Files
gate-config/config.xml

2649 lines
104 KiB
XML
Raw Normal View History

<?xml version="1.0"?>
<opnsense>
<theme>opnsense</theme>
<sysctl>
<item>
<descr>Increase UFS read-ahead speeds to match the state of hard drives and NCQ.</descr>
<tunable>vfs.read_max</tunable>
<value>default</value>
</item>
<item>
<descr>Set the ephemeral port range to be lower.</descr>
<tunable>net.inet.ip.portrange.first</tunable>
<value>default</value>
</item>
<item>
<descr>Drop packets to closed TCP ports without returning a RST</descr>
<tunable>net.inet.tcp.blackhole</tunable>
<value>default</value>
</item>
<item>
<descr>Do not send ICMP port unreachable messages for closed UDP ports</descr>
<tunable>net.inet.udp.blackhole</tunable>
<value>default</value>
</item>
<item>
<descr>Randomize the ID field in IP packets</descr>
<tunable>net.inet.ip.random_id</tunable>
<value>default</value>
</item>
<item>
<descr>
Source routing is another way for an attacker to try to reach non-routable addresses behind your box.
It can also be used to probe for information about your internal networks. These functions come enabled
as part of the standard FreeBSD core system.
</descr>
<tunable>net.inet.ip.sourceroute</tunable>
<value>default</value>
</item>
<item>
<descr>
Source routing is another way for an attacker to try to reach non-routable addresses behind your box.
It can also be used to probe for information about your internal networks. These functions come enabled
as part of the standard FreeBSD core system.
</descr>
<tunable>net.inet.ip.accept_sourceroute</tunable>
<value>default</value>
</item>
<item>
<descr>
This option turns off the logging of redirect packets because there is no limit and this could fill
up your logs consuming your whole hard drive.
</descr>
<tunable>net.inet.icmp.log_redirect</tunable>
<value>default</value>
</item>
<item>
<descr>Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)</descr>
<tunable>net.inet.tcp.drop_synfin</tunable>
<value>default</value>
</item>
<item>
<descr>Enable sending IPv6 redirects</descr>
<tunable>net.inet6.ip6.redirect</tunable>
<value>default</value>
</item>
<item>
<descr>Enable privacy settings for IPv6 (RFC 4941)</descr>
<tunable>net.inet6.ip6.use_tempaddr</tunable>
<value>default</value>
</item>
<item>
<descr>Prefer privacy addresses and use them over the normal addresses</descr>
<tunable>net.inet6.ip6.prefer_tempaddr</tunable>
<value>default</value>
</item>
<item>
<descr>Generate SYN cookies for outbound SYN-ACK packets</descr>
<tunable>net.inet.tcp.syncookies</tunable>
<value>default</value>
</item>
<item>
<descr>Maximum incoming/outgoing TCP datagram size (receive)</descr>
<tunable>net.inet.tcp.recvspace</tunable>
<value>default</value>
</item>
<item>
<descr>Maximum incoming/outgoing TCP datagram size (send)</descr>
<tunable>net.inet.tcp.sendspace</tunable>
<value>default</value>
</item>
<item>
<descr>Do not delay ACK to try and piggyback it onto a data packet</descr>
<tunable>net.inet.tcp.delayed_ack</tunable>
<value>default</value>
</item>
<item>
<descr>Maximum outgoing UDP datagram size</descr>
<tunable>net.inet.udp.maxdgram</tunable>
<value>default</value>
</item>
<item>
<descr>Handling of non-IP packets which are not passed to pfil (see if_bridge(4))</descr>
<tunable>net.link.bridge.pfil_onlyip</tunable>
<value>default</value>
</item>
<item>
<descr>Set to 1 to additionally filter on the physical interface for locally destined packets</descr>
<tunable>net.link.bridge.pfil_local_phys</tunable>
<value>default</value>
</item>
<item>
<tunable>net.link.bridge.pfil_member</tunable>
<value>0</value>
<descr>Set to 0 to disable filtering on the incoming and outgoing member interfaces.</descr>
</item>
<item>
<tunable>net.link.bridge.pfil_bridge</tunable>
<value>1</value>
<descr>Set to 1 to enable filtering on the bridge interface</descr>
</item>
<item>
<descr>Allow unprivileged access to tap(4) device nodes</descr>
<tunable>net.link.tap.user_open</tunable>
<value>default</value>
</item>
<item>
<descr>Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())</descr>
<tunable>kern.randompid</tunable>
<value>default</value>
</item>
<item>
<descr>Disable CTRL+ALT+Delete reboot from keyboard.</descr>
<tunable>hw.syscons.kbd_reboot</tunable>
<value>default</value>
</item>
<item>
<descr>Enable TCP extended debugging</descr>
<tunable>net.inet.tcp.log_debug</tunable>
<value>default</value>
</item>
<item>
<descr>Set ICMP Limits</descr>
<tunable>net.inet.icmp.icmplim</tunable>
<value>default</value>
</item>
<item>
<descr>TCP Offload Engine</descr>
<tunable>net.inet.tcp.tso</tunable>
<value>default</value>
</item>
<item>
<descr>UDP Checksums</descr>
<tunable>net.inet.udp.checksum</tunable>
<value>default</value>
</item>
<item>
<descr>Maximum socket buffer size</descr>
<tunable>kern.ipc.maxsockbuf</tunable>
<value>default</value>
</item>
<item>
<descr>Page Table Isolation (Meltdown mitigation, requires reboot.)</descr>
<tunable>vm.pmap.pti</tunable>
<value>default</value>
</item>
<item>
<descr>Disable Indirect Branch Restricted Speculation (Spectre V2 mitigation)</descr>
<tunable>hw.ibrs_disable</tunable>
<value>default</value>
</item>
<item>
<descr>Hide processes running as other groups</descr>
<tunable>security.bsd.see_other_gids</tunable>
<value>default</value>
</item>
<item>
<descr>Hide processes running as other users</descr>
<tunable>security.bsd.see_other_uids</tunable>
<value>default</value>
</item>
<item>
<descr>Enable/disable sending of ICMP redirects in response to IP packets for which a better,
and for the sender directly reachable, route and next hop is known.
</descr>
<tunable>net.inet.ip.redirect</tunable>
<value>default</value>
</item>
<item>
<descr>
Redirect attacks are the purposeful mass-issuing of ICMP type 5 packets. In a normal network, redirects
to the end stations should not be required. This option enables the NIC to drop all inbound ICMP redirect
packets without returning a response.
</descr>
<tunable>net.inet.icmp.drop_redirect</tunable>
<value>1</value>
</item>
<item>
<descr>Maximum outgoing UDP datagram size</descr>
<tunable>net.local.dgram.maxdgram</tunable>
<value>default</value>
</item>
<item>
<tunable>net.inet.tcp.mss_ifmtu</tunable>
<value>1</value>
<descr>Enable TCP MSS auto-adjust based on interface MTU</descr>
</item>
</sysctl>
<system>
<optimization>conservative</optimization>
<hostname>gate</hostname>
<domain>waw.eldorado.city</domain>
<dnsallowoverride>1</dnsallowoverride>
<group>
<name>admins</name>
<description>System Administrators</description>
<scope>system</scope>
<gid>1999</gid>
<member>0</member>
<priv>page-all</priv>
</group>
<user>
<name>root</name>
<descr>System Administrator</descr>
<scope>system</scope>
<groupname>admins</groupname>
<password>$2y$11$bze9aco9zESP42qWhxo7yORRiK1mRvoa5aa7lzXetRg4NDULMOyOu</password>
<uid>0</uid>
<dashboard/>
</user>
<nextuid>2000</nextuid>
<nextgid>2000</nextgid>
<timezone>Europe/Warsaw</timezone>
<timeservers>0.opnsense.pool.ntp.org 1.opnsense.pool.ntp.org 2.opnsense.pool.ntp.org 3.opnsense.pool.ntp.org</timeservers>
<webgui>
<protocol>https</protocol>
<ssl-certref>67058c2b680ff</ssl-certref>
<port/>
<ssl-ciphers/>
<interfaces>opt1,opt2,opt3,lan,opt4,opt5</interfaces>
<compression/>
</webgui>
<disablenatreflection>yes</disablenatreflection>
<usevirtualterminal>1</usevirtualterminal>
<disableconsolemenu>1</disableconsolemenu>
<disablevlanhwfilter>1</disablevlanhwfilter>
<disablechecksumoffloading>1</disablechecksumoffloading>
<disablesegmentationoffloading>1</disablesegmentationoffloading>
<disablelargereceiveoffloading>1</disablelargereceiveoffloading>
<powerd_ac_mode>hadp</powerd_ac_mode>
<powerd_battery_mode>hadp</powerd_battery_mode>
<powerd_normal_mode>hadp</powerd_normal_mode>
<bogons>
<interval>monthly</interval>
</bogons>
<pf_share_forward>1</pf_share_forward>
<lb_use_sticky>1</lb_use_sticky>
<ssh>
<group>admins</group>
<noauto>1</noauto>
<interfaces>lan</interfaces>
<kex/>
<ciphers/>
<macs/>
<keys/>
<keysig/>
<enabled>enabled</enabled>
<passwordauth>1</passwordauth>
<permitrootlogin>1</permitrootlogin>
</ssh>
<rrdbackup>-1</rrdbackup>
<netflowbackup>-1</netflowbackup>
<firmware version="1.0.1">
<mirror/>
<flavour/>
<plugins>os-acme-client,os-git-backup</plugins>
<type/>
<subscription/>
<reboot/>
</firmware>
<language>en_US</language>
<prefer_ipv4>1</prefer_ipv4>
<dnsallowoverride_exclude/>
<dnsserver/>
<backup>
<git version="1.0.0">
<enabled>1</enabled>
<url>ssh://projects-gate.radziel.com:40294/radziel/gate-config.git</url>
<branch>master</branch>
<privkey>-----BEGIN OPENSSH PRIVATE KEY-----&#xD;
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn&#xD;
NhAAAAAwEAAQAAAYEA0HPzKFtIswRQ5v5riYE/Z0WiKhpLVnXVwxkhTTV3JQ59pmW5fs3b&#xD;
dWqf2qyNnmCu6ITv1deKBTolihh8OLaGvis+DA8U1yPUxjFB/OPv16gIEF1erryOJfx2Q1&#xD;
ikGkWja+Bs/MSI7RY/uKkJyc/w1+plAJQMxy3Q37CSE1m3luGLLvz7tbIkE6ZpJdkXo8mL&#xD;
CF65YyofP9Q67WQ5AWZ5L7pryYUBgpPs4CPzkNESKcsx8S19LyubDpd8tw8IgJB+w0vkre&#xD;
/ikzhIA49kxeyNOcWk+j6nFLSBFT9k36T4BkKbBBJj6KBBzI8j+qhs6WYl4BbVb/ETufmw&#xD;
YzPj5+FZi9six59lPGdqVz8ZsHLbq553HlIlFWWkWpa/qK0ON/K2DmKgqeb9L7AvVQle7C&#xD;
hmkEenIz5Edkl+URW/fGEGaM4/9si3KpwQSegk05aS0DiMQeJNIw7S5aKerymKFOUwAbav&#xD;
LgF5eHeAu6aSXtaIDmLVIYx5YlCfVnz9WrOoKdsvAAAFiAucWlULnFpVAAAAB3NzaC1yc2&#xD;
EAAAGBANBz8yhbSLMEUOb+a4mBP2dFoioaS1Z11cMZIU01dyUOfaZluX7N23Vqn9qsjZ5g&#xD;
ruiE79XXigU6JYoYfDi2hr4rPgwPFNcj1MYxQfzj79eoCBBdXq68jiX8dkNYpBpFo2vgbP&#xD;
zEiO0WP7ipCcnP8NfqZQCUDMct0N+wkhNZt5bhiy78+7WyJBOmaSXZF6PJiwheuWMqHz/U&#xD;
Ou1kOQFmeS+6a8mFAYKT7OAj85DREinLMfEtfS8rmw6XfLcPCICQfsNL5K3v4pM4SAOPZM&#xD;
XsjTnFpPo+pxS0gRU/ZN+k+AZCmwQSY+igQcyPI/qobOlmJeAW1W/xE7n5sGMz4+fhWYvb&#xD;
IsefZTxnalc/GbBy26uedx5SJRVlpFqWv6itDjfytg5ioKnm/S+wL1UJXuwoZpBHpyM+RH&#xD;
ZJflEVv3xhBmjOP/bItyqcEEnoJNOWktA4jEHiTSMO0uWinq8pihTlMAG2ry4BeXh3gLum&#xD;
kl7WiA5i1SGMeWJQn1Z8/VqzqCnbLwAAAAMBAAEAAAGAA0j92TIjFwB86T8I4ShidZVb2m&#xD;
UCsJtNIfTTQ7Jm18nULMX9TTnKTnM+j1rZJS3/OQE1/xKVWsK7/7f7ZoYTNouw6ni8X9hG&#xD;
jKm5vAC4RsJKVOkGdSOElqWqvsyhUsar2NHhyylVF8Nvf/tYq6UKyyRRsNd5zL50mb81y3&#xD;
dGVOrmCiNeMNKyDds5XKmAsrSaQSiuVu6S19XXkzvZSCPeH2Sajpj5g/N32rUbrA8XcFrY&#xD;
RSWYi6CYzNCSBxfbZEdNU3rntvXF37mZZF9CDo/If23D1CLA2PjGqKt9FR+lJu0y6+nKqU&#xD;
9MxoWhZuWpxz6icSL0E5oweWdb/oRYjDTwOm5AF/jEofAVh4mivuOPDFVpFyDDNuTJ5jzS&#xD;
KOGkqOj5SE00RkoCmdUmnt7fxB4T+ZAQ+ZcPzXSBtVdzQolrGLijsSCAVKXR6tgXyKDeRU&#xD;
Ck6RVKlxnu5RrLBp2uzhVU8h5FqaEoWha7lFTeH/TGPvayMaGSfU4FL7RoNfmZrNHZAAAA&#xD;
wQCHDwFjTLSTq6oFNmJtojw83Lz3ObsVFvom27saZlb6iCUq7O972uEnG1iQUpQpGmI99L&#xD;
UlZ3K25v7ePbtjOpuKSv+cR7kOXa3EnvOyz0TwofnUYRRD3nk8dEJ9e1A0dbi76RUxVdmx&#xD;
ygc157MaxI1wClw+CKwsluFvUSigfv9IcyWRtH1bS0GHRVh8vfq0jmLV6g/zQGFGgFomB1&#xD;
sBiZmwdQzk+lkBYgOuqxdJWSVqmrvlIqcwUxSIuOohzNW+LqEAAADBANNcXSwb2TP+ljbu&#xD;
CqdgIvDeB6WEoIqQ/dTYAPZWiKh+T31mzBRqWC+vTHyh/MuhnRy4YCpq7Y9eT970xu+PWA&#xD;
Z3wCpXnXAwt/AU8yqMxA+KAtmX3f9DRBHEWysuDs4LRGBfC8Y5xyPNX1j1nt4WZTxq8jQ7&#xD;
A9KlK61sjcwTnxC0745S1QjGiOq1PookR/fw1gl+zgASMy+wOIkQi/ioSklEJNfYDFPGtG&#xD;
uljSlpIeI5J37mA0X7Jc3oRJrflvPF+QAAAMEA/Hpdxpztsc+0XiEZ4psGOFDEpEUfGtFw&#xD;
I2imT340O8OWzpR7bHLdjZJSN+fIlaFqX8u2XOGMwhd/nNMSF6MSp+3PXuUQc+vPNRjQA1&#xD;
2JMspHmjwyRMXZ2qzd7wY8yaDWnX5BHRwoFMm1FhqdevYuMm6QavnRrPFTdji45oo4gUSg&#xD;
+tD7qpNAPHRNrE5A5oMTXCeYUj1w0Gvmz8o7ww5qgRQzXIbf91orhFDiTci6OKcj018r0u&#xD;
xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA==&#xD;
-----END OPENSSH PRIVATE KEY-----&#xD;
</privkey>
<user>git</user>
<password/>
</git>
</backup>
<dns1gw>none</dns1gw>
<dns2gw>none</dns2gw>
<dns3gw>none</dns3gw>
<dns4gw>none</dns4gw>
<dns5gw>none</dns5gw>
<dns6gw>none</dns6gw>
<dns7gw>none</dns7gw>
<dns8gw>none</dns8gw>
<maximumstates/>
<maximumfrags/>
<aliasesresolveinterval/>
<maximumtableentries/>
<pfdebug>urgent</pfdebug>
<serialspeed>115200</serialspeed>
<primaryconsole>video</primaryconsole>
<use_mfs_var>1</use_mfs_var>
<use_mfs_tmp>1</use_mfs_tmp>
<thermal_hardware>coretemp</thermal_hardware>
<enablenatreflectionhelper>yes</enablenatreflectionhelper>
</system>
<interfaces>
<wan>
<if>pppoe0</if>
<descr>WAN</descr>
<enable>1</enable>
<lock>1</lock>
<spoofmac/>
<blockpriv>1</blockpriv>
<blockbogons>1</blockbogons>
<mtu>1540</mtu>
<ipaddr>pppoe</ipaddr>
</wan>
<lan>
<if>bridge0</if>
<descr>LAN_BRIDGE</descr>
<enable>1</enable>
<lock>1</lock>
<spoofmac/>
<mtu>1400</mtu>
<mss>1360</mss>
<ipaddr>172.27.72.254</ipaddr>
<subnet>21</subnet>
</lan>
<lo0>
<internal_dynamic>1</internal_dynamic>
<descr>Loopback</descr>
<enable>1</enable>
<if>lo0</if>
<ipaddr>127.0.0.1</ipaddr>
<ipaddrv6>::1</ipaddrv6>
<subnet>8</subnet>
<subnetv6>128</subnetv6>
<type>none</type>
<virtual>1</virtual>
</lo0>
<opt1>
<if>vtnet0</if>
<descr>ETH1</descr>
<enable>1</enable>
<spoofmac/>
</opt1>
<opt2>
<if>vtnet2</if>
<descr>ETH2</descr>
<enable>1</enable>
<spoofmac/>
</opt2>
<opt3>
<if>vtnet3</if>
<descr>ETH3</descr>
<enable>1</enable>
<spoofmac/>
</opt3>
<opt5>
<if>vtnet5</if>
<descr>SFP2</descr>
<enable>1</enable>
<lock>1</lock>
<spoofmac/>
</opt5>
<opt4>
<if>vtnet4</if>
<descr>SFP1</descr>
<enable>1</enable>
<lock>1</lock>
<spoofmac/>
</opt4>
<opt12>
<if>vtnet1</if>
<descr>ETH0</descr>
<enable>1</enable>
<spoofmac/>
</opt12>
<opt13>
<descr>SFP135</descr>
<if>vlan0435</if>
</opt13>
<opt14>
<descr>SFP235</descr>
<if>vlan0535</if>
</opt14>
<opt15>
<if>bridge2</if>
<descr>VLAN35_BRIDGE</descr>
<enable>1</enable>
<lock>1</lock>
<spoofmac/>
</opt15>
<opt6>
<if>wg0</if>
<descr>VPN</descr>
<enable>1</enable>
<spoofmac/>
</opt6>
<opt7>
<if>vlan05100</if>
<descr>SFP2100</descr>
<enable>1</enable>
<spoofmac/>
<ipaddr>192.168.100.254</ipaddr>
<subnet>24</subnet>
</opt7>
<wireguard>
<internal_dynamic>1</internal_dynamic>
<descr>WireGuard (Group)</descr>
<if>wireguard</if>
<virtual>1</virtual>
<enable>1</enable>
<type>group</type>
<networks/>
</wireguard>
</interfaces>
<dhcpd>
<lan>
<enable>1</enable>
<defaultleasetime>7200</defaultleasetime>
<maxleasetime>7260</maxleasetime>
<gateway>172.27.72.254</gateway>
<domain>waw.eldorado.city</domain>
<ddnsdomainalgorithm>hmac-md5</ddnsdomainalgorithm>
<numberoptions>
<item/>
</numberoptions>
<range>
<from>172.27.79.100</from>
<to>172.27.79.200</to>
</range>
<winsserver/>
<dnsserver>172.27.72.254</dnsserver>
<ntpserver/>
<staticmap>
<mac>48:da:35:6f:40:55</mac>
<ipaddr>172.27.72.2</ipaddr>
<hostname>hv-kvm</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>48:da:35:6f:ed:13</mac>
<ipaddr>172.27.72.3</ipaddr>
<hostname>trofeo-kvm</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>bc:24:11:c1:b3:02</mac>
<ipaddr>172.27.72.5</ipaddr>
<hostname>monit</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>bc:24:11:fe:5a:31</mac>
<ipaddr>172.27.72.10</ipaddr>
<hostname>hermes</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>bc:24:11:63:28:54</mac>
<ipaddr>172.27.72.15</ipaddr>
<hostname>pbs</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>64:51:06:f9:53:6c</mac>
<ipaddr>172.27.72.30</ipaddr>
<hostname>tank</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>64:51:06:f9:53:6e</mac>
<ipaddr>172.27.72.31</ipaddr>
<hostname>ilo-tank</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>10:9c:70:2c:a9:a8</mac>
<ipaddr>172.27.72.35</ipaddr>
<hostname>prusa3d</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>8c:dc:d4:b6:02:e5</mac>
<ipaddr>172.27.72.50</ipaddr>
<hostname>trofeo</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>4c:cc:6a:bb:94:e4</mac>
<ipaddr>172.27.72.52</ipaddr>
<hostname>trofeo-backup</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>38:8a:06:fb:e3:a0</mac>
<ipaddr>172.27.72.60</ipaddr>
<hostname>rgUltra</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>42:74:f3:60:e3:4a</mac>
<ipaddr>172.27.72.61</ipaddr>
<hostname>rgWatch</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>50:20:65:e9:ed:c4</mac>
<ipaddr>172.27.72.65</ipaddr>
<hostname>steamdeck</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>a4:ee:57:52:71:57</mac>
<ipaddr>172.27.72.198</ipaddr>
<hostname>scanner</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>00:00:f0:a2:f8:4e</mac>
<ipaddr>172.27.72.199</ipaddr>
<hostname>printer</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>98:25:4a:3d:1b:f4</mac>
<ipaddr>172.27.72.251</ipaddr>
<hostname>ap</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>24:2f:d0:cd:aa:1c</mac>
<ipaddr>172.27.72.252</ipaddr>
<hostname>switch</hostname>
<descr>TPLINK SG3210X-M2</descr>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>d6:fc:de:22:a7:7d</mac>
<ipaddr>172.27.75.30</ipaddr>
<hostname>pandora</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>b6:a3:ba:ce:de:78</mac>
<ipaddr>172.27.75.35</ipaddr>
<hostname>ikar</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>b6:d5:8b:99:fc:91</mac>
<ipaddr>172.27.75.40</ipaddr>
<hostname>iris</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>34:ce:00:a1:aa:de</mac>
<ipaddr>172.27.78.10</ipaddr>
<hostname>iot-airpurifier</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>2c:9f:fb:31:55:bc</mac>
<ipaddr>172.27.78.15</ipaddr>
<hostname>iot-ac</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>48:3f:da:48:f3:b2</mac>
<ipaddr>172.27.78.20</ipaddr>
<hostname>iot-env01</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>80:7d:3a:7f:ec:c2</mac>
<ipaddr>172.27.78.21</ipaddr>
<hostname>iot-env02</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>50:14:79:69:c4:64</mac>
<ipaddr>172.27.78.25</ipaddr>
<hostname>iot-robot</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>00:20:85:d8:95:03</mac>
<ipaddr>172.27.78.31</ipaddr>
<hostname>iot-ups-eaton5p-mmc</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>74:5e:1c:23:39:00</mac>
<ipaddr>172.27.78.32</ipaddr>
<hostname>iot-speaker1</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>74:5e:1c:22:40:92</mac>
<ipaddr>172.27.78.33</ipaddr>
<hostname>iot-speaker2</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>74:4d:bd:c6:5a:28</mac>
<ipaddr>172.27.78.34</ipaddr>
<hostname>iot-apollo-msr</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>a0:85:e3:6b:69:94</mac>
<ipaddr>172.27.78.35</ipaddr>
<hostname>iot-apollo-msr-up</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>c0:49:ef:56:4e:f0</mac>
<ipaddr>172.27.78.40</ipaddr>
<hostname>iot-clock</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>20:f8:3b:09:23:69</mac>
<ipaddr>172.27.78.45</ipaddr>
<hostname>iot-voice</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>40:91:51:4f:66:65</mac>
<ipaddr>172.27.78.50</ipaddr>
<hostname>iot-comp-switch</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>74:da:38:ea:df:df</mac>
<ipaddr>172.27.78.60</ipaddr>
<hostname>iot-doorcamera</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>00:22:6c:66:fa:69</mac>
<ipaddr>172.27.78.70</ipaddr>
<hostname>iot-audio-columns</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>00:22:6c:23:15:a2</mac>
<ipaddr>172.27.78.71</ipaddr>
<hostname>iot-audio-bedroom</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<staticmap>
<mac>08:b6:1f:76:dc:c4</mac>
<ipaddr>172.27.78.80</ipaddr>
<hostname>iot-desk</hostname>
<winsserver/>
<dnsserver/>
<ntpserver/>
</staticmap>
<pool/>
</lan>
</dhcpd>
<snmpd>
<syslocation/>
<syscontact/>
<rocommunity>public</rocommunity>
</snmpd>
<nat>
<outbound>
<mode>advanced</mode>
<rule>
<source>
<network>lan</network>
</source>
<destination>
<any>1</any>
</destination>
<descr/>
<category/>
<interface>wan</interface>
<tag/>
<tagged/>
<poolopts/>
<poolopts_sourcehashkey/>
<ipprotocol>inet</ipprotocol>
<created>
<username>root@172.27.72.50</username>
<time>1714577465.5569</time>
<description>/firewall_nat_out_edit.php made changes</description>
</created>
<target/>
<targetip_subnet>0</targetip_subnet>
<sourceport/>
<updated>
<username>root@172.27.72.50</username>
<time>1714641491.3222</time>
<description>/firewall_nat_out_edit.php made changes</description>
</updated>
</rule>
<rule>
<source>
<network>DOCKER_INTERNET_ACCESS</network>
</source>
<destination>
<any>1</any>
</destination>
<descr/>
<category/>
<interface>wan</interface>
<tag/>
<tagged/>
<poolopts/>
<poolopts_sourcehashkey/>
<ipprotocol>inet</ipprotocol>
<created>
<username>root@172.27.72.50</username>
<time>1714641526.0083</time>
<description>/firewall_nat_out_edit.php made changes</description>
</created>
<target/>
<targetip_subnet>0</targetip_subnet>
<sourceport/>
<updated>
<username>root@172.27.72.50</username>
<time>1714641676.8626</time>
<description>/firewall_nat_out_edit.php made changes</description>
</updated>
</rule>
<rule>
<source>
<network>172.27.72.0/21</network>
</source>
<destination>
<address>192.168.100.0/24</address>
</destination>
<descr/>
<category/>
<interface>opt7</interface>
<tag/>
<tagged/>
<poolopts/>
<poolopts_sourcehashkey/>
<ipprotocol>inet</ipprotocol>
<created>
<username>root@172.27.72.50</username>
<time>1756484210.437</time>
<description>/firewall_nat_out_edit.php made changes</description>
</created>
<target/>
<targetip_subnet>0</targetip_subnet>
<sourceport/>
<updated>
<username>root@172.27.72.50</username>
<time>1756552361.4583</time>
<description>/firewall_nat_out_edit.php made changes</description>
</updated>
</rule>
</outbound>
</nat>
<filter>
<rule uuid="e82e8330-2869-429b-9d84-a9499c55f09b">
<type>pass</type>
<ipprotocol>inet</ipprotocol>
<statetype>none</statetype>
<descr>Disable state track for VPN</descr>
<direction>any</direction>
<floating>yes</floating>
<quick>1</quick>
<source>
<any>1</any>
</source>
<destination>
<network>opt6</network>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1743337825.8559</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1743336711.2713</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="9ed618db-a5d6-4b89-a42f-762e0970c906">
<type>pass</type>
<ipprotocol>inet</ipprotocol>
<statetype>none</statetype>
<descr>Disable state track for VPN</descr>
<direction>any</direction>
<floating>yes</floating>
<quick>1</quick>
<source>
<network>opt6</network>
</source>
<destination>
<any>1</any>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1743340871.2695</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1743340871.2695</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="c630b4fb-eefe-4a14-bc09-36f763e5fe5e">
<type>pass</type>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<statetype>none</statetype>
<descr>Allow local routed no-state bridge</descr>
<direction>any</direction>
<floating>yes</floating>
<quick>1</quick>
<source>
<network>lan</network>
</source>
<destination>
<address>DOCKER_INTERNET_ACCESS</address>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1750491315.4742</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1750491315.4743</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="1c369d7e-89d8-41c4-bf29-846a56985a54">
<type>pass</type>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<statetype>none</statetype>
<descr>Allow local routed no-state bridge</descr>
<direction>any</direction>
<floating>yes</floating>
<quick>1</quick>
<source>
<address>DOCKER_INTERNET_ACCESS</address>
</source>
<destination>
<network>lan</network>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1750491359.305</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1750491359.305</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="7d04a283-e59b-4455-9409-923ebc75c06e">
<type>pass</type>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<statetype>keep state</statetype>
<gateway>LEOX</gateway>
<direction>in</direction>
<quick>1</quick>
<source>
<network>lan</network>
</source>
<destination>
<address>192.168.100.0/24</address>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1756485064.6127</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1756484978.0795</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="ee4a8d6f-7fa8-4ca9-80b9-be18b5995723">
<type>pass</type>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<statetype>sloppy state</statetype>
<descr>Default allow LAN to any rule</descr>
<direction>in</direction>
<disablereplyto>1</disablereplyto>
<quick>1</quick>
<source>
<address>DOCKER_INTERNET_ACCESS</address>
</source>
<destination>
<any>1</any>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1750448115.8309</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.78.61</username>
<time>1714644304.9414</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="54a8cd26-cde2-44d5-aa35-dddd37683455">
<type>pass</type>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<statetype>sloppy state</statetype>
<descr>Default allow LAN to any rule</descr>
<direction>in</direction>
<disablereplyto>1</disablereplyto>
<quick>1</quick>
<source>
<any>1</any>
</source>
<destination>
<address>DOCKER_INTERNET_ACCESS</address>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1750448106.778</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1750447525.1295</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="3efc5c9f-4a4a-4367-9083-72cffd261ec0">
<type>pass</type>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<statetype>sloppy state</statetype>
<descr>Default allow LAN to any rule</descr>
<direction>in</direction>
<disablereplyto>1</disablereplyto>
<quick>1</quick>
<source>
<network>lan</network>
</source>
<destination>
<any>1</any>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1750448201.1979</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
</rule>
<rule uuid="d3546d54-e750-46d3-ba8e-cda87b5e882d">
<type>pass</type>
<ipprotocol>inet6</ipprotocol>
<descr>Default allow LAN IPv6 to any rule</descr>
<interface>lan</interface>
<source>
<network>lan</network>
</source>
<destination>
<any/>
</destination>
</rule>
<rule uuid="d36f9f0f-dc09-4e32-8743-67def66e4fc5">
<type>pass</type>
<interface>opt6</interface>
<ipprotocol>inet</ipprotocol>
<statetype>keep state</statetype>
<direction>in</direction>
<quick>1</quick>
<source>
<network>opt6</network>
</source>
<destination>
<any>1</any>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1756639127.0681</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1756639127.0681</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="e634ac9e-0ad0-484f-970d-0b1df77f53ca">
<type>pass</type>
<interface>opt6</interface>
<ipprotocol>inet</ipprotocol>
<statetype>keep state</statetype>
<direction>in</direction>
<quick>1</quick>
<source>
<address>172.25.0.0/16</address>
</source>
<destination>
<network>opt6ip</network>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1756643455.7004</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1756643277.1658</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
<disabled>1</disabled>
</rule>
<rule uuid="4c206b3e-0423-454f-9acc-096e0cac55c0">
<type>pass</type>
<interface>opt6</interface>
<ipprotocol>inet</ipprotocol>
<statetype>keep state</statetype>
<direction>in</direction>
<quick>1</quick>
<source>
<address>172.25.0.0/16</address>
</source>
<destination>
<address>172.27.72.0/21</address>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1756645292.6728</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1756645074.4175</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
<disabled>1</disabled>
</rule>
<rule uuid="60bd097c-6384-4da6-ab1d-a0dcba78a121">
<type>pass</type>
<interface>opt6</interface>
<ipprotocol>inet</ipprotocol>
<statetype>keep state</statetype>
<descr>WG &#x2192; LAN 192.168.2.0/24</descr>
<direction>in</direction>
<disablereplyto>1</disablereplyto>
<disabled>1</disabled>
<quick>1</quick>
<source>
<address>172.25.0.0/16</address>
</source>
<destination>
<address>DOCKER_INTERNET_ACCESS</address>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1756650829.5088</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1756646482.5139</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<rule uuid="c243188a-187a-4754-8e02-32b08ccb1566">
<type>pass</type>
<interface>opt7</interface>
<ipprotocol>inet</ipprotocol>
<statetype>keep state</statetype>
<direction>in</direction>
<quick>1</quick>
<source>
<network>lan</network>
</source>
<destination>
<network>opt7</network>
</destination>
<updated>
<username>root@172.27.72.50</username>
<time>1756551785.4623</time>
<description>/firewall_rules_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1756551785.4623</time>
<description>/firewall_rules_edit.php made changes</description>
</created>
</rule>
<scrub>
<rule>
<interface>wireguard</interface>
<proto>any</proto>
<src>any</src>
<srcmask>24</srcmask>
<dst>any</dst>
<dstmask>24</dstmask>
<max-mss>1280</max-mss>
<descr>Wireguard MSS Clamping IPv4</descr>
<updated>
<username>root@172.27.72.50</username>
<time>1743337196.0138</time>
<description>/firewall_scrub_edit.php made changes</description>
</updated>
<created>
<username>root@172.27.72.50</username>
<time>1742927843.9337</time>
<description>/firewall_scrub_edit.php made changes</description>
</created>
</rule>
</scrub>
<bypassstaticroutes>yes</bypassstaticroutes>
</filter>
<rrd>
<enable/>
</rrd>
<load_balancer>
<monitor_type>
<name>ICMP</name>
<type>icmp</type>
<descr>ICMP</descr>
<options/>
</monitor_type>
<monitor_type>
<name>TCP</name>
<type>tcp</type>
<descr>Generic TCP</descr>
<options/>
</monitor_type>
<monitor_type>
<name>HTTP</name>
<type>http</type>
<descr>Generic HTTP</descr>
<options>
<path>/</path>
<host/>
<code>200</code>
</options>
</monitor_type>
<monitor_type>
<name>HTTPS</name>
<type>https</type>
<descr>Generic HTTPS</descr>
<options>
<path>/</path>
<host/>
<code>200</code>
</options>
</monitor_type>
<monitor_type>
<name>SMTP</name>
<type>send</type>
<descr>Generic SMTP</descr>
<options>
<send/>
<expect>220 *</expect>
</options>
</monitor_type>
</load_balancer>
<ntpd>
<prefer>0.opnsense.pool.ntp.org</prefer>
<interface>lan</interface>
</ntpd>
<widgets>
<sequence>system_information-container:00000000-col3:show,traffic_graphs-container:00000001-col3:show,gateways-container:00000002-col4:show,interface_list-container:00000003-col4:show,interface_statistics-container:00000004-col4:show,log-container:00000005-col4:show</sequence>
<column_count>2</column_count>
<traffic_graphs_interfaces>lan,wan</traffic_graphs_interfaces>
<interfacesstatisticsfilter>opt1,opt2,opt3,opt8,opt4,opt9,opt10</interfacesstatisticsfilter>
<interfaceslistfilter>opt1,opt2,opt3,opt8,opt4,opt5,opt9,opt10</interfaceslistfilter>
</widgets>
<revision>
<username>root@172.27.72.50</username>
<time>1756650829.6411</time>
<description>/firewall_rules_edit.php made changes</description>
</revision>
<OPNsense>
<wireguard>
<client version="1.0.0">
<clients>
<client uuid="93a5b9c2-542e-4363-b213-5c620c1d5604">
<enabled>1</enabled>
<name>Mikrus_Peer</name>
<pubkey>qnxaVzl1HQHenoXVDKsIXPWlL9v+Eo9+PXjKkJ7+4GI=</pubkey>
<psk/>
<tunneladdress>172.27.118.0/24,172.25.0.0/16</tunneladdress>
<serveraddress>srv11.mikr.us</serveraddress>
<serverport>20105</serverport>
<keepalive>10</keepalive>
</client>
</clients>
</client>
<general version="0.0.1">
<enabled>1</enabled>
</general>
<server version="1.0.0">
<servers>
<server uuid="76197e58-fa12-4488-9093-b9d806dcef05">
<enabled>1</enabled>
<name>Mikrus_VPN</name>
<instance>0</instance>
<pubkey/>
<privkey>ILxJyafNzX2AFbd+KEkKzFUTuW0x5LbmZbatP21YoVY=</privkey>
<port/>
<mtu/>
<dns/>
<tunneladdress>172.25.0.2/32</tunneladdress>
<disableroutes>1</disableroutes>
<gateway/>
<carp_depend_on/>
<peers>93a5b9c2-542e-4363-b213-5c620c1d5604</peers>
<endpoint/>
<peer_dns/>
</server>
</servers>
</server>
</wireguard>
<IPsec version="1.0.1">
<general>
<enabled/>
</general>
<keyPairs/>
<preSharedKeys/>
</IPsec>
<Swanctl version="1.0.0">
<Connections/>
<locals/>
<remotes/>
<children/>
<Pools/>
<VTIs/>
<SPDs/>
</Swanctl>
<OpenVPNExport version="0.0.1">
<servers/>
</OpenVPNExport>
<OpenVPN version="1.0.0">
<Overwrites/>
<Instances/>
<StaticKeys/>
</OpenVPN>
<captiveportal version="1.0.2">
<zones/>
<templates/>
</captiveportal>
<cron version="1.0.4">
<jobs>
<job uuid="f7300ae6-d894-42bd-afa6-9e08c34e64f2">
<origin>AcmeClient</origin>
<enabled>1</enabled>
<minutes>9</minutes>
<hours>0</hours>
<days>*</days>
<months>*</months>
<weekdays>*</weekdays>
<who>root</who>
<command>acmeclient cron-auto-renew</command>
<parameters/>
<description>AcmeClient Cronjob for Certificate AutoRenewal</description>
</job>
<job uuid="977ac468-1b28-4472-babb-d0ee61f596d6">
<origin>IDS</origin>
<enabled>0</enabled>
<minutes>0</minutes>
<hours>0</hours>
<days>*</days>
<months>*</months>
<weekdays>*</weekdays>
<who>root</who>
<command>ids update</command>
<parameters/>
<description>ids rule updates</description>
</job>
</jobs>
</cron>
<Firewall>
<Lvtemplate version="0.0.1">
<templates>
<template uuid="a8a9fbe2-d9be-4952-a525-886d6c3f4a2a">
<name>DOCKER_TEST</name>
<or>1</or>
<filters>src~172.27.78.60,dst~172.27.78.60</filters>
</template>
</templates>
</Lvtemplate>
<Alias version="1.0.1">
<geoip>
<url/>
</geoip>
<aliases>
<alias uuid="8f5ee931-4447-4d4f-b378-009be662e503">
<enabled>1</enabled>
<name>DOCKER_INTERNET_ACCESS</name>
<type>network</type>
<proto/>
<interface/>
<counters>0</counters>
<updatefreq/>
<content>192.168.2.0/24
192.168.4.0/24
192.168.8.0/24
192.168.16.0/24
192.168.24.0/24
192.168.3.0/24</content>
<categories/>
<description/>
</alias>
<alias uuid="06e3f7f4-d2db-41d3-b252-963b529a9b3d">
<enabled>1</enabled>
<name>IOT_NETWORKS</name>
<type>network</type>
<proto/>
<interface/>
<counters>0</counters>
<updatefreq/>
<content>172.27.78.0/24</content>
<categories/>
<description/>
</alias>
<alias uuid="e03d24b7-f90d-489b-99d7-e3bf609e171d">
<enabled>1</enabled>
<name>RFC1918_Networks</name>
<type>network</type>
<proto/>
<interface/>
<counters>0</counters>
<updatefreq/>
<content>192.168.0.0/16
10.0.0.0/8
172.16.0.0/12</content>
<categories/>
<description/>
</alias>
</aliases>
</Alias>
<Category version="1.0.0">
<categories/>
</Category>
<Filter version="1.0.4">
<rules/>
<snatrules/>
<npt/>
<onetoone/>
</Filter>
</Firewall>
<Netflow version="1.0.1">
<capture>
<interfaces>lan,wan</interfaces>
<egress_only>wan</egress_only>
<version>v9</version>
<targets/>
</capture>
<collect>
<enable>0</enable>
</collect>
<activeTimeout>1800</activeTimeout>
<inactiveTimeout>15</inactiveTimeout>
</Netflow>
<IDS version="1.0.9">
<rules/>
<policies/>
<userDefinedRules/>
<files>
<file uuid="b2a4fb52-691a-4c5f-b9ef-fabe338b1251">
<filename>abuse.ch.sslblacklist.rules</filename>
<enabled>1</enabled>
</file>
<file uuid="dba872cb-9c54-4dc3-b6d3-f0eb17869a72">
<filename>abuse.ch.sslipblacklist.rules</filename>
<enabled>1</enabled>
</file>
</files>
<fileTags/>
<general>
<enabled>0</enabled>
<ips>0</ips>
<promisc>0</promisc>
<interfaces>wan</interfaces>
<homenet>172.27.0.0/16,10.0.0.0/8,172.16.0.0/12</homenet>
<defaultPacketSize/>
<UpdateCron>977ac468-1b28-4472-babb-d0ee61f596d6</UpdateCron>
<AlertLogrotate>W0D23</AlertLogrotate>
<AlertSaveLogs>4</AlertSaveLogs>
<MPMAlgo/>
<detect>
<Profile/>
<toclient_groups/>
<toserver_groups/>
</detect>
<syslog>0</syslog>
<syslog_eve>0</syslog_eve>
<LogPayload>0</LogPayload>
<verbosity/>
</general>
</IDS>
<Interfaces>
<loopbacks version="1.0.0"/>
<neighbors version="1.0.0"/>
<vxlans version="1.0.2"/>
</Interfaces>
<Kea>
<ctrl_agent version="0.0.1">
<general>
<enabled>0</enabled>
<http_host>127.0.0.1</http_host>
<http_port>8000</http_port>
</general>
</ctrl_agent>
<dhcp4 version="1.0.0">
<general>
<enabled>0</enabled>
<interfaces/>
<valid_lifetime>4000</valid_lifetime>
<fwrules>1</fwrules>
</general>
<ha>
<enabled>0</enabled>
<this_server_name/>
</ha>
<subnets/>
<reservations/>
<ha_peers/>
</dhcp4>
</Kea>
<monit version="1.0.13">
<general>
<enabled>0</enabled>
<interval>120</interval>
<startdelay>120</startdelay>
<mailserver>127.0.0.1</mailserver>
<port>25</port>
<username/>
<password/>
<ssl>0</ssl>
<sslversion>auto</sslversion>
<sslverify>1</sslverify>
<logfile/>
<statefile/>
<eventqueuePath/>
<eventqueueSlots/>
<httpdEnabled>0</httpdEnabled>
<httpdUsername>root</httpdUsername>
<httpdPassword>fcnnHyrAgIL8tz8lgq1ujnIUrukeLj</httpdPassword>
<httpdPort>2812</httpdPort>
<httpdAllow/>
<mmonitUrl/>
<mmonitTimeout>5</mmonitTimeout>
<mmonitRegisterCredentials>1</mmonitRegisterCredentials>
</general>
<alert uuid="fed0fbb6-72bc-44a8-89b8-f5ba1f442402">
<enabled>0</enabled>
<recipient>root@localhost.local</recipient>
<noton>0</noton>
<events/>
<format/>
<reminder/>
<description/>
</alert>
<service uuid="fb4067c9-4d59-4374-b40e-a29452c6eb91">
<enabled>1</enabled>
<name>$HOST</name>
<description/>
<type>system</type>
<pidfile/>
<match/>
<path/>
<timeout>300</timeout>
<starttimeout>30</starttimeout>
<address/>
<interface/>
<start/>
<stop/>
<tests>d042d19e-058f-408b-99fa-3272251b74bc,62775b2e-9ed6-42d0-8369-662039abc4e5,65368259-459c-4262-b9c5-990bb17a1d67,51396bc7-39fa-4764-94e0-b2e244e1abdc</tests>
<depends/>
<polltime/>
</service>
<service uuid="c05ec3f4-d067-4660-a6c2-41e5333212c4">
<enabled>1</enabled>
<name>RootFs</name>
<description/>
<type>filesystem</type>
<pidfile/>
<match/>
<path>/</path>
<timeout>300</timeout>
<starttimeout>30</starttimeout>
<address/>
<interface/>
<start/>
<stop/>
<tests>07068733-0d52-46b8-a4d7-27ce47e6ca38</tests>
<depends/>
<polltime/>
</service>
<service uuid="127eabed-5fc5-4cee-ab8a-fd184f1b2e3d">
<enabled>0</enabled>
<name>carp_status_change</name>
<description/>
<type>custom</type>
<pidfile/>
<match/>
<path>/usr/local/opnsense/scripts/OPNsense/Monit/carp_status</path>
<timeout>300</timeout>
<starttimeout>30</starttimeout>
<address/>
<interface/>
<start/>
<stop/>
<tests>f6abe208-1565-481a-8724-48cab50202eb</tests>
<depends/>
<polltime/>
</service>
<service uuid="823b0122-7962-40c8-b0ae-8dc1d8513eae">
<enabled>0</enabled>
<name>gateway_alert</name>
<description/>
<type>custom</type>
<pidfile/>
<match/>
<path>/usr/local/opnsense/scripts/OPNsense/Monit/gateway_alert</path>
<timeout>300</timeout>
<starttimeout>30</starttimeout>
<address/>
<interface/>
<start/>
<stop/>
<tests>9b30b94a-ac33-4edf-905d-1d042ff2b800</tests>
<depends/>
<polltime/>
</service>
<test uuid="4d1d5cc8-78a6-4bab-95c8-2ae58742825d">
<name>Ping</name>
<type>NetworkPing</type>
<condition>failed ping</condition>
<action>alert</action>
<path/>
</test>
<test uuid="95ddd8d7-7f4d-4d11-b5b7-4dba212ade8a">
<name>NetworkLink</name>
<type>NetworkInterface</type>
<condition>failed link</condition>
<action>alert</action>
<path/>
</test>
<test uuid="933b643b-8b7c-4f6f-9633-967a21ad129f">
<name>NetworkSaturation</name>
<type>NetworkInterface</type>
<condition>saturation is greater than 75%</condition>
<action>alert</action>
<path/>
</test>
<test uuid="d042d19e-058f-408b-99fa-3272251b74bc">
<name>MemoryUsage</name>
<type>SystemResource</type>
<condition>memory usage is greater than 75%</condition>
<action>alert</action>
<path/>
</test>
<test uuid="62775b2e-9ed6-42d0-8369-662039abc4e5">
<name>CPUUsage</name>
<type>SystemResource</type>
<condition>cpu usage is greater than 75%</condition>
<action>alert</action>
<path/>
</test>
<test uuid="65368259-459c-4262-b9c5-990bb17a1d67">
<name>LoadAvg1</name>
<type>SystemResource</type>
<condition>loadavg (1min) is greater than 4</condition>
<action>alert</action>
<path/>
</test>
<test uuid="51396bc7-39fa-4764-94e0-b2e244e1abdc">
<name>LoadAvg5</name>
<type>SystemResource</type>
<condition>loadavg (5min) is greater than 3</condition>
<action>alert</action>
<path/>
</test>
<test uuid="11ca5ee4-a3c7-4037-9de1-796ab268af0d">
<name>LoadAvg15</name>
<type>SystemResource</type>
<condition>loadavg (15min) is greater than 2</condition>
<action>alert</action>
<path/>
</test>
<test uuid="07068733-0d52-46b8-a4d7-27ce47e6ca38">
<name>SpaceUsage</name>
<type>SpaceUsage</type>
<condition>space usage is greater than 75%</condition>
<action>alert</action>
<path/>
</test>
<test uuid="f6abe208-1565-481a-8724-48cab50202eb">
<name>ChangedStatus</name>
<type>ProgramStatus</type>
<condition>changed status</condition>
<action>alert</action>
<path/>
</test>
<test uuid="9b30b94a-ac33-4edf-905d-1d042ff2b800">
<name>NonZeroStatus</name>
<type>ProgramStatus</type>
<condition>status != 0</condition>
<action>alert</action>
<path/>
</test>
</monit>
<Gateways version="1.0.0">
<gateway_item uuid="10d9daa8-9d81-4a70-bc4d-df6e11cd788d">
<disabled>0</disabled>
<name>TO_DOCKER</name>
<descr/>
<interface>lan</interface>
<ipprotocol>inet</ipprotocol>
<gateway>172.27.72.10</gateway>
<defaultgw>0</defaultgw>
<fargw>0</fargw>
<monitor_disable>1</monitor_disable>
<monitor_noroute>0</monitor_noroute>
<monitor/>
<force_down>0</force_down>
<priority>253</priority>
<weight>1</weight>
<latencylow/>
<latencyhigh/>
<losslow/>
<losshigh/>
<interval/>
<time_period/>
<loss_interval/>
<data_length/>
</gateway_item>
<gateway_item uuid="29329704-8d93-428a-b64d-17dd28e18fa3">
<disabled>0</disabled>
<name>WAN_GW</name>
<descr>WAN Gateway</descr>
<interface>wan</interface>
<ipprotocol>inet</ipprotocol>
<gateway/>
<defaultgw>1</defaultgw>
<fargw>0</fargw>
<monitor_disable>1</monitor_disable>
<monitor_noroute>0</monitor_noroute>
<monitor/>
<force_down>0</force_down>
<priority>128</priority>
<weight>1</weight>
<latencylow/>
<latencyhigh/>
<losslow/>
<losshigh/>
<interval/>
<time_period/>
<loss_interval/>
<data_length/>
</gateway_item>
<gateway_item uuid="f28883da-45d4-4d22-a464-0779442989c7">
<disabled>0</disabled>
<name>LEOX</name>
<descr/>
<interface>opt7</interface>
<ipprotocol>inet</ipprotocol>
<gateway>192.168.100.1</gateway>
<defaultgw>0</defaultgw>
<fargw>0</fargw>
<monitor_disable>1</monitor_disable>
<monitor_noroute>0</monitor_noroute>
<monitor/>
<force_down>0</force_down>
<priority>255</priority>
<weight>1</weight>
<latencylow/>
<latencyhigh/>
<losslow/>
<losshigh/>
<interval/>
<time_period/>
<loss_interval/>
<data_length/>
</gateway_item>
<gateway_item uuid="75e06d96-6558-47aa-b66f-3ebccb1f7bfc">
<disabled>0</disabled>
<name>VPN_GW</name>
<descr/>
<interface>opt6</interface>
<ipprotocol>inet</ipprotocol>
<gateway>172.25.0.1</gateway>
<defaultgw>0</defaultgw>
<fargw>1</fargw>
<monitor_disable>1</monitor_disable>
<monitor_noroute>0</monitor_noroute>
<monitor/>
<force_down>0</force_down>
<priority>255</priority>
<weight>1</weight>
<latencylow/>
<latencyhigh/>
<losslow/>
<losshigh/>
<interval/>
<time_period/>
<loss_interval/>
<data_length/>
</gateway_item>
</Gateways>
<Syslog version="1.0.2">
<general>
<enabled>1</enabled>
<loglocal>1</loglocal>
<maxpreserve>31</maxpreserve>
<maxfilesize/>
</general>
<destinations/>
</Syslog>
<TrafficShaper version="1.0.3">
<pipes/>
<queues/>
<rules/>
</TrafficShaper>
<unboundplus version="1.0.9">
<general>
<enabled>1</enabled>
<port>53</port>
<stats>1</stats>
<active_interface>lan,opt16</active_interface>
<dnssec>0</dnssec>
<dns64>0</dns64>
<dns64prefix/>
<noarecords>0</noarecords>
<regdhcp>0</regdhcp>
<regdhcpdomain>waw.eldorado.city</regdhcpdomain>
<regdhcpstatic>1</regdhcpstatic>
<noreglladdr6>0</noreglladdr6>
<noregrecords>0</noregrecords>
<txtsupport>0</txtsupport>
<cacheflush>0</cacheflush>
<local_zone_type>transparent</local_zone_type>
<outgoing_interface/>
<enable_wpad>0</enable_wpad>
</general>
<advanced>
<hideidentity>0</hideidentity>
<hideversion>0</hideversion>
<prefetch>0</prefetch>
<prefetchkey>0</prefetchkey>
<dnssecstripped>0</dnssecstripped>
<aggressivensec>1</aggressivensec>
<serveexpired>0</serveexpired>
<serveexpiredreplyttl/>
<serveexpiredttl/>
<serveexpiredttlreset>0</serveexpiredttlreset>
<serveexpiredclienttimeout/>
<qnameminstrict>0</qnameminstrict>
<extendedstatistics>0</extendedstatistics>
<logqueries>0</logqueries>
<logreplies>0</logreplies>
<logtagqueryreply>0</logtagqueryreply>
<logservfail>0</logservfail>
<loglocalactions>0</loglocalactions>
<logverbosity>1</logverbosity>
<valloglevel>0</valloglevel>
<privatedomain>eldorado.city</privatedomain>
<privateaddress>0.0.0.0/8,10.0.0.0/8,100.64.0.0/10,169.254.0.0/16,172.16.0.0/12,192.0.2.0/24,172.27.0.0/16,198.18.0.0/15,198.51.100.0/24,203.0.113.0/24,233.252.0.0/24,::1/128,2001:db8::/32,fc00::/8,fd00::/8,fe80::/10</privateaddress>
<insecuredomain/>
<msgcachesize/>
<rrsetcachesize/>
<outgoingnumtcp/>
<incomingnumtcp/>
<numqueriesperthread/>
<outgoingrange/>
<jostletimeout/>
<cachemaxttl/>
<cachemaxnegativettl/>
<cacheminttl/>
<infrahostttl/>
<infrakeepprobing>0</infrakeepprobing>
<infracachenumhosts/>
<unwantedreplythreshold/>
</advanced>
<acls>
<default_action>allow</default_action>
</acls>
<dnsbl>
<enabled>0</enabled>
<safesearch/>
<type/>
<lists/>
<whitelists/>
<blocklists/>
<wildcards/>
<address/>
<nxdomain/>
</dnsbl>
<forwarding>
<enabled/>
</forwarding>
<dots/>
<hosts>
<host uuid="9e3fe858-4d77-4539-8ec7-b54e075b15ac">
<enabled>1</enabled>
<hostname>proxy</hostname>
<domain>waw.eldorado.city</domain>
<rr>A</rr>
<mxprio/>
<mx/>
<server>192.168.2.253</server>
<description/>
</host>
<host uuid="71dfc780-577e-4c9f-91fa-4fc67cd9a7d4">
<enabled>1</enabled>
<hostname>mail</hostname>
<domain>waw.eldorado.city</domain>
<rr>A</rr>
<mxprio/>
<mx/>
<server>192.168.2.20</server>
<description/>
</host>
<host uuid="aa404b52-64be-40fe-9a0a-33de90b52d25">
<enabled>1</enabled>
<hostname>gate</hostname>
<domain>waw.eldorado.city</domain>
<rr>A</rr>
<mxprio/>
<mx/>
<server>172.27.72.254</server>
<description/>
</host>
<host uuid="fcb9007a-828b-4c02-a536-41014e6929ea">
<enabled>1</enabled>
<hostname>hv</hostname>
<domain>waw.eldorado.city</domain>
<rr>A</rr>
<mxprio/>
<mx/>
<server>172.27.72.1</server>
<description/>
</host>
<host uuid="c3b8ae6e-9207-43c7-acdc-0a504585dba1">
<enabled>1</enabled>
<hostname>monit</hostname>
<domain>waw.eldorado.city</domain>
<rr>A</rr>
<mxprio/>
<mx/>
<server>172.27.72.5</server>
<description/>
</host>
</hosts>
<aliases>
<alias uuid="5c7712f8-ea33-431a-9bf2-d011526c292e">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>albert</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="b7ff5800-c776-41bd-ad55-a883ac607f0a">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>changedetection</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="99c29edc-4b5b-460d-a982-9a165b4eb75b">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>docker</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="51b07ac8-e65b-47a2-83a5-9cc0e43323c7">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>papers</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="dcd788e0-95a0-47fe-b688-d71a727cca9c">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>zigbee</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="afe0daa7-b36d-4b65-af30-5ae335f7c596">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>omada</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="3dbbc54a-9293-4963-8322-88b7cab40608">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>budget</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="db939265-3114-4c40-ac9b-d115d5e14e75">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>notes</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="64b7388e-259e-41e4-99c1-1104353dd835">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>adminer</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="f8a37c91-b6b5-436f-bc87-5e53a92e228e">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>own.books</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="9d053c9b-0c7a-4069-aeb1-eb27ab35dd8f">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>tube</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="98d6f434-415a-4b5f-96be-e31a770fefbe">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>misc.books</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
<alias uuid="b84d7e30-ddba-45e8-a4fb-e170add3f1e8">
<enabled>1</enabled>
<host>9e3fe858-4d77-4539-8ec7-b54e075b15ac</host>
<hostname>3d</hostname>
<domain>waw.eldorado.city</domain>
<description/>
</alias>
</aliases>
<domains>
<domain uuid="846846a8-8196-47e8-ae54-1cdc558bfed5">
<enabled>1</enabled>
<domain>ols.eldorado.city</domain>
<server>172.27.118.254</server>
<forward_tcp_upstream>0</forward_tcp_upstream>
<description/>
</domain>
</domains>
</unboundplus>
<DHCRelay version="1.0.1"/>
<AcmeClient version="4.1.0">
<settings>
<enabled>1</enabled>
<autoRenewal>1</autoRenewal>
<UpdateCron>f7300ae6-d894-42bd-afa6-9e08c34e64f2</UpdateCron>
<environment/>
<challengePort>43580</challengePort>
<TLSchallengePort>43581</TLSchallengePort>
<restartTimeout>600</restartTimeout>
<haproxyIntegration>0</haproxyIntegration>
<haproxyAclRef/>
<haproxyActionRef/>
<haproxyServerRef/>
<haproxyBackendRef/>
<logLevel>debug</logLevel>
<showIntro>0</showIntro>
</settings>
<accounts>
<account uuid="dda33900-79eb-442b-9351-58131f480626">
<id>6633b9c1250058.20326201</id>
<enabled>1</enabled>
<name>LetsEncrypt</name>
<description/>
<email>certs@radziel.com</email>
<ca>letsencrypt</ca>
<custom_ca/>
<eab_kid/>
<eab_hmac/>
<key>LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlKS0FJQkFBS0NBZ0VBb3haa0RlSGxQVjBaZ0wyRjdWeUFuYmJLdjlHRTFpOGh4OHNPSm5lVm5EZk5TM28yCk5EUzNwd3BFcVVXbHFjMTA4UGtiRjZWSWFLd2szaUFWTmwrUUYydGUwREdnN1M2TWJSRWpaMmZuRE5lRXUwMGQKMjRYQ2VXQ1hoQjRJVWpZUWtvMnk5OFhtZHExKzlNdnYyT2tNcG8rblNiQnY1WGxoWUh5eW8ycXllTXF3RHh3TAp2WnYrZVFSZ1FGTnlCaG9IanlVdHMxdXRJNG9JTUtzaEFVK01iK3kwUUUxZzV6RVpnVjZ2a2xZN0hvM3padjlZCk1udkxQSjRGVFFUcndPRGJGQ1ZMZWJWWDhST05kdzFWeFJNaVlsMVBybWZRZVAwMjJZTUFHbmpVVVppWmxhcUMKcGpKSVljeFRoTEVWTlFNSEVMQlliNVdWSEIzTjQ0ZzZ6bEtGK1BXNlN1YTViMU8zVnZwZ2NNZXEvTUI1bUdhbwpNU0NTL2M0NUN1VFl4VHh4MVNJUFhHRk80U1FHMGxML00rOW4xanh1ZkNEVExHVWhCb3hYMVJLTCs4Z29ubWNGCnZ5NTNaZFZxc2YyWnN0bUVrZXJXU3lpQVJWWUJzMWJyYkkvNmVNNTVYcVVwd01EdjlJeFR2NE5ielluWXZaZ2MKWWpNd2F4cVpaVnZDYXRxcDJ2enhJMS9zQmE3SFdIRUFRajU1MmFoN2VPeFprejZsbjhnVTJOVjRkUXJPb2lBaApydkhWckFqVUFJODNacXpkcDBWTmYvbE83elcxWVBkNWNhaFNqYmlrajhLWTFCR2g0VkZiWHpqdGZFVkhUMmFzCjVJbGRnN20yVVhWZW1yMDBmQ0NNdEh5cmJwaUg1Z1d5YVdnRmxMOGhQMlB1ckJ4ZmUwSlhnQ1ZLRXFFQ0F3RUEKQVFLQ0FnQUJIZ2tuY3pHLzN1QnEybUdOZzhHNTB1UEd0cWZEVStWV1doVEp2SzRBdVAwbUZEdEUxa3VmMEZreQpFN0VUM2IxOFhTaUxXKzJJRWczYW03dXBlTFFqQlBCTVd0cXdaVTQrL1F3U0RFc3Y4bFlOZG5USzZUcXczREdOCmpTc2ZiUkZsLzZTSFFBclpLMDBnWGpsUmNoOU5FTlRqazFyZzVwajlNVDJFRXhvUDY4dVMvdTB4cWx6dTlWRzMKZnhyYjRkZkZha3JLM01qdDRtYzE5aVl1dlIzSU1vWDFudElZSTJUNlZ1eTdBdTQ2d2x3MWkzQk9RRHpmT0hIdQoyaWJIVm9NSnUwdXVGTWo2ZE5qV1JQZ2Vkb2dZeG16aVZBSEFvbk42d0FRREttckIrRnF0Qk5NS1VuUGVmNmplCjB0dkRWamI1TFV3ZHo1ZUs3c1ZYVnJxWWFVWlRzSVpPaGR2TllsVUVFZnZzYjJVVC84elhvQ0FmOWVhdkEyOWIKbk1UNXVBc3dGeFJ3MzBqMStlWnVJZHhJZFROODB3bGl3K1dYQzFkcWFkYW1ScEZWeUtRSEUxam1wa3FuRTZ5eQpTRGFEd1JPK0FYV2Y5bDd5SWVXeU9vU0Z5dDhVeVEwNS9BY3pEN3FXRUpaK3RFd0JxN21SeWZnbXFNUFB6ZGQrCmxJMFBLL0F2Yzl4RUhaYmNIekpjVGlxdDB6Vk9sWkI1SUk0c3lUc3NodDRDa0krQkUyTTRDdkxqdCt3bWFNU2wKMGRzUXI0Z3FyclphSnAxVDIxYUEwNTNXR3dwcVM3eklEdzdvWm9SL0pLTWg1ZlJZUnBwR1VvdXpWRnZGZTJXYgpBZGxnTFZGYThpUGwxQW9DMlVmN2JxOFNhdC9nc1poL1MvMXMvb2VaaEhvekRxSFJGUUtDQVFFQTBhd2hxYnhWCkoycWtNVUw4ditxenI0aGtsYmF4cStVQllQdEdDdzRJOXlCMmFzbnE5dGxBSFQ5ZzUwY3JWZlpsTjRBMisvMEEKTFU2NFZlNFArSXVKaHJPT3F1U0JyL3lBN0dqMTRkL3lCMzNONDhHUGFtUEl0eFExU0Mzc29qbzNDTzhLcHc1Qgo5OXFMMSswYXRMRUZOd29DdUlyRmhEZFUxYlFsRERtSlRHNlcvbTRhWlNUQmE4Q0FGalIrYUt1MEtOVklhUnA5CjAwSEZiSVVMcU9UTThiRS9HRHh2Sk0xNTVOVFV4RjZpUktLeFM2SmppZi9CdUt6aHI5a3VGbEtyQmtJamZlcHEKaEdFamlBanRZTUNKUVpTbDZETGRkdFRGWGZ0MUM0SHFBUy9sdVFWSk4wQnBRU3dHNDZSRUhXcHhpWUh0d2RVOApSSDhoakU0RDF1SERJd0tDQVFFQXh4ODlHWFFnWGo3SkJZNGE1NGVkaE1ZeXNib2t5VVA4Vyt6SG9RTG5CWU4zCnBtOFhmTXkyeFl5eTBxNG8wbjFtZFNHeWMrSy83WEJnNGY2RCt0MTNacC84SXNWeWFLUk9NOU9UcmMwb1FGcUkKQzlwV1FkNmZmV0xmYnFzVDhkQnF2ME1KdWlkcTN2TlJPcU43MysvS0wrUWFXaS9CeXFSaEtEZXU1Ujc5ZnFJOQpza1Y0MEFmYjVCc1ZvWUVVU3B5cFJ5dklLR3RjZFJzQzBMVXZmRnY5SFBBWllwYkI1MVdNUlpwOUNhRW5SaHJvCjdqN2NCckt2ckxpVTRKNjJQZVBCaW0zeE5MeG5tVWpxd0p6VWJvN2lnb2RmZWViL29ISUhQZ2dyK2VTb1cxdXIKeWE5WkQrbzZ4T3phd3g4eFM1UDR2MzI5cjE4QlFpZ3B4aW11QVlJaGF3S0NBUUVBZ1JHOEd6ZURGK09PdFlCdQpCRm9mU0lQbW56NjZlbjFiYnU3ZlBEamtqZlFlMFRnQSt2bmJmT1doNmwwbU1TR2ZSeDRYT3VHUWRWT0xKK0tIClZGSFpVK0UraHJacG13TU4vZm5TdXJ2WHlvTEg5bGNWeU1FcU1vRXZGNEtsczJ1d3EwQXpSNGtBVk9ua3dnUUUKTjR6dEQrZUtxejFKdjAwc1hPMHJEUzV4OVdueWF5Y3QrbXM0NGZLN0puQWtESnorSjFDNzVXOVlXMjZXY0dvcQpOa3E2V21IbzNDdC9vNkVWVXljczNzRCtsTSt0NGtoUmpBYXpvdEpSajZWYXVJVWxJSklnTlFmVGtEQVg1a3JRCmpZbVlOSldqMTU5UU16RmhXYXhNYmN3SVY3aTdhanoxeUJ4UGJyNENjNm1RQUtlZ3dxd0h4eFZUcHpxM1ZSNUYKUU1iekR3S0NBUUFPak96VkVGUlJMcnRYeVpPVHVhZzhESk9sd3hsdkQ2WEFQZVEwa3RhNDQydDU0UUpSWDFBMwp6VmsvNWZRYnRZZ29KUWM2U3FhRnZrR0dJaWdZeTlndXlxQU5GbXFPMVByVjlLOEU4MG51c2U3aEZ0cFl3K0RaCnM4RHFBRnhidmtRZXA5SnRKUFk5Um9CNERYdysxL0hwWC96QS9GNW41VzBvR0RHU2twb3BoOGVFWUdrOG9tWmkKRzh5UDJiUFc0KzNHd3A5RXZOdXJ2d2FNbzhETmtKZEZaeElqenlwcU1pa202T3djS1FlS3F1cThoaUZqNStqSQpjVkNIdlhGSndudmhGcm1haGUzNEdJajIvRDdWdVdFNThwUjZmdlBORUtnUTAxNExTN2MxdmRRbXo4WnRVRXR0CkduVzk3bWlXd2tCYUZlRW5rSVN5QmVkUGtMb2phQlB6QW9JQkFCSWdYZU9Td1V0VjdiNlFLd0JPaitEeWNaTVAKdUhxbFNTR0pSMTkxSWwvWi9HZi9tWGRaWkRQc1Z4MHkvdGpYVmpQRU02SndPMlhzdXJUNFo1eUNXS2x5WUhkdwpkTHVWZ29id3Q0K01OaG1rMGlJVlQvTVRxUnhHc1BoMy94YldtUU5aeHZzZHgwd0piRXhSTjA3ekdueE1FcytVCm1hbEZDSktFVlkzbkxCZW5idDNtQjBBZTRZZlAwSGJkVVZVbkxu
<statusCode>200</statusCode>
<statusLastUpdate>1714666025</statusLastUpdate>
</account>
</accounts>
<certificates>
<certificate uuid="8005df68-27f8-41e8-897c-14e74862da8c">
<id>6633ba15689835.45131968</id>
<enabled>1</enabled>
<name>gate.waw.eldorado.city</name>
<description/>
<altNames/>
<account>dda33900-79eb-442b-9351-58131f480626</account>
<validationMethod>e4491024-506e-441a-9a2b-641d942c8270</validationMethod>
<keyLength>key_4096</keyLength>
<ocsp>0</ocsp>
<restartActions>a0fc919d-f269-42a0-b652-30221b93293c</restartActions>
<autoRenewal>1</autoRenewal>
<renewInterval>60</renewInterval>
<aliasmode>none</aliasmode>
<domainalias/>
<challengealias/>
<certRefId>67058c2b680ff</certRefId>
<lastUpdate>1754345417</lastUpdate>
<statusCode>200</statusCode>
<statusLastUpdate>1754345417</statusLastUpdate>
</certificate>
</certificates>
<validations>
<validation uuid="e4491024-506e-441a-9a2b-641d942c8270">
<id>6633b9fccf29e0.06795182</id>
<enabled>1</enabled>
<name>eldorado-city</name>
<description/>
<method>dns01</method>
<http_service>opnsense</http_service>
<http_opn_autodiscovery>1</http_opn_autodiscovery>
<http_opn_interface/>
<http_opn_ipaddresses/>
<http_haproxyInject>1</http_haproxyInject>
<http_haproxyFrontends/>
<tlsalpn_service>acme</tlsalpn_service>
<tlsalpn_acme_autodiscovery>1</tlsalpn_acme_autodiscovery>
<tlsalpn_acme_interface/>
<tlsalpn_acme_ipaddresses/>
<dns_service>dns_cf</dns_service>
<dns_sleep>60</dns_sleep>
<dns_active24_token/>
<dns_ad_key/>
<dns_ali_key/>
<dns_ali_secret/>
<dns_autodns_user/>
<dns_autodns_password/>
<dns_autodns_context/>
<dns_aws_id/>
<dns_aws_secret/>
<dns_azuredns_subscriptionid/>
<dns_azuredns_tenantid/>
<dns_azuredns_appid/>
<dns_azuredns_clientsecret/>
<dns_bunny_api_key/>
<dns_cf_email/>
<dns_cf_key/>
<dns_cf_token>chUMJkW8zMxMyifRy6kfqBjntb48VuduTbfoieX0</dns_cf_token>
<dns_cf_account_id>6d596fce34e6f32f9008dfc1889fa1f1</dns_cf_account_id>
<dns_cf_zone_id>5cf486ebd001b57ed01e624ec355cb69</dns_cf_zone_id>
<dns_cloudns_auth_id/>
<dns_cloudns_sub_auth_id/>
<dns_cloudns_auth_password/>
<dns_cx_key/>
<dns_cx_secret/>
<dns_cyon_user/>
<dns_cyon_password/>
<dns_da_key/>
<dns_da_insecure>1</dns_da_insecure>
<dns_ddnss_token/>
<dns_dgon_key/>
<dns_dnsexit_auth_user/>
<dns_dnsexit_auth_pass/>
<dns_dnsexit_api/>
<dns_dnshome_password/>
<dns_dnshome_subdomain/>
<dns_dnsimple_token/>
<dns_dnsservices_user/>
<dns_dnsservices_password/>
<dns_doapi_token/>
<dns_do_pid/>
<dns_do_password/>
<dns_domeneshop_token/>
<dns_domeneshop_secret/>
<dns_dp_id/>
<dns_dp_key/>
<dns_dh_key/>
<dns_duckdns_token/>
<dns_dyn_customer/>
<dns_dyn_user/>
<dns_dyn_password/>
<dns_dynu_clientid/>
<dns_dynu_secret/>
<dns_freedns_user/>
<dns_freedns_password/>
<dns_gandi_livedns_key/>
<dns_gandi_livedns_token/>
<dns_gcloud_key/>
<dns_googledomains_access_token/>
<dns_googledomains_zone/>
<dns_gd_key/>
<dns_gd_secret/>
<dns_hostingde_server/>
<dns_hostingde_apiKey/>
<dns_he_user/>
<dns_he_password/>
<dns_infoblox_credentials/>
<dns_infoblox_server/>
<dns_inwx_user/>
<dns_inws_password/>
<dns_ionos_prefix/>
<dns_ionos_secret/>
<dns_ipv64_token/>
<dns_ispconfig_user/>
<dns_ispconfig_password/>
<dns_ispconfig_api/>
<dns_ispconfig_insecure>1</dns_ispconfig_insecure>
<dns_jd_id/>
<dns_jd_region/>
<dns_jd_secret/>
<dns_joker_username/>
<dns_joker_password/>
<dns_kinghost_username/>
<dns_kinghost_password/>
<dns_knot_server/>
<dns_knot_key/>
<dns_lexicon_provider>cloudflare</dns_lexicon_provider>
<dns_lexicon_user/>
<dns_lexicon_token/>
<dns_linode_key/>
<dns_linode_v4_key/>
<dns_loopia_api>https://api.loopia.se/RPCSERV</dns_loopia_api>
<dns_loopia_user/>
<dns_loopia_password/>
<dns_lua_email/>
<dns_lua_key/>
<dns_miab_user/>
<dns_miab_password/>
<dns_miab_server/>
<dns_me_key/>
<dns_me_secret/>
<dns_mythic_beasts_key/>
<dns_mythic_beasts_secret/>
<dns_namecheap_user/>
<dns_namecheap_api/>
<dns_namecheap_sourceip/>
<dns_namecom_user/>
<dns_namecom_token/>
<dns_namesilo_key/>
<dns_nederhost_key/>
<dns_netcup_cid/>
<dns_netcup_key/>
<dns_netcup_pw/>
<dns_njalla_token/>
<dns_nsone_key/>
<dns_nsupdate_server/>
<dns_nsupdate_zone/>
<dns_nsupdate_key/>
<dns_oci_cli_user/>
<dns_oci_cli_tenancy/>
<dns_oci_cli_region/>
<dns_oci_cli_key/>
<dns_online_key/>
<dns_opnsense_host>localhost</dns_opnsense_host>
<dns_opnsense_port>443</dns_opnsense_port>
<dns_opnsense_key/>
<dns_opnsense_token/>
<dns_opnsense_insecure>0</dns_opnsense_insecure>
<dns_ovh_app_key/>
<dns_ovh_app_secret/>
<dns_ovh_consumer_key/>
<dns_ovh_endpoint/>
<dns_pleskxml_user/>
<dns_pleskxml_pass/>
<dns_pleskxml_uri/>
<dns_pdns_url/>
<dns_pdns_serverid/>
<dns_pdns_token/>
<dns_porkbun_key/>
<dns_porkbun_secret/>
<dns_sl_key/>
<dns_selfhost_user/>
<dns_selfhost_password/>
<dns_selfhost_map/>
<dns_servercow_username/>
<dns_servercow_password/>
<dns_simply_api_key/>
<dns_simply_account_name/>
<dns_transip_username/>
<dns_transip_key/>
<dns_udr_user/>
<dns_udr_password/>
<dns_uno_key/>
<dns_uno_user/>
<dns_vscale_key/>
<dns_vultr_key/>
<dns_yandex_token/>
<dns_zilore_key/>
<dns_zm_key/>
<dns_gdnsdk_user/>
<dns_gdnsdk_password/>
<dns_acmedns_user/>
<dns_acmedns_password/>
<dns_acmedns_subdomain/>
<dns_acmedns_updateurl/>
<dns_acmedns_baseurl/>
<dns_acmeproxy_endpoint/>
<dns_acmeproxy_username/>
<dns_acmeproxy_password/>
<dns_variomedia_key/>
<dns_schlundtech_user/>
<dns_schlundtech_password/>
<dns_easydns_apitoken/>
<dns_easydns_apikey/>
<dns_euserv_user/>
<dns_euserv_password/>
<dns_leaseweb_key/>
<dns_cn_user/>
<dns_cn_password/>
<dns_arvan_token/>
<dns_artfiles_username/>
<dns_artfiles_password/>
<dns_hetzner_token/>
<dns_hexonet_login/>
<dns_hexonet_password/>
<dns_1984hosting_user/>
<dns_1984hosting_password/>
<dns_kas_login/>
<dns_kas_authdata/>
<dns_kas_authtype>plain</dns_kas_authtype>
<dns_desec_token/>
<dns_desec_name/>
<dns_infomaniak_token/>
<dns_zone_username/>
<dns_zone_key/>
<dns_dynv6_token/>
<dns_cpanel_user/>
<dns_cpanel_token/>
<dns_cpanel_hostname/>
<dns_regru_username/>
<dns_regru_password/>
<dns_nic_username/>
<dns_nic_password/>
<dns_nic_client/>
<dns_nic_secret/>
<dns_world4you_username/>
<dns_world4you_password/>
<dns_aurora_key/>
<dns_aurora_secret/>
<dns_conoha_user/>
<dns_conoha_password/>
<dns_conoha_tenantid/>
<dns_conoha_idapi>https://identity.xxxx.conoha.io/v2.0</dns_conoha_idapi>
<dns_constellix_key/>
<dns_constellix_secret/>
<dns_exoscale_key/>
<dns_exoscale_secret/>
<dns_internetbs_key/>
<dns_internetbs_password/>
<dns_pointhq_key/>
<dns_pointhq_email/>
<dns_rackspace_user/>
<dns_rackspace_key/>
<dns_rage4_token/>
<dns_rage4_user/>
</validation>
</validations>
<actions>
<action uuid="a0fc919d-f269-42a0-b652-30221b93293c">
<id>670587be1b0347.49832014</id>
<enabled>1</enabled>
<name>Restart Web UI</name>
<description/>
<type>configd_restart_gui</type>
<sftp_host/>
<sftp_host_key/>
<sftp_port>22</sftp_port>
<sftp_user/>
<sftp_identity_type/>
<sftp_remote_path/>
<sftp_chgrp/>
<sftp_chmod/>
<sftp_chmod_key/>
<sftp_filename_cert/>
<sftp_filename_key/>
<sftp_filename_ca/>
<sftp_filename_fullchain/>
<remote_ssh_host/>
<remote_ssh_host_key/>
<remote_ssh_port>22</remote_ssh_port>
<remote_ssh_user/>
<remote_ssh_identity_type/>
<remote_ssh_command/>
<configd/>
<configd_generic_command/>
<acme_synology_dsm_hostname/>
<acme_synology_dsm_port>5000</acme_synology_dsm_port>
<acme_synology_dsm_scheme>http</acme_synology_dsm_scheme>
<acme_synology_dsm_username/>
<acme_synology_dsm_password/>
<acme_synology_dsm_create>1</acme_synology_dsm_create>
<acme_synology_dsm_deviceid/>
<acme_synology_dsm_devicename/>
<acme_fritzbox_url/>
<acme_fritzbox_username/>
<acme_fritzbox_password/>
<acme_panos_username/>
<acme_panos_password/>
<acme_panos_host/>
<acme_proxmoxve_user>root</acme_proxmoxve_user>
<acme_proxmoxve_server/>
<acme_proxmoxve_port>8006</acme_proxmoxve_port>
<acme_proxmoxve_nodename/>
<acme_proxmoxve_realm>pam</acme_proxmoxve_realm>
<acme_proxmoxve_tokenid>acme</acme_proxmoxve_tokenid>
<acme_proxmoxve_tokenkey/>
<acme_truenas_apikey/>
<acme_truenas_hostname>localhost</acme_truenas_hostname>
<acme_truenas_scheme>http</acme_truenas_scheme>
<acme_unifi_keystore>/usr/local/share/java/unifi/data/keystore</acme_unifi_keystore>
<acme_vault_url/>
<acme_vault_prefix>acme</acme_vault_prefix>
<acme_vault_kvv2>1</acme_vault_kvv2>
</action>
</actions>
</AcmeClient>
</OPNsense>
<openvpn/>
<ifgroups version="1.0.0"/>
<laggs version="1.0.0">
<lagg/>
</laggs>
<virtualip version="1.0.0">
<vip uuid="0140ed47-fd07-4ace-b724-c972cc89e1cc">
<interface>lan</interface>
<mode>other</mode>
<subnet>192.168.2.0</subnet>
<subnet_bits>24</subnet_bits>
<gateway/>
<noexpand>0</noexpand>
<nobind>0</nobind>
<password/>
<vhid/>
<advbase>1</advbase>
<advskew>0</advskew>
<descr/>
</vip>
</virtualip>
<vlans version="1.0.0">
<vlan uuid="07fb6fc2-067f-4b54-a218-989a27aa0e90">
<if>vtnet1</if>
<tag>35</tag>
<pcp>0</pcp>
<proto/>
<descr>Orange FTTP</descr>
<vlanif>vlan01</vlanif>
</vlan>
<vlan uuid="4da015a4-4be4-4027-8251-73d63aa457ba">
<if>vtnet4</if>
<tag>35</tag>
<pcp>0</pcp>
<proto/>
<descr>SFP1.35</descr>
<vlanif>vlan0435</vlanif>
</vlan>
<vlan uuid="dfff563c-29ee-424e-8b56-f735b38e9b64">
<if>vtnet5</if>
<tag>35</tag>
<pcp>0</pcp>
<proto/>
<descr>SFP2.35</descr>
<vlanif>vlan0535</vlanif>
</vlan>
<vlan uuid="ce794d53-7e8d-40a4-af17-0af3d2a081c8">
<if>vtnet5</if>
<tag>100</tag>
<pcp>0</pcp>
<proto/>
<descr>SFP2.100</descr>
<vlanif>vlan05100</vlanif>
</vlan>
</vlans>
<staticroutes version="1.0.0">
<route uuid="cb4c0b25-8ff1-44cd-b087-f478541bfc0c">
<network>192.168.2.0/24</network>
<gateway>TO_DOCKER</gateway>
<descr/>
<disabled>0</disabled>
</route>
<route uuid="d2a312a7-a555-4103-bed3-3bd7657fe308">
<network>192.168.3.0/24</network>
<gateway>TO_DOCKER</gateway>
<descr/>
<disabled>0</disabled>
</route>
<route uuid="ba4df1de-d36a-4766-a855-f6511fa4d3da">
<network>192.168.4.0/24</network>
<gateway>TO_DOCKER</gateway>
<descr/>
<disabled>0</disabled>
</route>
<route uuid="17a574b0-ecaf-4ac4-b656-6e9013139d70">
<network>192.168.8.0/24</network>
<gateway>TO_DOCKER</gateway>
<descr/>
<disabled>0</disabled>
</route>
<route uuid="88634155-8329-4aae-8ef2-a4c921276291">
<network>192.168.16.0/24</network>
<gateway>TO_DOCKER</gateway>
<descr/>
<disabled>0</disabled>
</route>
<route uuid="c6d0791c-e938-4d45-b51b-aa4caaf03572">
<network>192.168.24.0/24</network>
<gateway>TO_DOCKER</gateway>
<descr/>
<disabled>0</disabled>
</route>
<route uuid="2d824097-b344-4dcf-97a1-8820ed7a8687">
<network>172.25.0.0/16</network>
<gateway>VPN_GW</gateway>
<descr/>
<disabled>0</disabled>
</route>
</staticroutes>
<bridges>
<bridged>
<descr>LAN_BRIDGE</descr>
<maxaddr/>
<timeout/>
<bridgeif>bridge0</bridgeif>
<maxage/>
<fwdelay/>
<hellotime/>
<priority/>
<proto>rstp</proto>
<holdcnt/>
<members>opt1,opt2,opt3,opt5</members>
<ifpriority/>
<ifpathcost/>
</bridged>
<bridged>
<enablestp>1</enablestp>
<descr>VLAN35</descr>
<maxaddr/>
<timeout/>
<bridgeif>bridge2</bridgeif>
<maxage/>
<fwdelay/>
<hellotime/>
<priority/>
<proto>rstp</proto>
<holdcnt/>
<members>opt13,opt14</members>
<ifpriority/>
<ifpathcost/>
</bridged>
</bridges>
<gifs version="1.0.0">
<gif/>
</gifs>
<gres version="1.0.0">
<gre/>
</gres>
<ppps>
<ppp>
<ptpid>0</ptpid>
<type>pppoe</type>
<if>pppoe0</if>
<ports>vlan0535</ports>
<username>bez_ochrony-R6DZpZN@neostrada.pl</username>
<password>Ym0zMnQ2eiQ0S0w=</password>
<provider/>
<bandwidth/>
<mtu/>
<mru/>
<mrru/>
</ppp>
</ppps>
<wireless>
<clone/>
</wireless>
<ca uuid="478c769f-4427-4922-a3d7-092d6419d9d0">
<refid>67058c2b67c99</refid>
<descr>R11 (ACME Client)</descr>
<crt>Ci0tLS0tQkVHSU4gQ0VSVElGSUNBVEUtLS0tLQpNSUlGQmpDQ0F1NmdBd0lCQWdJUkFJcDlQaFBXTHpEdkk0YTlLUWRyTlBnd0RRWUpLb1pJaHZjTkFRRUxCUUF3ClR6RUxNQWtHQTFVRUJoTUNWVk14S1RBbkJnTlZCQW9USUVsdWRHVnlibVYwSUZObFkzVnlhWFI1SUZKbGMyVmgKY21Ob0lFZHliM1Z3TVJVd0V3WURWUVFERXd4SlUxSkhJRkp2YjNRZ1dERXdIaGNOTWpRd016RXpNREF3TURBdwpXaGNOTWpjd016RXlNak0xT1RVNVdqQXpNUXN3Q1FZRFZRUUdFd0pWVXpFV01CUUdBMVVFQ2hNTlRHVjBKM01nClJXNWpjbmx3ZERFTU1Bb0dBMVVFQXhNRFVqRXhNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DQVE4QU1JSUIKQ2dLQ0FRRUF1b2U4WEJzQU9jdktDczNVWnhENUFUeWxUcVZoeXliS1V2c1ZBYmU1S1BVb0h1MG5zeVFZT1djSgpEQWpzNERxd08zY092ZlBsT1ZSQkRFNnVRZGFaZE41UjIrOTcvMWk5cUxjVDl0NHgxZkp5eVhKcUM0TjBsWnhHCkFHUVVtZk94MlNMWnphaVNxaHdtZWovKzcxZ0Zld2lWZ2R0eEQ0Nzc0ekVKdXdtK1VFMWZqNUYyUFZxZG5vUHkKNmNSbXMrRUdaa05JR0lCbG9EY1ltcHVFTXBleHNyM0UrQlVBblNlSSsrSmpGNVpzbXlkblM4VGJLRjVwd25udwpTVnpnSkZEaHhMeWhCYXg3UUcwQXRNSkJQNmRZdUMvRlhKdWx1d21lOGY3cnNJVTUvYWdLNzBYRWVPdGxLc0xQClh6emU0MXhORy9jTEp5dXFDMEozVTA5NWFoMkgyUUlEQVFBQm80SDRNSUgxTUE0R0ExVWREd0VCL3dRRUF3SUIKaGpBZEJnTlZIU1VFRmpBVUJnZ3JCZ0VGQlFjREFnWUlLd1lCQlFVSEF3RXdFZ1lEVlIwVEFRSC9CQWd3QmdFQgovd0lCQURBZEJnTlZIUTRFRmdRVXhjOUdwT3IwdzhCNmJKWEVMYkJla2k4bTQ3a3dId1lEVlIwakJCZ3dGb0FVCmViUlo1bnUyNWVRQmM0QUlpTWdhV1BicG0yNHdNZ1lJS3dZQkJRVUhBUUVFSmpBa01DSUdDQ3NHQVFVRkJ6QUMKaGhab2RIUndPaTh2ZURFdWFTNXNaVzVqY2k1dmNtY3ZNQk1HQTFVZElBUU1NQW93Q0FZR1o0RU1BUUlCTUNjRwpBMVVkSHdRZ01CNHdIS0Fhb0JpR0ZtaDBkSEE2THk5NE1TNWpMbXhsYm1OeUxtOXlaeTh3RFFZSktvWklodmNOCkFRRUxCUUFEZ2dJQkFFN2lpVjBLQXh5UU9ORDFIL2x4WFBqRGo3STNpSHB2c0NVZjdiNjMySVlHanVrSmhNMXkKdjRIei9NclBVMGp0dmZacFF0U2xFVDQxeUJPeWtoMEZYK291MU5qNFNjT3Q5Wm1Xbk84bTJPRzBKQXRJSUUzOAowMVMwcWNZaHlPRTJHLzkzWkNrWHVmQkw3MTNxelhuUXY1Qy92aU95a05wS3FVZ3hkS2xFQytIaTlpMkRjYVIxCmU5S1V3UVVaUmh5NWovUEVkRWdsS2czbDlkdEQ0dHVUbTdrWnRCOHYzMm9PanpIVFl3KzdLZHpkWml3L3NCdG4KVWZoQlBPUk51YXk0cEp4bVkvV3JoU01kekZPMnEzR3UzTVVCY2RvMjdnb1lLakw5Q1RGOGovWno1NXljdFVvVgphbmVDV3MvYWpVWCtIeXBrQlRBK2M4TEdETG5XTzJOS3EwWUQvcG5BUmtBbllHUGZVRG9IUjlnVlNwL3FSeCtaCldnaGlETFpzTXdoTjF6anRTQzB1QldpdWdGM3ZUTnpZSUVGZmFQRzdXczNqRHJBTU1ZZWJROTVKUStISUJEL1IKUEJ1SFJUQnBxS2x5RG5rU0hESFlQaU5YM2FkUG9QQWNnZEYzSDIvVzBybW9zd01XZ1RsTG4xV3UwbXJrczcvcQpwZFdmUzZQSjFqdHk4MHIyVktzTS9EajNZSURmYmpYS2RhRlU1Qys4YmhmSkdxVTN0YUthdXV6MHdIVkdUM2VvCjZGbFdrV1l0YnQ0cGdkYW1sd1ZlWkVXK0xNN3FaRUpFc01OUHJmQzAzQVBLbVpzSmdwV0NEV09LWnZrWmN2alYKdVlrUTRvbVlDVFg1b2h5K2tuTWpkT21kSDljN1NwcUVXQkRDODZmaU5leCtPMFhPTUVaU2E4REEKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=</crt>
<prv/>
<serial/>
<caref/>
</ca>
<ca uuid="51ebcff9-22c9-4228-9d96-5080f50843e7">
<refid>67f2fbcd9505a</refid>
<descr>R10 (ACME Client)</descr>
<crt>Ci0tLS0tQkVHSU4gQ0VSVElGSUNBVEUtLS0tLQpNSUlGQlRDQ0F1MmdBd0lCQWdJUVM2aFNrL2VhTDZKekJrdW9CSTExMERBTkJna3Foa2lHOXcwQkFRc0ZBREJQCk1Rc3dDUVlEVlFRR0V3SlZVekVwTUNjR0ExVUVDaE1nU1c1MFpYSnVaWFFnVTJWamRYSnBkSGtnVW1WelpXRnkKWTJnZ1IzSnZkWEF4RlRBVEJnTlZCQU1UREVsVFVrY2dVbTl2ZENCWU1UQWVGdzB5TkRBek1UTXdNREF3TURCYQpGdzB5TnpBek1USXlNelU1TlRsYU1ETXhDekFKQmdOVkJBWVRBbFZUTVJZd0ZBWURWUVFLRXcxTVpYUW5jeUJGCmJtTnllWEIwTVF3d0NnWURWUVFERXdOU01UQXdnZ0VpTUEwR0NTcUdTSWIzRFFFQkFRVUFBNElCRHdBd2dnRUsKQW9JQkFRRFBWK1hteEZRUzdiUkgvc2tuV0haR1VDaU1IVDZJM3dXZDFiVVlLYjNkdFZxLyt2Yk9vNzZ2QUNGTApZbHBhUEFFdnhWZ0Q5b24vamhGRDY4RzE0QlFIbG85dkg5Zm51b0U1Q1hWbHQ4S3ZHRnMzSmlqbm8vUUhLMjBhCi82dFl2Sld1UVAvcHkxZkV0VnQvZUEwWVlid1g1MVRHdTBtUnpXNFkwWUNGN3FabE5yeDA2cnhRVE9yOElmTTQKRnBPVXVyRFRhemdHelJZU2VzcFNkY2l0ZHJMQ25GMllSVnh2WVh2R0xlNDhFMUtHQWRsWDVqZ2MzNDIxSDVLUgptdWRLSE14RnFISlY4TERtb3dmcy9hY2JacDQvU0l0eGhIRll5VHI2NzE3eVcwUXJQSFRuajdKSHdRZHF6WnEzCkRaYjNFb0VtVVZRSzdHSDI5L1hpOG9ySWxRMk5BZ01CQUFHamdmZ3dnZlV3RGdZRFZSMFBBUUgvQkFRREFnR0cKTUIwR0ExVWRKUVFXTUJRR0NDc0dBUVVGQndNQ0JnZ3JCZ0VGQlFjREFUQVNCZ05WSFJNQkFmOEVDREFHQVFILwpBZ0VBTUIwR0ExVWREZ1FXQkJTN3ZNTkhwZVM4cWNiRHBISU1FSTJpTmVISTZEQWZCZ05WSFNNRUdEQVdnQlI1CnRGbm1lN2JsNUFGemdBaUl5QnBZOXVtYmJqQXlCZ2dyQmdFRkJRY0JBUVFtTUNRd0lnWUlLd1lCQlFVSE1BS0cKRm1oMGRIQTZMeTk0TVM1cExteGxibU55TG05eVp5OHdFd1lEVlIwZ0JBd3dDakFJQmdabmdRd0JBZ0V3SndZRApWUjBmQkNBd0hqQWNvQnFnR0lZV2FIUjBjRG92TDNneExtTXViR1Z1WTNJdWIzSm5MekFOQmdrcWhraUc5dzBCCkFRc0ZBQU9DQWdFQWtySG5RVGZyZVoyQjVzM2lKZUU2SU9tUVJKV2pnVnpQdzEzOXZhQncxYkdXS0NJTDB2SW8Kend6bjFPWkRqQ1FpSGNGQ2t0RUpyNTlMOU1od1R5QVdzVnJkQWZZZitCOWhheFFuc0hLTlk2N3U0czVMenpmZAp1NlBVemVldFVLMjl2K1BzUG1JMmNKa3hwK2lOM2VwaTRoS3U5WnpVUFN3TXF0Q2NlYjdxUFZ4RWJwWXhZMXA5CjFuNVBKS0JMQlg5ZWI5TFU2bDh6U3hQV1Y3YkszbEc0WGFNSmduVDl4M2llczdtc0Z0cEtLNWJEdG90aWovbDAKR2FLZUE5N3BiNXV3RDlLZ1d2YUZYTUlFdDhqVlRqTEV2d1JkdkNuMjk0R1BERjA4VThsQWtJdjd0Z2hsdWFRaAoxUW5sRTRTRU40TE9FQ2o4ZHNJR0pYcEdVazNhVTNLa0p6OWljS3krYVVnQSsyY1AyMXVoNk5jRElTM1h5ZmFaClFqbURROTkzQ2hJSThTWFd1cFFaVkJpSXBjV080UnFaazNscjdCejVNVUN3ekRJQTM1OWU1N1NTcTVDQ2tZME4KNEI2VnVsazdMa3Rmd3JkR05WSTVCc0M5cXF4U3dTS2dSSmVaOXd5Z0lhZWhiSEZIRmhjQmFNREtwaVpsQkh5egpyc25ubEZYQ2I1czhIS241THNVZ0d2QjI0TDdzR05aUDJDWDdkaEhvditZaEQram96TFcycDlXNDk1OUJ6MkVpClJtcUR0bWlYTG56cVRwWGJJK3N1eUNzb2hLUmc2VW4wUkM0NytjcGlWd0hpWFpBVytjbjhlaU5JanFiVmdYTHgKS1BwZHp2dnRUbk9QbEM3U1FaU1ltZHVucjNCZjliNzdBaUMvWmlkc3RLMzZkUklMS3o3T0E1ND0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=</crt>
<prv/>
<serial/>
<caref/>
</ca>
<dhcpdv6/>
<cert uuid="bf077c25-b0ea-4bdd-ac18-b4db7c1cbfae">
<refid>662fcbdcbeca4</refid>
<descr>Web GUI TLS certificate</descr>
<caref/>
<crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUhIakNDQlFhZ0F3SUJBZ0lVRW9vaElTMTd4WmwyK2hYWlZmU2pJeUJTQXFzd0RRWUpLb1pJaHZjTkFRRUwKQlFBd2dZa3hIVEFiQmdOVkJBTU1GRTlRVG5ObGJuTmxMbXh2WTJGc1pHOXRZV2x1TVFzd0NRWURWUVFHRXdKTwpUREVWTUJNR0ExVUVDQXdNV25WcFpDMUliMnhzWVc1a01SVXdFd1lEVlFRSERBeE5hV1JrWld4b1lYSnVhWE14CkxUQXJCZ05WQkFvTUpFOVFUbk5sYm5ObElITmxiR1l0YzJsbmJtVmtJSGRsWWlCalpYSjBhV1pwWTJGMFpUQWUKRncweU5EQTBNamt4TmpNek16TmFGdzB5TlRBMU16RXhOak16TXpOYU1JR0pNUjB3R3dZRFZRUUREQlJQVUU1egpaVzV6WlM1c2IyTmhiR1J2YldGcGJqRUxNQWtHQTFVRUJoTUNUa3d4RlRBVEJnTlZCQWdNREZwMWFXUXRTRzlzCmJHRnVaREVWTUJNR0ExVUVCd3dNVFdsa1pHVnNhR0Z5Ym1sek1TMHdLd1lEVlFRS0RDUlBVRTV6Wlc1elpTQnoKWld4bUxYTnBaMjVsWkNCM1pXSWdZMlZ5ZEdsbWFXTmhkR1V3Z2dJaU1BMEdDU3FHU0liM0RRRUJBUVVBQTRJQwpEd0F3Z2dJS0FvSUNBUUNtSFlhaU1nYUtWTjgxeVpkWldSa3VJVEhxTEJLUEMzWVFiaHlwUWtzOS9uZWZkZmRLCm5ETEtrZHk3ZUpFcG9QS3hZd1BoWnV1emVDRXJDNGRlTCtuOFNiOUFxRzBJOU9iQ3JoUlIzNmNQT3ZKWklDVU0KU2dSMGM0UjQySmtrOXJYRnFmZkJsZllWWmtHREV3VUh3c1VlcTd6WXViS2pYWGN6UXpIMC9OTVEwRFFPVzc4SApyaTdHWUV4UVk4Nno2dkhwRDhlL2o1YllzdzhxYlFlb0RyTVRSRCtqWVIzcUNWUHBoQ1B1SkFsNlk3NkN3Tlk3Cm8yZThlSjdYTEdleVpnTmhhRFJCTHZQQS96SnJOTloyTmlMQVhDUVR0a0NqbktvQjVKRlVGZVB5b0FhK3crZ3oKeWl4b0FWWFJjYTVZeWoyS1g0bUZobEdOaHhCYjk5Tk1TT3RDQ2xkVGdqdG0xbUdjYzVraGxNQTF2c2FycE1WMQpTcE9zMVBaaWJsNC9ZT2ZkZ3ZyRWxObEsyL2FlSm84NmVjZzRmUGZvaGFvcDNoNldUMzFDb05PczY2OEM4V2YvCkhUbTIwdVVkZmpRbEEwb25IUENOVlY4a3RWRmJpSkp6aHNOblNtdk9TLzNLYXBQeDVqeGNKRWhrblo2aGc3VmgKZ0ZBdzVaajFTOXBHR0N1SktaRFFRcnJnVWxmRkU3c3NpSHNXdDVwaCtzak8zcC9mYUdHY2tPUE12YmF4V09yLwpnMW4ySnRzZjFBM09xMzRnSlhHcWVmWXN3Y2JEYnNCSjZyOHlVQ0k0V1hpYkV6V3JzTjV1dkFtZFZMWlhrUmdZCmpoaHJyQ0FDa3ZaZzlhTCtKNXZza2dnRFMzT1BCWHhUTWRTdHBsbFFZOWh5VzV6c1p2YjdiblpQMndJREFRQUIKbzRJQmVqQ0NBWFl3Q1FZRFZSMFRCQUl3QURBUkJnbGdoa2dCaHZoQ0FRRUVCQU1DQmtBd05BWUpZSVpJQVliNApRZ0VOQkNjV0pVOVFUbk5sYm5ObElFZGxibVZ5WVhSbFpDQlRaWEoyWlhJZ1EyVnlkR2xtYVdOaGRHVXdIUVlEClZSME9CQllFRktkbEFXc21URkdNbjR3K1BrOXRSV2hhYTByV01JR3pCZ05WSFNNRWdhc3dnYWloZ1kra2dZd3cKZ1lreEhUQWJCZ05WQkFNTUZFOVFUbk5sYm5ObExteHZZMkZzWkc5dFlXbHVNUXN3Q1FZRFZRUUdFd0pPVERFVgpNQk1HQTFVRUNBd01XblZwWkMxSWIyeHNZVzVrTVJVd0V3WURWUVFIREF4TmFXUmtaV3hvWVhKdWFYTXhMVEFyCkJnTlZCQW9NSkU5UVRuTmxibk5sSUhObGJHWXRjMmxuYm1Wa0lIZGxZaUJqWlhKMGFXWnBZMkYwWllJVUVvb2gKSVMxN3habDIraFhaVmZTakl5QlNBcXN3SFFZRFZSMGxCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQ0FJQwpNQXNHQTFVZER3UUVBd0lGb0RBZkJnTlZIUkVFR0RBV2doUlBVRTV6Wlc1elpTNXNiMk5oYkdSdmJXRnBiakFOCkJna3Foa2lHOXcwQkFRc0ZBQU9DQWdFQUJYcG1ZdUlrellqV01hRGlMZzRYVis1eUovcGU2Vk8rcVNBSCt6TGgKOTlWK01zaUtmblZta3grT0YranIrRVptUGc4bFV3VXJHRDBwVVU0NFRYT0t6RFUxcDRaVXMweFNIMVdzWGh1UQpYaFc0MFdqY3Z3YUZjdTlTdVRnWFh4RDNFckRtaWRzR3RINFkrUkpEdVBNK29VQmFTSlpBZG5YYzFQWVd4MmxtCnYzZ2xUaUxleEpzT1pZVXlqa09ueWZHQ2dZRzlZdEZmSEY0Yy80NWcvV3FyOGpJckYya1RmM3lHSHBJcGJxZU0KYittSDhGOW5rbEY4S0lnNGlxRnkvOVE0NHA0SDhoK29UT1BQeGdyblJBUXZ3UHhydXJhMjVCY2hsdFZBQm5OYQpQV3MrMW53WUhiVHlzd0llMXhyS3R6aWF6Tk9DZzhDTWJTVzl5S3pQSCtzK29PUTQ0UERCcXVHUktFLzBjY1A4CmlWendBMms1YVRCNDhwWG9WQi9Yc1lhSytYdWUvYWRnNVpIWks3NFkxZHZXUng1bVZkZ3NJUkZXWGNUZktOR1cKMjgzTldqNjN3RDA3ZXhNVkxndHErd0NWQ01tWUZVUW0vQk9nVXRXYkZ2V3JwaUFVbTJwbGtndkVENGlHd2dzcwoyN3FoMG9aVGUvazRzM3d5ZmZtemJ2NWR4dEFPMHZlakptODJLL0hoejRkM3pJNDBoenZUSkNtK1lUZVlPMXptCk1YLzd3WW9GRmVZWkxZazg3Z0FEcHVsOVUrNllDb1ArU1d2cUxYZTEwbThiWjhtNmVacUZNNE45RlA5aTJRRUMKWFRwK1RrZ0sybURTTjFETWpKVFI0KzVoaDBFUSszWlB4ZVdjalZDSTBmYlMzaGlJYnBuS1dFYnlJSTByRkJOSgpXN0k9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K</crt>
<csr/>
<prv>LS0tLS1CRUdJTiBQUklWQVRFIEtFWS0tLS0tCk1JSUpRd0lCQURBTkJna3Foa2lHOXcwQkFRRUZBQVNDQ1Mwd2dna3BBZ0VBQW9JQ0FRQ21IWWFpTWdhS1ZOODEKeVpkWldSa3VJVEhxTEJLUEMzWVFiaHlwUWtzOS9uZWZkZmRLbkRMS2tkeTdlSkVwb1BLeFl3UGhadXV6ZUNFcgpDNGRlTCtuOFNiOUFxRzBJOU9iQ3JoUlIzNmNQT3ZKWklDVU1TZ1IwYzRSNDJKa2s5clhGcWZmQmxmWVZaa0dECkV3VUh3c1VlcTd6WXViS2pYWGN6UXpIMC9OTVEwRFFPVzc4SHJpN0dZRXhRWTg2ejZ2SHBEOGUvajViWXN3OHEKYlFlb0RyTVRSRCtqWVIzcUNWUHBoQ1B1SkFsNlk3NkN3Tlk3bzJlOGVKN1hMR2V5WmdOaGFEUkJMdlBBL3pKcgpOTloyTmlMQVhDUVR0a0NqbktvQjVKRlVGZVB5b0FhK3crZ3p5aXhvQVZYUmNhNVl5ajJLWDRtRmhsR05oeEJiCjk5Tk1TT3RDQ2xkVGdqdG0xbUdjYzVraGxNQTF2c2FycE1WMVNwT3MxUFppYmw0L1lPZmRndnJFbE5sSzIvYWUKSm84NmVjZzRmUGZvaGFvcDNoNldUMzFDb05PczY2OEM4V2YvSFRtMjB1VWRmalFsQTBvbkhQQ05WVjhrdFZGYgppSkp6aHNOblNtdk9TLzNLYXBQeDVqeGNKRWhrblo2aGc3VmhnRkF3NVpqMVM5cEdHQ3VKS1pEUVFycmdVbGZGCkU3c3NpSHNXdDVwaCtzak8zcC9mYUdHY2tPUE12YmF4V09yL2cxbjJKdHNmMUEzT3EzNGdKWEdxZWZZc3djYkQKYnNCSjZyOHlVQ0k0V1hpYkV6V3JzTjV1dkFtZFZMWlhrUmdZamhocnJDQUNrdlpnOWFMK0o1dnNrZ2dEUzNPUApCWHhUTWRTdHBsbFFZOWh5VzV6c1p2YjdiblpQMndJREFRQUJBb0lDQUMvenpRWXNSN3dPQlFOTFp0L1pldzNZCmNrYkZvelBjM0orZ2tiQ0FuU1RQdk90d3k4cWpiWHdSZ0RVeitEK2FvUVI0NzBsVmd3dmpUVHZXVDZUdVV1N0wKd1NSaW1sc2dDeTgrdmtubU5KME9hS0EyeWNzUzROZFc4M0pKSUdoTnVhcE9SdUdBcnpGOU84TWhMZTRRR1FRaQpFbGxEdmVBdjNuV1RXNnY3Z2RoVUtmck5IRWVVemhiZy9KYW1RU2lwMVZ4d2ZEcDlzazlxM1NGanFQYW9DNlN2CnFtazQ0MEJJb2dzQ1pMYmRlMGp6Mnk1MmlVRmRDZGlidjBxaEhHd2d5N0FHT3pObjRPQ2hLb1pORWUyODhlb3kKancyTHFud3dnTmtjQ0tITDBlb2JyT2JMdWMrZGVKVXJjWUVNL29YT0Y5Ykdmblhua01vNHA0M003QmVVNHloTgpVWm85SkFnbUpJeXlLK3l6cDB4bDVLbUpsZ2RrSFozd05ocFhqWFB0U1M5RU8zeEFVYVc1UkoycUtheFduT0l2CjFza3ZiL1N5bTl2NWZxT2J1MVhJOVMrUWYza2d6MWJhWHFsU25JQ3RydEhKcW53Z2QzR01WRnhTd3JxeklMMVYKMWlhZTdaMWVKcUMrNFpmMFh3K2tScW5DTUtJRE5NSmtsK3dFSUZRRkJoWXAreDArRmVDanR5a2duRzl1RnNEdApzdFB6SjRuWTJaZzJveEdsLzRqL05ZaDZyTkdsRGdJcVMrWHBmdnk3cEpxaWlzUmJKR2FjelY0VDk1WnJ0UzI3CkRBVFI5Yk53czZWTUg4M0xueHFkaUdFNmtWUGRMQ0hmYXd6ajcyNG9rNFk3STlJOG94eWlwSE1TQ2k0NHNSeW4KcHhOdFFwQkFkdkxWMHdvVy8xcnRBb0lCQVFEZlJRV3NxaDhDLzNJbHBIY09vUFVMSUwxV1RiZ004Ryt5ZUpCZApueDlqajd4bkcrQU9naWVBQ2R6N09ZTUx4SFIzR2o0Q1NzZk1zbm5LRzBHbWdINExieXJReE1Dc3htMFZsMWlVClVvUGNoTExLY2gwL0pGOFZUU2M1cStmbGoxUlNMZmlYNVJkVFRiVS8reXk1ZE5Fa2xUMS9oVjlTUk9YVmRiK3AKL3AvckpiWG4rUmpzaUZrTlVSVnVPUjZ6N080VEsrNGxoRXVDN0s3MnMzY1NmRW9BamVnelU5Rk5wRERQVEZDVApHaFQ0T2diRGpRSW5OZUpBTFRCZzNNZ3h6ZlpOTm1NYTZPS1IyUG5KOU5UVUNCS1pBMUFOTWRNZVlDY1g5WDMxCmtqaUxoR0JDVXhUVWRLN1c3WmdVS28wRkxBaHRFdEF2WWhnVGRYWGljQWpBb3gyL0FvSUJBUUMrZDVhWFQ2WFUKQ1h5OG41TFVMRTltd05pdnJBaHJ6UkNNelk0NDFKRDJlYk5xUC9MLzViTjVIeWVHdVRxVkI4dExENHpxa0Vxcgp1d2k1NEt4RlhhdURSRHB0SGxWa1dubTA1TVJqa1ZyNU1KQ3ZXRTBzOWtEOWVYdFQ3VWptWU9ET2VkNXVMbjdFClV5NXc1UG01VDI2S1IxdllYZEwvTlFZUzBiODhXaEwzV1FRSHljRGpMUkp5NzJubWV0SWRUS1VJaXQrMVVBZFMKTlU4NXdhNnlwQjZQYWpkQ0tsL1RXa1F2TDJHS050VTQxd1FnKzVvWWlucUtoL2JwOC9UQWJJekZ3U0txbktwSQo2QlFaSFNVRzZEYk92UkQ4OTVSSktVT1RwV3B3R0tFWEkvd1dlTDhwSkNtKzMwcWNCb3A3SCsrNTBTSGRLMVVsCmJCazlZc0l1U0V6bEFvSUJBUURhOGtqYVJnb2JXbjJKeEhxc2NkTmJra09hT3FUZXEzb2R2blYwR2ZNaUkzWlMKZHRlRjRzVHhucnFCOHFnOEJlOWdUTys2TjdNdlhXWnBkOGt0aXB3UWduZXVPd1BuYXI3V2laQm9BM01qOFUyVAprY3gwZXlwekxUSG1NRm84bUEzTWVTQnJkRkVuYy9EbVNWNVdqK1A0eUJHQzJEdmQ1WXF0aGNicTRiUFpXU1hGCjBsVkt2M3Iwd0NzUDZCdmZ2ZHpLR0M1MXhBSjQ1Ym0rVzhmTTdPMTFGYlE3Z1ZxamxQdjRqWklHYjNGWTZ5NXUKM2Z6YWp0RE10b1BXdVN2cEMxMFo0dGZWTDhQZjJyTTZCVW9nazdvSksySjVUZjhHcnF3bnBxcGJBNFZIN0F5cApmZWZUWUltRVk0TGJZODdlMzR0enl4czFIREVZQS93U2ptTkc1YTdwQW9JQkFFSlBILzVObkUzVmY3ZXJWbExICm1sMExobVNpWDh3bitEc00xUmF6NmtQazJyR0MwZmFFNFphcFlmbGxReC9mTnNkTEFxUW0xOWd4cFRnUkgraUcKVTgrL1VSZnNGNDU0Y1Nhby9qWXJ4S0E4YUNLamV6ck1BSlErVnRGQktzQUp1am9uODJnb2g3bVJ1L2xSdmg3bApxSFk3b1o0U0RBTU5VcS82bGJsTklvMDZVRXpsMEdGR3I4V1QxQ3FKVjkwYmNka25mL3AvZ2d6OHdqZzVWYmliCnFvZ0RVbm1XaHdYdHh3OG1UNjd1cUF6QnpvNHRDZGpCWFNnZGJiakZWZEFuK2xwZWd0TWk5NldxSmxVWDhHd1gKSy8yTmxQeDh0UU5EZW1OTWsyR3pNV0g5QlNaTm96K1BkM2tjQTcyT0NXZ1VGa0Y2clc5eVJwSmdyK2pQR1F0RAo0SUVDZ2dFQkFNbXFSNFFKZ2U1dFpJTDFZTi9ueG11TjdrZUxPTlVabUZaVzFMWXpkZS9KNUppeEhlaHRDenhqClo2dU9yUXowV2ZLcXQzdEJpRXpESTNDaEVrdC85YTErT1BQcHZNb1FRQVVnOWtxQlhydTF3Y0hpTXpQWGhiWFEKTHZIYVVZM0N1REtFZ0RlMGRxNWhIQW1vTzhISFBXK21nTVVmTWszTFZVdnZ4ZV
</cert>
<cert uuid="43bb2073-5362-4358-b96a-8e7109beaa2c">
<refid>67058c2b680ff</refid>
<descr>gate.waw.eldorado.city (ACME Client)</descr>
<caref>67f2fbcd9505a</caref>
<crt>LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUdDVENDQlBHZ0F3SUJBZ0lTQlhlZ1Y4c29MSEUxOXJoOVRvVEFWV3JPTUEwR0NTcUdTSWIzRFFFQkN3VUEKTURNeEN6QUpCZ05WQkFZVEFsVlRNUll3RkFZRFZRUUtFdzFNWlhRbmN5QkZibU55ZVhCME1Rd3dDZ1lEVlFRRApFd05TTVRBd0hoY05NalV3T0RBME1qRXhNVFExV2hjTk1qVXhNVEF5TWpFeE1UUTBXakFoTVI4d0hRWURWUVFECkV4Wm5ZWFJsTG5kaGR5NWxiR1J2Y21Ga2J5NWphWFI1TUlJQ0lqQU5CZ2txaGtpRzl3MEJBUUVGQUFPQ0FnOEEKTUlJQ0NnS0NBZ0VBeUlVS21WaVRnZnJLY3JodXAzeDRLd3lCVWtuTFpUTUp3c3piVFR2TWJ5SVhLWHBpOWFCNwppd29xSWRpaWV6NG5UVEEvNUQ0RkNmWnlPNzZ2a2R0T0xNU1V1WGprSlBIM2tvOEVPWHRqZXAzUnNtNTg5ZkUxCmJYbEYzOFR0b0xSRmdHd25EenFVWmZ5UjFOZmRPUWU5RFNXTklqSEh1SmRjWkN6WURoc3J6dENuTVB3YUlpa3gKdmdST2xvZVM5RkQ4bUlBRGJhMXpoU253bCtHRnNubnFWY2txY2Q2bTlFMkVjYlg5WXdXUWl2d09UNnZVZURQcwprTzg3T2Q1VEZYeGJBdzRmbnd3NGNydTdYV2ZubjQ1R09NTTdQaG5tbkxrNTI2SHFDNFh4TWx5SEdKbUtHVVFOCldVTE9RNGVVblVLTGpJR0ZYYlNxNm5vY25aZlRnYUs1Z2pmcUxCdHpXZmRkQW5uOVhPdzVHME9UbFBKVmt5RkEKVUt4SjJJZUR4NEpmUFZDWmRZYUVGMlFBcW1xY2crTUxGUEhycXl3cXF5K0RwTTlvUk5DN2lraFRoRm5JeWxIbgoybDBCWC9ZTGlFL2Q2VWtpL1dKV05TNUNnbGFHMWM1YlJ0NHQ4MEhqb3FPeTIzVS8vVG1OMjFPVGFFZzhiWDE3Ci9zT09ZRXZMeWVFbTZLQzhNdUpQWDBlMGlFOFAyWWNqZnVRejgrVVJiaDRDcyt2YUsxWkdkQngzQmZmczNuK1AKTDg0czJTWmlESy9qSGtHZTZ1RkNzUlJvS1hDN1MzTkpWcXZtTUVaellIVGlWWkdjUHBZek82ekp1dFdHd2dNRAp4QitXUk5sck5FRGV0Q0w1dW1JZnNSM01MajFEUk5uYVdKWEFZOE1taXBKVFFsZTJvVitZSXIwQ0F3RUFBYU9DCkFpY3dnZ0lqTUE0R0ExVWREd0VCL3dRRUF3SUZvREFkQmdOVkhTVUVGakFVQmdnckJnRUZCUWNEQVFZSUt3WUIKQlFVSEF3SXdEQVlEVlIwVEFRSC9CQUl3QURBZEJnTlZIUTRFRmdRVXUrcjBqVzNlZG9aYmxtODk3RWV3MC9XMgo3bmt3SHdZRFZSMGpCQmd3Rm9BVXU3ekRSNlhrdktuR3c2UnlEQkNOb2pYaHlPZ3dNd1lJS3dZQkJRVUhBUUVFCkp6QWxNQ01HQ0NzR0FRVUZCekFDaGhkb2RIUndPaTh2Y2pFd0xta3ViR1Z1WTNJdWIzSm5MekFoQmdOVkhSRUUKR2pBWWdoWm5ZWFJsTG5kaGR5NWxiR1J2Y21Ga2J5NWphWFI1TUJNR0ExVWRJQVFNTUFvd0NBWUdaNEVNQVFJQgpNQzRHQTFVZEh3UW5NQ1V3STZBaG9CK0dIV2gwZEhBNkx5OXlNVEF1WXk1c1pXNWpjaTV2Y21jdk56a3VZM0pzCk1JSUJCUVlLS3dZQkJBSFdlUUlFQWdTQjlnU0I4d0R4QUhZQUdnVC9TZEJVSFVDdjlxRER2L0hZeEdjdlR1enUKSTBCb21Hc1hRQzdjaVgwQUFBR1lkeUtqY2dBQUJBTUFSekJGQWlBSHM0aHBHYXhQNGkrdUwydi90UXlITFBBUQpyNGYvbDYvbjBnSUZ0YzBhcEFJaEFNS0doYUJ5Ty9UaDlSb2VpY2djaks2clg4RE8rQ2VDY2VEcUdQaEJrd1piCkFIY0FFdkZPTkwxVGNreUVCaG5Eano5NkUvam50V0tIaUp4dE1BV0U2K1dHSmpvQUFBR1lkeUtqU1FBQUJBTUEKU0RCR0FpRUFwc0lVeG9UY2ZKalVBcFRoVkl5QUYzVURKbE1zRjFqbDZBb1NqTkY0ajhjQ0lRQ1ZXZWhFWnV3Vwo3VHdCODFjcXpqQWtGeW96VnJySzVPbFN1OGRGYm1TTjdqQU5CZ2txaGtpRzl3MEJBUXNGQUFPQ0FRRUF2UDJUCm9hdEVEaThHcHA5Y1IyWjV1WmxrTEJjdUhPajkxRTRYZWg2cGZEZ05Rcmg1VTQ3WUxsRU9YeWovRnlwdWVUcTYKMVFQc2x5eXpRSDhvSWtpUitYSjczRkEwN2UyREsxb2o4L3VuRVZuenZrM0JzUnVhcEw1WWp0OUtIVHJxMDg3RwpaMDZKMWlna1BSNUo2OUpaRmhRd2ZSL3B2TmxGWFVpK2t2N1F3T05ad3hKbG9MZWlMV3V2aHpIeERqS1htdzNmClBKOHFCN2d3S3BXWXJJcld3TXRDbHdyWGxrRXZLeTJkbDhZT3BYSHhZb0luOTlRTTdRWjFKZ3FXWnQxMytVNjYKeGJyU3dZSXZYazZHd1JQbE9zQWU1RGdoNGoyNDJhaXlDVUZaOVBlMUt0bG9JdE05eDl2TEl2b1AwcHBoRktRcwpnTk01ZVBKNnFqZzJYRC9vMWc9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==</crt>
<csr/>
<prv>LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlKSndJQkFBS0NBZ0VBeUlVS21WaVRnZnJLY3JodXAzeDRLd3lCVWtuTFpUTUp3c3piVFR2TWJ5SVhLWHBpCjlhQjdpd29xSWRpaWV6NG5UVEEvNUQ0RkNmWnlPNzZ2a2R0T0xNU1V1WGprSlBIM2tvOEVPWHRqZXAzUnNtNTgKOWZFMWJYbEYzOFR0b0xSRmdHd25EenFVWmZ5UjFOZmRPUWU5RFNXTklqSEh1SmRjWkN6WURoc3J6dENuTVB3YQpJaWt4dmdST2xvZVM5RkQ4bUlBRGJhMXpoU253bCtHRnNubnFWY2txY2Q2bTlFMkVjYlg5WXdXUWl2d09UNnZVCmVEUHNrTzg3T2Q1VEZYeGJBdzRmbnd3NGNydTdYV2ZubjQ1R09NTTdQaG5tbkxrNTI2SHFDNFh4TWx5SEdKbUsKR1VRTldVTE9RNGVVblVLTGpJR0ZYYlNxNm5vY25aZlRnYUs1Z2pmcUxCdHpXZmRkQW5uOVhPdzVHME9UbFBKVgpreUZBVUt4SjJJZUR4NEpmUFZDWmRZYUVGMlFBcW1xY2crTUxGUEhycXl3cXF5K0RwTTlvUk5DN2lraFRoRm5JCnlsSG4ybDBCWC9ZTGlFL2Q2VWtpL1dKV05TNUNnbGFHMWM1YlJ0NHQ4MEhqb3FPeTIzVS8vVG1OMjFPVGFFZzgKYlgxNy9zT09ZRXZMeWVFbTZLQzhNdUpQWDBlMGlFOFAyWWNqZnVRejgrVVJiaDRDcyt2YUsxWkdkQngzQmZmcwozbitQTDg0czJTWmlESy9qSGtHZTZ1RkNzUlJvS1hDN1MzTkpWcXZtTUVaellIVGlWWkdjUHBZek82ekp1dFdHCndnTUR4QitXUk5sck5FRGV0Q0w1dW1JZnNSM01MajFEUk5uYVdKWEFZOE1taXBKVFFsZTJvVitZSXIwQ0F3RUEKQVFLQ0FnQnNUN0RSOUE1NWYwWXJnWVFENUMvazBQUnB4b0tmUDFwZVp0bHVkb2FPNFJNeHpISDN5NS93RXFWLwpjczBSVlJsVmtHSnlueTJKbkIxSU9GQU5zVEFnN202SFlNMmJSemc3YWhVV0Y1ZzhlMUx4MXN5WTdKbTNjSEpWCjFNR210TGwyRFBWc1BIQThScGxmSnRyUUcyWDYyL1hJS3F0L0FnTmQrUHNiWTRIZVRNYUNweXBXbVhuTThmYWgKU01vUVBrNnk4VExvNDNBcTFlU25wYUhhTGhCdUZpTmZMcTF2K1E4NWZOeEp5SSt6QTBPWHRYRW5IS1VFQkxVeApKTzRzQk9nRVZuU3VMS094RmNhM1JaRFBsc0pIbHUxQk5peGpLNG9kSVBDVEdONllIWEs3enZQUmdmalQ1a29VCklBQWVrZnRmQWZkUURtN2tDT0c4SG02WTc1VFQxUkhLbjBDc2QzaGhZdVQvNGF5VDRhKytRbDJtZzc5Vm1ISG0KQlF4L0tSSG8zazh0ZkRRWHdTVGh0RStvV3ZxOUV1VHNNWkhOQWxDSGhtbHI3TEFZcm4vZFIrd2pGL0pjR3l5dQpwc2JtdXVPYkJVUWNOLzBEdTR3VUxVbEJWOG5nSTNHNUVNRnFGSjlrUXViWHV0MDcvWjhCZVZPRmNqNnBoR25vCkpwQW1JbjFNcTVqbjU1Z3ZvYU04ek9FRU5xZGRYME9GZ0xLTkUrTzNNMGRPM1FjMTlKSk1ubHVTR0tMdWVmT1kKa0J4dE9Wa1gyT2l1Z1BLTWo0OEo4NXh5UTlIcXBlY0ZLRGNWMEFKakRoYlBYL0Jxd3NtTHRpYjFNY0RoNW1rTQpkcm9IMFZtYmZBakRQUEtQL3VTbUhzR0FKWFRwTVh2SjdFUGM0Ymx4dFdqUkZOOEpBUUtDQVFFQTZUVHVjM0tkCmJlbEZlVzIvcCtiY1VMNEpnS2RycHU3M29jNkg4SzJndSs3R3JOOUJINUVDbGE0WHZESnZhYUNML0FueHlNRnIKc3Rrc1c3emtRbWF3aUcrcHFaZUhCc3RqZTNYc3pTR09oa3pzUmYyMUk5YmMvMXlGRmVVZ0ZZS3lWMEs4WjI1aApuSDBBNTNDdDFEcnlxYjJ1WWFoUVh0VWZHaXZ0TnkrVEtsU2NUOVJkRWx3SjcwemdwdFBhSWM4MHd1OG9pK3AvCjZrV3FaOHlEK0Y4eHFpcEQ3K0c5aXI5T201Wkl3QjJRWjE1T3BhV09Ha3RTWEcvbUlvL0tXUkF5WGF5ZjFXTGcKcGJmVldIMWFVOFJxQ2dBdGljZnJWVmJpL0Y0dkN6RGJrVjl5YkZpTERRNjFUSFhKeURMcWdCY0xUaWRKU1FRTAo4N1lLWHpQSy9KM01xUUtDQVFFQTNCNC9HRlJzU3lySGdmMTFFWTFHRTdueS9HSSttK05iL2poeW5VeEJ6MllYCi9ZUGFhb1puamsyeFZiYzQ1eFZSSmp1RXo0MlhDL3hna08rdlRzZVhvalVjUzVOY0pBVmFCN2paOEpVdVhPYTkKNDJQNzlzNzdOWTJJcXlobTNGZzBaUURnWnlPTGY5TE5oVG1nQjlydUJlcFVFNnI1ZjVWOWxCSGlqMTlSZXlacwpMOFgzUDI3TUtaUzcyTmpGaTR0V0xGNjhaRUp0UWtENlRzZ0tmdVRBRTNvTVhpOTFDMWFnUUVqS2txbWh5Y1paCmt3K1ZEbmNSMzl6RmtrWk9QMlI4SUwyQlNpZ1BTcCtEK3VwRGZxalRkc210c2lCTC85Y3psVmVKVndEb3FGQWgKR2U3RmEzaXR0SnZXZGd6VTh1dmQzYitxdEZuYUM0RjdiNDMweHJjOTlRS0NBUUJjbTNscGZRVkpSVTRpZDFPWgpjRkxpK1dRNm84RmJMQ0JJTUFUSnJabGJwK2xiY3RpZ21Xd21WbGowa2k2dUNtUXNkU0ovcjFkK1VVR05PSWlJCldkRVdqUWtaNEtOdExrMVdGTEV4a0hiUm5EQmpadW1NenVFNXd0clNwQWRHbzMwQXErNjNRQjBoRUg3UWFXMk8KRHM2WVcwdXBXalo0UWplMG8rYnllRUQvbVZQdFc0Nk9JT0NORjhGS1hteUw2b1d3TjFxcG5UaW9wbnVSOXFRZAplR2YzaEFzd2NqdGJvcmFya0ZWWmZTUC8rSEpRMDFxSDFJdGpTOGhleHl6Nml6VUUvKzBFeHR3ZzBzeTA5Q3B2CmcxcjhsNjk5dkZjV3I0YzU0b2paNzgveGZhNnBtY3UySnJZV0k5dzZWUVhNVWRwYWNiMW5jbVR3cGNTZW82bWoKQVdMcEFvSUJBQll5a3FoUWN5OU5YQnMyeFNTRSs2a25tbUpyUWVjVWtZVmNpZXBrODBvSUFLbFhMNktJZFU3NwpkTU94RzNMcVNtbXhuTjRWYUVNVUsyVFNWdnA1MUVmT1ZWRWx4aWYzeGpGN0tiZENSQStvVVVQcUpGR3FZOWp0CnNmZVl0bTdJRWxpUk14QVRuSkRDWUdsciswQnZpb3RjS3loa21JNk9NOERINFBJV2FiQWltc3hpaVdHRE9lR0QKbDBIeDhsSDFOalo1UTBSVkVwR1kzZVV0OVNrQXhvSHdUK2o3bmpFTGhsT1ZRNkJ3ck5rZFFKRTlCQW9XWmQ0TwpkSG9nenVsRHArVGhWM1Z6L3I3R3dWZC9ZbGtXaTJTeVIrcnJxTjVmQkZ1dUhUS0I2L1IxU0RGR1MvQmZsaHpkCmprNFBVelpBSlBxa3hvRXpnbktnbHlNVHpMaHhhRFVDZ2dFQWRNbW9nZUlURkRGcjZKTXNreThNWDJlK2g4NDEKYlBQQXhkcG5saEZCaHNYeTZZQW1LSzJ4Vk9lN3c1ZFNOV1N4VGt2Wk9oTWlOSGpEcWsxU1BFeXg1QlV6MGZvQwpQRHI4YUtvQlFsT0JWTUNoRDhISmNEVTJrTHlXY3pnVmJLaFBQdW1zREh3L0J5djBpN2xqR1RGNGRYUUFIM1hVCnpXTUdwQlVBc29VeGpiYUZXM0pLS080dk9Ha243QjZZVUZhRk00TDNReX
</cert>
<syslog>
<nologdefaultpass>1</nologdefaultpass>
<nologbogons>1</nologbogons>
<nologprivatenets>1</nologprivatenets>
</syslog>
<hasync version="1.0.0">
<disablepreempt>0</disablepreempt>
<disconnectppps>0</disconnectppps>
<pfsyncenabled>0</pfsyncenabled>
<pfsyncinterface>lan</pfsyncinterface>
<pfsyncpeerip/>
<pfsyncversion>1400</pfsyncversion>
<synchronizetoip/>
<username/>
<password/>
<syncitems/>
</hasync>
</opnsense>