config.xml 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779
  1. <?xml version="1.0"?>
  2. <opnsense>
  3. <theme>opnsense</theme>
  4. <sysctl version="1.0.1" persisted_at="1759220133.28">
  5. <item/>
  6. </sysctl>
  7. <system>
  8. <optimization>normal</optimization>
  9. <hostname>kai-vpn01</hostname>
  10. <domain>infra.kaiser-zehnder.ch</domain>
  11. <dnsallowoverride>1</dnsallowoverride>
  12. <dnsallowoverride_exclude/>
  13. <group uuid="5e7f8fe9-7b59-4453-9933-924fb92c3899">
  14. <gid>1999</gid>
  15. <name>admins</name>
  16. <scope>system</scope>
  17. <description>System Administrators</description>
  18. <priv>page-all</priv>
  19. <member>0</member>
  20. <source_networks/>
  21. </group>
  22. <user uuid="6eeaeadf-3606-4ac4-829b-285ddcd4147b">
  23. <uid>0</uid>
  24. <name>root</name>
  25. <disabled>0</disabled>
  26. <scope>system</scope>
  27. <expires/>
  28. <authorizedkeys/>
  29. <otp_seed/>
  30. <shell/>
  31. <password>$2y$11$9J1gO8mVI7XgczEGqZVV6ejuszDv9aqhyQ25bEZ3gizmUvOjBmCR.</password>
  32. <pwd_changed_at/>
  33. <landing_page/>
  34. <comment/>
  35. <email/>
  36. <apikeys/>
  37. <priv/>
  38. <language/>
  39. <descr>System Administrator</descr>
  40. <dashboard/>
  41. </user>
  42. <timezone>Europe/Zurich</timezone>
  43. <timeservers>0.opnsense.pool.ntp.org 1.opnsense.pool.ntp.org 2.opnsense.pool.ntp.org 3.opnsense.pool.ntp.org</timeservers>
  44. <webgui>
  45. <protocol>https</protocol>
  46. <ssl-certref>68db91b18331c</ssl-certref>
  47. </webgui>
  48. <disablenatreflection>yes</disablenatreflection>
  49. <usevirtualterminal>1</usevirtualterminal>
  50. <disableconsolemenu/>
  51. <disablevlanhwfilter>1</disablevlanhwfilter>
  52. <disablechecksumoffloading>1</disablechecksumoffloading>
  53. <disablesegmentationoffloading>1</disablesegmentationoffloading>
  54. <disablelargereceiveoffloading>1</disablelargereceiveoffloading>
  55. <ipv6allow>1</ipv6allow>
  56. <powerd_ac_mode>hadp</powerd_ac_mode>
  57. <powerd_battery_mode>hadp</powerd_battery_mode>
  58. <powerd_normal_mode>hadp</powerd_normal_mode>
  59. <bogons>
  60. <interval>monthly</interval>
  61. </bogons>
  62. <pf_share_forward>1</pf_share_forward>
  63. <lb_use_sticky>1</lb_use_sticky>
  64. <ssh>
  65. <group>admins</group>
  66. </ssh>
  67. <rrdbackup>-1</rrdbackup>
  68. <netflowbackup>-1</netflowbackup>
  69. <firmware version="1.0.1" persisted_at="1759220133.19">
  70. <mirror/>
  71. <flavour/>
  72. <plugins>os-git-backup</plugins>
  73. <type/>
  74. <subscription/>
  75. <reboot>0</reboot>
  76. </firmware>
  77. <dnsserver>10.100.88.1</dnsserver>
  78. <language>en_US</language>
  79. <backup>
  80. <git version="1.0.0" persisted_at="1759221074.34">
  81. <enabled>1</enabled>
  82. <url>https://git.newday.ch/opnbkp/opnsense-backup.git</url>
  83. <branch>master</branch>
  84. <privkey/>
  85. <user>opnbkp</user>
  86. <password>Ghith$BiWom7</password>
  87. </git>
  88. </backup>
  89. <backupcount>100</backupcount>
  90. </system>
  91. <interfaces>
  92. <lo0>
  93. <internal_dynamic>1</internal_dynamic>
  94. <descr>Loopback</descr>
  95. <enable>1</enable>
  96. <if>lo0</if>
  97. <ipaddr>127.0.0.1</ipaddr>
  98. <ipaddrv6>::1</ipaddrv6>
  99. <subnet>8</subnet>
  100. <subnetv6>128</subnetv6>
  101. <type>none</type>
  102. <virtual>1</virtual>
  103. </lo0>
  104. <wan>
  105. <if>hn0</if>
  106. <enable>1</enable>
  107. <ipaddr>dhcp</ipaddr>
  108. <ipaddrv6>dhcp6</ipaddrv6>
  109. <blockbogons>0</blockbogons>
  110. <subnet/>
  111. <dhcphostname/>
  112. <spoofmac/>
  113. <mtu/>
  114. <mss/>
  115. <blockpriv>0</blockpriv>
  116. </wan>
  117. </interfaces>
  118. <dnsmasq version="1.0.8" persisted_at="1759220815.06">
  119. <enable>1</enable>
  120. <regdhcp>0</regdhcp>
  121. <regdhcpstatic>0</regdhcpstatic>
  122. <dhcpfirst>0</dhcpfirst>
  123. <strict_order>0</strict_order>
  124. <domain_needed>0</domain_needed>
  125. <no_private_reverse>0</no_private_reverse>
  126. <no_resolv>0</no_resolv>
  127. <log_queries>0</log_queries>
  128. <no_hosts>0</no_hosts>
  129. <strictbind>0</strictbind>
  130. <dnssec>0</dnssec>
  131. <regdhcpdomain/>
  132. <interface>lan</interface>
  133. <port>0</port>
  134. <dns_forward_max/>
  135. <cache_size/>
  136. <local_ttl/>
  137. <add_mac/>
  138. <add_subnet>0</add_subnet>
  139. <strip_subnet>0</strip_subnet>
  140. <dhcp>
  141. <no_interface/>
  142. <fqdn>1</fqdn>
  143. <domain/>
  144. <local>1</local>
  145. <lease_max/>
  146. <authoritative>0</authoritative>
  147. <default_fw_rules>1</default_fw_rules>
  148. <reply_delay/>
  149. <enable_ra>0</enable_ra>
  150. <nosync>0</nosync>
  151. </dhcp>
  152. <no_ident>1</no_ident>
  153. </dnsmasq>
  154. <snmpd>
  155. <syslocation/>
  156. <syscontact/>
  157. <rocommunity>public</rocommunity>
  158. </snmpd>
  159. <filter>
  160. <rule>
  161. <type>pass</type>
  162. <ipprotocol>inet</ipprotocol>
  163. <descr>Default allow LAN to any rule</descr>
  164. <interface>lan</interface>
  165. <source>
  166. <network>lan</network>
  167. </source>
  168. <destination>
  169. <any/>
  170. </destination>
  171. </rule>
  172. <rule>
  173. <type>pass</type>
  174. <ipprotocol>inet6</ipprotocol>
  175. <descr>Default allow LAN IPv6 to any rule</descr>
  176. <interface>lan</interface>
  177. <source>
  178. <network>lan</network>
  179. </source>
  180. <destination>
  181. <any/>
  182. </destination>
  183. </rule>
  184. </filter>
  185. <rrd>
  186. <enable/>
  187. </rrd>
  188. <ntpd>
  189. <prefer>0.opnsense.pool.ntp.org</prefer>
  190. </ntpd>
  191. <revision>
  192. <username>root@10.100.88.11</username>
  193. <description>/diag_backup.php made changes</description>
  194. <time>1759221074.34</time>
  195. </revision>
  196. <OPNsense>
  197. <wireguard>
  198. <client version="1.0.0" persisted_at="1759220133.04">
  199. <clients/>
  200. </client>
  201. <general version="0.0.1" persisted_at="1759220133.04">
  202. <enabled>0</enabled>
  203. </general>
  204. <server version="1.0.0" persisted_at="1759220133.04">
  205. <servers/>
  206. </server>
  207. </wireguard>
  208. <IPsec version="1.0.5" persisted_at="1759220815.24">
  209. <general>
  210. <enabled/>
  211. <preferred_oldsa>0</preferred_oldsa>
  212. <disablevpnrules>0</disablevpnrules>
  213. <passthrough_networks/>
  214. <user_source/>
  215. <local_group/>
  216. </general>
  217. <charon>
  218. <max_ikev1_exchanges/>
  219. <threads>16</threads>
  220. <ikesa_table_size>32</ikesa_table_size>
  221. <ikesa_table_segments>4</ikesa_table_segments>
  222. <init_limit_half_open>1000</init_limit_half_open>
  223. <ignore_acquire_ts>1</ignore_acquire_ts>
  224. <install_routes>0</install_routes>
  225. <cisco_unity>0</cisco_unity>
  226. <make_before_break>0</make_before_break>
  227. <retransmit_tries/>
  228. <retransmit_timeout/>
  229. <retransmit_base/>
  230. <retransmit_jitter/>
  231. <retransmit_limit/>
  232. <syslog>
  233. <daemon>
  234. <ike_name>1</ike_name>
  235. <log_level>0</log_level>
  236. <app>1</app>
  237. <asn>1</asn>
  238. <cfg>1</cfg>
  239. <chd>1</chd>
  240. <dmn>1</dmn>
  241. <enc>1</enc>
  242. <esp>1</esp>
  243. <ike>1</ike>
  244. <imc>1</imc>
  245. <imv>1</imv>
  246. <job>1</job>
  247. <knl>1</knl>
  248. <lib>1</lib>
  249. <mgr>1</mgr>
  250. <net>1</net>
  251. <pts>1</pts>
  252. <tls>1</tls>
  253. <tnc>1</tnc>
  254. </daemon>
  255. </syslog>
  256. <plugins>
  257. <attr>
  258. <subnet/>
  259. <split-include/>
  260. <x_28674/>
  261. <x_28675/>
  262. <x_28672/>
  263. <x_28673>0</x_28673>
  264. <x_28679/>
  265. <dns/>
  266. <nbns/>
  267. </attr>
  268. <eap-radius>
  269. <servers/>
  270. <accounting>0</accounting>
  271. <class_group>0</class_group>
  272. </eap-radius>
  273. <xauth-pam>
  274. <pam_service>ipsec</pam_service>
  275. <session>0</session>
  276. <trim_email>1</trim_email>
  277. </xauth-pam>
  278. </plugins>
  279. </charon>
  280. <keyPairs/>
  281. <preSharedKeys/>
  282. </IPsec>
  283. <Swanctl version="1.0.0" persisted_at="1759220133.08">
  284. <Connections/>
  285. <locals/>
  286. <remotes/>
  287. <children/>
  288. <Pools/>
  289. <VTIs/>
  290. <SPDs/>
  291. </Swanctl>
  292. <OpenVPNExport version="0.0.1" persisted_at="1759220133.29">
  293. <servers/>
  294. </OpenVPNExport>
  295. <OpenVPN version="1.0.1" persisted_at="1759220133.29">
  296. <Overwrites/>
  297. <Instances/>
  298. <StaticKeys/>
  299. </OpenVPN>
  300. <captiveportal version="1.0.4" persisted_at="1759220133.29">
  301. <zones/>
  302. <templates/>
  303. </captiveportal>
  304. <cron version="1.0.4" persisted_at="1759220133.30">
  305. <jobs/>
  306. </cron>
  307. <DHCRelay version="1.0.1" persisted_at="1759220133.31"/>
  308. <Firewall>
  309. <Lvtemplate version="0.0.1" persisted_at="1759220133.32">
  310. <templates/>
  311. </Lvtemplate>
  312. <Alias version="1.0.1" persisted_at="1759220133.53">
  313. <geoip>
  314. <url/>
  315. </geoip>
  316. <aliases/>
  317. </Alias>
  318. <Category version="1.0.0" persisted_at="1759220133.53">
  319. <categories/>
  320. </Category>
  321. <Filter version="1.0.4" persisted_at="1759220133.60">
  322. <rules/>
  323. <snatrules/>
  324. <npt/>
  325. <onetoone/>
  326. </Filter>
  327. </Firewall>
  328. <Netflow version="1.0.1" persisted_at="1759220133.32">
  329. <capture>
  330. <interfaces/>
  331. <egress_only/>
  332. <version>v9</version>
  333. <targets/>
  334. </capture>
  335. <collect>
  336. <enable>0</enable>
  337. </collect>
  338. <activeTimeout>1800</activeTimeout>
  339. <inactiveTimeout>15</inactiveTimeout>
  340. </Netflow>
  341. <IDS version="1.1.0" persisted_at="1759220133.82">
  342. <rules/>
  343. <policies/>
  344. <userDefinedRules/>
  345. <files/>
  346. <fileTags/>
  347. <general>
  348. <enabled>0</enabled>
  349. <ips>0</ips>
  350. <promisc>0</promisc>
  351. <interfaces>wan</interfaces>
  352. <homenet>192.168.0.0/16,10.0.0.0/8,172.16.0.0/12</homenet>
  353. <defaultPacketSize/>
  354. <UpdateCron/>
  355. <AlertLogrotate>W0D23</AlertLogrotate>
  356. <AlertSaveLogs>4</AlertSaveLogs>
  357. <MPMAlgo/>
  358. <detect>
  359. <Profile/>
  360. <toclient_groups/>
  361. <toserver_groups/>
  362. </detect>
  363. <syslog>0</syslog>
  364. <syslog_eve>0</syslog_eve>
  365. <LogPayload>0</LogPayload>
  366. <verbosity/>
  367. <eveLog>
  368. <http>
  369. <enable>0</enable>
  370. <extended>0</extended>
  371. <dumpAllHeaders/>
  372. </http>
  373. <tls>
  374. <enable>0</enable>
  375. <extended>0</extended>
  376. <sessionResumption>0</sessionResumption>
  377. <custom/>
  378. </tls>
  379. </eveLog>
  380. </general>
  381. </IDS>
  382. <Interfaces>
  383. <loopbacks version="1.0.0" persisted_at="1759220133.87"/>
  384. <neighbors version="1.0.0" persisted_at="1759220133.87"/>
  385. <vxlans version="1.0.2" persisted_at="1759220133.90"/>
  386. </Interfaces>
  387. <Kea>
  388. <ctrl_agent version="0.0.1" persisted_at="1759220133.90">
  389. <general>
  390. <enabled>0</enabled>
  391. <http_host>127.0.0.1</http_host>
  392. <http_port>8000</http_port>
  393. </general>
  394. </ctrl_agent>
  395. <dhcp4 version="1.0.4" persisted_at="1759220133.91">
  396. <general>
  397. <enabled>0</enabled>
  398. <manual_config>0</manual_config>
  399. <interfaces/>
  400. <valid_lifetime>4000</valid_lifetime>
  401. <fwrules>1</fwrules>
  402. <dhcp_socket_type>raw</dhcp_socket_type>
  403. </general>
  404. <ha>
  405. <enabled>0</enabled>
  406. <this_server_name/>
  407. <max_unacked_clients>2</max_unacked_clients>
  408. </ha>
  409. <subnets/>
  410. <reservations/>
  411. <ha_peers/>
  412. </dhcp4>
  413. <dhcp6 version="1.0.0" persisted_at="1759220133.91">
  414. <general>
  415. <enabled>0</enabled>
  416. <manual_config>0</manual_config>
  417. <interfaces/>
  418. <valid_lifetime>4000</valid_lifetime>
  419. <fwrules>1</fwrules>
  420. </general>
  421. <ha>
  422. <enabled>0</enabled>
  423. <this_server_name/>
  424. <max_unacked_clients>2</max_unacked_clients>
  425. </ha>
  426. <subnets/>
  427. <reservations/>
  428. <pd_pools/>
  429. <ha_peers/>
  430. </dhcp6>
  431. </Kea>
  432. <monit version="1.0.14" persisted_at="1759220814.91">
  433. <general>
  434. <enabled>0</enabled>
  435. <interval>120</interval>
  436. <startdelay>120</startdelay>
  437. <mailserver>127.0.0.1</mailserver>
  438. <port>25</port>
  439. <username/>
  440. <password/>
  441. <ssl>0</ssl>
  442. <sslversion>auto</sslversion>
  443. <sslverify>1</sslverify>
  444. <logfile/>
  445. <statefile/>
  446. <eventqueuePath/>
  447. <eventqueueSlots/>
  448. <httpdEnabled>0</httpdEnabled>
  449. <httpdUsername>root</httpdUsername>
  450. <httpdPassword/>
  451. <httpdPort>2812</httpdPort>
  452. <httpdAllow/>
  453. <mmonitUrl/>
  454. <mmonitTimeout>5</mmonitTimeout>
  455. <mmonitRegisterCredentials>1</mmonitRegisterCredentials>
  456. </general>
  457. <alert uuid="c181bef4-c5ff-45a9-b28d-b9cff5dd6209">
  458. <enabled>0</enabled>
  459. <recipient>root@localhost.local</recipient>
  460. <noton>0</noton>
  461. <events/>
  462. <format/>
  463. <reminder/>
  464. <description/>
  465. </alert>
  466. <service uuid="b7cad802-b591-4799-8a5b-b0f98aab4061">
  467. <enabled>1</enabled>
  468. <name>$HOST</name>
  469. <description/>
  470. <type>system</type>
  471. <pidfile/>
  472. <match/>
  473. <path/>
  474. <timeout>300</timeout>
  475. <starttimeout>30</starttimeout>
  476. <address/>
  477. <interface/>
  478. <start/>
  479. <stop/>
  480. <tests>0763b2d1-1c1f-4037-847a-39c7fa714c3c,3abc81ef-f64a-423e-bff2-278f44451e75,89294e97-f308-4791-bb55-00ca37afc8ff,2e0f6dde-cbc2-47ab-9b99-815899dc76e7</tests>
  481. <depends/>
  482. <polltime/>
  483. </service>
  484. <service uuid="37866a3b-ca2e-443d-871d-3a19cbf3d265">
  485. <enabled>1</enabled>
  486. <name>RootFs</name>
  487. <description/>
  488. <type>filesystem</type>
  489. <pidfile/>
  490. <match/>
  491. <path>/</path>
  492. <timeout>300</timeout>
  493. <starttimeout>30</starttimeout>
  494. <address/>
  495. <interface/>
  496. <start/>
  497. <stop/>
  498. <tests>ae5eaa04-b3c3-4862-a750-63c42141b553</tests>
  499. <depends/>
  500. <polltime/>
  501. </service>
  502. <service uuid="a86bfd4e-232a-4602-9ede-cefff74fff32">
  503. <enabled>0</enabled>
  504. <name>carp_status_change</name>
  505. <description/>
  506. <type>custom</type>
  507. <pidfile/>
  508. <match/>
  509. <path>/usr/local/opnsense/scripts/monit/carp_status.php</path>
  510. <timeout>300</timeout>
  511. <starttimeout>30</starttimeout>
  512. <address/>
  513. <interface/>
  514. <start/>
  515. <stop/>
  516. <tests>cb81b3da-5363-44f0-bf88-da61b26a2a54</tests>
  517. <depends/>
  518. <polltime/>
  519. </service>
  520. <service uuid="6dba41f1-1482-459f-aadb-da21df4ac44d">
  521. <enabled>0</enabled>
  522. <name>gateway_alert</name>
  523. <description/>
  524. <type>custom</type>
  525. <pidfile/>
  526. <match/>
  527. <path>/usr/local/opnsense/scripts/monit/gateway_alert.php</path>
  528. <timeout>300</timeout>
  529. <starttimeout>30</starttimeout>
  530. <address/>
  531. <interface/>
  532. <start/>
  533. <stop/>
  534. <tests>3966faa2-da92-4f18-b5b6-3bb74cdc145a</tests>
  535. <depends/>
  536. <polltime/>
  537. </service>
  538. <test uuid="4ad0b264-f36c-47dc-9f64-89010f25ed64">
  539. <name>Ping</name>
  540. <type>NetworkPing</type>
  541. <condition>failed ping</condition>
  542. <action>alert</action>
  543. <path/>
  544. </test>
  545. <test uuid="8d810eac-151f-4d94-8e35-c0848ef3c395">
  546. <name>NetworkLink</name>
  547. <type>NetworkInterface</type>
  548. <condition>failed link</condition>
  549. <action>alert</action>
  550. <path/>
  551. </test>
  552. <test uuid="afd37de6-3181-47f6-8fca-ea116aaf517a">
  553. <name>NetworkSaturation</name>
  554. <type>NetworkInterface</type>
  555. <condition>saturation is greater than 75%</condition>
  556. <action>alert</action>
  557. <path/>
  558. </test>
  559. <test uuid="0763b2d1-1c1f-4037-847a-39c7fa714c3c">
  560. <name>MemoryUsage</name>
  561. <type>SystemResource</type>
  562. <condition>memory usage is greater than 75%</condition>
  563. <action>alert</action>
  564. <path/>
  565. </test>
  566. <test uuid="3abc81ef-f64a-423e-bff2-278f44451e75">
  567. <name>CPUUsage</name>
  568. <type>SystemResource</type>
  569. <condition>cpu usage is greater than 75%</condition>
  570. <action>alert</action>
  571. <path/>
  572. </test>
  573. <test uuid="89294e97-f308-4791-bb55-00ca37afc8ff">
  574. <name>LoadAvg1</name>
  575. <type>SystemResource</type>
  576. <condition>loadavg (1min) is greater than 2</condition>
  577. <action>alert</action>
  578. <path/>
  579. </test>
  580. <test uuid="2e0f6dde-cbc2-47ab-9b99-815899dc76e7">
  581. <name>LoadAvg5</name>
  582. <type>SystemResource</type>
  583. <condition>loadavg (5min) is greater than 1.5</condition>
  584. <action>alert</action>
  585. <path/>
  586. </test>
  587. <test uuid="675ec514-3a79-45a3-9f3a-7a2986017513">
  588. <name>LoadAvg15</name>
  589. <type>SystemResource</type>
  590. <condition>loadavg (15min) is greater than 1</condition>
  591. <action>alert</action>
  592. <path/>
  593. </test>
  594. <test uuid="ae5eaa04-b3c3-4862-a750-63c42141b553">
  595. <name>SpaceUsage</name>
  596. <type>SpaceUsage</type>
  597. <condition>space usage is greater than 75%</condition>
  598. <action>alert</action>
  599. <path/>
  600. </test>
  601. <test uuid="cb81b3da-5363-44f0-bf88-da61b26a2a54">
  602. <name>ChangedStatus</name>
  603. <type>ProgramStatus</type>
  604. <condition>changed status</condition>
  605. <action>alert</action>
  606. <path/>
  607. </test>
  608. <test uuid="3966faa2-da92-4f18-b5b6-3bb74cdc145a">
  609. <name>NonZeroStatus</name>
  610. <type>ProgramStatus</type>
  611. <condition>status != 0</condition>
  612. <action>alert</action>
  613. <path/>
  614. </test>
  615. </monit>
  616. <Gateways version="1.0.0" persisted_at="1759220732.39"/>
  617. <Syslog version="1.0.2" persisted_at="1759220133.95">
  618. <general>
  619. <enabled>1</enabled>
  620. <loglocal>1</loglocal>
  621. <maxpreserve>31</maxpreserve>
  622. <maxfilesize/>
  623. </general>
  624. <destinations/>
  625. </Syslog>
  626. <TrafficShaper version="1.0.3" persisted_at="1759220133.96">
  627. <pipes/>
  628. <queues/>
  629. <rules/>
  630. </TrafficShaper>
  631. <trust>
  632. <general version="1.0.1" persisted_at="1759220134.18">
  633. <store_intermediate_certs>0</store_intermediate_certs>
  634. <install_crls>0</install_crls>
  635. <fetch_crls>0</fetch_crls>
  636. <enable_legacy_sect>1</enable_legacy_sect>
  637. <enable_config_constraints>0</enable_config_constraints>
  638. <CipherString/>
  639. <Ciphersuites/>
  640. <SignatureAlgorithms/>
  641. <groups/>
  642. <MinProtocol/>
  643. <MinProtocol_DTLS/>
  644. </general>
  645. </trust>
  646. <unboundplus version="1.0.12" persisted_at="1759220134.28">
  647. <general>
  648. <enabled>1</enabled>
  649. <port>53</port>
  650. <stats>0</stats>
  651. <active_interface/>
  652. <dnssec>0</dnssec>
  653. <dns64>0</dns64>
  654. <dns64prefix/>
  655. <noarecords>0</noarecords>
  656. <regdhcp>0</regdhcp>
  657. <regdhcpdomain/>
  658. <regdhcpstatic>0</regdhcpstatic>
  659. <noreglladdr6>0</noreglladdr6>
  660. <noregrecords>0</noregrecords>
  661. <txtsupport>0</txtsupport>
  662. <cacheflush>0</cacheflush>
  663. <local_zone_type>transparent</local_zone_type>
  664. <outgoing_interface/>
  665. <enable_wpad>0</enable_wpad>
  666. </general>
  667. <advanced>
  668. <hideidentity>0</hideidentity>
  669. <hideversion>0</hideversion>
  670. <prefetch>0</prefetch>
  671. <prefetchkey>0</prefetchkey>
  672. <dnssecstripped>0</dnssecstripped>
  673. <aggressivensec>1</aggressivensec>
  674. <serveexpired>0</serveexpired>
  675. <serveexpiredreplyttl/>
  676. <serveexpiredttl/>
  677. <serveexpiredttlreset>0</serveexpiredttlreset>
  678. <serveexpiredclienttimeout/>
  679. <qnameminstrict>0</qnameminstrict>
  680. <extendedstatistics>0</extendedstatistics>
  681. <logqueries>0</logqueries>
  682. <logreplies>0</logreplies>
  683. <logtagqueryreply>0</logtagqueryreply>
  684. <logservfail>0</logservfail>
  685. <loglocalactions>0</loglocalactions>
  686. <logverbosity>1</logverbosity>
  687. <valloglevel>0</valloglevel>
  688. <privatedomain/>
  689. <privateaddress>0.0.0.0/8,10.0.0.0/8,100.64.0.0/10,169.254.0.0/16,172.16.0.0/12,192.0.2.0/24,192.168.0.0/16,198.18.0.0/15,198.51.100.0/24,203.0.113.0/24,233.252.0.0/24,::1/128,2001:db8::/32,fc00::/8,fd00::/8,fe80::/10</privateaddress>
  690. <insecuredomain/>
  691. <msgcachesize/>
  692. <rrsetcachesize/>
  693. <outgoingnumtcp/>
  694. <incomingnumtcp/>
  695. <numqueriesperthread/>
  696. <outgoingrange/>
  697. <jostletimeout/>
  698. <discardtimeout/>
  699. <cachemaxttl/>
  700. <cachemaxnegativettl/>
  701. <cacheminttl/>
  702. <infrahostttl/>
  703. <infrakeepprobing>0</infrakeepprobing>
  704. <infracachenumhosts/>
  705. <unwantedreplythreshold/>
  706. </advanced>
  707. <acls>
  708. <default_action>allow</default_action>
  709. </acls>
  710. <dnsbl>
  711. <enabled>0</enabled>
  712. <safesearch>0</safesearch>
  713. <type/>
  714. <lists/>
  715. <whitelists/>
  716. <blocklists/>
  717. <wildcards/>
  718. <address/>
  719. <nxdomain>0</nxdomain>
  720. </dnsbl>
  721. <forwarding>
  722. <enabled>0</enabled>
  723. </forwarding>
  724. <dots/>
  725. <hosts/>
  726. <aliases/>
  727. </unboundplus>
  728. </OPNsense>
  729. <hasync version="1.0.2" persisted_at="1759220133.23">
  730. <disablepreempt>0</disablepreempt>
  731. <disconnectppps>0</disconnectppps>
  732. <pfsyncinterface/>
  733. <pfsyncpeerip/>
  734. <pfsyncversion>1400</pfsyncversion>
  735. <synchronizetoip/>
  736. <verifypeer>0</verifypeer>
  737. <username/>
  738. <password/>
  739. <syncitems/>
  740. </hasync>
  741. <openvpn/>
  742. <ifgroups version="1.0.0" persisted_at="1759220133.60"/>
  743. <bridges version="1.0.0" persisted_at="1759220133.83">
  744. <bridged/>
  745. </bridges>
  746. <gifs version="1.0.0" persisted_at="1759220133.84">
  747. <gif/>
  748. </gifs>
  749. <gres version="1.0.0" persisted_at="1759220133.84">
  750. <gre/>
  751. </gres>
  752. <laggs version="1.0.0" persisted_at="1759220133.87">
  753. <lagg/>
  754. </laggs>
  755. <virtualip version="1.0.1" persisted_at="1759220133.87">
  756. <vip/>
  757. </virtualip>
  758. <vlans version="1.0.0" persisted_at="1759220133.90">
  759. <vlan/>
  760. </vlans>
  761. <staticroutes version="1.0.0" persisted_at="1759220133.92"/>
  762. <ppps>
  763. <ppp/>
  764. </ppps>
  765. <wireless>
  766. <clone/>
  767. </wireless>
  768. <ca/>
  769. <dhcpd/>
  770. <dhcpdv6/>
  771. <cert uuid="bb23b478-030e-4306-af47-543e454bb90e">
  772. <refid>68db91b18331c</refid>
  773. <descr>Web GUI TLS certificate</descr>
  774. <caref/>
  775. <crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUhFakNDQlBxZ0F3SUJBZ0lVYkZ4YVEzSTljOWJjRHBqVTV3azdhckZrWWV3d0RRWUpLb1pJaHZjTkFRRUwKQlFBd2dZWXhHakFZQmdOVkJBTU1FVTlRVG5ObGJuTmxMbWx1ZEdWeWJtRnNNUXN3Q1FZRFZRUUdFd0pPVERFVgpNQk1HQTFVRUNBd01XblZwWkMxSWIyeHNZVzVrTVJVd0V3WURWUVFIREF4TmFXUmtaV3hvWVhKdWFYTXhMVEFyCkJnTlZCQW9NSkU5UVRuTmxibk5sSUhObGJHWXRjMmxuYm1Wa0lIZGxZaUJqWlhKMGFXWnBZMkYwWlRBZUZ3MHkKTlRBNU16QXdPREUxTkRoYUZ3MHlOakV4TURFd09ERTFORGhhTUlHR01Sb3dHQVlEVlFRRERCRlBVRTV6Wlc1egpaUzVwYm5SbGNtNWhiREVMTUFrR0ExVUVCaE1DVGt3eEZUQVRCZ05WQkFnTURGcDFhV1F0U0c5c2JHRnVaREVWCk1CTUdBMVVFQnd3TVRXbGtaR1ZzYUdGeWJtbHpNUzB3S3dZRFZRUUtEQ1JQVUU1elpXNXpaU0J6Wld4bUxYTnAKWjI1bFpDQjNaV0lnWTJWeWRHbG1hV05oZEdVd2dnSWlNQTBHQ1NxR1NJYjNEUUVCQVFVQUE0SUNEd0F3Z2dJSwpBb0lDQVFERnZqTzZwbDlUR0p5SVZxRzdld0JKcGZpZmlZNzc0NHZrVktsckhVZUNFMWpUcHlPVHdxUk1LYVpMCnRFc3pRb1lwZ05JbGRKdDVQSWtSMy81cW5wOE12eGYwc2VuV0hSS1RvalFDaGsrQlg4bUtWNnZSbEtaTTBkcE4KdXVWWXkxOUZTM3d6cVJWa1NSUVBQcUt1TXVCOUpKSGxSOGl0K1Y1aGp1N2k3VmFsZmUrM2JZL0h2S3gxT1NLYwpNenFITkJLazJZeDhVTGlNSmdmdjlub2tVVFpXWG9xU1J3a3NwYWdFSlRpUzcySlNSWGM4eDhpeFlhYlhUWit5Cnd0YVF4WU1oOTByS1psdnlLZCtuaW43SU5YclYzTmp3ai9sc3RXRkQ5MUdraVdpenQ3ZzRIS3FuV2tScndsMjYKaVNpbDYxZThqdUFna1Y1QnJSelo3cWVnN3d6bEhMcThCWnBZQlZTL0xhNnFzWHpaUXFkV3N3QzFEa0lpMklDawp2Zm1hbGxmL0NLdnZwREsyUzVxeTJGNlJsaHMzM0FjQm0rQmFNSkVuWVQxZEgweEl2OFFRZC9NTHZ2emVuVDRXCmcxZ0lXRnU1dmtPbDN4cUJ0OEJqaWpWbE0vSXBjbmsza1BId2Z2Qk51clVsbWpmd3RSUDRJZnRVSFBXcWpndzYKN1lBM2dPZEpnaEJqU3FVUHVia2pUZm92TVVQZVI5YlRyS0hLWWxaejAwUXQyd0NyVXgwMnJvWWdqRzlUNHhnTgpibk1ibTJ4cmg3eHpjNGI2STdqRnd2QlU5TkhFdWl1MkIzaUcvZ1N2Y05rRW1qVzFxMHdGY2VSK2czK09pVUI0CkxPNkQxb3M2OTY3RjZWc2VXUU8xSlg0a0pWWTE2Vlc1eWR4RXdqRUFhcURNekVzUmpRSURBUUFCbzRJQmREQ0MKQVhBd0NRWURWUjBUQkFJd0FEQVJCZ2xnaGtnQmh2aENBUUVFQkFNQ0JrQXdOQVlKWUlaSUFZYjRRZ0VOQkNjVwpKVTlRVG5ObGJuTmxJRWRsYm1WeVlYUmxaQ0JUWlhKMlpYSWdRMlZ5ZEdsbWFXTmhkR1V3SFFZRFZSME9CQllFCkZQaHRwL0tTeWNHa2NiK1NYUGdFbjVNMWNUcFpNSUd3QmdOVkhTTUVnYWd3Z2FXaGdZeWtnWWt3Z1lZeEdqQVkKQmdOVkJBTU1FVTlRVG5ObGJuTmxMbWx1ZEdWeWJtRnNNUXN3Q1FZRFZRUUdFd0pPVERFVk1CTUdBMVVFQ0F3TQpXblZwWkMxSWIyeHNZVzVrTVJVd0V3WURWUVFIREF4TmFXUmtaV3hvWVhKdWFYTXhMVEFyQmdOVkJBb01KRTlRClRuTmxibk5sSUhObGJHWXRjMmxuYm1Wa0lIZGxZaUJqWlhKMGFXWnBZMkYwWllJVWJGeGFRM0k5YzliY0RwalUKNXdrN2FyRmtZZXd3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQ0FJQ01Bc0dBMVVkRHdRRQpBd0lGb0RBY0JnTlZIUkVFRlRBVGdoRlBVRTV6Wlc1elpTNXBiblJsY201aGJEQU5CZ2txaGtpRzl3MEJBUXNGCkFBT0NBZ0VBamRUMGttOEViUktzUzhCWjgycnJpRUdBajFzSE9WbGhkM2QwMHI0cmM0OFdCZFJJOXRiRGtBcnAKb3JBZ1FIK3M2M0FKL0VaNW0rdXE3cE9jb1lBTVhSUzk4UE9ySVM1R01PNUVnbTUvRUR2UVNBRzI3K0lDSnBYQgpBZjJBREt6b3I2Q2d4cTF1L3dUZHdaUjhHVERxd1FrVTBJcE9KUURLSkhSVVducjJEL1VsdHo4S0tGT0xIT3JHCkN3RlRQWEE3Z2dNYkhqMnM5ZldtMmpuTjBvclBxUjJTdW9UZ2I3YlVaa1hqbFBpNjdsVTB4V3pTSEJsdWxQdGgKT2RZY3VHK2tWZmNibTlUTVZldGU0bHdhM1pGUnBET3VKVnlOMzdEZy9PbEZqKytDU1dNNjNFV25BK1JrSFp4TgpHdVRZT3RyVlp3Vm9XUldpWWIwMS80a09EaWRyUHV2Tzc2VXZGQzJmUVFWYTFuQUQ1bXhsMEFOQi83VjRRbTMxCnRWTHpJeE5vZmxQM1ZNL2xTeWZ3aVNFUklGbEtvdlZLS1VMbWErRTE3UFkrWnNYSEFIbUxEd05abWpnMTNrSC8KWDJBaDR6ZFFJU1NxYjhSQkhpUFYrdFZHUlFzUWNYZUM5TFQ4bEhET2swRnRSRlhINVNwNHowK3ZLZG1GSmsyTgo3YU91d3FST0xkNnZNTHVHT0lnaDVIK25IOUJoRktRZExjcnd5TDJjRjdlTktGZnJDcitndzZnV2ZaV1hQMUtQCmQ4dlUrTzIxUHRGMDB0Z25ONnQ5WTBBQWlRb3pvT1hLSU5xWWxiWGlEejBYakZ5aG8xOEhRbEQ2aUNZbHkrU28KMTEvREYyK21ObVNHQmpCT0ZCcVMrSEw2ZVJSRjM4VGxsY25qYWxPUEpxR0Rac1RhYjBVPQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==</crt>
  776. <csr/>
  777. <prv>LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUpSQUlCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQ1M0d2dna3FBZ0VBQW9JQ0FRREZ2ak82cGw5VEdKeUkKVnFHN2V3QkpwZmlmaVk3NzQ0dmtWS2xySFVlQ0UxalRweU9Ud3FSTUthWkx0RXN6UW9ZcGdOSWxkSnQ1UElrUgozLzVxbnA4TXZ4ZjBzZW5XSFJLVG9qUUNoaytCWDhtS1Y2dlJsS1pNMGRwTnV1Vll5MTlGUzN3enFSVmtTUlFQClBxS3VNdUI5SkpIbFI4aXQrVjVoanU3aTdWYWxmZSszYlkvSHZLeDFPU0tjTXpxSE5CS2syWXg4VUxpTUpnZnYKOW5va1VUWldYb3FTUndrc3BhZ0VKVGlTNzJKU1JYYzh4OGl4WWFiWFRaK3l3dGFReFlNaDkwcktabHZ5S2QrbgppbjdJTlhyVjNOandqL2xzdFdGRDkxR2tpV2l6dDdnNEhLcW5Xa1Jyd2wyNmlTaWw2MWU4anVBZ2tWNUJyUnpaCjdxZWc3d3psSExxOEJacFlCVlMvTGE2cXNYelpRcWRXc3dDMURrSWkySUNrdmZtYWxsZi9DS3Z2cERLMlM1cXkKMkY2UmxoczMzQWNCbStCYU1KRW5ZVDFkSDB4SXY4UVFkL01MdnZ6ZW5UNFdnMWdJV0Z1NXZrT2wzeHFCdDhCagppalZsTS9JcGNuazNrUEh3ZnZCTnVyVWxtamZ3dFJQNElmdFVIUFdxamd3NjdZQTNnT2RKZ2hCalNxVVB1YmtqClRmb3ZNVVBlUjliVHJLSEtZbFp6MDBRdDJ3Q3JVeDAycm9ZZ2pHOVQ0eGdOYm5NYm0yeHJoN3h6YzRiNkk3akYKd3ZCVTlOSEV1aXUyQjNpRy9nU3ZjTmtFbWpXMXEwd0ZjZVIrZzMrT2lVQjRMTzZEMW9zNjk2N0Y2VnNlV1FPMQpKWDRrSlZZMTZWVzV5ZHhFd2pFQWFxRE16RXNSalFJREFRQUJBb0lDQUJJL0YzTGZxejExc0phbXQ4eDBSY3N3Cm4zSnozNjBWTlhGZm05L0xGekFhTE90MWZzT1hCYVlVS2NqT2lDbmd0NVNEZmVDcTZUVy9XajZRckFucjU4S1EKck5zNEY0V3ZCUlI1QzlJMzBTK2ZtOFNYaTc2T1l1ZGFiZDhYb2RZWENMYlNNbEcvVzc2aDU2ZElkbEViVjJUMAp4NVJLa3IvMW1nODlLeTg4QzBUQXR0Vk1MTStYZEtwcHdwY2w1YWxZS3IyVXZYRXpMdlJGQmgwa1llZVJWREdWClk3VlZETFJXb2pHbEVFVlpXczg3VGJkZXVxd2VLMUVEL3FVZ3lXcHViMGZtYVJEOWI2VTIxcHUveHl4emt0N0MKYVlUanpzdUlmbTNSRjhncm94ZXM3NDRZbkdsT01RWVRMS2JyeFJrYVVFR1JSWDU3MWlDNm9wdVJlVno3bktBcgpYVjZXcnh6Vkw0MHZmdjc1QUM0dUpodTFPSjVmM0phNzhVbDJDemRKRk1mRmU4NEFhNTRZbkJUMWM0bUdGUUtvCm5INHJTY0FCOERrcWViM3czTkZwaGd0dkY2S1YrOEoxeGlkT25JbzB0N21Qc1BzRzJxdVNpRVZ1UnpRSldMOXcKZ3pBWWxFTGhkQnpEdHdBWjc1MDBRWXZpMjBiZnNQQkdMblh0bHcrSDNzT2plVnNoSjdhbUZ3SjBTS3dSL1MzMAo1UDVaUElIYVJkb2Z5QVNqSWVtVm9sZFg2emJqOVE3Z0hQN1ZMdGFzODRPRXNNL24zMHB3VkNjaHliaFhDV29HCm5VMWN0MlJCUWpqSDBZV0ErN1NlYzROdWZEd2FVN0Q1RGlYRzlITFlNc1hxYzFPR0hEd3RPc1c5aWNIMjdxMGgKbVlMR1RaNGV6WTA1Nk5udy9hUVpBb0lCQVFEaEhDekNDZG1OWUlpVHUyUXZrOFFoZUZnOTVGRjZlL0dqUHd1cQpMRHlXa3p4OWp3M0c4ZTJIZkJtRWtpaEJJUkNHTEZFZ2lGZWtvYjY1U0FqY2theTF0V1BnTEpCZm50ME5rQ3ZXCkZxS05vWXR4Sm00TFNSMmZ0S3l0SUEybGZQMzNvQnRacE81emFQbWMrb00zR0lySURsQTA0M3FBVzliblRkdlMKdUo5NVora29Kd0NrTVBCdG50VS8yZ1VZMEtudjVsVnJaUHgyMHdEZm9PVWxVTW93YXFDKzM1S0p3a1k5WVdnMgo4S2RzeUg5VzJtSm5tZXdNS0xKclNiYm1SNjB6M0c1NG10Tlo4YWFMT1dpcjJYWW0rK1ViWEs1WlpZU1IxVTBUClB2RjB3eGoxUDdWZUJmQ2Evc0JyangvVGltV0IzZ1h4ZjJjYm1YcDFhdlBwUHY4L0FvSUJBUURnNEtnMXNTT04Kc2xzcEk5cUF0RjdqTWo3Y0cwNHhhSnlaQlBsN3I2MlNiejF3TGM4V1ZXdTFqSzZua1dveDJMeGtCNEEwSFlrMAp2NDNvVW5HSGdHZVBmQnNsWUJRZ0JkbkNrTVkxeFZRRDc1Q1E2SDlnYm9wSW1BamhrbStiUExpZXhxOFFYaWxYCmhDRmFOK1AybC9oS0pvZEJweVRBN2lldE8xVkF4K0tVZ21xNkRLcFAzSlJYWit1STE4S3c2R0k2b2hqSnAxb2YKQUtjQ0hBNDk2eXZibkNvVzhLR0V3S0hZek9hSzhuamdPMnoxV1d0cGZMRGRBWGNqSDBuV3o4K3J0Q3hvYkpxagpHRG5VOWJiY2pzRDJzTHdKcXg4MzJyMGtzZ2E3Y1pPMWoyNHZUM1VRNDNYOENmZHpYMGFyQWFGZi9XYk91UGJBCkZ3NXUzd3NTYThnekFvSUJBUUNrbVNWZy9ETEczVDhBUnBVSzlORUVhQ3FkbHNTOCtzUEV5ZVNObWFyenJ0VWMKT2UybytsemtKQ25FZGRwWlJRUUFGNGQ2Y2pjamVlRXJPVERCbHdMaUdxL2N5cmtHTWZNUVo4cWwwQWNyNkdNOQphUXd0MUZpRTNtY2tiN3VLdGNvOXRpUkpkLytqQTY4QXlXd0liVG1NN21wWFFiM2cvVVkxK3dneEhDMy9aNnRrCllLQm5iaUZmQmpTSGE3TXVZZVRnTlZ0Z0c0YytteXFZV2Qwelc4OTdkM3Z5RlNmZzh0ekpKT0EreTlpZ0FqcWEKRnpTODdCOWRCS1R4TGdVK2ZFcDVFVVQxaXIvZmxJSmlhcWZPZ0VPVVhiczROcHlGWVdWOS9LbE8yVWRVU1JPRwp2LzZ0c1VvdEN2bEhyRzlwRGxrS2pIMXNCK3dza2h5b25udWFvU1doQW9JQkFRRFRyeWNvdzhMd0U4RDBqU2VXCm1EUHFNdFl4WkJMTE4rcVJzTGtZMFZyV3laaFFEUTh2dXVGVldVVGZ3R2J5M1U4WjZtV29xVlVMTG5ackI1Q1AKT1RSRFFWUmNib0VEVS82VXhLdVEybHdvQ0U5UjJVcHVnQi8wRGdudUxXYVoveUxiYzdRLytDTjZtb3E2M25uZApHMWxDazlvbTF5d2w0UW5BYkdYb1FVRHRBNGRyODVndTdUbEd2akJkOUp6MDR3djBuYm92dVRXQWthQ2t2N3c0ClZUUkgyazFVb3Rlb201eSs5TUxnY1RlUC9PQ29aTEJUOEdpYzRsQS80NmdpYWlUWFFSZThoTjljUCtYUXJpeWcKbWxEUzU3TmFkcGRBZ013anl1SERlVHJPWW1JYWJ2V0lIRlpvRndtMHRTOVVzb2d5VDl1REpXSkJtSEtoczV3OApqdkU1QW9JQkFRRFh1SVZyK3ZHeXRtN05VTWs5MU11SWxUM2dwWnNlRWwyeXltRlV5VHlOVmNVbWFxZTZSdnU0ClhMdXRSdFo2YkVzWmEySkVjVER4U0UxNTcrcmYrUjRrL0UxcTVobzZ0eEcvV21OdzF2eGd2eXk5aWE0NGZIL2wKTllub095aVVmTEZrMGRXbk5VcGlmeWdmaWQ1cmJtb2x3dzUyZW9QRDgzbkN5ZmpXL2RFSlZ1Z2dJMTZrRkV5WQo3RHBldnQvcVJHOVh0S3RXbTN2V0hjMUZ3Q0Y5NndtWHpvWDQwUW1xSU9LbE54NEU3NkxBOCtvRkdVdU5sTmk1CnVjZkt5VXZ4a25JU3Z6K0h5YVYxN0c3eUdVb0NRK2w4VVZHZUFIaUp3R0JUQnY1MUFzN2xnQXM1K04rUTVJc20KZllBR09OUkZNOUczQmpuZk8zeHk0S1I3enVHc3FyMm8KLS0tLS1FTkQgUFJJVkFURSBLRVktLS0tLQo=</prv>
  778. </cert>
  779. </opnsense>