2.9nervecenterSet the ephemeral port range to be lower.net.inet.ip.portrange.first1024Drop packets to closed TCP ports without returning a RSTnet.inet.tcp.blackhole2Do not send ICMP port unreachable messages for closed UDP portsnet.inet.udp.blackhole1Randomize the ID field in IP packets (default is 0: sequential IP IDs)net.inet.ip.random_id1Drop SYN-FIN packets (breaks RFC1379, but nobody uses it anyway)net.inet.tcp.drop_synfin1Disable sending IPv4 redirectsnet.inet.ip.redirect0Disable sending IPv6 redirectsnet.inet6.ip6.redirect0Generate SYN cookies for outbound SYN-ACK packetsnet.inet.tcp.syncookies1Maximum incoming/outgoing TCP datagram size (receive)net.inet.tcp.recvspace65228Maximum incoming/outgoing TCP datagram size (send)net.inet.tcp.sendspace65228IP Fastforwardingnet.inet.ip.fastforwarding1Do not delay ACK to try and piggyback it onto a data packetnet.inet.tcp.delayed_ack0Maximum outgoing UDP datagram sizenet.inet.udp.maxdgram57344Handling of non-IP packets which are not passed to pfil (see if_bridge(4))net.link.bridge.pfil_onlyip0Allow unprivileged access to tap(4) device nodesnet.link.tap.user_open1Verbosity of the rndtest driver (0: do not display results on console)kern.rndtest.verbose0Randomize PID's (see src/sys/kern/kern_fork.c: sysctl_kern_randompid())kern.randompid347Maximum size of the IP input queuenet.inet.ip.intr_queue_maxlen1000normalpfSenselocaladmin$1$dSJImFph$GvZ7.1UbuWu.Yb8etC0re.Etc/UTC300pool.ntp.orghttpyessis0192.168.1.124100Mbsis1dhcp100Mbdyndns192.168.1.100192.168.1.199publicpassDefault LAN -> anylan0****root/usr/bin/nice -n20 newsyslog1,310-5***root/usr/bin/nice -n20 adjkerntz -a1*1**root/usr/bin/nice -n20 /etc/rc.update_bogons.sh*/60****root/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout11***root/usr/bin/nice -n20 /etc/rc.dyndns.update*/60****root/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 virusprot*/60****root/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 3600 snort2c*/5****root/usr/local/bin/checkreload.sh*/5****root/etc/ping_hosts.sh*/140****root/usr/local/sbin/reset_slbd.sh