pfsense.org/crash_reporter.php",
|
75
|
"debug" => false,
|
76
|
"latest_config" => "10.8",
|
77
|
"nopkg_platforms" => array("cdrom"),
|
78
|
"minimum_ram_warning" => "101",
|
79
|
"minimum_ram_warning_text" => "128 MB",
|
80
|
"minimum_nic_count" => "1",
|
81
|
"minimum_nic_count_text" => "*AT LEAST* 1",
|
82
|
"wan_interface_name" => "wan",
|
83
|
"nopccard_platforms" => array("wrap", "net48xx"),
|
84
|
"xmlrpcbaseurl" => "https://packages.pfsense.org",
|
85
|
"captiveportal_path" => "/usr/local/captiveportal",
|
86
|
"captiveportal_element_path" => "/var/db/cpelements",
|
87
|
"captiveportal_element_sizelimit" => 1048576,
|
88
|
"xmlrpcpath" => "/xmlrpc.php",
|
89
|
"embeddedbootupslice" => "/dev/ad0a",
|
90
|
"services_dhcp_server_enable" => true,
|
91
|
"wireless_regex" => "/^(ndis|wi|ath|an|ral|ural|iwi|wlan|rum|run|bwn|zyd|mwl|bwi|ipw|iwn|malo|uath|upgt|urtw|wpi)/",
|
92
|
"help_base_url" => "/help.php"
|
93
|
);
|
94
|
|
95
|
/* IP TOS flags */
|
96
|
$iptos = array("lowdelay", "throughput", "reliability");
|
97
|
|
98
|
/* TCP flags */
|
99
|
$tcpflags = array("syn", "ack", "fin", "rst", "psh", "urg", "ece", "cwr");
|
100
|
|
101
|
if(file_exists("/etc/platform")) {
|
102
|
$arch = php_uname("m");
|
103
|
/* Do not remove this, it is not needed for the snapshots URL but is needed later for the -RELEASE/stable URLs */
|
104
|
//$arch = ($arch == "i386") ? "" : '/' . $arch;
|
105
|
|
106
|
/* Full installs and NanoBSD use the same update directory and manifest in 2.x */
|
107
|
$g['update_url']="https://snapshots.pfsense.org/FreeBSD_stable/10/{$arch}/pfSense_HEAD/.updaters/";
|
108
|
$g['update_manifest']="https://updates.pfSense.org/manifest";
|
109
|
|
110
|
$g['platform'] = trim(file_get_contents("/etc/platform"));
|
111
|
if($g['platform'] == "nanobsd") {
|
112
|
$g['firmware_update_text']="pfSense-*.img.gz";
|
113
|
$g['hidedownloadbackup'] = true;
|
114
|
$g['hidebackupbeforeupgrade'] = true;
|
115
|
|
116
|
} else {
|
117
|
$g['firmware_update_text']="pfSense-*.tgz";
|
118
|
}
|
119
|
}
|
120
|
|
121
|
/* Default sysctls */
|
122
|
$sysctls = array("net.inet.ip.portrange.first" => "1024",
|
123
|
"net.inet.tcp.blackhole" => "2",
|
124
|
"net.inet.udp.blackhole" => "1",
|
125
|
"net.inet.ip.random_id" => "1",
|
126
|
"net.inet.tcp.drop_synfin" => "1",
|
127
|
"net.inet.ip.redirect" => "1",
|
128
|
"net.inet6.ip6.redirect" => "1",
|
129
|
"net.inet6.ip6.use_tempaddr" => "0",
|
130
|
"net.inet6.ip6.prefer_tempaddr" => "0",
|
131
|
"net.inet.tcp.syncookies" => "1",
|
132
|
"net.inet.tcp.recvspace" => "65228",
|
133
|
"net.inet.tcp.sendspace" => "65228",
|
134
|
"net.inet.ip.fastforwarding" => "0",
|
135
|
"net.inet.tcp.delayed_ack" => "0",
|
136
|
"net.inet.udp.maxdgram" => "57344",
|
137
|
"net.link.bridge.pfil_onlyip" => "0",
|
138
|
"net.link.bridge.pfil_member" => "1",
|
139
|
"net.link.bridge.pfil_bridge" => "0",
|
140
|
"net.link.tap.user_open" => "1",
|
141
|
"kern.randompid" => "347",
|
142
|
"net.inet.ip.intr_queue_maxlen" => "1000",
|
143
|
"hw.syscons.kbd_reboot" => "0",
|
144
|
"net.inet.tcp.log_debug" => "0",
|
145
|
"net.inet.tcp.tso" => "1",
|
146
|
"net.inet.icmp.icmplim" => "0",
|
147
|
"vfs.read_max" => "32",
|
148
|
"kern.ipc.maxsockbuf" => "4262144",
|
149
|
"debug.pfftpproxy" => "0",
|
150
|
"net.inet.ip.process_options" => 0,
|
151
|
"kern.random.sys.harvest.interrupt" => 0,
|
152
|
"kern.random.sys.harvest.point_to_point" => 0,
|
153
|
"kern.random.sys.harvest.ethernet" => 0,
|
154
|
"net.route.netisr_maxqlen" => 1024,
|
155
|
"net.inet.udp.checksum" => 1,
|
156
|
"net.bpf.zerocopy_enable" => 1
|
157
|
);
|
158
|
|
159
|
/* Include override values for the above if needed. If the file doesn't exist, don't try to load it. */
|
160
|
if (file_exists("/etc/inc/globals_override.inc"))
|
161
|
@include("globals_override.inc");
|
162
|
|
163
|
$config_parsed = false;
|
164
|
|
165
|
?>
|