Projet

Général

Profil

Télécharger (12,8 ko) Statistiques
| Branche: | Tag: | Révision:

univnautes / conf.default / config.xml @ master

1
<?xml version="1.0"?>
2
<!-- pfSense default system configuration -->
3
<pfsense>
4
	<version>9.9</version>
5
	<lastchange></lastchange>
6
	<theme>pfsense_ng</theme>
7
	<system>
8
		<optimization>normal</optimization>
9
		<hostname>pfSense</hostname>
10
		<domain>localdomain</domain>
11
		<dnsserver/>
12
		<dnsallowoverride/>
13
		<group>
14
			<name>all</name>
15
			<description><![CDATA[All Users]]></description>
16
			<scope>system</scope>
17
			<gid>1998</gid>
18
			<member>0</member>
19
		</group>
20
		<group>
21
			<name>admins</name>
22
			<description><![CDATA[System Administrators]]></description>
23
			<scope>system</scope>
24
			<gid>1999</gid>
25
			<member>0</member>
26
			<priv>page-all</priv>
27
		</group>
28
		<user>
29
			<name>admin</name>
30
			<descr><![CDATA[System Administrator]]></descr>
31
			<scope>system</scope>
32
			<groupname>admins</groupname>
33
			<password>$1$dSJImFph$GvZ7.1UbuWu.Yb8etC0re.</password>
34
			<uid>0</uid>
35
			<priv>user-shell-access</priv>
36
		</user>
37
		<nextuid>2000</nextuid>
38
		<nextgid>2000</nextgid>
39
		<timezone>Etc/UTC</timezone>
40
		<time-update-interval>300</time-update-interval>
41
		<timeservers>0.pfsense.pool.ntp.org</timeservers>
42
		<webgui>
43
			<protocol>https</protocol>
44
		</webgui>
45
		<disablenatreflection>yes</disablenatreflection>
46
		<!-- <disableconsolemenu/> -->
47
		<!-- <disablefirmwarecheck/> -->
48
		<!-- <shellcmd></shellcmd> -->
49
		<!-- <earlyshellcmd></earlyshellcmd> -->
50
		<!-- <harddiskstandby></harddiskstandby> -->
51
		<disablesegmentationoffloading/>
52
		<disablelargereceiveoffloading/>
53
		<ipv6allow/>
54
		<powerd_ac_mode>hadp</powerd_ac_mode>
55
		<powerd_battery_mode>hadp</powerd_battery_mode>
56
		<powerd_normal_mode>hadp</powerd_normal_mode>
57
		<bogons>
58
			<interval>monthly</interval>
59
		</bogons>
60
		<kill_states/>
61
	</system>
62
	<interfaces>
63
		<wan>
64
			<enable/>
65
			<if>vr1</if>
66
			<mtu></mtu>
67
			<ipaddr>dhcp</ipaddr>
68
			<ipaddrv6>dhcp6</ipaddrv6>
69
			<!-- *or* ipv4-address *or* 'pppoe' *or* 'pptp' *or* 'bigpond' -->
70
			<subnet></subnet>
71
			<gateway></gateway>
72
			<blockpriv/>
73
			<blockbogons/>
74
			<dhcphostname></dhcphostname>
75
			<media></media>
76
			<mediaopt></mediaopt>
77
			<dhcp6-duid></dhcp6-duid>
78
			<dhcp6-ia-pd-len>0</dhcp6-ia-pd-len>
79
			<!--
80
			<wireless>
81
				*see below (opt[n])*
82
			</wireless>
83
			-->
84
		</wan>
85
		<lan>
86
			<enable/>
87
			<if>vr0</if>
88
			<ipaddr>192.168.1.1</ipaddr>
89
			<subnet>24</subnet>
90
			<ipaddrv6>track6</ipaddrv6>
91
			<subnetv6>64</subnetv6>
92
			<media></media>
93
			<mediaopt></mediaopt>
94
			<track6-interface>wan</track6-interface>
95
			<track6-prefix-id>0</track6-prefix-id>
96
			<!--
97
			<wireless>
98
				*see below (opt[n])*
99
			</wireless>
100
			-->
101
		</lan>
102
		<!--
103
		<opt[n]>
104
			<enable/>
105
			<descr></descr>
106
			<if></if>
107
			<ipaddr></ipaddr>
108
			<subnet></subnet>
109
			<media></media>
110
			<mediaopt></mediaopt>
111
			<bridge>lan|wan|opt[n]</bridge>
112
			<wireless>
113
				<mode>hostap *or* bss *or* ibss</mode>
114
				<ssid></ssid>
115
				<channel></channel>
116
				<wep>
117
					<enable/>
118
					<key>
119
						<txkey/>
120
						<value></value>
121
					</key>
122
				</wep>
123
			</wireless>
124
		</opt[n]>
125
		-->
126
	</interfaces>
127
	<!--
128
	<vlans>
129
		<vlan>
130
			<tag></tag>
131
			<if></if>
132
			<descr></descr>
133
		</vlan>
134
	</vlans>
135
	-->
136
	<staticroutes>
137
		<!--
138
		<route>
139
			<interface>lan|opt[n]|pptp</interface>
140
			<network>xxx.xxx.xxx.xxx/xx</network>
141
			<gateway>xxx.xxx.xxx.xxx</gateway>
142
			<descr></descr>
143
		</route>
144
		-->
145
	</staticroutes>
146
	<dhcpd>
147
		<lan>
148
			<enable/>
149
			<range>
150
				<from>192.168.1.100</from>
151
				<to>192.168.1.199</to>
152
			</range>
153
			<!--
154
			<winsserver>xxx.xxx.xxx.xxx</winsserver>
155
			<defaultleasetime></defaultleasetime>
156
			<maxleasetime></maxleasetime>
157
			<gateway>xxx.xxx.xxx.xxx</gateway>
158
			<domain></domain>
159
			<dnsserver></dnsserver>
160
			<ntpserver>xxx.xxx.xxx.xxx</ntpserver>
161
			<next-server></next-server>
162
			<filename></filename>
163
			<filename32></filename32>
164
			<filename64></filename64>
165
			-->
166
		</lan>
167
		<!--
168
		<opt[n]>
169
			...
170
		</opt[n]>
171
		-->
172
		<!--
173
		<staticmap>
174
			<mac>xx:xx:xx:xx:xx:xx</mac>
175
			<ipaddr>xxx.xxx.xxx.xxx</ipaddr>
176
			<descr></descr>
177
		</staticmap>
178
		-->
179
	</dhcpd>
180
	<pptpd>
181
		<mode><!-- off *or* server *or* redir --></mode>
182
		<redir/>
183
		<localip/>
184
		<remoteip/>
185
		<!-- <accounting/> -->
186
		<!--
187
		<user>
188
			<name></name>
189
			<password></password>
190
		</user>
191
		-->
192
	</pptpd>
193
	<dnsmasq>
194
		<enable/>
195
		<!--
196
		<hosts>
197
			<host></host>
198
			<domain></domain>
199
			<ip></ip>
200
			<descr></descr>
201
		</hosts>
202
		-->
203
	</dnsmasq>
204
	<snmpd>
205
		<!-- <enable/> -->
206
		<syslocation/>
207
		<syscontact/>
208
		<rocommunity>public</rocommunity>
209
	</snmpd>
210
	<diag>
211
		<ipv6nat>
212
			<!-- <enable/> -->
213
			<ipaddr/>
214
		</ipv6nat>
215
	</diag>
216
	<bridge>
217
		<!-- <filteringbridge/> -->
218
	</bridge>
219
	<syslog>
220
		<!--
221
		<reverse/>
222
		<enable/>
223
		<remoteserver>xxx.xxx.xxx.xxx</remoteserver>
224
		<filter/>
225
		<dhcp/>
226
		<system/>
227
		<nologdefaultblock/>
228
		-->
229
	</syslog>
230
	<!--
231
	<captiveportal>
232
		<enable/>
233
		<interface>lan|opt[n]</interface>
234
		<idletimeout>minutes</idletimeout>
235
		<timeout>minutes</timeout>
236
		<page>
237
			<htmltext></htmltext>
238
			<errtext></errtext>
239
		</page>
240
		<httpslogin/>
241
		<httpsname></httpsname>
242
		<redirurl></redirurl>
243
		<radiusip></radiusip>
244
		<radiusport></radiusport>
245
		<radiuskey></radiuskey>
246
		<nomacfilter/>
247
	</captiveportal>
248
	-->
249
	<nat>
250
		<outbound>
251
			<mode>automatic</mode>
252
			<!--
253
			<rule>
254
				<interface></interface>
255
				<source>
256
					<network>xxx.xxx.xxx.xxx/xx</network>
257
				</source>
258
				<destination>
259
					<not/>
260
					<any/>
261
					*or*
262
					<network>xxx.xxx.xxx.xxx/xx</network>
263
				</destination>
264
				<target>xxx.xxx.xxx.xxx</target>
265
				<descr></descr>
266
			</rule>
267
			-->
268
		</outbound>
269
		<!--
270
		<rule>
271
			<interface></interface>
272
			<external-address></external-address>
273
			<protocol></protocol>
274
			<external-port></external-port>
275
			<target></target>
276
			<local-port></local-port>
277
			<descr></descr>
278
		</rule>
279
		-->
280
		<!--
281
		<onetoone>
282
			<interface></interface>
283
			<external>xxx.xxx.xxx.xxx</external>
284
			<internal>xxx.xxx.xxx.xxx</internal>
285
			<subnet></subnet>
286
			<descr></descr>
287
		</onetoone>
288
		-->
289
		<!--
290
		<servernat>
291
			<ipaddr></ipaddr>
292
			<descr></descr>
293
		</servernat>
294
		-->
295
	</nat>
296
	<filter>
297
		<!-- <tcpidletimeout></tcpidletimeout> -->
298
		<rule>
299
			<type>pass</type>
300
			<ipprotocol>inet</ipprotocol>
301
			<descr><![CDATA[Default allow LAN to any rule]]></descr>
302
			<interface>lan</interface>
303
			<tracker>0100000101</tracker>
304
			<source>
305
				<network>lan</network>
306
			</source>
307
			<destination>
308
				<any/>
309
			</destination>
310
		</rule>
311
		<rule>
312
			<type>pass</type>
313
			<ipprotocol>inet6</ipprotocol>
314
			<descr><![CDATA[Default allow LAN IPv6 to any rule]]></descr>
315
			<interface>lan</interface>
316
			<tracker>0100000102</tracker>
317
			<source>
318
				<network>lan</network>
319
			</source>
320
			<destination>
321
				<any/>
322
			</destination>
323
		</rule>
324
		<!-- rule syntax:
325
		<rule>
326
			<disabled/>
327
			<id>[0-9]*</id>
328
			<type>pass|block|reject</type>
329
			<ipprotocol>inet|inet6</ipprotocol>
330
			<descr>...</descr>
331
			<interface>lan|opt[n]|wan|pptp</interface>
332
			<protocol>tcp|udp|tcp/udp|...</protocol>
333
			<icmptype></icmptype>
334
			<source>
335
				<not/>
336

    
337
				<address>xxx.xxx.xxx.xxx(/xx) or alias</address>
338
				*or*
339
				<network>lan|opt[n]|pptp</network>
340
				*or*
341
				<any/>
342

    
343
				<port>a[-b]</port>
344
			</source>
345
			<destination>
346
				*same as for source*
347
			</destination>
348
			<frags/>
349
			<log/>
350
		</rule>
351
		-->
352
	</filter>
353
	<shaper>
354
		<!-- <enable/> -->
355
		<!-- <schedulertype>hfsc</schedulertype> -->
356
		<!-- rule syntax:
357
		<rule>
358
			<disabled/>
359
			<descr></descr>
360

    
361
			<targetpipe>number (zero based)</targetpipe>
362
			*or*
363
			<targetqueue>number (zero based)</targetqueue>
364

    
365
			<interface>lan|wan|opt[n]|pptp</interface>
366
			<protocol>tcp|udp</protocol>
367
			<direction>in|out</direction>
368
			<source>
369
				<not/>
370

    
371
				<address>xxx.xxx.xxx.xxx(/xx)</address>
372
				*or*
373
				<network>lan|opt[n]|pptp</network>
374
				*or*
375
				<any/>
376

    
377
				<port>a[-b]</port>
378
			</source>
379
			<destination>
380
				*same as for source*
381
			</destination>
382

    
383
			<iplen>from[-to]</iplen>
384
			<iptos>(!)lowdelay,throughput,reliability,mincost,congestion</iptos>
385
			<tcpflags>(!)fin,syn,rst,psh,ack,urg</tcpflags>
386
		</rule>
387
		<pipe>
388
			<descr></descr>
389
			<bandwidth></bandwidth>
390
			<delay></delay>
391
			<mask>source|destination</mask>
392
		</pipe>
393
		<queue>
394
			<descr></descr>
395
			<targetpipe>number (zero based)</targetpipe>
396
			<weight></weight>
397
			<mask>source|destination</mask>
398
		</queue>
399
		-->
400
	</shaper>
401
	<ipsec>
402
		<!-- <enable/> -->
403
		<!-- syntax:
404
		<tunnel>
405
			<disabled/>
406
			<auto/>
407
			<descr></descr>
408
			<interface>lan|wan|opt[n]</interface>
409
			<local-subnet>
410
				<address>xxx.xxx.xxx.xxx(/xx)</address>
411
				*or*
412
				<network>lan|opt[n]</network>
413
			</local-subnet>
414
			<remote-subnet>xxx.xxx.xxx.xxx/xx</remote-subnet>
415
			<remote-gateway></remote-gateway>
416
			<p1>
417
				<mode></mode>
418
				<myident>
419
					<myaddress/>
420
					*or*
421
					<address>xxx.xxx.xxx.xxx</address>
422
					*or*
423
					<fqdn>the.fq.dn</fqdn>
424
				</myident>
425
				<encryption-algorithm></encryption-algorithm>
426
				<hash-algorithm></hash-algorithm>
427
				<dhgroup></dhgroup>
428
				<lifetime></lifetime>
429
				<pre-shared-key></pre-shared-key>
430
			</p1>
431
			<p2>
432
				<protocol></protocol>
433
				<encryption-algorithm-option></encryption-algorithm-option>
434
				<hash-algorithm-option></hash-algorithm-option>
435
				<pfsgroup></pfsgroup>
436
				<lifetime></lifetime>
437
			</p2>
438
		</tunnel>
439
		<mobileclients>
440
			<enable/>
441
			<p1>
442
				<mode></mode>
443
				<myident>
444
					<myaddress/>
445
					*or*
446
					<address>xxx.xxx.xxx.xxx</address>
447
					*or*
448
					<fqdn>the.fq.dn</fqdn>
449
				</myident>
450
				<encryption-algorithm></encryption-algorithm>
451
				<hash-algorithm></hash-algorithm>
452
				<dhgroup></dhgroup>
453
				<lifetime></lifetime>
454
			</p1>
455
			<p2>
456
				<protocol></protocol>
457
				<encryption-algorithm-option></encryption-algorithm-option>
458
				<hash-algorithm-option></hash-algorithm-option>
459
				<pfsgroup></pfsgroup>
460
				<lifetime></lifetime>
461
			</p2>
462
		</mobileclients>
463
		<mobilekey>
464
			<ident></ident>
465
			<pre-shared-key></pre-shared-key>
466
		</mobilekey>
467
		-->
468
	</ipsec>
469
	<aliases>
470
		<!--
471
		<alias>
472
			<name></name>
473
			<address>xxx.xxx.xxx.xxx(/xx)</address>
474
			<descr></descr>
475
		</alias>
476
		-->
477
	</aliases>
478
	<proxyarp>
479
		<!--
480
		<proxyarpnet>
481
			<network>xxx.xxx.xxx.xxx/xx</network>
482
			*or*
483
			<range>
484
				<from>xxx.xxx.xxx.xxx</from>
485
				<to>xxx.xxx.xxx.xxx</to>
486
			</range>
487
		</proxyarpnet>
488
		-->
489
	</proxyarp>
490
	<cron>
491
		<item>
492
			<minute>1,31</minute>
493
			<hour>0-5</hour>
494
			<mday>*</mday>
495
			<month>*</month>
496
			<wday>*</wday>
497
			<who>root</who>
498
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
499
		</item>
500
		<item>
501
			<minute>1</minute>
502
			<hour>3</hour>
503
			<mday>1</mday>
504
			<month>*</month>
505
			<wday>*</wday>
506
			<who>root</who>
507
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
508
		</item>
509
		<item>
510
			<minute>*/60</minute>
511
			<hour>*</hour>
512
			<mday>*</mday>
513
			<month>*</month>
514
			<wday>*</wday>
515
			<who>root</who>
516
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
517
		</item>
518
		<item>
519
			<minute>1</minute>
520
			<hour>1</hour>
521
			<mday>*</mday>
522
			<month>*</month>
523
			<wday>*</wday>
524
			<who>root</who>
525
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
526
		</item>
527
		<item>
528
			<minute>*/60</minute>
529
			<hour>*</hour>
530
			<mday>*</mday>
531
			<month>*</month>
532
			<wday>*</wday>
533
			<who>root</who>
534
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
535
		</item>
536
		<item>
537
			<minute>30</minute>
538
			<hour>12</hour>
539
			<mday>*</mday>
540
			<month>*</month>
541
			<wday>*</wday>
542
			<who>root</who>
543
			<command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
544
		</item>
545
	</cron>
546
	<wol>
547
		<!--
548
		<wolentry>
549
			<interface>lan|opt[n]</interface>
550
			<mac>xx:xx:xx:xx:xx:xx</mac>
551
			<descr></descr>
552
		</wolentry>
553
		-->
554
	</wol>
555
	<rrd>
556
		<enable/>
557
	</rrd>
558
	<load_balancer>
559
		<monitor_type>
560
			<name>ICMP</name>
561
			<type>icmp</type>
562
			<descr><![CDATA[ICMP]]></descr>
563
			<options/>
564
		</monitor_type>
565
		<monitor_type>
566
			<name>TCP</name>
567
			<type>tcp</type>
568
			<descr><![CDATA[Generic TCP]]></descr>
569
			<options/>
570
		</monitor_type>
571
		<monitor_type>
572
			<name>HTTP</name>
573
			<type>http</type>
574
			<descr><![CDATA[Generic HTTP]]></descr>
575
			<options>
576
				<path>/</path>
577
				<host/>
578
				<code>200</code>
579
			</options>
580
		</monitor_type>
581
		<monitor_type>
582
			<name>HTTPS</name>
583
			<type>https</type>
584
			<descr><![CDATA[Generic HTTPS]]></descr>
585
			<options>
586
				<path>/</path>
587
				<host/>
588
				<code>200</code>
589
			</options>
590
		</monitor_type>
591
		<monitor_type>
592
			<name>SMTP</name>
593
			<type>send</type>
594
			<descr><![CDATA[Generic SMTP]]></descr>
595
			<options>
596
				<send></send>
597
				<expect>220 *</expect>
598
			</options>
599
		</monitor_type>
600
	</load_balancer>
601
	<widgets>
602
		<sequence>system_information-container:col1:show,captive_portal_status-container:col1:close,carp_status-container:col1:close,cpu_graphs-container:col1:close,gateways-container:col1:close,gmirror_status-container:col1:close,installed_packages-container:col1:close,interface_statistics-container:col1:close,interfaces-container:col2:show,ipsec-container:col2:close,load_balancer_status-container:col2:close,log-container:col2:close,picture-container:col2:close,rss-container:col2:close,services_status-container:col2:close,traffic_graphs-container:col2:close</sequence>
603
	</widgets>
604
</pfsense>
    (1-1/1)