diff --git a/config.xml b/config.xml index f144fd1..c02c4bb 100644 --- a/config.xml +++ b/config.xml @@ -1,205 +1,205 @@ opnsense - - - Increase UFS read-ahead speeds to match the state of hard drives and NCQ. + + vfs.read_max - default + + Increase UFS read-ahead speeds to match the state of hard drives and NCQ. - - Set the ephemeral port range to be lower. + net.inet.ip.portrange.first - default + + Set the ephemeral port range to be lower. - - Drop packets to closed TCP ports without returning a RST + net.inet.tcp.blackhole - default + + Drop packets to closed TCP ports without returning a RST - - Do not send ICMP port unreachable messages for closed UDP ports + net.inet.udp.blackhole - default + + Do not send ICMP port unreachable messages for closed UDP ports - - Randomize the ID field in IP packets + net.inet.ip.random_id - default + + Randomize the ID field in IP packets - - - Source routing is another way for an attacker to try to reach non-routable addresses behind your box. - It can also be used to probe for information about your internal networks. These functions come enabled - as part of the standard FreeBSD core system. - + net.inet.ip.sourceroute - default - - + Source routing is another way for an attacker to try to reach non-routable addresses behind your box. It can also be used to probe for information about your internal networks. These functions come enabled as part of the standard FreeBSD core system. - net.inet.ip.accept_sourceroute - default - + + net.inet.ip.accept_sourceroute + + + Source routing is another way for an attacker to try to reach non-routable addresses behind your box. + It can also be used to probe for information about your internal networks. These functions come enabled + as part of the standard FreeBSD core system. + + + + net.inet.icmp.log_redirect + This option turns off the logging of redirect packets because there is no limit and this could fill up your logs consuming your whole hard drive. - net.inet.icmp.log_redirect - default - - Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway) + net.inet.tcp.drop_synfin - default + + Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway) - - Enable sending IPv6 redirects + net.inet6.ip6.redirect - default + + Enable sending IPv6 redirects - - Enable privacy settings for IPv6 (RFC 4941) + net.inet6.ip6.use_tempaddr - default + + Enable privacy settings for IPv6 (RFC 4941) - - Prefer privacy addresses and use them over the normal addresses + net.inet6.ip6.prefer_tempaddr - default + + Prefer privacy addresses and use them over the normal addresses - - Generate SYN cookies for outbound SYN-ACK packets + net.inet.tcp.syncookies - default + + Generate SYN cookies for outbound SYN-ACK packets - - Maximum incoming/outgoing TCP datagram size (receive) + net.inet.tcp.recvspace - default + + Maximum incoming/outgoing TCP datagram size (receive) - - Maximum incoming/outgoing TCP datagram size (send) + net.inet.tcp.sendspace - default + + Maximum incoming/outgoing TCP datagram size (send) - - Do not delay ACK to try and piggyback it onto a data packet + net.inet.tcp.delayed_ack - default + + Do not delay ACK to try and piggyback it onto a data packet - - Maximum outgoing UDP datagram size + net.inet.udp.maxdgram - default + + Maximum outgoing UDP datagram size - - Handling of non-IP packets which are not passed to pfil (see if_bridge(4)) + net.link.bridge.pfil_onlyip - default + + Handling of non-IP packets which are not passed to pfil (see if_bridge(4)) - - Set to 1 to additionally filter on the physical interface for locally destined packets + net.link.bridge.pfil_local_phys - default + + Set to 1 to additionally filter on the physical interface for locally destined packets - + net.link.bridge.pfil_member 0 Set to 0 to disable filtering on the incoming and outgoing member interfaces. - + net.link.bridge.pfil_bridge 1 Set to 1 to enable filtering on the bridge interface - - Allow unprivileged access to tap(4) device nodes + net.link.tap.user_open - default + + Allow unprivileged access to tap(4) device nodes - - Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid()) + kern.randompid - default + + Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid()) - - Disable CTRL+ALT+Delete reboot from keyboard. + hw.syscons.kbd_reboot - default + + Disable CTRL+ALT+Delete reboot from keyboard. - - Enable TCP extended debugging + net.inet.tcp.log_debug - default + + Enable TCP extended debugging - - Set ICMP Limits + net.inet.icmp.icmplim - default + + Set ICMP Limits - - TCP Offload Engine + net.inet.tcp.tso - default + + TCP Offload Engine - - UDP Checksums + net.inet.udp.checksum - default + + UDP Checksums - - Maximum socket buffer size + kern.ipc.maxsockbuf - default + + Maximum socket buffer size - - Page Table Isolation (Meltdown mitigation, requires reboot.) + vm.pmap.pti - default + + Page Table Isolation (Meltdown mitigation, requires reboot.) - - Disable Indirect Branch Restricted Speculation (Spectre V2 mitigation) + hw.ibrs_disable - default + + Disable Indirect Branch Restricted Speculation (Spectre V2 mitigation) - - Hide processes running as other groups + security.bsd.see_other_gids - default + + Hide processes running as other groups - - Hide processes running as other users + security.bsd.see_other_uids - default + + Hide processes running as other users - + + net.inet.ip.redirect + Enable/disable sending of ICMP redirects in response to IP packets for which a better, and for the sender directly reachable, route and next hop is known. - net.inet.ip.redirect - default - + + net.inet.icmp.drop_redirect + 1 Redirect attacks are the purposeful mass-issuing of ICMP type 5 packets. In a normal network, redirects to the end stations should not be required. This option enables the NIC to drop all inbound ICMP redirect packets without returning a response. - net.inet.icmp.drop_redirect - 1 - - Maximum outgoing UDP datagram size + net.local.dgram.maxdgram - default + + Maximum outgoing UDP datagram size - + net.inet.tcp.mss_ifmtu 1 Enable TCP MSS auto-adjust based on interface MTU @@ -210,21 +210,31 @@ gate waw.eldorado.city 1 - - admins - System Administrators - system + 1999 - 0 - page-all - - - root - System Administrator + admins system - admins - $2y$11$bze9aco9zESP42qWhxo7yORRiK1mRvoa5aa7lzXetRg4NDULMOyOu + System Administrators + page-all + 0 + + 0 + root + 0 + system + + + + + $2y$11$bze9aco9zESP42qWhxo7yORRiK1mRvoa5aa7lzXetRg4NDULMOyOu + + + + + + + System Administrator 2000 @@ -286,44 +296,44 @@ 1 ssh://projects-gate.radziel.com:40294/radziel/gate-config.git master - -----BEGIN OPENSSH PRIVATE KEY----- -b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn -NhAAAAAwEAAQAAAYEA0HPzKFtIswRQ5v5riYE/Z0WiKhpLVnXVwxkhTTV3JQ59pmW5fs3b -dWqf2qyNnmCu6ITv1deKBTolihh8OLaGvis+DA8U1yPUxjFB/OPv16gIEF1erryOJfx2Q1 -ikGkWja+Bs/MSI7RY/uKkJyc/w1+plAJQMxy3Q37CSE1m3luGLLvz7tbIkE6ZpJdkXo8mL -CF65YyofP9Q67WQ5AWZ5L7pryYUBgpPs4CPzkNESKcsx8S19LyubDpd8tw8IgJB+w0vkre -/ikzhIA49kxeyNOcWk+j6nFLSBFT9k36T4BkKbBBJj6KBBzI8j+qhs6WYl4BbVb/ETufmw -YzPj5+FZi9six59lPGdqVz8ZsHLbq553HlIlFWWkWpa/qK0ON/K2DmKgqeb9L7AvVQle7C -hmkEenIz5Edkl+URW/fGEGaM4/9si3KpwQSegk05aS0DiMQeJNIw7S5aKerymKFOUwAbav -LgF5eHeAu6aSXtaIDmLVIYx5YlCfVnz9WrOoKdsvAAAFiAucWlULnFpVAAAAB3NzaC1yc2 -EAAAGBANBz8yhbSLMEUOb+a4mBP2dFoioaS1Z11cMZIU01dyUOfaZluX7N23Vqn9qsjZ5g -ruiE79XXigU6JYoYfDi2hr4rPgwPFNcj1MYxQfzj79eoCBBdXq68jiX8dkNYpBpFo2vgbP -zEiO0WP7ipCcnP8NfqZQCUDMct0N+wkhNZt5bhiy78+7WyJBOmaSXZF6PJiwheuWMqHz/U -Ou1kOQFmeS+6a8mFAYKT7OAj85DREinLMfEtfS8rmw6XfLcPCICQfsNL5K3v4pM4SAOPZM -XsjTnFpPo+pxS0gRU/ZN+k+AZCmwQSY+igQcyPI/qobOlmJeAW1W/xE7n5sGMz4+fhWYvb -IsefZTxnalc/GbBy26uedx5SJRVlpFqWv6itDjfytg5ioKnm/S+wL1UJXuwoZpBHpyM+RH -ZJflEVv3xhBmjOP/bItyqcEEnoJNOWktA4jEHiTSMO0uWinq8pihTlMAG2ry4BeXh3gLum -kl7WiA5i1SGMeWJQn1Z8/VqzqCnbLwAAAAMBAAEAAAGAA0j92TIjFwB86T8I4ShidZVb2m -UCsJtNIfTTQ7Jm18nULMX9TTnKTnM+j1rZJS3/OQE1/xKVWsK7/7f7ZoYTNouw6ni8X9hG -jKm5vAC4RsJKVOkGdSOElqWqvsyhUsar2NHhyylVF8Nvf/tYq6UKyyRRsNd5zL50mb81y3 -dGVOrmCiNeMNKyDds5XKmAsrSaQSiuVu6S19XXkzvZSCPeH2Sajpj5g/N32rUbrA8XcFrY -RSWYi6CYzNCSBxfbZEdNU3rntvXF37mZZF9CDo/If23D1CLA2PjGqKt9FR+lJu0y6+nKqU -9MxoWhZuWpxz6icSL0E5oweWdb/oRYjDTwOm5AF/jEofAVh4mivuOPDFVpFyDDNuTJ5jzS -KOGkqOj5SE00RkoCmdUmnt7fxB4T+ZAQ+ZcPzXSBtVdzQolrGLijsSCAVKXR6tgXyKDeRU -Ck6RVKlxnu5RrLBp2uzhVU8h5FqaEoWha7lFTeH/TGPvayMaGSfU4FL7RoNfmZrNHZAAAA -wQCHDwFjTLSTq6oFNmJtojw83Lz3ObsVFvom27saZlb6iCUq7O972uEnG1iQUpQpGmI99L -UlZ3K25v7ePbtjOpuKSv+cR7kOXa3EnvOyz0TwofnUYRRD3nk8dEJ9e1A0dbi76RUxVdmx -ygc157MaxI1wClw+CKwsluFvUSigfv9IcyWRtH1bS0GHRVh8vfq0jmLV6g/zQGFGgFomB1 -sBiZmwdQzk+lkBYgOuqxdJWSVqmrvlIqcwUxSIuOohzNW+LqEAAADBANNcXSwb2TP+ljbu -CqdgIvDeB6WEoIqQ/dTYAPZWiKh+T31mzBRqWC+vTHyh/MuhnRy4YCpq7Y9eT970xu+PWA -Z3wCpXnXAwt/AU8yqMxA+KAtmX3f9DRBHEWysuDs4LRGBfC8Y5xyPNX1j1nt4WZTxq8jQ7 -A9KlK61sjcwTnxC0745S1QjGiOq1PookR/fw1gl+zgASMy+wOIkQi/ioSklEJNfYDFPGtG -uljSlpIeI5J37mA0X7Jc3oRJrflvPF+QAAAMEA/Hpdxpztsc+0XiEZ4psGOFDEpEUfGtFw -I2imT340O8OWzpR7bHLdjZJSN+fIlaFqX8u2XOGMwhd/nNMSF6MSp+3PXuUQc+vPNRjQA1 -2JMspHmjwyRMXZ2qzd7wY8yaDWnX5BHRwoFMm1FhqdevYuMm6QavnRrPFTdji45oo4gUSg -+tD7qpNAPHRNrE5A5oMTXCeYUj1w0Gvmz8o7ww5qgRQzXIbf91orhFDiTci6OKcj018r0u -xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== ------END OPENSSH PRIVATE KEY----- + -----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn +NhAAAAAwEAAQAAAYEA0HPzKFtIswRQ5v5riYE/Z0WiKhpLVnXVwxkhTTV3JQ59pmW5fs3b +dWqf2qyNnmCu6ITv1deKBTolihh8OLaGvis+DA8U1yPUxjFB/OPv16gIEF1erryOJfx2Q1 +ikGkWja+Bs/MSI7RY/uKkJyc/w1+plAJQMxy3Q37CSE1m3luGLLvz7tbIkE6ZpJdkXo8mL +CF65YyofP9Q67WQ5AWZ5L7pryYUBgpPs4CPzkNESKcsx8S19LyubDpd8tw8IgJB+w0vkre +/ikzhIA49kxeyNOcWk+j6nFLSBFT9k36T4BkKbBBJj6KBBzI8j+qhs6WYl4BbVb/ETufmw +YzPj5+FZi9six59lPGdqVz8ZsHLbq553HlIlFWWkWpa/qK0ON/K2DmKgqeb9L7AvVQle7C +hmkEenIz5Edkl+URW/fGEGaM4/9si3KpwQSegk05aS0DiMQeJNIw7S5aKerymKFOUwAbav +LgF5eHeAu6aSXtaIDmLVIYx5YlCfVnz9WrOoKdsvAAAFiAucWlULnFpVAAAAB3NzaC1yc2 +EAAAGBANBz8yhbSLMEUOb+a4mBP2dFoioaS1Z11cMZIU01dyUOfaZluX7N23Vqn9qsjZ5g +ruiE79XXigU6JYoYfDi2hr4rPgwPFNcj1MYxQfzj79eoCBBdXq68jiX8dkNYpBpFo2vgbP +zEiO0WP7ipCcnP8NfqZQCUDMct0N+wkhNZt5bhiy78+7WyJBOmaSXZF6PJiwheuWMqHz/U +Ou1kOQFmeS+6a8mFAYKT7OAj85DREinLMfEtfS8rmw6XfLcPCICQfsNL5K3v4pM4SAOPZM +XsjTnFpPo+pxS0gRU/ZN+k+AZCmwQSY+igQcyPI/qobOlmJeAW1W/xE7n5sGMz4+fhWYvb +IsefZTxnalc/GbBy26uedx5SJRVlpFqWv6itDjfytg5ioKnm/S+wL1UJXuwoZpBHpyM+RH +ZJflEVv3xhBmjOP/bItyqcEEnoJNOWktA4jEHiTSMO0uWinq8pihTlMAG2ry4BeXh3gLum +kl7WiA5i1SGMeWJQn1Z8/VqzqCnbLwAAAAMBAAEAAAGAA0j92TIjFwB86T8I4ShidZVb2m +UCsJtNIfTTQ7Jm18nULMX9TTnKTnM+j1rZJS3/OQE1/xKVWsK7/7f7ZoYTNouw6ni8X9hG +jKm5vAC4RsJKVOkGdSOElqWqvsyhUsar2NHhyylVF8Nvf/tYq6UKyyRRsNd5zL50mb81y3 +dGVOrmCiNeMNKyDds5XKmAsrSaQSiuVu6S19XXkzvZSCPeH2Sajpj5g/N32rUbrA8XcFrY +RSWYi6CYzNCSBxfbZEdNU3rntvXF37mZZF9CDo/If23D1CLA2PjGqKt9FR+lJu0y6+nKqU +9MxoWhZuWpxz6icSL0E5oweWdb/oRYjDTwOm5AF/jEofAVh4mivuOPDFVpFyDDNuTJ5jzS +KOGkqOj5SE00RkoCmdUmnt7fxB4T+ZAQ+ZcPzXSBtVdzQolrGLijsSCAVKXR6tgXyKDeRU +Ck6RVKlxnu5RrLBp2uzhVU8h5FqaEoWha7lFTeH/TGPvayMaGSfU4FL7RoNfmZrNHZAAAA +wQCHDwFjTLSTq6oFNmJtojw83Lz3ObsVFvom27saZlb6iCUq7O972uEnG1iQUpQpGmI99L +UlZ3K25v7ePbtjOpuKSv+cR7kOXa3EnvOyz0TwofnUYRRD3nk8dEJ9e1A0dbi76RUxVdmx +ygc157MaxI1wClw+CKwsluFvUSigfv9IcyWRtH1bS0GHRVh8vfq0jmLV6g/zQGFGgFomB1 +sBiZmwdQzk+lkBYgOuqxdJWSVqmrvlIqcwUxSIuOohzNW+LqEAAADBANNcXSwb2TP+ljbu +CqdgIvDeB6WEoIqQ/dTYAPZWiKh+T31mzBRqWC+vTHyh/MuhnRy4YCpq7Y9eT970xu+PWA +Z3wCpXnXAwt/AU8yqMxA+KAtmX3f9DRBHEWysuDs4LRGBfC8Y5xyPNX1j1nt4WZTxq8jQ7 +A9KlK61sjcwTnxC0745S1QjGiOq1PookR/fw1gl+zgASMy+wOIkQi/ioSklEJNfYDFPGtG +uljSlpIeI5J37mA0X7Jc3oRJrflvPF+QAAAMEA/Hpdxpztsc+0XiEZ4psGOFDEpEUfGtFw +I2imT340O8OWzpR7bHLdjZJSN+fIlaFqX8u2XOGMwhd/nNMSF6MSp+3PXuUQc+vPNRjQA1 +2JMspHmjwyRMXZ2qzd7wY8yaDWnX5BHRwoFMm1FhqdevYuMm6QavnRrPFTdji45oo4gUSg ++tD7qpNAPHRNrE5A5oMTXCeYUj1w0Gvmz8o7ww5qgRQzXIbf91orhFDiTci6OKcj018r0u +xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== +-----END OPENSSH PRIVATE KEY----- git @@ -1291,8 +1301,8 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== (system) - /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php made changes - + /usr/local/opnsense/mvc/script/run_migrations.php made changes + @@ -1335,12 +1345,14 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== - + 0 0 + + @@ -1349,6 +1361,8 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== 4 1000 1 + 0 + 0 @@ -1379,6 +1393,29 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== 1 + + + + + + + + 0 + + + + + + + 0 + 0 + + + ipsec + 0 + 1 + + @@ -1400,7 +1437,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== - + @@ -1580,7 +1617,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== 8000 - + 0 @@ -1597,6 +1634,24 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== + + + 0 + 0 + + 4000 + 1 + + + 0 + + 2 + + + + + + @@ -1918,7 +1973,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== - + 1 53 @@ -2005,6 +2060,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== 0 + 0 @@ -2016,6 +2072,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== A + 192.168.2.253 @@ -2026,6 +2083,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== A + 192.168.2.20 @@ -2036,6 +2094,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== A + 172.27.72.254 @@ -2046,6 +2105,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== A + 172.27.72.1 @@ -2056,6 +2116,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== A + 172.27.72.5 @@ -2563,7 +2624,7 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== - + vtnet5 @@ -2626,21 +2687,27 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== 0 - - - LAN_BRIDGE - - + + bridge0 + opt12,opt1,opt2,opt3,opt4,opt5 + 0 + 0 + rstp + - - - rstp - opt12,opt1,opt2,opt3,opt4,opt5 - - + + + + + + + + + + LAN_BRIDGE @@ -2705,13 +2772,14 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== 1 1 - + 0 0 1400 + 0 @@ -2732,4 +2800,39 @@ xNByHw9ei5+9RnAAAADnJhZHppZWxAaGVybWVzAQIDBA== + + 0 + 0 + 0 + 0 + 0 + 0 + 0 + 0 + 0 + 0 + 0 + 0 + + + + + + + + 0 + 0 + + + 1 + + + 0 + 1 + + 0 + 0 + + 1 +