<?xml version="1.0"?>
<pfsense>
	<version>3.0</version>
	<lastchange/>
	<theme>nervecenter</theme>
	<system>
		<optimization>normal</optimization>
		<hostname>pfsense</hostname>
		<domain>local</domain>
		<username>admin</username>
		<password>$1$DN5aReUV$VMRmGuwDa1lCvu2Ff5X751</password>
		<timezone>Etc/UTC</timezone>
		<time-update-interval/>
		<timeservers>0.pfsense.pool.ntp.org</timeservers>
		<webgui>
			<protocol>http</protocol>
			<port/>
			<certificate/>
			<private-key/>
		</webgui>
		<disablenatreflection>yes</disablenatreflection>
		<dnsserver>151.99.125.2</dnsserver>
		<dnsallowoverride/>
		<ssh>
			<authorizedkeys/>
			<port/>
		</ssh>
		<enablesshd>yes</enablesshd>
		<maximumstates/>
		<shapertype/>
	</system>
	<interfaces>
		<lan>
			<if>em0</if>
			<ipaddr>192.168.50.69</ipaddr>
			<subnet>24</subnet>
			<media/>
			<mediaopt/>
			<bandwidth>100</bandwidth>
			<bandwidthtype>Mb</bandwidthtype>
			<bridge/>
		</lan>
		<wan>
			<if>xl0</if>
			<mtu/>
			<blockpriv/>
			<blockbogons/>
			<media/>
			<mediaopt/>
			<bandwidth>100</bandwidth>
			<bandwidthtype>Mb</bandwidthtype>
			<disableftpproxy/>
			<ipaddr>80.18.75.234</ipaddr>
			<subnet>29</subnet>
			<gateway>80.18.75.233</gateway>
			<spoofmac/>
		</wan>
		<opt1>
			<if>fxp0</if>
			<descr>ICMS</descr>
			<bridge/>
			<enable/>
			<ipaddr>192.168.69.254</ipaddr>
			<subnet>24</subnet>
			<gateway/>
			<spoofmac/>
			<mtu/>
		</opt1>
		<opt2>
			<descr>DMZ</descr>
			<if>fxp1</if>
			<bridge/>
			<ipaddr>192.168.71.254</ipaddr>
			<subnet>24</subnet>
			<gateway/>
			<spoofmac/>
			<mtu/>
			<enable/>
		</opt2>
	</interfaces>
	<staticroutes>
		<route>
			<interface>lan</interface>
			<network>192.168.100.0/24</network>
			<gateway>192.168.50.254</gateway>
			<descr>Rete Milano - VPN Altevie</descr>
		</route>
		<route>
			<interface>lan</interface>
			<network>192.168.39.0/24</network>
			<gateway>192.168.50.254</gateway>
			<descr>Rete Roma - VPN Altevie</descr>
		</route>
	</staticroutes>
	<pppoe>
		<username/>
		<password/>
		<provider/>
	</pppoe>
	<pptp>
		<username/>
		<password/>
		<local/>
		<subnet/>
		<remote/>
	</pptp>
	<bigpond>
		<username/>
		<password/>
		<authserver/>
		<authdomain/>
		<minheartbeatinterval/>
	</bigpond>
	<dyndns>
		<type>dyndns</type>
		<username/>
		<password/>
		<host/>
		<mx/>
	</dyndns>
	<dhcpd>
		<lan>
			<range>
				<from>192.168.1.100</from>
				<to>192.168.1.199</to>
			</range>
		</lan>
		<opt1>
			<range>
				<from>192.168.69.100</from>
				<to>192.168.69.199</to>
			</range>
			<defaultleasetime/>
			<maxleasetime/>
			<netmask/>
			<failover_peerip/>
			<gateway>192.168.69.254</gateway>
			<ddnsdomain/>
			<next-server/>
			<filename/>
			<dnsserver>151.99.125.2</dnsserver>
			<dnsserver>192.168.50.57</dnsserver>
		</opt1>
	</dhcpd>
	<pptpd>
		<mode/>
		<redir/>
		<localip/>
		<remoteip/>
	</pptpd>
	<ovpn/>
	<dnsmasq>
		<enable/>
	</dnsmasq>
	<snmpd>
		<syslocation/>
		<syscontact/>
		<rocommunity>public</rocommunity>
	</snmpd>
	<diag>
		<ipv6nat/>
	</diag>
	<bridge/>
	<syslog/>
	<nat>
		<ipsecpassthru/>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>80</external-port>
			<target>192.168.69.22</target>
			<local-port>80</local-port>
			<interface>wan</interface>
			<descr>Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>3389</external-port>
			<target>192.168.69.22</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>3390</external-port>
			<target>192.168.69.19</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>3391</external-port>
			<target>192.168.69.18</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>RDP .18</descr>
		</rule>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>3392</external-port>
			<target>192.168.69.26</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>RDP .26 per BC Piergiorgio Roman</descr>
		</rule>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>3393</external-port>
			<target>192.168.69.49</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>RDP .26 per BC Piergiorgio Roman</descr>
		</rule>
		<rule>
			<external-address>80.18.75.237</external-address>
			<protocol>tcp</protocol>
			<external-port>3394</external-port>
			<target>192.168.69.48</target>
			<local-port>3389</local-port>
			<interface>wan</interface>
			<descr>RDP .26 per BC Piergiorgio Roman</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>80</external-port>
			<target>192.168.71.15</target>
			<local-port>80</local-port>
			<interface>wan</interface>
			<descr>ICMS NAT per WAR</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>54000</external-port>
			<target>192.168.71.61</target>
			<local-port>54000</local-port>
			<interface>wan</interface>
			<descr>Espedia NAT PPM j2ee</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>51000</external-port>
			<target>192.168.71.61</target>
			<local-port>51000</local-port>
			<interface>wan</interface>
			<descr>Espedia NAT EID j2ee</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>8080</external-port>
			<target>192.168.71.61</target>
			<local-port>8080</local-port>
			<interface>wan</interface>
			<descr>Espedia NAT WebServer</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>8010</external-port>
			<target>192.168.71.61</target>
			<local-port>8010</local-port>
			<interface>wan</interface>
			<descr>Espedia NAT EID Webservices</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>8040</external-port>
			<target>192.168.71.61</target>
			<local-port>8040</local-port>
			<interface>wan</interface>
			<descr>Espedia NAT PPM Webservices</descr>
		</rule>
		<rule>
			<external-address>80.18.75.238</external-address>
			<protocol>tcp/udp</protocol>
			<external-port>80</external-port>
			<target>192.168.69.4</target>
			<local-port>80</local-port>
			<interface>wan</interface>
			<descr>ICMS Solman WebDispatcher</descr>
		</rule>
		<rule>
			<external-address>80.18.75.238</external-address>
			<protocol>tcp/udp</protocol>
			<external-port>3299</external-port>
			<target>192.168.69.4</target>
			<local-port>3299</local-port>
			<interface>wan</interface>
			<descr>ICMS Saprouter</descr>
		</rule>
		<rule>
			<external-address>80.18.75.238</external-address>
			<protocol>tcp/udp</protocol>
			<external-port>8100</external-port>
			<target>192.168.69.4</target>
			<local-port>8100</local-port>
			<interface>wan</interface>
			<descr>ICMS Solman WebDispatcher 8100</descr>
		</rule>
		<rule>
			<external-address>80.18.75.238</external-address>
			<protocol>tcp/udp</protocol>
			<external-port>10110</external-port>
			<target>192.168.69.4</target>
			<local-port>10110</local-port>
			<interface>wan</interface>
			<descr>ICMS idra remote</descr>
		</rule>
		<rule>
			<external-address>80.18.75.235</external-address>
			<protocol>tcp</protocol>
			<external-port>21</external-port>
			<target>192.168.71.61</target>
			<local-port>21</local-port>
			<interface>wan</interface>
			<descr>Espedia NAT PPM Webservices</descr>
		</rule>
		<advancedoutbound>
			<rule>
				<source>
					<network>192.168.69.0/24</network>
				</source>
				<sourceport/>
				<descr>Nat rule per servizi ALTEVIE</descr>
				<target>192.168.50.69</target>
				<interface>lan</interface>
				<destination>
					<address>192.168.50.0/24</address>
				</destination>
				<natport/>
				<dstport/>
			</rule>
			<rule>
				<source>
					<network>192.168.69.0/24</network>
				</source>
				<sourceport/>
				<descr>ICMS SAPRouter output rule</descr>
				<target>80.18.75.238</target>
				<interface>wan</interface>
				<destination>
					<any/>
				</destination>
				<natport/>
				<dstport>3299</dstport>
			</rule>
			<rule>
				<source>
					<network>192.168.50.0/24</network>
				</source>
				<sourceport/>
				<descr>Auto created rule for LAN</descr>
				<target/>
				<interface>wan</interface>
				<destination>
					<any/>
				</destination>
				<natport/>
			</rule>
			<rule>
				<source>
					<network>192.168.69.0/24</network>
				</source>
				<sourceport/>
				<descr>ICMS output rule</descr>
				<target/>
				<interface>wan</interface>
				<destination>
					<any/>
				</destination>
				<natport/>
				<dstport/>
			</rule>
			<rule>
				<source>
					<network>192.168.71.0/24</network>
				</source>
				<sourceport/>
				<descr>DMZ output rule</descr>
				<target/>
				<interface>wan</interface>
				<destination>
					<any/>
				</destination>
				<natport/>
				<dstport/>
			</rule>
			<enable/>
		</advancedoutbound>
	</nat>
	<filter>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>3299</port>
			</destination>
			<descr>NAT </descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>80</port>
			</destination>
			<descr>NAT </descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>10110</port>
			</destination>
			<descr>NAT </descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.22</address>
				<port>80</port>
			</destination>
			<descr>NAT Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.22</address>
				<port>3389</port>
			</destination>
			<descr>NAT Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.15</address>
				<port>80</port>
			</destination>
			<descr>NAT ICMS NAT per WAR</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
			</destination>
			<descr>NAT Server Espedia</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
				<port>8080</port>
			</destination>
			<descr>NAT Espedia NAT WebServer</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
				<port>51000</port>
			</destination>
			<descr>NAT Espedia NAT EID j2ee</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
				<port>54000</port>
			</destination>
			<descr>NAT Espedia NAT PPM j2ee</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
				<port>8010</port>
			</destination>
			<descr>NAT Espedia NAT EID Webservices</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
				<port>8040</port>
			</destination>
			<descr>NAT Espedia NAT PPM Webservices</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp/udp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>80</port>
			</destination>
			<descr>NAT ICMS Solman WebDispatcher</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp/udp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>3299</port>
			</destination>
			<descr>NAT ICMS Saprouter</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp/udp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>8100</port>
			</destination>
			<descr>NAT ICMS Solman WebDispatcher 8100</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<protocol>tcp/udp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.4</address>
				<port>10110</port>
			</destination>
			<log/>
			<descr>NAT ICMS idra remote</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.19</address>
				<port>3389</port>
			</destination>
			<descr>NAT Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.18</address>
				<port>3389</port>
			</destination>
			<descr>NAT Portale SAP ICM.S</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>wan</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.26</address>
				<port>3389</port>
			</destination>
			<descr>RDP .26 per BC Piergiorgio Roman</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.49</address>
				<port>3389</port>
			</destination>
			<descr>NAT RDP .26 per BC Piergiorgio Roman</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.69.48</address>
				<port>3389</port>
			</destination>
			<descr>NAT RDP .26 per BC Piergiorgio Roman</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>192.168.71.61</address>
				<port>21</port>
			</destination>
			<descr>NAT Espedia NAT PPM Webservices</descr>
		</rule>
		<rule>
			<interface>wan</interface>
			<protocol>tcp</protocol>
			<source>
				<any/>
			</source>
			<destination>
				<address>80.18.75.235</address>
				<port>21</port>
			</destination>
			<descr>NAT Espedia NAT PPM Webservices</descr>
		</rule>
		<rule>
			<type>pass</type>
			<interface>opt2</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<descr/>
		</rule>
		<rule>
			<type>pass</type>
			<interface>opt1</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<descr/>
		</rule>
		<rule>
			<type>pass</type>
			<interface>lan</interface>
			<max-src-nodes/>
			<max-src-states/>
			<statetimeout/>
			<statetype>keep state</statetype>
			<os/>
			<source>
				<any/>
			</source>
			<destination>
				<any/>
			</destination>
			<descr>Default LAN -&gt; any</descr>
		</rule>
	</filter>
	<shaper/>
	<ipsec>
		<preferredoldsa/>
	</ipsec>
	<aliases/>
	<proxyarp/>
	<cron>
		<item>
			<minute>0</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 newsyslog</command>
		</item>
		<item>
			<minute>1,31</minute>
			<hour>0-5</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 adjkerntz -a</command>
		</item>
		<item>
			<minute>1</minute>
			<hour>3</hour>
			<mday>1</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</command>
		</item>
		<item>
			<minute>*/60</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout</command>
		</item>
		<item>
			<minute>1</minute>
			<hour>1</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /etc/rc.dyndns.update</command>
		</item>
		<item>
			<minute>*/60</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot</command>
		</item>
		<item>
			<minute>*/60</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 3600 snort2c</command>
		</item>
		<item>
			<minute>*/5</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/local/bin/checkreload.sh</command>
		</item>
		<item>
			<minute>*/5</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/etc/ping_hosts.sh</command>
		</item>
		<item>
			<minute>*/140</minute>
			<hour>*</hour>
			<mday>*</mday>
			<month>*</month>
			<wday>*</wday>
			<who>root</who>
			<command>/usr/local/sbin/reset_slbd.sh</command>
		</item>
	</cron>
	<wol/>
	<installedpackages/>
	<revision>
		<description>/firewall_rules.php made unknown change</description>
		<time>1249663904</time>
	</revision>
	<rrd>
		<enable/>
	</rrd>
	<virtualip>
		<vip>
			<mode>proxyarp</mode>
			<interface>wan</interface>
			<descr/>
			<type>single</type>
			<subnet_bits>32</subnet_bits>
			<subnet>80.18.75.238</subnet>
		</vip>
		<vip>
			<mode>proxyarp</mode>
			<interface>wan</interface>
			<descr>ESPEDIA Virtual IP</descr>
			<type>single</type>
			<subnet_bits>32</subnet_bits>
			<subnet>80.18.75.235</subnet>
		</vip>
		<vip>
			<mode>proxyarp</mode>
			<interface>wan</interface>
			<descr>IP 237</descr>
			<type>single</type>
			<subnet_bits>32</subnet_bits>
			<subnet>80.18.75.237</subnet>
		</vip>
		<vip>
			<mode>proxyarp</mode>
			<interface>wan</interface>
			<descr>IP address ALTEVIE router</descr>
			<type>single</type>
			<subnet_bits>32</subnet_bits>
			<subnet>192.168.50.69</subnet>
		</vip>
	</virtualip>
	<dhcrelay>
		<server>192.168.50.57</server>
		<opt1>
			<enable/>
		</opt1>
	</dhcrelay>
</pfsense>

