<?xml version="1.0"?>
<pfsense>
	<version>24.0</version>
	<lastchange></lastchange>
	<system>
		<optimization>normal</optimization>
		<hostname>pfsense</hostname>
		<domain>Lab4PurpleSec</domain>
		<group>
			<name>all</name>
			<description><![CDATA[All Users]]></description>
			<scope>system</scope>
			<gid>1998</gid>
		</group>
		<group>
			<name>admins</name>
			<description><![CDATA[System Administrators]]></description>
			<scope>system</scope>
			<gid>1999</gid>
			<member>0</member>
			<priv>page-all</priv>
		</group>
		<user>
			<name>admin</name>
			<descr><![CDATA[System Administrator]]></descr>
			<scope>system</scope>
			<groupname>admins</groupname>
			<uid>0</uid>
			<priv>user-shell-access</priv>
			<expires></expires>
			<dashboardcolumns>2</dashboardcolumns>
			<authorizedkeys></authorizedkeys>
			<ipsecpsk></ipsecpsk>
			<webguicss>pfSense.css</webguicss>
			<bcrypt-hash>$2y$10$y5p2VjbUMLmNN8TC1hXbpOayKXBA1W9cZGcQ.KO0yiBaAIO9LUqNa</bcrypt-hash>
		</user>
		<nextuid>2000</nextuid>
		<nextgid>2000</nextgid>
		<timeservers>2.pfsense.pool.ntp.org</timeservers>
		<webgui>
			<protocol>http</protocol>
			<loginautocomplete></loginautocomplete>
			<ssl-certref>68a6f06f6d985</ssl-certref>
			<althostnames></althostnames>
			<dashboardcolumns>2</dashboardcolumns>
			<webguicss>pfSense.css</webguicss>
			<logincss>1e3f75;</logincss>
		</webgui>
		<disablenatreflection>yes</disablenatreflection>
		<disablesegmentationoffloading></disablesegmentationoffloading>
		<disablelargereceiveoffloading></disablelargereceiveoffloading>
		<ipv6allow></ipv6allow>
		<maximumtableentries>400000</maximumtableentries>
		<powerd_ac_mode>hadp</powerd_ac_mode>
		<powerd_battery_mode>hadp</powerd_battery_mode>
		<powerd_normal_mode>hadp</powerd_normal_mode>
		<bogons>
			<interval>monthly</interval>
		</bogons>
		<hn_altq_enable></hn_altq_enable>
		<already_run_config_upgrade></already_run_config_upgrade>
		<ssh>
			<enable>enabled</enable>
		</ssh>
		<timezone>Etc/UTC</timezone>
		<language>en_US</language>
		<gitsync>
			<repositoryurl></repositoryurl>
			<branch></branch>
		</gitsync>
		<disablechecksumoffloading></disablechecksumoffloading>
		<pkg_repo_conf_path>/usr/local/etc/pfSense/pkg/repos/pfSense-repo-2.7.2.conf</pkg_repo_conf_path>
		<dnsserver>8.8.8.8</dnsserver>
		<dnsserver>1.1.1.1</dnsserver>
		<dnsserver>8.8.4.4</dnsserver>
		<dnsallowoverride></dnsallowoverride>
	</system>
	<interfaces>
		<wan>
			<enable></enable>
			<if>em0</if>
			<descr><![CDATA[WAN]]></descr>
			<alias-address></alias-address>
			<alias-subnet>32</alias-subnet>
			<spoofmac></spoofmac>
			<ipaddr>dhcp</ipaddr>
			<dhcphostname></dhcphostname>
			<dhcprejectfrom></dhcprejectfrom>
			<adv_dhcp_pt_timeout></adv_dhcp_pt_timeout>
			<adv_dhcp_pt_retry></adv_dhcp_pt_retry>
			<adv_dhcp_pt_select_timeout></adv_dhcp_pt_select_timeout>
			<adv_dhcp_pt_reboot></adv_dhcp_pt_reboot>
			<adv_dhcp_pt_backoff_cutoff></adv_dhcp_pt_backoff_cutoff>
			<adv_dhcp_pt_initial_interval></adv_dhcp_pt_initial_interval>
			<adv_dhcp_pt_values>SavedCfg</adv_dhcp_pt_values>
			<adv_dhcp_send_options></adv_dhcp_send_options>
			<adv_dhcp_request_options></adv_dhcp_request_options>
			<adv_dhcp_required_options></adv_dhcp_required_options>
			<adv_dhcp_option_modifiers></adv_dhcp_option_modifiers>
			<adv_dhcp_config_advanced></adv_dhcp_config_advanced>
			<adv_dhcp_config_file_override></adv_dhcp_config_file_override>
			<adv_dhcp_config_file_override_path></adv_dhcp_config_file_override_path>
			<subnet></subnet>
			<gateway></gateway>
			<ipaddrv6></ipaddrv6>
			<subnetv6></subnetv6>
			<gatewayv6></gatewayv6>
		</wan>
		<lan>
			<enable></enable>
			<if>em1</if>
			<descr><![CDATA[LAN]]></descr>
			<ipaddr>192.168.10.1</ipaddr>
			<subnet>24</subnet>
			<spoofmac></spoofmac>
			<gateway></gateway>
			<ipaddrv6></ipaddrv6>
			<subnetv6></subnetv6>
			<gatewayv6></gatewayv6>
		</lan>
		<opt1>
			<if>em2</if>
			<descr><![CDATA[DMZ]]></descr>
			<enable></enable>
			<alias-address></alias-address>
			<alias-subnet>32</alias-subnet>
			<spoofmac></spoofmac>
			<ipaddr>192.168.20.1</ipaddr>
			<subnet>24</subnet>
		</opt1>
	</interfaces>
	<staticroutes></staticroutes>
	<dhcpd>
		<lan>
			<range>
				<from>192.168.10.100</from>
				<to>192.168.10.200</to>
			</range>
			<failover_peerip></failover_peerip>
			<defaultleasetime></defaultleasetime>
			<maxleasetime></maxleasetime>
			<netmask></netmask>
			<gateway></gateway>
			<domain></domain>
			<domainsearchlist></domainsearchlist>
			<ddnsdomain></ddnsdomain>
			<ddnsdomainprimary></ddnsdomainprimary>
			<ddnsdomainsecondary></ddnsdomainsecondary>
			<ddnsdomainkeyname></ddnsdomainkeyname>
			<ddnsdomainkeyalgorithm>hmac-md5</ddnsdomainkeyalgorithm>
			<ddnsdomainkey></ddnsdomainkey>
			<mac_allow></mac_allow>
			<mac_deny></mac_deny>
			<ddnsclientupdates>allow</ddnsclientupdates>
			<tftp></tftp>
			<ldap></ldap>
			<nextserver></nextserver>
			<filename></filename>
			<filename32></filename32>
			<filename64></filename64>
			<filename32arm></filename32arm>
			<filename64arm></filename64arm>
			<uefihttpboot></uefihttpboot>
			<rootpath></rootpath>
			<numberoptions></numberoptions>
			<dnsregpolicy></dnsregpolicy>
			<earlydnsregpolicy></earlydnsregpolicy>
			<ddnsdomainprimaryport></ddnsdomainprimaryport>
			<ddnsdomainsecondaryport></ddnsdomainsecondaryport>
		</lan>
		<opt1>
			<range>
				<from>192.168.20.100</from>
				<to>192.168.20.200</to>
			</range>
			<failover_peerip></failover_peerip>
			<defaultleasetime></defaultleasetime>
			<maxleasetime></maxleasetime>
			<netmask></netmask>
			<gateway></gateway>
			<domain></domain>
			<domainsearchlist></domainsearchlist>
			<ddnsdomain></ddnsdomain>
			<ddnsdomainprimary></ddnsdomainprimary>
			<ddnsdomainsecondary></ddnsdomainsecondary>
			<ddnsdomainkeyname></ddnsdomainkeyname>
			<ddnsdomainkeyalgorithm>hmac-md5</ddnsdomainkeyalgorithm>
			<ddnsdomainkey></ddnsdomainkey>
			<mac_allow></mac_allow>
			<mac_deny></mac_deny>
			<ddnsclientupdates>allow</ddnsclientupdates>
			<tftp></tftp>
			<ldap></ldap>
			<nextserver></nextserver>
			<filename></filename>
			<filename32></filename32>
			<filename64></filename64>
			<filename32arm></filename32arm>
			<filename64arm></filename64arm>
			<uefihttpboot></uefihttpboot>
			<rootpath></rootpath>
			<numberoptions></numberoptions>
			<dnsregpolicy></dnsregpolicy>
			<earlydnsregpolicy></earlydnsregpolicy>
			<ddnsdomainprimaryport></ddnsdomainprimaryport>
			<ddnsdomainsecondaryport></ddnsdomainsecondaryport>
		</opt1>
	</dhcpd>
	<dhcpdv6>
		<lan>
			<range>
				<from>::1000</from>
				<to>::2000</to>
			</range>
			<ramode>disabled</ramode>
			<rapriority>medium</rapriority>
		</lan>
	</dhcpdv6>
	<snmpd>
		<syslocation></syslocation>
		<syscontact></syscontact>
		<rocommunity>public</rocommunity>
	</snmpd>
	<diag>
		<ipv6nat></ipv6nat>
	</diag>
	<syslog>
		<filterdescriptions>1</filterdescriptions>
		<nentries>500</nentries>
		<logcompressiontype>none</logcompressiontype>
		<format>rfc5424</format>
		<rotatecount></rotatecount>
		<remoteserver>192.168.10.110:514</remoteserver>
		<remoteserver2></remoteserver2>
		<remoteserver3></remoteserver3>
		<sourceip></sourceip>
		<ipproto>ipv4</ipproto>
		<logconfigchanges>enabled</logconfigchanges>
		<filter></filter>
		<system></system>
	</syslog>
	<nat>
		<outbound>
			<mode>automatic</mode>
		</outbound>
		<separator></separator>
		<rule>
			<source>
				<any></any>
			</source>
			<destination>
				<network>wanip</network>
				<port>80</port>
			</destination>
			<ipprotocol>inet</ipprotocol>
			<protocol>tcp</protocol>
			<target>192.168.20.105</target>
			<local-port>80</local-port>
			<interface>wan</interface>
			<descr><![CDATA[Reverse proxy Nginx]]></descr>
			<associated-rule-id></associated-rule-id>
			<created>
				<time>1756053585</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1761499766</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
	</nat>
	<filter>
		<rule>
			<id></id>
			<tracker>1756799588</tracker>
			<type>pass</type>
			<interface>wan</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<protocol>tcp</protocol>
			<source>
				<network>wan</network>
			</source>
			<destination>
				<network>opt1</network>
				<port>80</port>
			</destination>
			<descr><![CDATA[Allow HTTP access to the DMZ from the WAN]]></descr>
			<created>
				<time>1756799588</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1761322135</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<rule>
			<id></id>
			<tracker>1761322152</tracker>
			<type>pass</type>
			<interface>wan</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<protocol>tcp</protocol>
			<source>
				<network>wan</network>
			</source>
			<destination>
				<network>opt1</network>
				<port>443</port>
			</destination>
			<descr><![CDATA[Allow HTTPS access to the DMZ from the WAN]]></descr>
			<updated>
				<time>1761322152</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
			<created>
				<time>1761322152</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
		</rule>
		<rule>
			<id></id>
			<tracker>1755861407</tracker>
			<type>block</type>
			<interface>wan</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<source>
				<network>wan</network>
			</source>
			<destination>
				<network>lan</network>
			</destination>
			<descr><![CDATA[General rule : Block WAN -&gt; LAN]]></descr>
			<created>
				<time>1755861407</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1761288280</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<rule>
			<id></id>
			<tracker>0100000101</tracker>
			<type>pass</type>
			<interface>lan</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statepolicy></statepolicy>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<source>
				<network>lan</network>
			</source>
			<destination>
				<network>opt1</network>
			</destination>
			<descr><![CDATA[Default allow LAN -&gt; DMZ]]></descr>
			<updated>
				<time>1756799738</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<rule>
			<id></id>
			<tracker>1756801419</tracker>
			<type>pass</type>
			<interface>lan</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statepolicy></statepolicy>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<source>
				<network>lan</network>
			</source>
			<destination>
				<network>wan</network>
			</destination>
			<descr><![CDATA[Default allow LAN -&gt; WAN]]></descr>
			<updated>
				<time>1756801419</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
			<created>
				<time>1756801419</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
		</rule>
		<rule>
			<id></id>
			<tracker>1756799659</tracker>
			<type>pass</type>
			<interface>lan</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statepolicy></statepolicy>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<source>
				<network>lan</network>
			</source>
			<destination>
				<any></any>
			</destination>
			<descr><![CDATA[Default allow LAN to any rule]]></descr>
			<created>
				<time>1756799659</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1756799705</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<rule>
			<id></id>
			<tracker>1756801551</tracker>
			<type>pass</type>
			<interface>opt1</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<protocol>tcp</protocol>
			<source>
				<network>opt1</network>
			</source>
			<destination>
				<address>192.168.10.104</address>
				<port>1514-1515</port>
			</destination>
			<descr><![CDATA[Specific rule : Allow Wazuh agents communications]]></descr>
			<created>
				<time>1756801551</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1761288470</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<rule>
			<id></id>
			<tracker>1756801576</tracker>
			<type>block</type>
			<interface>opt1</interface>
			<ipprotocol>inet</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<source>
				<network>opt1</network>
			</source>
			<destination>
				<network>lan</network>
			</destination>
			<descr><![CDATA[General rule : Block DMZ -&gt; LAN]]></descr>
			<created>
				<time>1756801576</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1761321141</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<rule>
			<id></id>
			<tracker>1756799947</tracker>
			<type>pass</type>
			<interface>opt1</interface>
			<ipprotocol>inet46</ipprotocol>
			<tag></tag>
			<tagged></tagged>
			<max></max>
			<max-src-nodes></max-src-nodes>
			<max-src-conn></max-src-conn>
			<max-src-states></max-src-states>
			<statetimeout></statetimeout>
			<statetype><![CDATA[keep state]]></statetype>
			<os></os>
			<source>
				<network>opt1</network>
			</source>
			<destination>
				<any></any>
			</destination>
			<descr><![CDATA[General rule : Allow  DMZ -&gt; WAN]]></descr>
			<created>
				<time>1756799947</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</created>
			<updated>
				<time>1761323855</time>
				<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
			</updated>
		</rule>
		<separator>
			<opt1></opt1>
			<wan></wan>
			<lan></lan>
		</separator>
	</filter>
	<shaper></shaper>
	<ipsec>
		<client></client>
	</ipsec>
	<aliases>
		<alias>
			<name>DMZ_WEB01_LIN</name>
			<type>host</type>
			<address>192.168.20.105</address>
			<descr><![CDATA[Vulnerable Web server]]></descr>
			<detail><![CDATA[Entry added Fri, 12 Sep 2025 10:53:38 +0000]]></detail>
		</alias>
		<alias>
			<name>DMZ_MS2_LIN</name>
			<type>host</type>
			<address>192.168.20.104</address>
			<descr><![CDATA[Metasploitable2 vulnerable machine]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:02:17 +0000]]></detail>
		</alias>
		<alias>
			<name>DMZ_MS3_LIN</name>
			<type>host</type>
			<address>192.168.20.106</address>
			<descr><![CDATA[Metasploitable3 vulnerable machine (Linux)]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:02:17 +0000]]></detail>
		</alias>
		<alias>
			<name>DMZ_MS3_WIN</name>
			<type>host</type>
			<address>192.168.20.107</address>
			<descr><![CDATA[Metasploitable3 vulnerable machine (Windows)]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:02:17 +0000]]></detail>
		</alias>
		<alias>
			<name>LAN_SIEM_LIN</name>
			<type>host</type>
			<address>192.168.10.104</address>
			<descr><![CDATA[Wazuh manager]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:08:00 +0000]]></detail>
		</alias>
		<alias>
			<name>LAN_ATTACK_LIN</name>
			<type>host</type>
			<address>192.168.10.109</address>
			<descr><![CDATA[Kali attack machine]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:08:00 +0000]]></detail>
		</alias>
		<alias>
			<name>LAN_DC01_WIN</name>
			<type>host</type>
			<address>192.168.10.30</address>
			<descr><![CDATA[Active Directory domain controller]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:08:00 +0000]]></detail>
		</alias>
		<alias>
			<name>LAN_WS01_WIN</name>
			<type>host</type>
			<address>192.168.10.31</address>
			<descr><![CDATA[Active Directory WS01 client]]></descr>
			<detail><![CDATA[Entry added Fri, 24 Oct 2025 09:08:00 +0000]]></detail>
		</alias>
	</aliases>
	<proxyarp></proxyarp>
	<cron>
		<item>
			<minute>*/1</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/sbin/newsyslog</command>
		</item>
		<item>
			<minute>1</minute>
			<hour>3</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/etc/rc.periodic daily</command>
		</item>
		<item>
			<minute>15</minute>
			<hour>4</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>6</wday>
			<who>root</who>
			<command>/etc/rc.periodic weekly</command>
		</item>
		<item>
			<minute>30</minute>
			<hour>5</hour>
			<mday>1</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/etc/rc.periodic monthly</command>
		</item>
		<item>
			<minute>1,31</minute>
			<hour>0-5</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
		</item>
		<item>
			<minute>1</minute>
			<hour>3</hour>
			<mday>1</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
		</item>
		<item>
			<minute>1</minute>
			<hour>1</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
		</item>
		<item>
			<minute>*/60</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
		</item>
		<item>
			<minute>30</minute>
			<hour>12</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /etc/rc.update_urltables</command>
		</item>
		<item>
			<minute>1</minute>
			<hour>0</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /etc/rc.update_pkg_metadata</command>
		</item>
		<item>
			<minute>*/5</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /usr/local/bin/php-cgi -f /usr/local/pkg/suricata/suricata_check_cron_misc.inc</command>
		</item>
		<item>
			<minute>*/5</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /sbin/pfctl -q -t snort2c -T expire 3600</command>
		</item>
		<item>
			<minute>6</minute>
			<hour>0,12</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /usr/local/bin/php-cgi -f /usr/local/pkg/suricata/suricata_check_for_rule_updates.php</command>
		</item>
	</cron>
	<wol></wol>
	<rrd>
		<enable></enable>
		<category>left=system-processor&amp;right=&amp;resolution=300&amp;timePeriod=-1d&amp;startDate=&amp;endDate=&amp;startTime=0&amp;endTime=0&amp;graphtype=line&amp;invert=true&amp;refresh-interval=0</category>
	</rrd>
	<widgets>
		<sequence>system_information:col1:open:0,disks:col1:open:0,interfaces:col2:open:0</sequence>
		<period>10</period>
	</widgets>
	<openvpn></openvpn>
	<dnshaper></dnshaper>
	<unbound>
		<enable></enable>
		<dnssec></dnssec>
		<active_interface>all</active_interface>
		<outgoing_interface>all</outgoing_interface>
		<custom_options></custom_options>
		<hideidentity></hideidentity>
		<hideversion></hideversion>
		<dnssecstripped></dnssecstripped>
		<port></port>
		<tlsport></tlsport>
		<sslcertref>68a6f06f6d985</sslcertref>
		<system_domain_local_zone_type>transparent</system_domain_local_zone_type>
	</unbound>
	<vlans></vlans>
	<qinqs></qinqs>
	<revision>
		<time>1761760261</time>
		<description><![CDATA[admin@192.168.10.100 (Local Database): Successfully edited user admin]]></description>
		<username><![CDATA[admin@192.168.10.100 (Local Database)]]></username>
	</revision>
	<gateways>
		<gateway_item>
			<interface>wan</interface>
			<gateway>dynamic</gateway>
			<name>WAN_DHCP</name>
			<weight>1</weight>
			<ipprotocol>inet</ipprotocol>
			<descr><![CDATA[Interface WAN_DHCP Gateway]]></descr>
			<gw_down_kill_states></gw_down_kill_states>
		</gateway_item>
	</gateways>
	<captiveportal></captiveportal>
	<dnsmasq>
		<hosts>
			<host>DMZ-WEB01-LIN</host>
			<domain>home.lab</domain>
			<ip>192.168.20.105</ip>
			<descr><![CDATA[Vulnerable Web server]]></descr>
			<aliases></aliases>
		</hosts>
	</dnsmasq>
	<ntpd>
		<gps></gps>
	</ntpd>
	<cert>
		<refid>68a6f06f6d985</refid>
		<descr><![CDATA[webConfigurator default (68a6f06f6d985)]]></descr>
		<type>server</type>
		<!-- SSL CERTIFICATE REMOVED - pfSense WILL REGENERATE IT AUTOMATICALLY ON FIRST BOOT -->
		<crt></crt>
		<!-- SSL PRIVATE KEY REMOVED - pfSense WILL REGENERATE IT AUTOMATICALLY ON FIRST BOOT -->
		<prv></prv>
	</cert>
	<ppps></ppps>
	<installedpackages>
		<package>
			<name>Cron</name>
			<descr><![CDATA[The cron utility is used to manage commands on a schedule.]]></descr>
			<version>0.3.8_3</version>
			<configurationfile>cron.xml</configurationfile>
			<include_file>/usr/local/pkg/cron.inc</include_file>
		</package>
		<package>
			<name>suricata</name>
			<website>http://suricata-ids.org/</website>
			<descr><![CDATA[High Performance Network IDS, IPS and Security Monitoring engine by OISF.]]></descr>
			<version>7.0.8_1</version>
			<configurationfile>suricata.xml</configurationfile>
			<include_file>/usr/local/pkg/suricata/suricata.inc</include_file>
		</package>
		<suricata>
			<config>
				<forcekeepsettings>on</forcekeepsettings>
				<sid_list_migration>1</sid_list_migration>
				<suricata_config_ver>7.0.8_1</suricata_config_ver>
				<enable_vrt_rules>off</enable_vrt_rules>
				<snortcommunityrules>on</snortcommunityrules>
				<enable_etopen_rules>on</enable_etopen_rules>
				<enable_etpro_rules>off</enable_etpro_rules>
				<autogeoipupdate>off</autogeoipupdate>
				<hide_deprecated_rules>off</hide_deprecated_rules>
				<enable_etopen_custom_url>off</enable_etopen_custom_url>
				<enable_etpro_custom_url>off</enable_etpro_custom_url>
				<enable_snort_custom_url>off</enable_snort_custom_url>
				<enable_gplv2_custom_url>off</enable_gplv2_custom_url>
				<enable_feodo_botnet_c2_rules>off</enable_feodo_botnet_c2_rules>
				<enable_abuse_ssl_blacklist_rules>off</enable_abuse_ssl_blacklist_rules>
				<enable_extra_rules>off</enable_extra_rules>
				<extra_rules></extra_rules>
				<snort_rules_file></snort_rules_file>
				<oinkcode></oinkcode>
				<etprocode></etprocode>
				<rm_blocked>1h_b</rm_blocked>
				<autoruleupdate>12h_up</autoruleupdate>
				<etopen_custom_rule_url></etopen_custom_rule_url>
				<etpro_custom_rule_url></etpro_custom_rule_url>
				<snort_custom_url></snort_custom_url>
				<gplv2_custom_url></gplv2_custom_url>
				<maxmind_geoipdb_uid></maxmind_geoipdb_uid>
				<maxmind_geoipdb_key></maxmind_geoipdb_key>
				<log_to_systemlog>on</log_to_systemlog>
				<update_notify>off</update_notify>
				<rule_categories_notify>off</rule_categories_notify>
				<log_to_systemlog_facility>local1</log_to_systemlog_facility>
				<log_to_systemlog_priority>notice</log_to_systemlog_priority>
				<live_swap_updates>off</live_swap_updates>
				<clearblocks>on</clearblocks>
				<autoruleupdatetime>00:06</autoruleupdatetime>
				<enable_log_mgmt>on</enable_log_mgmt>
				<clearlogs>off</clearlogs>
				<suricataloglimit>off</suricataloglimit>
				<suricataloglimitsize></suricataloglimitsize>
				<alert_log_limit_size>10000</alert_log_limit_size>
				<alert_log_retention>336</alert_log_retention>
				<block_log_limit_size>10000</block_log_limit_size>
				<block_log_retention>336</block_log_retention>
				<http_log_limit_size>10000</http_log_limit_size>
				<http_log_retention>168</http_log_retention>
				<stats_log_limit_size>10000</stats_log_limit_size>
				<stats_log_retention>168</stats_log_retention>
				<tls_log_limit_size>10000</tls_log_limit_size>
				<tls_log_retention>336</tls_log_retention>
				<file_store_retention>168</file_store_retention>
				<file_store_limit_size>1812</file_store_limit_size>
				<tls_certs_store_retention>168</tls_certs_store_retention>
				<eve_log_limit_size>10000</eve_log_limit_size>
				<eve_log_retention>168</eve_log_retention>
				<sid_changes_log_limit_size>250</sid_changes_log_limit_size>
				<sid_changes_log_retention>336</sid_changes_log_retention>
				<pkt_capture_file_retention>168</pkt_capture_file_retention>
				<auto_manage_sids>off</auto_manage_sids>
				<et_iqrisk_enable>off</et_iqrisk_enable>
			</config>
			<sid_mgmt_lists>
				<item>
					<name>disablesid-sample.conf</name>
					<modtime>1755022426</modtime>
					<content>IyBleGFtcGxlIGRpc2FibGVzaWQuY29uZgoKIyBFeGFtcGxlIG9mIG1vZGlmeWluZyBzdGF0ZSBmb3IgaW5kaXZpZHVhbCBydWxlcwojIDE6MTAzNCwxOjk4MzcsMToxMjcwLDE6MzM5MCwxOjcxMCwxOjEyNDksMzoxMzAxMAoKIyBFeGFtcGxlIG9mIG1vZGlmeWluZyBzdGF0ZSBmb3IgcnVsZSByYW5nZXMKIyAxOjIyMC0xOjMyNjQsMzoxMzAxMC0zOjEzMDEzCgojIENvbW1lbnRzIGFyZSBhbGxvd2VkIGluIHRoaXMgZmlsZSwgYW5kIGNhbiBhbHNvIGJlIG9uIHRoZSBzYW1lIGxpbmUKIyBBcyB0aGUgbW9kaWZ5IHN0YXRlIHN5bnRheCwgYXMgbG9uZyBhcyBpdCBpcyBhIHRyYWlsaW5nIGNvbW1lbnQKIyAxOjEwMTEgIyBJIERpc2FibGVkIHRoaXMgcnVsZSBiZWNhdXNlIEkgY291bGQhCgojIEV4YW1wbGUgb2YgbW9kaWZ5aW5nIHN0YXRlIGZvciBNUyBhbmQgY3ZlIHJ1bGVzLCBub3RlIHRoZSB1c2Ugb2YgdGhlIDogCiMgaW4gY3ZlLiBUaGlzIHdpbGwgbW9kaWZ5IE1TMDktMDA4LCBjdmUgMjAwOS0wMjMzLCBidWd0cmFxIDIxMzAxLAojIGFuZCBhbGwgTVMwMCBhbmQgYWxsIGN2ZSAyMDAwIHJlbGF0ZWQgc2lkcyEgIFRoZXNlIHN1cHBvcnQgcmVndWxhciBleHByZXNzaW9uCiMgbWF0Y2hpbmcgb25seSBhZnRlciB5b3UgaGF2ZSBzcGVjaWZpZWQgd2hhdCB5b3UgYXJlIGxvb2tpbmcgZm9yLCBpLmUuIAojIE1TMDAtPHJlZ2V4PiBvciBjdmU6PHJlZ2V4PiwgdGhlIGZpcnN0IHNlY3Rpb24gQ0FOTk9UIGNvbnRhaW4gYSByZWd1bGFyCiMgZXhwcmVzc2lvbiAoTVNcZHsyfS1cZCspIHdpbGwgTk9UIHdvcmssIHVzZSB0aGUgcGNyZToga2V5d29yZCAoYmVsb3cpCiMgZm9yIHRoaXMuCiMgTVMwOS0wMDgsY3ZlOjIwMDktMDIzMyxidWd0cmFxOjIxMzAxLE1TMDAtXGQrLGN2ZToyMDAwLVxkKwoKIyBFeGFtcGxlIG9mIHVzaW5nIHRoZSBwY3JlOiBrZXl3b3JkIHRvIG1vZGlmeSBydWxlc3RhdGUuICB0aGUgcGNyZSBrZXl3b3JkIAojIGFsbG93cyBmb3IgZnVsbCB1c2Ugb2YgcmVndWxhciBleHByZXNzaW9uIHN5bnRheCwgeW91IGRvIG5vdCBuZWVkIHRvIGRlc2lnbmF0ZQojIHdpdGggLyBhbmQgYWxsIHBjcmUgc2VhcmNoZXMgYXJlIHRyZWF0ZWQgYXMgY2FzZSBpbnNlbnNpdGl2ZS4gRm9yIG1vcmUgaW5mb3JtYXRpb24gCiMgYWJvdXQgcmVndWxhciBleHByZXNzaW9uIHN5bnRheDogaHR0cDovL3d3dy5yZWd1bGFyLWV4cHJlc3Npb25zLmluZm8vCiMgVGhlIGZvbGxvd2luZyBleGFtcGxlIG1vZGlmaWVzIHN0YXRlIGZvciBhbGwgTVMwNyB0aHJvdWdoIE1TMTAgCiMgcGNyZTpNUygwWzctOV18MTApLVxkKwojIHBjcmU6Ikpvb21sYSIKCiMgRXhhbXBsZSBvZiBtb2RpZnlpbmcgc3RhdGUgZm9yIHNwZWNpZmljIGNhdGVnb3JpZXMgZW50aXJlbHkuCiMgInNub3J0XyIgbGltaXRzIHRvIFNub3J0IFZSVCBydWxlcywgImVtZXJnaW5nLSIgbGltaXRzIHRvIAojIEVtZXJnaW5nIFRocmVhdHMgT3BlbiBydWxlcywgImV0cHJvLSIgbGltaXRzIHRvIEVULVBSTyBydWxlcy4KIyAic2hlbGxjb2RlIiB3aXRoIG5vIHByZWZpeCB3b3VsZCBtYXRjaCBpbiBhbnkgdmVuZG9yIHNldC4KIyBzbm9ydF93ZWItaWlzLGVtZXJnaW5nLXNoZWxsY29kZSxldHByby1pbWFwLHNoZWxsY29kZQoKIyBBbnkgb2YgdGhlIGFib3ZlIHZhbHVlcyBjYW4gYmUgb24gYSBzaW5nbGUgbGluZSBvciBtdWx0aXBsZSBsaW5lcywgd2hlbiAKIyBvbiBhIHNpbmdsZSBsaW5lIHRoZXkgc2ltcGx5IG5lZWQgdG8gYmUgc2VwYXJhdGVkIGJ5IGEgLAojIDE6OTgzNywxOjIyMC0xOjMyNjQsMzoxMzAxMC0zOjEzMDEzLHBjcmU6TVMoMFswLTddKS1cZCssTVMwOS0wMDgsY3ZlOjIwMDktMDIzMwoKIyBUaGUgbW9kaWZpY2F0aW9ucyBpbiB0aGlzIGZpbGUgYXJlIGZvciBzYW1wbGUvZXhhbXBsZSBwdXJwb3NlcyBvbmx5IGFuZAojIHNob3VsZCBub3QgYWN0aXZlbHkgYmUgdXNlZCwgeW91IG5lZWQgdG8gbW9kaWZ5IHRoaXMgZmlsZSB0byBmaXQgeW91ciAKIyBlbnZpcm9ubWVudC4KCg==</content>
				</item>
				<item>
					<name>dropsid-sample.conf</name>
					<modtime>1755022426</modtime>
					<content>IyBOb3RlOiBUaGlzIGZpbGUgaXMgdXNlZCB0byBzcGVjaWZ5IHdoYXQgcnVsZXMgeW91IHdpc2ggdG8gYmUgc2V0IHRvIGhhdmUKIyBhbiBhY3Rpb24gb2YgZHJvcCByYXRoZXIgdGhhbiBhbGVydC4KCiMgRXhhbXBsZSBvZiBtb2RpZnlpbmcgc3RhdGUgZm9yIGluZGl2aWR1YWwgcnVsZXMKIyAxOjEwMzQsMTo5ODM3LDE6MTI3MCwxOjMzOTAsMTo3MTAsMToxMjQ5LDM6MTMwMTAKCiMgRXhhbXBsZSBvZiBtb2RpZnlpbmcgc3RhdGUgZm9yIHJ1bGUgcmFuZ2VzCiMgMToyMjAtMTozMjY0LDM6MTMwMTAtMzoxMzAxMwoKIyBDb21tZW50cyBhcmUgYWxsb3dlZCBpbiB0aGlzIGZpbGUsIGFuZCBjYW4gYWxzbyBiZSBvbiB0aGUgc2FtZSBsaW5lCiMgQXMgdGhlIG1vZGlmeSBzdGF0ZSBzeW50YXgsIGFzIGxvbmcgYXMgaXQgaXMgYSB0cmFpbGluZyBjb21tZW50CiMgMToxMDExICMgSSBEaXNhYmxlZCB0aGlzIHJ1bGUgYmVjYXVzZSBJIGNvdWxkIQoKIyBFeGFtcGxlIG9mIG1vZGlmeWluZyBzdGF0ZSBmb3IgTVMgYW5kIGN2ZSBydWxlcywgbm90ZSB0aGUgdXNlIG9mIHRoZSA6IAojIGluIGN2ZS4gVGhpcyB3aWxsIG1vZGlmeSBNUzA5LTAwOCwgY3ZlIDIwMDktMDIzMywgYnVndHJhcSAyMTMwMSwKIyBhbmQgYWxsIE1TMDAgYW5kIGFsbCBjdmUgMjAwMCByZWxhdGVkIHNpZHMhICBUaGVzZSBzdXBwb3J0IHJlZ3VsYXIgZXhwcmVzc2lvbgojIG1hdGNoaW5nIG9ubHkgYWZ0ZXIgeW91IGhhdmUgc3BlY2lmaWVkIHdoYXQgeW91IGFyZSBsb29raW5nIGZvciwgaS5lLiAKIyBNUzAwLTxyZWdleD4gb3IgY3ZlOjxyZWdleD4sIHRoZSBmaXJzdCBzZWN0aW9uIENBTk5PVCBjb250YWluIGEgcmVndWxhcgojIGV4cHJlc3Npb24gKE1TXGR7Mn0tXGQrKSB3aWxsIE5PVCB3b3JrLCB1c2UgdGhlIHBjcmU6IGtleXdvcmQgKGJlbG93KQojIGZvciB0aGlzLgojIE1TMDktMDA4LGN2ZToyMDA5LTAyMzMsYnVndHJhcToyMTMwMSxNUzAwLVxkKyxjdmU6MjAwMC1cZCsKCiMgRXhhbXBsZSBvZiB1c2luZyB0aGUgcGNyZToga2V5d29yZCB0byBtb2RpZnkgcnVsZXN0YXRlLiAgdGhlIHBjcmUga2V5d29yZCAKIyBhbGxvd3MgZm9yIGZ1bGwgdXNlIG9mIHJlZ3VsYXIgZXhwcmVzc2lvbiBzeW50YXgsIHlvdSBkbyBub3QgbmVlZCB0byBkZXNpZ25hdGUKIyB3aXRoIC8gYW5kIGFsbCBwY3JlIHNlYXJjaGVzIGFyZSB0cmVhdGVkIGFzIGNhc2UgaW5zZW5zaXRpdmUuIEZvciBtb3JlIGluZm9ybWF0aW9uIAojIGFib3V0IHJlZ3VsYXIgZXhwcmVzc2lvbiBzeW50YXg6IGh0dHA6Ly93d3cucmVndWxhci1leHByZXNzaW9ucy5pbmZvLwojIFRoZSBmb2xsb3dpbmcgZXhhbXBsZSBtb2RpZmllcyBzdGF0ZSBmb3IgYWxsIE1TMDcgdGhyb3VnaCBNUzEwIAojIHBjcmU6TVMoMFs3LTldfDEwKS1cZCsKCiMgVGhlIGZvbGxvd2luZyBleGFtcGxlIG1vZGlmaWVzIHN0YXRlIGZvciBTbm9ydCBWUlQgcnVsZXMgdGFnZ2VkIHdpdGggSVBTIAojIFBvbGljeSBTZWN1cml0eSBhbmQgaXBzIGRyb3AKIyAtLS0tLS0tLS0tLS0tLS0tLQojIHBjcmU6InBjcmU6c2VjdXJpdHktaXBzXHMqZHJvcCIKCiMgRXhhbXBsZSBvZiBtb2RpZnlpbmcgc3RhdGUgZm9yIHNwZWNpZmljIGNhdGVnb3JpZXMgZW50aXJlbHkKIyBWUlQtd2ViLWlpcyxFVC1zaGVsbGNvZGUsRVQtZW1lcmdpbmd0aHJlYXRzLXNtdHAsQ3VzdG9tLXNoZWxsY29kZSxDdXN0b20tZW1lcmdpbmd0aHJlYXRzLXNtdHAKCiMgQW55IG9mIHRoZSBhYm92ZSB2YWx1ZXMgY2FuIGJlIG9uIGEgc2luZ2xlIGxpbmUgb3IgbXVsdGlwbGUgbGluZXMsIHdoZW4gCiMgb24gYSBzaW5nbGUgbGluZSB0aGV5IHNpbXBseSBuZWVkIHRvIGJlIHNlcGFyYXRlZCBieSBhICwKIyAxOjk4MzcsMToyMjAtMTozMjY0LDM6MTMwMTAtMzoxMzAxMyxwY3JlOk1TKDBbMC03XSktXGQrLE1TMDktMDA4LGN2ZToyMDA5LTAyMzMKCiMgVGhlIG1vZGlmaWNhdGlvbnMgaW4gdGhpcyBmaWxlIGFyZSBmb3Igc2FtcGxlL2V4YW1wbGUgcHVycG9zZXMgb25seSBhbmQKIyBzaG91bGQgbm90IGFjdGl2ZWx5IGJlIHVzZWQsIHlvdSBuZWVkIHRvIG1vZGlmeSB0aGlzIGZpbGUgdG8gZml0IHlvdXIgCiMgZW52aXJvbm1lbnQuCg==</content>
				</item>
				<item>
					<name>enablesid-sample.conf</name>
					<modtime>1755022426</modtime>
					<content>IyBleGFtcGxlIGVuYWJsZXNpZC5jb25mCgojIEV4YW1wbGUgb2YgbW9kaWZ5aW5nIHN0YXRlIGZvciBpbmRpdmlkdWFsIHJ1bGVzCiMgMToxMDM0LDE6OTgzNywxOjEyNzAsMTozMzkwLDE6NzEwLDE6MTI0OSwzOjEzMDEwCgojIEV4YW1wbGUgb2YgbW9kaWZ5aW5nIHN0YXRlIGZvciBydWxlIHJhbmdlcwojIDE6MjIwLTE6MzI2NCwzOjEzMDEwLTM6MTMwMTMKCiMgQ29tbWVudHMgYXJlIGFsbG93ZWQgaW4gdGhpcyBmaWxlLCBhbmQgY2FuIGFsc28gYmUgb24gdGhlIHNhbWUgbGluZQojIEFzIHRoZSBtb2RpZnkgc3RhdGUgc3ludGF4LCBhcyBsb25nIGFzIGl0IGlzIGEgdHJhaWxpbmcgY29tbWVudAojIDE6MTAxMSAjIEkgRGlzYWJsZWQgdGhpcyBydWxlIGJlY2F1c2UgSSBjb3VsZCEKCiMgRXhhbXBsZSBvZiBtb2RpZnlpbmcgc3RhdGUgZm9yIE1TIGFuZCBjdmUgcnVsZXMsIG5vdGUgdGhlIHVzZSBvZiB0aGUgOiAKIyBpbiBjdmUuIFRoaXMgd2lsbCBtb2RpZnkgTVMwOS0wMDgsIGN2ZSAyMDA5LTAyMzMsIGJ1Z3RyYXEgMjEzMDEsCiMgYW5kIGFsbCBNUzAwIGFuZCBhbGwgY3ZlIDIwMDAgcmVsYXRlZCBzaWRzISAgVGhlc2Ugc3VwcG9ydCByZWd1bGFyIGV4cHJlc3Npb24KIyBtYXRjaGluZyBvbmx5IGFmdGVyIHlvdSBoYXZlIHNwZWNpZmllZCB3aGF0IHlvdSBhcmUgbG9va2luZyBmb3IsIGkuZS4gCiMgTVMwMC08cmVnZXg+IG9yIGN2ZTo8cmVnZXg+LCB0aGUgZmlyc3Qgc2VjdGlvbiBDQU5OT1QgY29udGFpbiBhIHJlZ3VsYXIKIyBleHByZXNzaW9uIChNU1xkezJ9LVxkKykgd2lsbCBOT1Qgd29yaywgdXNlIHRoZSBwY3JlOiBrZXl3b3JkIChiZWxvdykKIyBmb3IgdGhpcy4KIyBNUzA5LTAwOCxjdmU6MjAwOS0wMjMzLGJ1Z3RyYXE6MjEzMDEsTVMwMC1cZCssY3ZlOjIwMDAtXGQrCgojIEV4YW1wbGUgb2YgdXNpbmcgdGhlIHBjcmU6IGtleXdvcmQgdG8gbW9kaWZ5IHJ1bGVzdGF0ZS4gIHRoZSBwY3JlIGtleXdvcmQgCiMgYWxsb3dzIGZvciBmdWxsIHVzZSBvZiByZWd1bGFyIGV4cHJlc3Npb24gc3ludGF4LCB5b3UgZG8gbm90IG5lZWQgdG8gZGVzaWduYXRlCiMgd2l0aCAvIGFuZCBhbGwgcGNyZSBzZWFyY2hlcyBhcmUgdHJlYXRlZCBhcyBjYXNlIGluc2Vuc2l0aXZlLiBGb3IgbW9yZSBpbmZvcm1hdGlvbiAKIyBhYm91dCByZWd1bGFyIGV4cHJlc3Npb24gc3ludGF4OiBodHRwOi8vd3d3LnJlZ3VsYXItZXhwcmVzc2lvbnMuaW5mby8KIyBUaGUgZm9sbG93aW5nIGV4YW1wbGUgbW9kaWZpZXMgc3RhdGUgZm9yIGFsbCBNUzA3IHRocm91Z2ggTVMxMCAKIyBwY3JlOk1TKDBbNy05XXwxMCktXGQrCiMgcGNyZToiSm9vbWxhIgoKIyBFeGFtcGxlIG9mIG1vZGlmeWluZyBzdGF0ZSBmb3Igc3BlY2lmaWMgY2F0ZWdvcmllcyBlbnRpcmVseS4KIyAic25vcnRfIiBsaW1pdHMgdG8gU25vcnQgVlJUIHJ1bGVzLCAiZW1lcmdpbmctIiBsaW1pdHMgdG8gCiMgRW1lcmdpbmcgVGhyZWF0cyBPcGVuIHJ1bGVzLCAiZXRwcm8tIiBsaW1pdHMgdG8gRVQtUFJPIHJ1bGVzLgojICJzaGVsbGNvZGUiIHdpdGggbm8gcHJlZml4IHdvdWxkIG1hdGNoIGluIGFueSB2ZW5kb3Igc2V0LgojIHNub3J0X3dlYi1paXMsZW1lcmdpbmctc2hlbGxjb2RlLGV0cHJvLWltYXAsc2hlbGxjb2RlCgojIEFueSBvZiB0aGUgYWJvdmUgdmFsdWVzIGNhbiBiZSBvbiBhIHNpbmdsZSBsaW5lIG9yIG11bHRpcGxlIGxpbmVzLCB3aGVuIAojIG9uIGEgc2luZ2xlIGxpbmUgdGhleSBzaW1wbHkgbmVlZCB0byBiZSBzZXBhcmF0ZWQgYnkgYSAsCiMgMTo5ODM3LDE6MjIwLTE6MzI2NCwzOjEzMDEwLTM6MTMwMTMscGNyZTpNUygwWzAtN10pLVxkKyxNUzA5LTAwOCxjdmU6MjAwOS0wMjMzCgo=</content>
				</item>
				<item>
					<name>modifysid-sample.conf</name>
					<modtime>1755022426</modtime>
					<content>IyBleGFtcGxlIG1vZGlmeXNpZC5jb25mCiMKIyBmb3JtYXR0aW5nIGlzIHNpbXBsZQojIDxzaWQsIGNhdGVnb3J5LCBsaXN0IG9mIHNpZHMmY2F0ZWdvcmllcz4gIndoYXQgSSdtIHJlcGxhY2luZyIgIndoYXQgSSdtIHJlcGxhY2luZyBpdCB3aXRoIgojCiMgTm90ZSB0aGF0IHRoaXMgd2lsbCBvbmx5IHdvcmsgd2l0aCBHSUQ6MSBydWxlcywgc2ltcGx5IGJlY2F1c2UgbW9kaWZ5aW5nCiMgR0lEOjMgU08gc3R1YiBydWxlcyB3b3VsZCBub3QgYWN0dWFsbHkgYWZmZWN0IHRoZSBydWxlLgojCiMgSWYgeW91IGFyZSBhdHRlbXB0aW5nIHRvIGNoYW5nZSBydWxlc3RhdGUgKGVuYWJsZSxkaXNhYmxlKSBmcm9tIGhlcmUKIyB0aGVuIHlvdSBhcmUgZG9pbmcgaXQgd3JvbmcuIERvIHRoaXMgZnJvbSB3aXRoaW4gdGhlIHJlc3BlY3RpdmUgCiMgcnVsZXN0YXRlIG1vZGlmaWNhdGlvbiBjb25maWd1cmF0aW9uIGZpbGVzLgoKIyB0aGUgZm9sbG93aW5nIGFwcGxpZXMgdG8gc2lkIDEwMDEwIG9ubHkgYW5kIHJlcHJlc2VudHMgd2hhdCB3b3VsZCBub3JtYWxseQojIGJlIHMvdG9fY2xpZW50L2Zyb21fc2VydmVyLwojIDEwMDEwICJ0b19jbGllbnQiICJmcm9tX3NlcnZlciIKCiMgdGhlIGZvbGxvd2luZyB3b3VsZCByZXBsYWNlIEhUVFBfUE9SVFMgd2l0aCBIVFRQU19QT1JUUyBmb3IgQUxMIEdJRDoxCiMgcnVsZXMKIyAiSFRUUF9QT1JUUyIgIkhUVFBTX1BPUlRTIgoKIyBtdWx0aXBsZSBzaWRzIGNhbiBiZSBzcGVjaWZpZWQgYXMgbm90ZWQgYmVsb3c6CiMgMzAyLDQyOSwxODIxICIkRVhURVJOQUxfTkVUIiAiJEhPTUVfTkVUIgoKIyBtb2RpZnkgYWxsIHNpZ25hdHVyZXMgaW4gYSBjYXRlZ29yeS4gRXhhbXBsZTogcmVwbGFjZSAiJEVYVEVSTkFMX05FVFMiIHdpdGggImFueSIgdG8gYmUgYWxlcnRzIG9uIGluc2lkZXIgdGhyZWF0cyBhcyB3ZWxsCiMgZW1lcmdpbmctc2NhbiAiJEVYVEVSTkFMX05FVCIgImFueSIKCiMgbW9kaWZ5IGFsbCBzaWduYXR1cmVzIGluIG11bHRpcGxlIGNhdGVnb3JpZXMKIyBlbWVyZ2luZy1zY2FuLGVtZXJnaW5nLXNxbCAiJEVYVEVSTkFMX05FVCIgImFueSIKCiMgbW9kaWZ5IGFsbCBzaWduYXR1cmVzIGZvciBhIGNhdGVnb3J5IGFuZCBzcGVjaWZpYyBTSURzIGZyb20gb3RoZXIgY2F0ZWdvcmllcwojIGVtZXJnaW5nLXNxbCwyMTAwNjkxLDIwMDk4MTcgIiRFWFRFUk5BTF9ORVQiICJhbnkiCg==</content>
				</item>
			</sid_mgmt_lists>
			<rule>
				<interface>wan</interface>
				<enable>on</enable>
				<uuid>62796</uuid>
				<descr><![CDATA[WAN]]></descr>
				<enable_verbose_logging>off</enable_verbose_logging>
				<max_pcap_log_size>32</max_pcap_log_size>
				<max_pcap_log_files>100</max_pcap_log_files>
				<pcap_log_conditional>alerts</pcap_log_conditional>
				<enable_stats_collection>off</enable_stats_collection>
				<enable_stats_log>off</enable_stats_log>
				<append_stats_log>off</append_stats_log>
				<stats_upd_interval>10</stats_upd_interval>
				<enable_telegraf_stats>off</enable_telegraf_stats>
				<enable_http_log>on</enable_http_log>
				<append_http_log>on</append_http_log>
				<enable_tls_log>off</enable_tls_log>
				<append_tls_log>on</append_tls_log>
				<enable_tls_store>off</enable_tls_store>
				<http_log_extended>on</http_log_extended>
				<tls_log_extended>on</tls_log_extended>
				<tls_session_resumption>off</tls_session_resumption>
				<enable_pcap_log>off</enable_pcap_log>
				<pcap_use_stream_depth>off</pcap_use_stream_depth>
				<pcap_honor_pass_rules>off</pcap_honor_pass_rules>
				<enable_file_store>off</enable_file_store>
				<tls_log_filetype>regular</tls_log_filetype>
				<http_log_filetype>regular</http_log_filetype>
				<runmode>autofp</runmode>
				<autofp_scheduler>hash</autofp_scheduler>
				<max_pending_packets>1024</max_pending_packets>
				<inspect_recursion_limit>3000</inspect_recursion_limit>
				<intf_snaplen>1518</intf_snaplen>
				<detect_eng_profile>medium</detect_eng_profile>
				<mpm_algo>auto</mpm_algo>
				<spm_algo>auto</spm_algo>
				<sgh_mpm_context>auto</sgh_mpm_context>
				<blockoffenders>off</blockoffenders>
				<ips_mode>ips_mode_legacy</ips_mode>
				<ips_netmap_threads>auto</ips_netmap_threads>
				<blockoffenderskill>on</blockoffenderskill>
				<block_drops_only>off</block_drops_only>
				<passlist_debug_log>off</passlist_debug_log>
				<blockoffendersip>both</blockoffendersip>
				<passlistname>default</passlistname>
				<homelistname>default</homelistname>
				<externallistname>default</externallistname>
				<suppresslistname>default</suppresslistname>
				<alertsystemlog>off</alertsystemlog>
				<alertsystemlog_facility>local0</alertsystemlog_facility>
				<alertsystemlog_priority>notice</alertsystemlog_priority>
				<enable_eve_log>on</enable_eve_log>
				<eve_output_type>regular</eve_output_type>
				<eve_systemlog_facility>syslog</eve_systemlog_facility>
				<eve_systemlog_priority>notice</eve_systemlog_priority>
				<eve_log_ethernet>no</eve_log_ethernet>
				<eve_log_alerts>on</eve_log_alerts>
				<eve_log_alerts_payload>on</eve_log_alerts_payload>
				<eve_log_alerts_packet>on</eve_log_alerts_packet>
				<eve_log_alerts_metadata>on</eve_log_alerts_metadata>
				<eve_log_alerts_http>on</eve_log_alerts_http>
				<eve_log_alerts_xff>off</eve_log_alerts_xff>
				<eve_log_alerts_xff_mode>extra-data</eve_log_alerts_xff_mode>
				<eve_log_alerts_xff_deployment>reverse</eve_log_alerts_xff_deployment>
				<eve_log_alerts_xff_header>X-Forwarded-For</eve_log_alerts_xff_header>
				<eve_log_alerts_verdict>off</eve_log_alerts_verdict>
				<eve_log_alerts_tagged>off</eve_log_alerts_tagged>
				<eve_log_drops>on</eve_log_drops>
				<eve_log_alert_drops>on</eve_log_alert_drops>
				<eve_log_drops_verdict>off</eve_log_drops_verdict>
				<eve_log_drops_flows>all</eve_log_drops_flows>
				<eve_log_anomaly>off</eve_log_anomaly>
				<eve_log_anomaly_type_decode>off</eve_log_anomaly_type_decode>
				<eve_log_anomaly_type_stream>off</eve_log_anomaly_type_stream>
				<eve_log_anomaly_type_applayer>on</eve_log_anomaly_type_applayer>
				<eve_log_anomaly_packethdr>off</eve_log_anomaly_packethdr>
				<eve_log_http>on</eve_log_http>
				<eve_log_dns>off</eve_log_dns>
				<eve_log_tls>off</eve_log_tls>
				<eve_log_dhcp>off</eve_log_dhcp>
				<eve_log_nfs>on</eve_log_nfs>
				<eve_log_smb>on</eve_log_smb>
				<eve_log_krb5>on</eve_log_krb5>
				<eve_log_ikev2>on</eve_log_ikev2>
				<eve_log_tftp>on</eve_log_tftp>
				<eve_log_bittorrent>off</eve_log_bittorrent>
				<eve_log_pgsql>on</eve_log_pgsql>
				<eve_log_quic>on</eve_log_quic>
				<eve_log_rdp>off</eve_log_rdp>
				<eve_log_sip>off</eve_log_sip>
				<eve_log_files>off</eve_log_files>
				<eve_log_ssh>off</eve_log_ssh>
				<eve_log_smtp>on</eve_log_smtp>
				<eve_log_stats>off</eve_log_stats>
				<eve_log_flow>off</eve_log_flow>
				<eve_log_netflow>off</eve_log_netflow>
				<eve_log_snmp>off</eve_log_snmp>
				<eve_log_mqtt>on</eve_log_mqtt>
				<eve_log_ftp>on</eve_log_ftp>
				<eve_log_http2>on</eve_log_http2>
				<eve_log_rfb>on</eve_log_rfb>
				<eve_log_stats_totals>on</eve_log_stats_totals>
				<eve_log_stats_deltas>off</eve_log_stats_deltas>
				<eve_log_stats_threads>off</eve_log_stats_threads>
				<eve_log_http_extended>off</eve_log_http_extended>
				<eve_log_tls_extended>off</eve_log_tls_extended>
				<eve_log_dhcp_extended>off</eve_log_dhcp_extended>
				<eve_log_smtp_extended>off</eve_log_smtp_extended>
				<eve_log_http_extended_headers>accept, accept-charset, accept-datetime, accept-encoding, accept-language, accept-range, age, allow, authorization, cache-control, connection, content-encoding, content-language, content-length, content-location, content-md5, content-range, content-type, cookie, date, dnt, etags, from, last-modified, link, location, max-forwards, origin, pragma, proxy-authenticate, proxy-authorization, range, referrer, refresh, retry-after, server, set-cookie, te, trailer, transfer-encoding, upgrade, vary, via, warning, www-authenticate, x-authenticated-user, x-flash-version, x-forwarded-proto, x-requested-with</eve_log_http_extended_headers>
				<eve_log_smtp_extended_fields>bcc, received, reply-to, x-mailer, x-originating-ip</eve_log_smtp_extended_fields>
				<eve_log_tls_extended_fields></eve_log_tls_extended_fields>
				<eve_log_files_magic>off</eve_log_files_magic>
				<eve_log_files_hash>none</eve_log_files_hash>
				<eve_log_drop>on</eve_log_drop>
				<delayed_detect>off</delayed_detect>
				<intf_promisc_mode>on</intf_promisc_mode>
				<eve_redis_server>127.0.0.1</eve_redis_server>
				<eve_redis_port>6379</eve_redis_port>
				<eve_redis_mode>list</eve_redis_mode>
				<eve_redis_key>suricata</eve_redis_key>
				<ip_max_frags>65535</ip_max_frags>
				<ip_frag_timeout>60</ip_frag_timeout>
				<frag_memcap>33554432</frag_memcap>
				<defrag_memcap_policy>ignore</defrag_memcap_policy>
				<ip_max_trackers>65535</ip_max_trackers>
				<frag_hash_size>65536</frag_hash_size>
				<flow_memcap>134217728</flow_memcap>
				<flow_memcap_policy>ignore</flow_memcap_policy>
				<flow_prealloc>10000</flow_prealloc>
				<flow_hash_size>65536</flow_hash_size>
				<flow_emerg_recovery>30</flow_emerg_recovery>
				<flow_prune>5</flow_prune>
				<flow_tcp_new_timeout>60</flow_tcp_new_timeout>
				<flow_tcp_established_timeout>3600</flow_tcp_established_timeout>
				<flow_tcp_closed_timeout>120</flow_tcp_closed_timeout>
				<flow_tcp_emerg_new_timeout>10</flow_tcp_emerg_new_timeout>
				<flow_tcp_emerg_established_timeout>300</flow_tcp_emerg_established_timeout>
				<flow_tcp_emerg_closed_timeout>20</flow_tcp_emerg_closed_timeout>
				<flow_udp_new_timeout>30</flow_udp_new_timeout>
				<flow_udp_established_timeout>300</flow_udp_established_timeout>
				<flow_udp_emerg_new_timeout>10</flow_udp_emerg_new_timeout>
				<flow_udp_emerg_established_timeout>100</flow_udp_emerg_established_timeout>
				<flow_icmp_new_timeout>30</flow_icmp_new_timeout>
				<flow_icmp_established_timeout>300</flow_icmp_established_timeout>
				<flow_icmp_emerg_new_timeout>10</flow_icmp_emerg_new_timeout>
				<flow_icmp_emerg_established_timeout>100</flow_icmp_emerg_established_timeout>
				<stream_memcap>268435456</stream_memcap>
				<stream_prealloc_sessions>32768</stream_prealloc_sessions>
				<reassembly_memcap>131217728</reassembly_memcap>
				<reassembly_depth>1048576</reassembly_depth>
				<reassembly_to_server_chunk>2560</reassembly_to_server_chunk>
				<reassembly_to_client_chunk>2560</reassembly_to_client_chunk>
				<max_synack_queued>5</max_synack_queued>
				<enable_midstream_sessions>off</enable_midstream_sessions>
				<stream_memcap_policy>ignore</stream_memcap_policy>
				<reassembly_memcap_policy>ignore</reassembly_memcap_policy>
				<midstream_policy>ignore</midstream_policy>
				<stream_checksum_validation>off</stream_checksum_validation>
				<enable_async_sessions>off</enable_async_sessions>
				<stream_bypass>off</stream_bypass>
				<stream_drop_invalid>off</stream_drop_invalid>
				<app_layer_error_policy>ignore</app_layer_error_policy>
				<asn1_max_frames>256</asn1_max_frames>
				<bittorrent_parser>yes</bittorrent_parser>
				<dcerpc_parser>yes</dcerpc_parser>
				<dhcp_parser>yes</dhcp_parser>
				<dns_global_memcap>16777216</dns_global_memcap>
				<dns_state_memcap>524288</dns_state_memcap>
				<dns_request_flood_limit>500</dns_request_flood_limit>
				<dns_parser_udp>yes</dns_parser_udp>
				<dns_parser_tcp>yes</dns_parser_tcp>
				<dns_parser_udp_ports>53</dns_parser_udp_ports>
				<dns_parser_tcp_ports>53</dns_parser_tcp_ports>
				<enip_parser>yes</enip_parser>
				<ftp_parser>yes</ftp_parser>
				<ftp_data_parser>on</ftp_data_parser>
				<http_parser>yes</http_parser>
				<http_parser_memcap>67108864</http_parser_memcap>
				<http2_parser>yes</http2_parser>
				<ikev2_parser>yes</ikev2_parser>
				<imap_parser>detection-only</imap_parser>
				<krb5_parser>yes</krb5_parser>
				<mqtt_parser>yes</mqtt_parser>
				<msn_parser>detection-only</msn_parser>
				<nfs_parser>yes</nfs_parser>
				<ntp_parser>yes</ntp_parser>
				<pgsql_parser>no</pgsql_parser>
				<quic_parser>yes</quic_parser>
				<rdp_parser>yes</rdp_parser>
				<rfb_parser>yes</rfb_parser>
				<sip_parser>yes</sip_parser>
				<smb_parser>yes</smb_parser>
				<smtp_parser>yes</smtp_parser>
				<smtp_parser_decode_mime>off</smtp_parser_decode_mime>
				<smtp_parser_decode_base64>on</smtp_parser_decode_base64>
				<smtp_parser_decode_quoted_printable>on</smtp_parser_decode_quoted_printable>
				<smtp_parser_extract_urls>on</smtp_parser_extract_urls>
				<smtp_parser_compute_body_md5>off</smtp_parser_compute_body_md5>
				<snmp_parser>yes</snmp_parser>
				<ssh_parser>yes</ssh_parser>
				<telnet_parser>yes</telnet_parser>
				<tftp_parser>yes</tftp_parser>
				<tls_parser>yes</tls_parser>
				<tls_detect_ports>443</tls_detect_ports>
				<tls_encrypt_handling>default</tls_encrypt_handling>
				<tls_ja3_fingerprint>off</tls_ja3_fingerprint>
				<enable_iprep>off</enable_iprep>
				<host_memcap>33554432</host_memcap>
				<host_hash_size>4096</host_hash_size>
				<host_prealloc>1000</host_prealloc>
				<host_os_policy>
					<item>
						<name>default</name>
						<bind_to>all</bind_to>
						<policy>bsd</policy>
					</item>
				</host_os_policy>
				<libhtp_policy>
					<item>
						<name>default</name>
						<bind_to>all</bind_to>
						<personality>IDS</personality>
						<request-body-limit>4096</request-body-limit>
						<response-body-limit>4096</response-body-limit>
						<double-decode-path>no</double-decode-path>
						<double-decode-query>no</double-decode-query>
						<uri-include-all>no</uri-include-all>
						<meta-field-limit>18432</meta-field-limit>
					</item>
				</libhtp_policy>
				<rulesets>emerging-attack_response.rules||emerging-botcc.portgrouped.rules||emerging-botcc.rules||ftp-events.rules||http-events.rules||emerging-coinminer.rules||http2-events.rules||emerging-compromised.rules||kerberos-events.rules||emerging-exploit.rules||smb-events.rules||smtp-events.rules||ssh-events.rules||emerging-ftp.rules||emerging-hunting.rules||emerging-icmp.rules||emerging-malware.rules||emerging-p2p.rules||emerging-phishing.rules||emerging-remote_access.rules||emerging-scan.rules||emerging-shellcode.rules||emerging-sql.rules||emerging-telnet.rules||emerging-tftp.rules||emerging-tor.rules||emerging-user_agents.rules||emerging-web_client.rules||emerging-web_server.rules||app-layer-events.rules||decoder-events.rules||dhcp-events.rules||dnp3-events.rules||dns-events.rules||files.rules||ipsec-events.rules||modbus-events.rules||mqtt-events.rules||nfs-events.rules||ntp-events.rules||quic-events.rules||rfb-events.rules||stream-events.rules||tls-events.rules</rulesets>
				<ips_policy_enable>off</ips_policy_enable>
				<autoflowbitrules>on</autoflowbitrules>
			</rule>
			<rule>
				<interface>lan</interface>
				<enable>on</enable>
				<uuid>3885</uuid>
				<descr><![CDATA[LAN]]></descr>
				<enable_verbose_logging>off</enable_verbose_logging>
				<max_pcap_log_size>32</max_pcap_log_size>
				<max_pcap_log_files>100</max_pcap_log_files>
				<pcap_log_conditional>alerts</pcap_log_conditional>
				<enable_stats_collection>off</enable_stats_collection>
				<enable_stats_log>off</enable_stats_log>
				<append_stats_log>off</append_stats_log>
				<stats_upd_interval>10</stats_upd_interval>
				<enable_telegraf_stats>off</enable_telegraf_stats>
				<enable_http_log>on</enable_http_log>
				<append_http_log>on</append_http_log>
				<enable_tls_log>off</enable_tls_log>
				<append_tls_log>on</append_tls_log>
				<enable_tls_store>off</enable_tls_store>
				<http_log_extended>on</http_log_extended>
				<tls_log_extended>on</tls_log_extended>
				<tls_session_resumption>off</tls_session_resumption>
				<enable_pcap_log>off</enable_pcap_log>
				<pcap_use_stream_depth>off</pcap_use_stream_depth>
				<pcap_honor_pass_rules>off</pcap_honor_pass_rules>
				<enable_file_store>off</enable_file_store>
				<tls_log_filetype>regular</tls_log_filetype>
				<http_log_filetype>regular</http_log_filetype>
				<runmode>autofp</runmode>
				<autofp_scheduler>hash</autofp_scheduler>
				<max_pending_packets>1024</max_pending_packets>
				<inspect_recursion_limit>3000</inspect_recursion_limit>
				<intf_snaplen>1518</intf_snaplen>
				<detect_eng_profile>medium</detect_eng_profile>
				<mpm_algo>auto</mpm_algo>
				<spm_algo>auto</spm_algo>
				<sgh_mpm_context>auto</sgh_mpm_context>
				<blockoffenders>off</blockoffenders>
				<ips_mode>ips_mode_legacy</ips_mode>
				<ips_netmap_threads>auto</ips_netmap_threads>
				<blockoffenderskill>on</blockoffenderskill>
				<block_drops_only>off</block_drops_only>
				<passlist_debug_log>off</passlist_debug_log>
				<blockoffendersip>both</blockoffendersip>
				<passlistname>default</passlistname>
				<homelistname>default</homelistname>
				<externallistname>default</externallistname>
				<suppresslistname>default</suppresslistname>
				<alertsystemlog>off</alertsystemlog>
				<alertsystemlog_facility>local0</alertsystemlog_facility>
				<alertsystemlog_priority>notice</alertsystemlog_priority>
				<enable_eve_log>on</enable_eve_log>
				<eve_output_type>regular</eve_output_type>
				<eve_systemlog_facility>syslog</eve_systemlog_facility>
				<eve_systemlog_priority>notice</eve_systemlog_priority>
				<eve_log_ethernet>no</eve_log_ethernet>
				<eve_log_alerts>on</eve_log_alerts>
				<eve_log_alerts_payload>on</eve_log_alerts_payload>
				<eve_log_alerts_packet>on</eve_log_alerts_packet>
				<eve_log_alerts_metadata>off</eve_log_alerts_metadata>
				<eve_log_alerts_http>off</eve_log_alerts_http>
				<eve_log_alerts_xff>off</eve_log_alerts_xff>
				<eve_log_alerts_xff_mode>extra-data</eve_log_alerts_xff_mode>
				<eve_log_alerts_xff_deployment>reverse</eve_log_alerts_xff_deployment>
				<eve_log_alerts_xff_header>X-Forwarded-For</eve_log_alerts_xff_header>
				<eve_log_alerts_verdict>off</eve_log_alerts_verdict>
				<eve_log_alerts_tagged>off</eve_log_alerts_tagged>
				<eve_log_drops>on</eve_log_drops>
				<eve_log_alert_drops>on</eve_log_alert_drops>
				<eve_log_drops_verdict>off</eve_log_drops_verdict>
				<eve_log_drops_flows>all</eve_log_drops_flows>
				<eve_log_anomaly>off</eve_log_anomaly>
				<eve_log_anomaly_type_decode>off</eve_log_anomaly_type_decode>
				<eve_log_anomaly_type_stream>off</eve_log_anomaly_type_stream>
				<eve_log_anomaly_type_applayer>on</eve_log_anomaly_type_applayer>
				<eve_log_anomaly_packethdr>off</eve_log_anomaly_packethdr>
				<eve_log_http>on</eve_log_http>
				<eve_log_dns>off</eve_log_dns>
				<eve_log_tls>off</eve_log_tls>
				<eve_log_dhcp>off</eve_log_dhcp>
				<eve_log_nfs>on</eve_log_nfs>
				<eve_log_smb>on</eve_log_smb>
				<eve_log_krb5>on</eve_log_krb5>
				<eve_log_ikev2>on</eve_log_ikev2>
				<eve_log_tftp>on</eve_log_tftp>
				<eve_log_bittorrent>off</eve_log_bittorrent>
				<eve_log_pgsql>off</eve_log_pgsql>
				<eve_log_quic>on</eve_log_quic>
				<eve_log_rdp>off</eve_log_rdp>
				<eve_log_sip>off</eve_log_sip>
				<eve_log_files>off</eve_log_files>
				<eve_log_ssh>off</eve_log_ssh>
				<eve_log_smtp>on</eve_log_smtp>
				<eve_log_stats>off</eve_log_stats>
				<eve_log_flow>off</eve_log_flow>
				<eve_log_netflow>off</eve_log_netflow>
				<eve_log_snmp>on</eve_log_snmp>
				<eve_log_mqtt>off</eve_log_mqtt>
				<eve_log_ftp>on</eve_log_ftp>
				<eve_log_http2>on</eve_log_http2>
				<eve_log_rfb>on</eve_log_rfb>
				<eve_log_stats_totals>on</eve_log_stats_totals>
				<eve_log_stats_deltas>off</eve_log_stats_deltas>
				<eve_log_stats_threads>off</eve_log_stats_threads>
				<eve_log_http_extended>off</eve_log_http_extended>
				<eve_log_tls_extended>off</eve_log_tls_extended>
				<eve_log_dhcp_extended>off</eve_log_dhcp_extended>
				<eve_log_smtp_extended>off</eve_log_smtp_extended>
				<eve_log_http_extended_headers>accept, accept-charset, accept-datetime, accept-encoding, accept-language, accept-range, age, allow, authorization, cache-control, connection, content-encoding, content-language, content-length, content-location, content-md5, content-range, content-type, cookie, date, dnt, etags, from, last-modified, link, location, max-forwards, origin, pragma, proxy-authenticate, proxy-authorization, range, referrer, refresh, retry-after, server, set-cookie, te, trailer, transfer-encoding, upgrade, vary, via, warning, www-authenticate, x-authenticated-user, x-flash-version, x-forwarded-proto, x-requested-with</eve_log_http_extended_headers>
				<eve_log_smtp_extended_fields>bcc, received, reply-to, x-mailer, x-originating-ip</eve_log_smtp_extended_fields>
				<eve_log_tls_extended_fields></eve_log_tls_extended_fields>
				<eve_log_files_magic>off</eve_log_files_magic>
				<eve_log_files_hash>none</eve_log_files_hash>
				<eve_log_drop>on</eve_log_drop>
				<delayed_detect>off</delayed_detect>
				<intf_promisc_mode>on</intf_promisc_mode>
				<eve_redis_server>127.0.0.1</eve_redis_server>
				<eve_redis_port>6379</eve_redis_port>
				<eve_redis_mode>list</eve_redis_mode>
				<eve_redis_key>suricata</eve_redis_key>
				<ip_max_frags>65535</ip_max_frags>
				<ip_frag_timeout>60</ip_frag_timeout>
				<frag_memcap>33554432</frag_memcap>
				<defrag_memcap_policy>ignore</defrag_memcap_policy>
				<ip_max_trackers>65535</ip_max_trackers>
				<frag_hash_size>65536</frag_hash_size>
				<flow_memcap>134217728</flow_memcap>
				<flow_memcap_policy>ignore</flow_memcap_policy>
				<flow_prealloc>10000</flow_prealloc>
				<flow_hash_size>65536</flow_hash_size>
				<flow_emerg_recovery>30</flow_emerg_recovery>
				<flow_prune>5</flow_prune>
				<flow_tcp_new_timeout>60</flow_tcp_new_timeout>
				<flow_tcp_established_timeout>3600</flow_tcp_established_timeout>
				<flow_tcp_closed_timeout>120</flow_tcp_closed_timeout>
				<flow_tcp_emerg_new_timeout>10</flow_tcp_emerg_new_timeout>
				<flow_tcp_emerg_established_timeout>300</flow_tcp_emerg_established_timeout>
				<flow_tcp_emerg_closed_timeout>20</flow_tcp_emerg_closed_timeout>
				<flow_udp_new_timeout>30</flow_udp_new_timeout>
				<flow_udp_established_timeout>300</flow_udp_established_timeout>
				<flow_udp_emerg_new_timeout>10</flow_udp_emerg_new_timeout>
				<flow_udp_emerg_established_timeout>100</flow_udp_emerg_established_timeout>
				<flow_icmp_new_timeout>30</flow_icmp_new_timeout>
				<flow_icmp_established_timeout>300</flow_icmp_established_timeout>
				<flow_icmp_emerg_new_timeout>10</flow_icmp_emerg_new_timeout>
				<flow_icmp_emerg_established_timeout>100</flow_icmp_emerg_established_timeout>
				<stream_memcap>268435456</stream_memcap>
				<stream_prealloc_sessions>32768</stream_prealloc_sessions>
				<reassembly_memcap>131217728</reassembly_memcap>
				<reassembly_depth>1048576</reassembly_depth>
				<reassembly_to_server_chunk>2560</reassembly_to_server_chunk>
				<reassembly_to_client_chunk>2560</reassembly_to_client_chunk>
				<max_synack_queued>5</max_synack_queued>
				<enable_midstream_sessions>off</enable_midstream_sessions>
				<stream_memcap_policy>ignore</stream_memcap_policy>
				<reassembly_memcap_policy>ignore</reassembly_memcap_policy>
				<midstream_policy>ignore</midstream_policy>
				<stream_checksum_validation>off</stream_checksum_validation>
				<enable_async_sessions>off</enable_async_sessions>
				<stream_bypass>off</stream_bypass>
				<stream_drop_invalid>off</stream_drop_invalid>
				<app_layer_error_policy>ignore</app_layer_error_policy>
				<asn1_max_frames>256</asn1_max_frames>
				<bittorrent_parser>yes</bittorrent_parser>
				<dcerpc_parser>yes</dcerpc_parser>
				<dhcp_parser>yes</dhcp_parser>
				<dns_global_memcap>16777216</dns_global_memcap>
				<dns_state_memcap>524288</dns_state_memcap>
				<dns_request_flood_limit>500</dns_request_flood_limit>
				<dns_parser_udp>yes</dns_parser_udp>
				<dns_parser_tcp>yes</dns_parser_tcp>
				<dns_parser_udp_ports>53</dns_parser_udp_ports>
				<dns_parser_tcp_ports>53</dns_parser_tcp_ports>
				<enip_parser>yes</enip_parser>
				<ftp_parser>yes</ftp_parser>
				<ftp_data_parser>on</ftp_data_parser>
				<http_parser>yes</http_parser>
				<http_parser_memcap>67108864</http_parser_memcap>
				<http2_parser>yes</http2_parser>
				<ikev2_parser>yes</ikev2_parser>
				<imap_parser>detection-only</imap_parser>
				<krb5_parser>yes</krb5_parser>
				<mqtt_parser>yes</mqtt_parser>
				<msn_parser>detection-only</msn_parser>
				<nfs_parser>yes</nfs_parser>
				<ntp_parser>yes</ntp_parser>
				<pgsql_parser>no</pgsql_parser>
				<quic_parser>yes</quic_parser>
				<rdp_parser>yes</rdp_parser>
				<rfb_parser>yes</rfb_parser>
				<sip_parser>yes</sip_parser>
				<smb_parser>yes</smb_parser>
				<smtp_parser>yes</smtp_parser>
				<smtp_parser_decode_mime>off</smtp_parser_decode_mime>
				<smtp_parser_decode_base64>on</smtp_parser_decode_base64>
				<smtp_parser_decode_quoted_printable>on</smtp_parser_decode_quoted_printable>
				<smtp_parser_extract_urls>on</smtp_parser_extract_urls>
				<smtp_parser_compute_body_md5>off</smtp_parser_compute_body_md5>
				<snmp_parser>yes</snmp_parser>
				<ssh_parser>yes</ssh_parser>
				<telnet_parser>yes</telnet_parser>
				<tftp_parser>yes</tftp_parser>
				<tls_parser>yes</tls_parser>
				<tls_detect_ports>443</tls_detect_ports>
				<tls_encrypt_handling>default</tls_encrypt_handling>
				<tls_ja3_fingerprint>off</tls_ja3_fingerprint>
				<enable_iprep>off</enable_iprep>
				<host_memcap>33554432</host_memcap>
				<host_hash_size>4096</host_hash_size>
				<host_prealloc>1000</host_prealloc>
				<host_os_policy>
					<item>
						<name>default</name>
						<bind_to>all</bind_to>
						<policy>bsd</policy>
					</item>
				</host_os_policy>
				<libhtp_policy>
					<item>
						<name>default</name>
						<bind_to>all</bind_to>
						<personality>IDS</personality>
						<request-body-limit>4096</request-body-limit>
						<response-body-limit>4096</response-body-limit>
						<double-decode-path>no</double-decode-path>
						<double-decode-query>no</double-decode-query>
						<uri-include-all>no</uri-include-all>
						<meta-field-limit>18432</meta-field-limit>
					</item>
				</libhtp_policy>
				<rulesets>emerging-attack_response.rules||emerging-botcc.portgrouped.rules||emerging-botcc.rules||ftp-events.rules||http-events.rules||emerging-coinminer.rules||http2-events.rules||emerging-compromised.rules||kerberos-events.rules||emerging-exploit.rules||smb-events.rules||smtp-events.rules||ssh-events.rules||emerging-ftp.rules||emerging-hunting.rules||emerging-icmp.rules||emerging-malware.rules||emerging-p2p.rules||emerging-phishing.rules||emerging-remote_access.rules||emerging-scan.rules||emerging-shellcode.rules||emerging-sql.rules||emerging-telnet.rules||emerging-tftp.rules||emerging-tor.rules||emerging-user_agents.rules||emerging-web_client.rules||emerging-web_server.rules||app-layer-events.rules||decoder-events.rules||dhcp-events.rules||dnp3-events.rules||dns-events.rules||files.rules||ipsec-events.rules||modbus-events.rules||mqtt-events.rules||nfs-events.rules||ntp-events.rules||quic-events.rules||rfb-events.rules||stream-events.rules||tls-events.rules</rulesets>
				<ips_policy_enable>off</ips_policy_enable>
				<autoflowbitrules>on</autoflowbitrules>
			</rule>
			<rule>
				<interface>opt1</interface>
				<enable>on</enable>
				<uuid>63833</uuid>
				<descr><![CDATA[DMZ]]></descr>
				<enable_verbose_logging>off</enable_verbose_logging>
				<max_pcap_log_size>32</max_pcap_log_size>
				<max_pcap_log_files>100</max_pcap_log_files>
				<pcap_log_conditional>alerts</pcap_log_conditional>
				<enable_stats_collection>off</enable_stats_collection>
				<enable_stats_log>off</enable_stats_log>
				<append_stats_log>off</append_stats_log>
				<stats_upd_interval>10</stats_upd_interval>
				<enable_telegraf_stats>off</enable_telegraf_stats>
				<enable_http_log>on</enable_http_log>
				<append_http_log>on</append_http_log>
				<enable_tls_log>off</enable_tls_log>
				<append_tls_log>on</append_tls_log>
				<enable_tls_store>off</enable_tls_store>
				<http_log_extended>on</http_log_extended>
				<tls_log_extended>on</tls_log_extended>
				<tls_session_resumption>off</tls_session_resumption>
				<enable_pcap_log>off</enable_pcap_log>
				<pcap_use_stream_depth>off</pcap_use_stream_depth>
				<pcap_honor_pass_rules>off</pcap_honor_pass_rules>
				<enable_file_store>off</enable_file_store>
				<tls_log_filetype>regular</tls_log_filetype>
				<http_log_filetype>regular</http_log_filetype>
				<runmode>autofp</runmode>
				<autofp_scheduler>hash</autofp_scheduler>
				<max_pending_packets>1024</max_pending_packets>
				<inspect_recursion_limit>3000</inspect_recursion_limit>
				<intf_snaplen>1518</intf_snaplen>
				<detect_eng_profile>medium</detect_eng_profile>
				<mpm_algo>auto</mpm_algo>
				<spm_algo>auto</spm_algo>
				<sgh_mpm_context>auto</sgh_mpm_context>
				<blockoffenders>off</blockoffenders>
				<ips_mode>ips_mode_legacy</ips_mode>
				<ips_netmap_threads>auto</ips_netmap_threads>
				<blockoffenderskill>on</blockoffenderskill>
				<block_drops_only>off</block_drops_only>
				<passlist_debug_log>off</passlist_debug_log>
				<blockoffendersip>both</blockoffendersip>
				<passlistname>default</passlistname>
				<homelistname>default</homelistname>
				<externallistname>default</externallistname>
				<suppresslistname>default</suppresslistname>
				<alertsystemlog>off</alertsystemlog>
				<alertsystemlog_facility>local0</alertsystemlog_facility>
				<alertsystemlog_priority>notice</alertsystemlog_priority>
				<enable_eve_log>on</enable_eve_log>
				<eve_output_type>regular</eve_output_type>
				<eve_systemlog_facility>syslog</eve_systemlog_facility>
				<eve_systemlog_priority>notice</eve_systemlog_priority>
				<eve_log_ethernet>no</eve_log_ethernet>
				<eve_log_alerts>on</eve_log_alerts>
				<eve_log_alerts_payload>on</eve_log_alerts_payload>
				<eve_log_alerts_packet>on</eve_log_alerts_packet>
				<eve_log_alerts_metadata>off</eve_log_alerts_metadata>
				<eve_log_alerts_http>off</eve_log_alerts_http>
				<eve_log_alerts_xff>off</eve_log_alerts_xff>
				<eve_log_alerts_xff_mode>extra-data</eve_log_alerts_xff_mode>
				<eve_log_alerts_xff_deployment>reverse</eve_log_alerts_xff_deployment>
				<eve_log_alerts_xff_header>X-Forwarded-For</eve_log_alerts_xff_header>
				<eve_log_alerts_verdict>off</eve_log_alerts_verdict>
				<eve_log_alerts_tagged>off</eve_log_alerts_tagged>
				<eve_log_drops>on</eve_log_drops>
				<eve_log_alert_drops>off</eve_log_alert_drops>
				<eve_log_drops_verdict>off</eve_log_drops_verdict>
				<eve_log_drops_flows>all</eve_log_drops_flows>
				<eve_log_anomaly>off</eve_log_anomaly>
				<eve_log_anomaly_type_decode>off</eve_log_anomaly_type_decode>
				<eve_log_anomaly_type_stream>off</eve_log_anomaly_type_stream>
				<eve_log_anomaly_type_applayer>on</eve_log_anomaly_type_applayer>
				<eve_log_anomaly_packethdr>off</eve_log_anomaly_packethdr>
				<eve_log_http>on</eve_log_http>
				<eve_log_dns>off</eve_log_dns>
				<eve_log_tls>off</eve_log_tls>
				<eve_log_dhcp>off</eve_log_dhcp>
				<eve_log_nfs>on</eve_log_nfs>
				<eve_log_smb>on</eve_log_smb>
				<eve_log_krb5>on</eve_log_krb5>
				<eve_log_ikev2>on</eve_log_ikev2>
				<eve_log_tftp>on</eve_log_tftp>
				<eve_log_bittorrent>off</eve_log_bittorrent>
				<eve_log_pgsql>off</eve_log_pgsql>
				<eve_log_quic>on</eve_log_quic>
				<eve_log_rdp>off</eve_log_rdp>
				<eve_log_sip>off</eve_log_sip>
				<eve_log_files>off</eve_log_files>
				<eve_log_ssh>off</eve_log_ssh>
				<eve_log_smtp>on</eve_log_smtp>
				<eve_log_stats>off</eve_log_stats>
				<eve_log_flow>off</eve_log_flow>
				<eve_log_netflow>off</eve_log_netflow>
				<eve_log_snmp>on</eve_log_snmp>
				<eve_log_mqtt>off</eve_log_mqtt>
				<eve_log_ftp>on</eve_log_ftp>
				<eve_log_http2>on</eve_log_http2>
				<eve_log_rfb>on</eve_log_rfb>
				<eve_log_stats_totals>on</eve_log_stats_totals>
				<eve_log_stats_deltas>off</eve_log_stats_deltas>
				<eve_log_stats_threads>off</eve_log_stats_threads>
				<eve_log_http_extended>on</eve_log_http_extended>
				<eve_log_tls_extended>off</eve_log_tls_extended>
				<eve_log_dhcp_extended>off</eve_log_dhcp_extended>
				<eve_log_smtp_extended>off</eve_log_smtp_extended>
				<eve_log_http_extended_headers>accept, accept-charset, accept-datetime, accept-encoding, accept-language, accept-range, age, allow, authorization, cache-control, connection, content-encoding, content-language, content-length, content-location, content-md5, content-range, content-type, cookie, date, dnt, etags, from, last-modified, link, location, max-forwards, origin, pragma, proxy-authenticate, proxy-authorization, range, referrer, refresh, retry-after, server, set-cookie, te, trailer, transfer-encoding, upgrade, vary, via, warning, www-authenticate, x-authenticated-user, x-flash-version, x-forwarded-proto, x-requested-with</eve_log_http_extended_headers>
				<eve_log_smtp_extended_fields>bcc, received, reply-to, x-mailer, x-originating-ip</eve_log_smtp_extended_fields>
				<eve_log_tls_extended_fields></eve_log_tls_extended_fields>
				<eve_log_files_magic>off</eve_log_files_magic>
				<eve_log_files_hash>none</eve_log_files_hash>
				<eve_log_drop>on</eve_log_drop>
				<delayed_detect>off</delayed_detect>
				<intf_promisc_mode>on</intf_promisc_mode>
				<eve_redis_server>127.0.0.1</eve_redis_server>
				<eve_redis_port>6379</eve_redis_port>
				<eve_redis_mode>list</eve_redis_mode>
				<eve_redis_key>suricata</eve_redis_key>
				<ip_max_frags>65535</ip_max_frags>
				<ip_frag_timeout>60</ip_frag_timeout>
				<frag_memcap>33554432</frag_memcap>
				<defrag_memcap_policy>ignore</defrag_memcap_policy>
				<ip_max_trackers>65535</ip_max_trackers>
				<frag_hash_size>65536</frag_hash_size>
				<flow_memcap>134217728</flow_memcap>
				<flow_memcap_policy>ignore</flow_memcap_policy>
				<flow_prealloc>10000</flow_prealloc>
				<flow_hash_size>65536</flow_hash_size>
				<flow_emerg_recovery>30</flow_emerg_recovery>
				<flow_prune>5</flow_prune>
				<flow_tcp_new_timeout>60</flow_tcp_new_timeout>
				<flow_tcp_established_timeout>3600</flow_tcp_established_timeout>
				<flow_tcp_closed_timeout>120</flow_tcp_closed_timeout>
				<flow_tcp_emerg_new_timeout>10</flow_tcp_emerg_new_timeout>
				<flow_tcp_emerg_established_timeout>300</flow_tcp_emerg_established_timeout>
				<flow_tcp_emerg_closed_timeout>20</flow_tcp_emerg_closed_timeout>
				<flow_udp_new_timeout>30</flow_udp_new_timeout>
				<flow_udp_established_timeout>300</flow_udp_established_timeout>
				<flow_udp_emerg_new_timeout>10</flow_udp_emerg_new_timeout>
				<flow_udp_emerg_established_timeout>100</flow_udp_emerg_established_timeout>
				<flow_icmp_new_timeout>30</flow_icmp_new_timeout>
				<flow_icmp_established_timeout>300</flow_icmp_established_timeout>
				<flow_icmp_emerg_new_timeout>10</flow_icmp_emerg_new_timeout>
				<flow_icmp_emerg_established_timeout>100</flow_icmp_emerg_established_timeout>
				<stream_memcap>268435456</stream_memcap>
				<stream_prealloc_sessions>32768</stream_prealloc_sessions>
				<reassembly_memcap>131217728</reassembly_memcap>
				<reassembly_depth>1048576</reassembly_depth>
				<reassembly_to_server_chunk>2560</reassembly_to_server_chunk>
				<reassembly_to_client_chunk>2560</reassembly_to_client_chunk>
				<max_synack_queued>5</max_synack_queued>
				<enable_midstream_sessions>off</enable_midstream_sessions>
				<stream_memcap_policy>ignore</stream_memcap_policy>
				<reassembly_memcap_policy>ignore</reassembly_memcap_policy>
				<midstream_policy>ignore</midstream_policy>
				<stream_checksum_validation>off</stream_checksum_validation>
				<enable_async_sessions>off</enable_async_sessions>
				<stream_bypass>off</stream_bypass>
				<stream_drop_invalid>off</stream_drop_invalid>
				<app_layer_error_policy>ignore</app_layer_error_policy>
				<asn1_max_frames>256</asn1_max_frames>
				<bittorrent_parser>yes</bittorrent_parser>
				<dcerpc_parser>yes</dcerpc_parser>
				<dhcp_parser>yes</dhcp_parser>
				<dns_global_memcap>16777216</dns_global_memcap>
				<dns_state_memcap>524288</dns_state_memcap>
				<dns_request_flood_limit>500</dns_request_flood_limit>
				<dns_parser_udp>yes</dns_parser_udp>
				<dns_parser_tcp>yes</dns_parser_tcp>
				<dns_parser_udp_ports>53</dns_parser_udp_ports>
				<dns_parser_tcp_ports>53</dns_parser_tcp_ports>
				<enip_parser>yes</enip_parser>
				<ftp_parser>yes</ftp_parser>
				<ftp_data_parser>on</ftp_data_parser>
				<http_parser>yes</http_parser>
				<http_parser_memcap>67108864</http_parser_memcap>
				<http2_parser>yes</http2_parser>
				<ikev2_parser>yes</ikev2_parser>
				<imap_parser>detection-only</imap_parser>
				<krb5_parser>yes</krb5_parser>
				<mqtt_parser>yes</mqtt_parser>
				<msn_parser>detection-only</msn_parser>
				<nfs_parser>yes</nfs_parser>
				<ntp_parser>yes</ntp_parser>
				<pgsql_parser>no</pgsql_parser>
				<quic_parser>yes</quic_parser>
				<rdp_parser>yes</rdp_parser>
				<rfb_parser>yes</rfb_parser>
				<sip_parser>yes</sip_parser>
				<smb_parser>yes</smb_parser>
				<smtp_parser>yes</smtp_parser>
				<smtp_parser_decode_mime>off</smtp_parser_decode_mime>
				<smtp_parser_decode_base64>on</smtp_parser_decode_base64>
				<smtp_parser_decode_quoted_printable>on</smtp_parser_decode_quoted_printable>
				<smtp_parser_extract_urls>on</smtp_parser_extract_urls>
				<smtp_parser_compute_body_md5>off</smtp_parser_compute_body_md5>
				<snmp_parser>yes</snmp_parser>
				<ssh_parser>yes</ssh_parser>
				<telnet_parser>yes</telnet_parser>
				<tftp_parser>yes</tftp_parser>
				<tls_parser>yes</tls_parser>
				<tls_detect_ports>443</tls_detect_ports>
				<tls_encrypt_handling>default</tls_encrypt_handling>
				<tls_ja3_fingerprint>off</tls_ja3_fingerprint>
				<enable_iprep>off</enable_iprep>
				<host_memcap>33554432</host_memcap>
				<host_hash_size>4096</host_hash_size>
				<host_prealloc>1000</host_prealloc>
				<host_os_policy>
					<item>
						<name>default</name>
						<bind_to>all</bind_to>
						<policy>bsd</policy>
					</item>
				</host_os_policy>
				<libhtp_policy>
					<item>
						<name>default</name>
						<bind_to>all</bind_to>
						<personality>IDS</personality>
						<request-body-limit>4096</request-body-limit>
						<response-body-limit>4096</response-body-limit>
						<double-decode-path>no</double-decode-path>
						<double-decode-query>no</double-decode-query>
						<uri-include-all>no</uri-include-all>
						<meta-field-limit>18432</meta-field-limit>
					</item>
				</libhtp_policy>
				<rulesets>app-layer-events.rules||decoder-events.rules||dhcp-events.rules||emerging-attack_response.rules||dnp3-events.rules||emerging-botcc.portgrouped.rules||dns-events.rules||emerging-botcc.rules||files.rules||ftp-events.rules||http-events.rules||emerging-coinminer.rules||http2-events.rules||emerging-compromised.rules||ipsec-events.rules||kerberos-events.rules||modbus-events.rules||mqtt-events.rules||nfs-events.rules||ntp-events.rules||quic-events.rules||rfb-events.rules||emerging-exploit.rules||smb-events.rules||smtp-events.rules||emerging-file_sharing.rules||ssh-events.rules||emerging-ftp.rules||stream-events.rules||tls-events.rules||emerging-hunting.rules||emerging-icmp.rules||emerging-info.rules||emerging-malware.rules||emerging-netbios.rules||emerging-p2p.rules||emerging-phishing.rules||emerging-remote_access.rules||emerging-scan.rules||emerging-shellcode.rules||emerging-smtp.rules||emerging-snmp.rules||emerging-sql.rules||emerging-telnet.rules||emerging-tftp.rules||emerging-tor.rules||emerging-user_agents.rules||emerging-web_client.rules||emerging-web_server.rules</rulesets>
				<ips_policy_enable>off</ips_policy_enable>
				<autoflowbitrules>on</autoflowbitrules>
			</rule>
		</suricata>
		<menu>
			<name>Suricata</name>
			<tooltiptext>Configure Suricata settings</tooltiptext>
			<section>Services</section>
			<url>/suricata/suricata_interfaces.php</url>
		</menu>
		<menu>
			<name>Cron</name>
			<section>Services</section>
			<configfile>cron.xml</configfile>
			<url>/packages/cron/cron.php</url>
		</menu>
		<service>
			<name>suricata</name>
			<rcfile>suricata.sh</rcfile>
			<executable>suricata</executable>
			<description><![CDATA[Suricata IDS/IPS Daemon]]></description>
		</service>
	</installedpackages>
	<dhcpbackend>isc</dhcpbackend>
	<sshdata>
		<!-- SSH PRIVATE KEYS REMOVED - pfSense WILL REGENERATE THEM AUTOMATICALLY ON FIRST BOOT -->
		<!-- Only public keys are kept for reference -->
		<sshkeyfile>
			<filename>ssh_host_rsa_key</filename>
			<!-- PRIVATE KEY REMOVED - pfSense WILL REGENERATE IT AUTOMATICALLY -->
			<xmldata></xmldata>
		</sshkeyfile>
		<sshkeyfile>
			<filename>ssh_host_rsa_key.pub</filename>
			<xmldata>FZG3kptQAAB7f8X1jE0UoOJm/Mgi59Q9kkCIHAR8vc/b7Gy9y1L/nhf4BX7gSPOCPH7mhPg/BeAA7sc8cIRIMFu0qmFpuzdeJ84mGp97cGqlohXHYQKZMLeyiotBtggP4ipnGQImIdfemT6VoamUNumbP63a0Vm+I05pejvMreFfqOgy9fbpAl+Nt5Ilq87XUHmSsDcTXSQJ2nuwahO5OCMfZXfauRVY7TpEgMdh9doxyYBkMPpZ1DR+2Iaa3p9j4TKjMaHHh1PWYqgwVjMxtJdkeWwIhBkONndoCXvZO5/qm6lxhyc24J0b+G4SN3QFzHogo2w6NZoLZXQm6gR9ka+4frJjGUwKdQzLqy+RZwnyDMXfkUQ1utZF2hPCadeLJqTw1RPgpydANq4Anvj2mdksfLx64irn6yJ2kZcY+qSAiIcPx6yFNMHsc35R6IXom+4uwlUxQSuSXEUbxEN0MfqqxHnO60TxwbwciCJEYXzt7WAlyJY9TGXrcDYZArV2+ipvZhLJtU09sEnEUvQeoxkJGIGCRk62ZCt7U9HuyJNmifdnMRdmo8S5EJKKmVVpiGRr5814zeiaQyx2Oz6sRdANK5bKXDsNfX9wbr9N+8WgoxeqqD8oNMWE2vvAXqOAeVVyZ1wDO2n5dlN+psKNrmJ0sgssNVzOqtOysul2TCuSSicl4egyJVkfnl6f56qrTrptcY9AHOkSUHVw6s6goOBEztW3fSdFNOZ66s3deF1sAeZelrurvbwNLloOqW78fH9/zcOw/h2rpeyX8g2zP/XQlX/gPMJf/wA=</xmldata>
		</sshkeyfile>
		<sshkeyfile>
			<filename>ssh_host_ed25519_key</filename>
			<!-- PRIVATE KEY REMOVED - pfSense WILL REGENERATE IT AUTOMATICALLY -->
			<xmldata></xmldata>
		</sshkeyfile>
		<sshkeyfile>
			<filename>ssh_host_ed25519_key.pub</filename>
			<xmldata>Ky7O0E1NMTI1NbRUcAQCZ2O/qkRnw5woF09DvxBXU5CYp3NBboG7p3GxmWOal5FlgG9STpFxQYi7Y7p2mXaOr79nqpNZfrh3YlB6YZVCUX5+iUNBWnFqXnFqTmKSXkZ+bqpeYlFBIhcA</xmldata>
		</sshkeyfile>
	</sshdata>
</pfsense>
