5.2nervecenterSet the ephemeral port range to be lower.net.inet.ip.portrange.first1024Drop packets to closed TCP ports without returning a RSTnet.inet.tcp.blackhole2Do not send ICMP port unreachable messages for closed UDP portsnet.inet.udp.blackhole1Randomize the ID field in IP packets (default is 0: sequential IP IDs)net.inet.ip.random_id1Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)net.inet.tcp.drop_synfin1Enable sending IPv4 redirectsnet.inet.ip.redirect1Enable sending IPv6 redirectsnet.inet6.ip6.redirect1Generate SYN cookies for outbound SYN-ACK packetsnet.inet.tcp.syncookies1Maximum incoming/outgoing TCP datagram size (receive)net.inet.tcp.recvspace65228Maximum incoming/outgoing TCP datagram size (send)net.inet.tcp.sendspace65228IP Fastforwardingnet.inet.ip.fastforwarding1Do not delay ACK to try and piggyback it onto a data packetnet.inet.tcp.delayed_ack0Maximum outgoing UDP datagram sizenet.inet.udp.maxdgram57344Handling of non-IP packets which are not passed to pfil (see if_bridge(4))net.link.bridge.pfil_onlyip0Set to 0 to disable filtering on the incoming and outgoing member interfaces.net.link.bridge.pfil_member1Set to 1 to enable filtering on the bridge interfacenet.link.bridge.pfil_bridge0Allow unprivileged access to tap(4) device nodesnet.link.tap.user_open1Verbosity of the rndtest driver (0: do not display results on console)kern.rndtest.verbose0Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())kern.randompid347Maximum size of the IP input queuenet.inet.ip.intr_queue_maxlen1000Disable CTRL+ALT+Delete reboot from keyboard.hw.syscons.kbd_reboot0Enable TCP Inflight modenet.inet.tcp.inflight.enable1Enable TCP extended debuggingnet.inet.tcp.log_debug0Set ICMP Limitsnet.inet.icmp.icmplim500normalpfSenselocalallAll Userssystem19980adminsSystem Administratorssystem19990page-alladminSystem Administratorsystemadmins$1$dSJImFph$GvZ7.1UbuWu.Yb8etC0re.0user-shell-access20002000Etc/UTC3000.pfsense.pool.ntp.orghttpyessis1dhcp100Mbsis0192.168.1.124100Mbdyndns192.168.1.100192.168.1.199publicpassDefault allow LAN to any rulelan0****root/usr/bin/nice -n20 newsyslog1,310-5***root/usr/bin/nice -n20 adjkerntz -a131**root/usr/bin/nice -n20 /etc/rc.update_bogons.sh*/60****root/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout11***root/usr/bin/nice -n20 /etc/rc.dyndns.update*/60****root/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot*/60****root/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 3600 snort2c*/5****root/usr/local/bin/checkreload.sh*/5****root/etc/ping_hosts.sh*/140****root/usr/local/sbin/reset_slbd.sh