<?xml version="1.0"?>
<m0n0wall>
	<version>1.11</version>
	<system>
		<hostname>m0n0wall</hostname>
		<domain>spaloss.net</domain>
		<dnsallowoverride/>
		<username>admin</username>
		<password>xxxxxxxxxxx</password>
		<timezone>America/New_York</timezone>
		<time-update-interval>300</time-update-interval>
		<timeservers>sundial.columbia.edu</timeservers>
		<webgui>
			<protocol>http</protocol>
			<port/>
			<certificate/>
			<private-key/>
		</webgui>
		<dnsserver>68.39.224.5</dnsserver>
		<dnsserver>68.39.224.7</dnsserver>
	</system>
	<interfaces>
		<lan>
			<if>dc0</if>
			<ipaddr>10.3.0.4</ipaddr>
			<subnet>24</subnet>
		</lan>
		<wan>
			<if>rl0</if>
			<mtu/>
			<spoofmac/>
			<ipaddr>dhcp</ipaddr>
			<dhcphostname/>
			<blockpriv/>
		</wan>
		<opt1>
			<descr>WLAN</descr>
			<if>rl1</if>
			<ipaddr>10.3.1.1</ipaddr>
			<subnet>24</subnet>
			<bridge/>
			<enable/>
		</opt1>
	</interfaces>
	<staticroutes>
		<route>
			<interface>opt1</interface>
			<network>10.3.0.0/24</network>
			<gateway>10.3.1.1</gateway>
			<descr>WLAN to LAN</descr>
		</route>
		<route>
			<interface>lan</interface>
			<network>10.3.1.0/24</network>
			<gateway>10.3.0.4</gateway>
			<descr>LAN to WLAN</descr>
		</route>
	</staticroutes>
	<pppoe/>
	<pptp/>
	<bigpond/>
	<dyndns>
		<type>dyndns-custom</type>
		<username>xxxxxxxx</username>
		<password>xxxxxxxx</password>
		<host>xxxxxxxxx</host>
		<mx/>
		<wildcard/>
		<enable/>
	</dyndns>
	<dhcpd>
		<lan>
			<range>
				<from>192.168.1.100</from>
				<to>192.168.1.199</to>
			</range>
		</lan>
		<opt1>
			<range>
				<from>10.3.1.100</from>
				<to>10.3.1.200</to>
			</range>
			<defaultleasetime>7200</defaultleasetime>
			<maxleasetime>86400</maxleasetime>
			<enable/>
		</opt1>
	</dhcpd>
	<pptpd>
		<mode>redir</mode>
		<redir>10.3.0.1</redir>
		<localip/>
		<remoteip/>
		<radius>
			<server/>
			<secret/>
		</radius>
	</pptpd>
	<dnsmasq>
		<enable/>
		<hosts>
			<host>betaserver</host>
			<domain>spaloss.net</domain>
			<ip>10.3.0.1</ip>
			<descr>Spaloss.net</descr>
		</hosts>
	</dnsmasq>
	<snmpd>
		<syslocation/>
		<syscontact/>
		<rocommunity>public</rocommunity>
		<enable/>
	</snmpd>
	<diag>
		<ipv6nat>
			<ipaddr/>
		</ipv6nat>
	</diag>
	<bridge/>
	<syslog>
		<reverse/>
		<nentries>200</nentries>
		<remoteserver>10.3.0.5</remoteserver>
		<filter/>
		<dhcp/>
		<system/>
	</syslog>
	<nat>
		<rule>
			<protocol>tcp</protocol>
			<external-port>80</external-port>
			<target>10.3.0.1</target>
			<local-port>80</local-port>
			<interface>wan</interface>
			<descr>HTTP Spaloss.net</descr>
		</rule>
		<rule>
			<protocol>tcp</protocol>
			<external-port>443</external-port>
			<target>10.3.0.1</target>
			<local-port>443</local-port>
			<interface>wan</interface>
			<descr>HTTPs Spaloss.net DEV Server</descr>
		</rule>
		<rule>
			<protocol>tcp</protocol>
			<external-port>21</external-port>
			<target>10.3.0.1</target>
			<local-port>21</local-port>
			<interface>wan</interface>
			<descr>FTP to Spaloss.net</descr>
		</rule>
		<rule>
			<protocol>tcp</protocol>
			<external-port>3389</external-port>
			<target>10.3.0.1</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>Terminal Services</descr>
		</rule>
		<rule>
			<protocol>tcp</protocol>
			<external-port>5500-5510</external-port>
			<target>10.3.0.1</target>
			<local-port>5500</local-port>
			<interface>wan</interface>
			<descr>Passive FTP Range Spaloss.net</descr>
		</rule>
		<rule>
			<protocol>tcp</protocol>
			<external-port>6881</external-port>
			<target>10.3.0.1</target>
			<local-port>6881</local-port>
			<interface>wan</interface>
			<descr>Bit Torrent</descr>
		</rule>
		<rule>
			<protocol>tcp</protocol>
			<external-port>8080</external-port>
			<target>10.3.0.1</target>
			<local-port>8080</local-port>
			<interface>wan</interface>
			<descr>HTTP Spaloss.net DEV Server</descr>
		</rule>
	</nat>
	<filter>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>1723</port>
			</destination>
			<descr>PPTP to Betaserver</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>80</port>
			</destination>
			<descr>HTTP Spaloss.net</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>8080</port>
			</destination>
			<descr>HTTP Spaloss.net DEV Server</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>443</port>
			</destination>
			<descr>HTTPs Spaloss.net DEV Server</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>3389</port>
			</destination>
			<disabled/>
			<descr>NAT Terminal Services</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>21</port>
			</destination>
			<disabled/>
			<descr>FTP to Betaserver</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>5500-5510</port>
			</destination>
			<disabled/>
			<descr>Passive FTP Range to Spaloss.net</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>6881</port>
			</destination>
			<disabled/>
			<descr>NAT Bit Torrent</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>opt1</interface>
			<protocol>gre</protocol>
			<source>
				<network>opt1</network>
			</source>
			<destination>
				<address>10.3.0.1</address>
			</destination>
			<descr>Pass PPTP (GRE) traffic to LAN</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>opt1</interface>
			<protocol>tcp</protocol>
			<source>
				<network>opt1</network>
			</source>
			<destination>
				<address>10.3.0.1</address>
				<port>1723</port>
			</destination>
			<descr>Pass PPTP (TCP) traffic to LAN</descr>
		</rule>
		<rule>
			<type>block</type>
			<interface>opt1</interface>
			<source>
				<any/>
			</source>
			<destination>
				<network>lan</network>
			</destination>
			<descr>Block WLAN traffic to LAN</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>opt1</interface>
			<source>
				<network>opt1</network>
			</source>
			<destination>
				<network>lan</network>
				<not/>
			</destination>
			<descr>Allow WLAN to any *BUT* LAN</descr>
		</rule>
		<rule>
			<type>pass</type>
			<descr>Default LAN -&gt; any</descr>
			<interface>lan</interface>
			<source>
				<network>lan</network>
			</source>
			<destination>
				<any/>
			</destination>
		</rule>
	</filter>
	<ipsec>
		<mobilekey>
			<ident>pcc.net</ident>
			<pre-shared-key>xxxxxxxxxxx</pre-shared-key>
		</mobilekey>
		<tunnel>
			<interface>wan</interface>
			<local-subnet>
				<network>lan</network>
			</local-subnet>
			<remote-subnet>192.168.3.0/24</remote-subnet>
			<remote-gateway>xxx.xxx.xxx.xxx/xx</remote-gateway>
			<p1>
				<mode>aggressive</mode>
				<myident>
					<address>xxx.xxx.xxx.xxx</address>
				</myident>
				<encryption-algorithm>blowfish</encryption-algorithm>
				<hash-algorithm>sha1</hash-algorithm>
				<dhgroup>2</dhgroup>
				<lifetime>28800</lifetime>
				<pre-shared-key>xxxxxxxxx</pre-shared-key>
			</p1>
			<p2>
				<protocol>esp</protocol>
				<encryption-algorithm-option>blowfish</encryption-algorithm-option>
				<hash-algorithm-option>hmac_sha1</hash-algorithm-option>
				<pfsgroup>2</pfsgroup>
				<lifetime>86400</lifetime>
			</p2>
			<descr>pcc.net</descr>
		</tunnel>
		<enable/>
	</ipsec>
	<aliases>
		<alias>
			<name>betaserver</name>
			<address>10.3.0.1</address>
			<descr>Betaserver</descr>
		</alias>
		<alias>
			<name>PCC</name>
			<address>192.168.3.0/24</address>
			<descr>Personal Computer Care</descr>
		</alias>
	</aliases>
	<proxyarp/>
	<wol>
		<wolentry>
			<interface>lan</interface>
			<mac>00:40:F4:1E:E8:23</mac>
			<descr>Jim-WS</descr>
		</wolentry>
	</wol>
	<shaper>
		<pipe>
			<descr>m_Total Upload</descr>
			<bandwidth>230</bandwidth>
		</pipe>
		<pipe>
			<descr>m_Total Download</descr>
			<bandwidth>2850</bandwidth>
		</pipe>
		<queue>
			<descr>m_High Priority #1 Upload</descr>
			<targetpipe>0</targetpipe>
			<weight>50</weight>
		</queue>
		<queue>
			<descr>m_High Priority #2 Upload</descr>
			<targetpipe>0</targetpipe>
			<weight>30</weight>
		</queue>
		<queue>
			<descr>m_High Priority #3 Upload</descr>
			<targetpipe>0</targetpipe>
			<weight>15</weight>
		</queue>
		<queue>
			<descr>m_Bulk Upload</descr>
			<targetpipe>0</targetpipe>
			<weight>4</weight>
		</queue>
		<queue>
			<descr>m_Hated Upload</descr>
			<targetpipe>0</targetpipe>
			<weight>1</weight>
		</queue>
		<queue>
			<descr>m_Bulk Download</descr>
			<targetpipe>1</targetpipe>
			<weight>30</weight>
		</queue>
		<queue>
			<descr>m_Hated Download</descr>
			<targetpipe>1</targetpipe>
			<weight>10</weight>
		</queue>
		<queue>
			<descr>m_High Priority Download</descr>
			<targetpipe>1</targetpipe>
			<weight>60</weight>
		</queue>
		<rule>
			<interface>wan</interface>
			<source>
				<address>10.3.0.6</address>
			</source>
			<destination>
				<any/>
			</destination>
			<direction>out</direction>
			<iplen>0-100</iplen>
			<iptos>lowdelay,throughput,reliability,mincost,congestion</iptos>
			<tcpflags/>
			<descr>VoIP Upload</descr>
			<targetqueue>0</targetqueue>
		</rule>
		<rule>
			<descr>m_Small Pkt Upload</descr>
			<targetqueue>0</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<iplen>0-100</iplen>
		</rule>
		<rule>
			<descr>m_Outbound DNS Query</descr>
			<targetqueue>0</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
				<port>53</port>
			</destination>
			<protocol>udp</protocol>
		</rule>
		<rule>
			<descr>m_AH Upload</descr>
			<targetqueue>0</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>ah</protocol>
		</rule>
		<rule>
			<descr>m_ESP Upload</descr>
			<targetqueue>0</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>esp</protocol>
		</rule>
		<rule>
			<descr>m_GRE Upload</descr>
			<targetqueue>0</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>gre</protocol>
		</rule>
		<rule>
			<descr>m_ICMP Upload</descr>
			<targetqueue>1</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>icmp</protocol>
		</rule>
		<rule>
			<descr>m_TCP ACK Upload</descr>
			<targetqueue>2</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<iplen>0-80</iplen>
			<protocol>tcp</protocol>
			<tcpflags>ack</tcpflags>
		</rule>
		<rule>
			<descr>m_Catch-All Upload</descr>
			<targetqueue>3</targetqueue>
			<interface>wan</interface>
			<direction>out</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
		</rule>
		<rule>
			<interface>wan</interface>
			<source>
				<any/>
			</source>
			<destination>
				<address>10.3.0.6</address>
			</destination>
			<direction>in</direction>
			<iplen/>
			<iptos>lowdelay,throughput,reliability,mincost,congestion</iptos>
			<tcpflags/>
			<descr>VoIP Download</descr>
			<targetqueue>7</targetqueue>
		</rule>
		<rule>
			<descr>m_ICMP Download</descr>
			<targetqueue>7</targetqueue>
			<interface>wan</interface>
			<direction>in</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>icmp</protocol>
		</rule>
		<rule>
			<descr>m_Small Pkt Download</descr>
			<targetqueue>7</targetqueue>
			<interface>wan</interface>
			<direction>in</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<iplen>0-100</iplen>
		</rule>
		<rule>
			<descr>m_AH Download</descr>
			<targetqueue>7</targetqueue>
			<interface>wan</interface>
			<direction>in</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>ah</protocol>
		</rule>
		<rule>
			<descr>m_ESP Download</descr>
			<targetqueue>7</targetqueue>
			<interface>wan</interface>
			<direction>in</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>esp</protocol>
		</rule>
		<rule>
			<descr>m_GRE Download</descr>
			<targetqueue>7</targetqueue>
			<interface>wan</interface>
			<direction>in</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<protocol>gre</protocol>
		</rule>
		<rule>
			<descr>m_Catch-All Download</descr>
			<targetqueue>5</targetqueue>
			<interface>wan</interface>
			<direction>in</direction>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
		</rule>
		<magic>
			<maxup>256</maxup>
			<maxdown>3000</maxdown>
		</magic>
		<enable/>
	</shaper>
</m0n0wall>
