From c056b2cc4e0376d0ed7ba96d222a36dc3e8af887 Mon Sep 17 00:00:00 2001 From: Michael Date: Sun, 4 Feb 2018 19:32:53 +0100 Subject: [PATCH] geoip alias and intro tweak (#3) --- source/intro.rst | 1 - source/manual/aliases.rst | 14 ++++++++++++++ source/manual/images/firewall_geoip_alias.png | Bin 0 -> 25627 bytes 3 files changed, 14 insertions(+), 1 deletion(-) create mode 100644 source/manual/images/firewall_geoip_alias.png diff --git a/source/intro.rst b/source/intro.rst index a7c24ac7..6889cca5 100644 --- a/source/intro.rst +++ b/source/intro.rst @@ -71,7 +71,6 @@ OPNsense Core Features - Road warrior - IPsec - OpenVPN - - Legacy PPTP support - High Availability & Hardware Failover diff --git a/source/manual/aliases.rst b/source/manual/aliases.rst index 8757505a..29c401be 100644 --- a/source/manual/aliases.rst +++ b/source/manual/aliases.rst @@ -22,6 +22,8 @@ OPNsense offers the following alias types: +------------+------------------------------------------------------+ | URL Tables | A table of ip addresses that can be fetched | +------------+------------------------------------------------------+ +| GeoIP | Select countries or whole regions | ++------------+------------------------------------------------------+ ----- Hosts @@ -66,6 +68,18 @@ URL tables can be used to fetch a list of ip addresses from a remote server. There are several IP lists available for free, most notably are the "Don't Route Or Peer" lists from Spamhaus. +----- +GeoIP +----- +With GeoIP alias you can select one or more countries or whole continents to block +or allow. Use the *toggle all* checkbox to select all countries within the given +region. + +This feature was reworked with 17.7.7 and supersedes the GeoIP blocking via IPS. + + .. image:: images/firewall_geoip_alias.png + :scale: 100% + -------------- Import Feature -------------- diff --git a/source/manual/images/firewall_geoip_alias.png b/source/manual/images/firewall_geoip_alias.png new file mode 100644 index 0000000000000000000000000000000000000000..a3cefd50c951a3e11d1f270713a8b2d88adfd333 GIT binary patch literal 25627 zcmcG$cT`hvw=Nn$@TW8jN)u43NR{4$B4|KBKtVc)fb`xw2&gm(y-SxGYUo{h2{qKv zdr9a$wkSR6!tu zZV(8c;vanAOpe=G2nh5T1bOx1y=(F|%E$HnQOXH!9P*Np=Fjk_oc2GxEMJH!m_NRd zeGeUDPZ8PJWZaqZ&l*=Z_|fkaJpE6l%LU5(4kcRLLhMEZOwo^Pyn(Y|Iy5TVNVtVN zgUEuf0@}=4$Z|L3?u$DD_udSgL?m1)`F@Q`03kXVbP^n-*7{6aMfqW#t6ox_B3|be zK&L=DCDk8Yu3uEY`dNerv=;xPP3T)V8Pf7}^2a9|wdrr$Uap(M%hyNY`OeVpQf8BG zOcZdGr_W}vtv9v7u@BmnFFo6mUWBARc__E!!vX>|KaJrnEDE>Q7xmde212GoRiX-dfRgp+F?L8qz(oO5~u|zVwV@*1jUvriXyFM>0Rqror4_yLURfj6w5M zHs{VPruMsxR$fec@3zJ^K^VUDk9G>jDdp8W;y8ez7YZ>hAL;s+S z*r`q#e#8U@P9~7SHHbh6^0-{!M9}m)e%)ObhmZhTo zmGIUFm5rpD=i_V4=GxO&i4DOA!?m4R5oi>OnH}3$C;*Au{%iTDI@azf+4$I~g0Nze z!+4=%-iC`)|JtkxMfqHcu)3OU%*;b zm9B2%Q$G1-Qlh(4ZgZM?+eP5X%rv&7e4$IuOOIq>Tqi=Kp4M#uo@2#9-`s|3{m$_JA>2ipGBZ8 z&(J|`*ZnVmGoW?u%`|2x(*kR!AS=*Wl(Z#uby?a3`wgC9?Uz@GnhN-Ukl3H#pLPyn zTHaet(bnL)nmjhB%c?MQnPe6mV+g%b)#aK$g&&sU2hY25f_yKxmXDg+#MybzmMwBM z6u#(0JCnNj<+9yyMFI=oSP?=pfC+;owZm9t6e)H#N%u(}X`J*Kf(k#N8a zY#_yy=MC&7x~hwknj3orO+Vl+y$ss*pV}~+5%8e2g3Ys)Ug7#_R(3mc^>F4f0Vgau z*3L8uc-2U`vC)lna)P4cg;@43eH;J~p$sPOMQX>b9Ud-D=9U*s!;jjMac3{v3qE{+ z6(>d&8m#cQH-Ymi>KD1D3-a^x;W+bly6;vt#i-qjs2}eM6vjMg+e$GA50@Sxr+mc= zi{qf1FUW<_r1FWvTtFY+Yg{F3AB6Z+T3uY5R4>&1$(nbT=B?&n{}X*EXc+6Dcm9!O zE)l$z{x!jMip+;r%yh5 zYL;`3zL9nROaJkvP`41S<_FNf{2gtil$g($^8PS$UJ;ssxJsasWp?kBm`CFSa5U6A zdnYDVNtIhQF^@G}ZJ9v$8RquQuRm%(e{kSa?cUw@8L}~{P}afm-0P}d`(`!Gb7+vZ z3$lSyZ*Yd{OVqtJlvo$ZQ!6Lh)S2PYM3Jr6Jnz4zZPlEana{%AwbkmPCAchdvJ6mH zyEZFdmeTwa#hmghB=6Mhmb>AUfN?1;OuYetY&X7}H&pHnr4^o z{>KgMgO1cRyMJ#f`*fLeyiF5YQFT_|hWT2jUO!)u@5;?%_3O!W6lQydeWS6<*Lsnw zd=-)p%M+K7Uh-p6>i4mho$ZJJab=f!zLRutz|8KtI|zZury9_5Yb zb2t@O0B3l!6(S=H~||Z7eU0cG*1T)*#d!sy$3!qsgHOd z-BsQ^VC~yi9{nCr*0)Is+v`pSIOH*$pqq+}j6 zy3GcZ>{zwrqzH})isKx24II>}<(EENBr&s?aJd~vHYi)?ovj!h_#}udgx6nUBqT7a zx1ggl)oM_4q&J(X6$VQPbgfL(r|jA8$2|;(I#=P~X`U!?`Rz07{1ReMx0wcAF|HXCB+Ou@rZ+#dx#K+BftIvGlSw=*?x# zw}2}l@WP~48NgXLS+!r*w<{N-=24RsO=q4QF9t@sYg5JuV0mX=iny1neuOT?y0Ir+ zWs7UL%6w~|ks)N`)_t1+pM@1J3!h|RHm<$(q-o@p>(wG90;VT18+*|7>=_c~zTB91 ze`*te)yh-x0(jb-FZQeUS|7BcuC!D!?C1m39^E4b`zZB`wrn*tMr(_PJg+8CE>Vz0 zQ7vcnjg!-ba=z&0hqem#015{JVC6@-EoaVOzOD97R1|FaQ@{3%zR79caQK#*X?8)5 znTy(iBwKz~ecp!Z;%Hr#4;ImIF+xt1Rq9aI%Jd6(es2qpRzBNFiU2nn3`F1R?q(}c zmnee|WDKNwnwrLBCDG%?&g;?ULA#PPF5{zgX>t4p?Xo;AKTN$F8zA3>!DXK&t4tj-95k><b!;%nOj)s-R`0n^a9S zr7e;5bVqtkty)c8=&3D=zd#-CM&FWeWam)$@WHQvJa-I|=(JU_U!=b&tumAMMdrH{SzZK*A4z)0`r4Y2bOr3JvOY<|fvOrE%ND<$z+6lSG}&us|G zdz;U*Uxs^su*afvp%UEsVMHA<|D=1R6pE1RsuXo~MZuI$U0EAw>aQ)8Co zqc?>wQ9=0wchBH5PSf7wZV_E`MTxjSv9&S_ak0q~&oAYbH?|#iWhctYMzY~4+C4b_ zr~S$N7P}rvY>2*YT8=TBQ%%heu2K&xs|e>N)yKR-dj6Oth(eFixQGtld!|Z|D2gk% zp$p1KKp3)7o?}nP1VqpR?bb6|@($R~V`=mpSJ(kk@N7-GN9oSGqBi~azR}23C*=&d zy4CbE)M3%?=)G>Wa+AD#^DQArd5-hIvXEgK)p0a|{?rx)LCFgP7EX7_V z+C9R+G9!XNO=s?Rid4}47kBdE3Yk8GS?Cz-2ra$?RLBWCy&Qyg|TPT@NM z7IApYzoTV`&gwFmZPIC)Dl{6I28OgIT~)g7H65>aN!~ZX!jgBtIG%!kn{2^H_=(k6?Lny)8OIP?r;6#Qbl<# zWlrMv{;-cQuKcr6ZoS#(x3>{dsGa1ap;eYudOxRDy?z&=tv)k!&<$O?H25&^=M}^$ z*dH1#g=33QQjB%HoDY8O6f1f`pz#&_|FO9jPAC3wOA5FRC=NffvQiM~b^V%~ zaP;eSi+rpNAn5;a^M@yy0Z-#E-~c`w5SpRcACW z?A~AwtS6L=O~as{-F_q)Lqz0SJM5b!Z8kpjtEyS$-QD`Zxa)a8{CQ`Gjbx|Tx@3BX zbj*fO*A1>$KvpU6`vo>GEeX|7^C!msSg2){K((#7dB3mk37QVLN`zr(0NGNNPrE&d z?j}v8s|#=|)_dX}G>vhI062yYi}(1qo$D`tvsZj$dlF8hsN~S^oR{wIlC~f5vkK_m zsC)y5q*#bBe(DQi@cEYcrKQt&hH7wTGwu69?UJsMUqMG9k7RgWTu&L%eUv5LlrHM= z`1V^x`O1Ryl|h3Y|CZHlLGPwH%v?p^Y{^x&FGb3YSKQbQ^0?gPx$q==s zn`y{QcL=TN;^?lj_&F7RJ<*QM4c(X%7`iZ0$u8y;do`veLEM&27eFj1tTl5@Hs)tC z5{tBHT4SiZeV7G2T*k+q!9j@t1)iDiexVB+`c||fng`wV6B*F zbg=J{CvbU*>S38v$)`+>&|<_3qnq)eWldcFvg$^^CIx&#y#1%2F8<6T_(9B-nNY#4tVNB6d#h}XUg+59e^FZ-CRJhM$=B;8qU zXD5d}lj%_@>7w8rqo5}Vd?fAEK~MOl^!DiFzeTaP2QLYNLYd11ZT0%ztOSdR^@Woi zI0h@FJx9cgdC8fIiM38nQD_L@mp-H}R!=r${zGl_mcQj^fF-^f=$ zN0X@YK%yh*Bc^@ITK)M!h^vcTvqb@3G3sIcw~wNXnl=@TjG3wI?D!N%?&Q%l|FhT_ z+FWz=s6uKa9qxQEN_`;g#0E>df>HZPZ!?|E(AD`8U=ePFkA`#}G z%x`9ibaZqMtZ9>_xR4RkXoGl@RUsZ5|)W5UN%y`FL&mf!6&`nzu3i10vn__W%pW9-)-U?SBr?F6gy_8 zzN)L^UUJ+{9K%2eM$e}j+Yp<&qsH(tzHwotQD)r9c;H*t@8i^?fiexxzy;&L#&@Ox zt;IUCHuvXW#^$*r`m(Yz&%D+eiDeEFp1i_BPptxE zR59>?@~UPCE5B(y9YxC(wd)tod?8vQ9IZuL{hk4RC=u)B(w9cnYTGKzS(>8^iO3Z&^xNiQk%P;YiVl-*DAhjC1ly>nVs89!01nbT{}l9mZroz`gD1%r~Xi( zJm^Gta?IrAg3aJA>!Z}=M-^`SA>ouR^ghQeuw<;`#}b1UWRZ3zQW@lxEb6e@9S6Qz zNZ#w#_!CBF#LPmqXZM4jq?v8Lc9%#PoC7dXzgZDGlJz+-zZbrGa1Y!_VC;-zbkP0Gh)*xnnWD3aE4G6l{ zdU->4tK$rxhTr9#U%WfMv@9s%hW8f%y-6T^itW@t_(MgcQv5<*kDFNpy@rYU;Du5F z_&EEPpPO69!m6W_I%u?|s;_w+Y1s2~afw7G=SjQMngxjJ?q`endg`FJBfO!fu10VD zuRbltZ+fLwMZx@r@*CO;XHU)mDCB2-v9}jwNX4hfZFYk<<6jOh>gP}1d%AdX{38M^ znQa2%Z!1%tPY=YWRV02OO~alnjC{2)aOBHsiWgz+^d5`rp!p8qq5oaVnvbnnn*f+T z0S4ACphz8LmY>;XiQ!dtSwEyc2+bQYbLU5z6r+|!~N|C1ntk^&d9k%c>xKo0DFm48z$a}a`jpw#B9$&(p;7Ek@e2{#A6>|O z841Vif=H-?4F7bpdp^i~(mmhH^7o2l*zRB@NgMA2N>kvDf4ZaZHj4ZJ@ReRygNr7` zLCb~6f~W{Dl=IqWM!M29Mud{IcatdZJvhrx@Fe}C$1EAFJSHMz!u+9kx#KxV?h)XB zX)-lJ(RP&7QgFYa%mW@h$h|xo>BFBzehcg8$tHy~RAFKWg*M*!K^kd+$Ra=DRs$*! zXuZ{o`r6%F@LH3uk0>kusU-%YB~{*JOT{}aEGDgAdD{Qi8PwGISr#OU6LX!svQ^2P zr2*O!qRIbm0|Yfe8;2VsH_7QGoVPy~isKu+8`p8@KN{BuoAkwhbh**I;t$N~NK3#? zSp9xacN80K(A}*@5S6c4B7^to0&sq0WW)$X35pA$8vE*)Y%aOCvBoAPId(T`?I!n3 zsZnR+`55e8p`Qw{>0#bS1)eoG9w%lQdY3JBM7R_#I@fvsd3^mDXM{H8kK|vLg}VSRP}I1 z7w!JTWE)j-fKG%D`#wMbQ|j9*OJVU+>a>dII56O--%hRkXkivko>bRc1U|1r%wnDQ z`>}9&yO=_2JIiA!fi~m1X0ohm`OD%13v+Q?4$uqfkB1#aU>s&Z#XLK_8*A9(;uF7* zYWnfli#2Hz&DwWZYRDX+e=-xwi*v{_2K4BTF%i!G%<7tVJc0hK`qfPP`>CzSqtq$i z+;UAIF3(#x-?;V0PxW=A@@x!>ocLL*)3X+|q+IORg4eaFQ*Ec$VL3&=-BvglHdXuvBeUqZzb!d+451 zcpTUF^Ccc8{TC~QG&RhjO`A|c@^}@M-ZiZHT4lo$x37pM2+?|Yj^by|z_)tVT@KkVo~i7>xNxjjXD=7gr;Mi6jph77dqzBTpd!CL3I@ze%(**aqv z8*aPoL!Gr}dv))(>_mP<*L8qBs#7e!+%jK%yp@xcO;UF49@d}yIQYukuhfW{hGva^ zEli4vV%GIKvZ@Nor5DTrOQ9_YtRCz?EIh1zSZi6>TENP1wC& z9nC)PJ}HvK?kynZCcQUnMr9;pX*ZIJy_b<3?v+-%oQ_|6Gj$7?1P9^uP{ICi*~oV1 zlU25ntWElUOQ=VAok4or-PzY@8eCg|bBDJq-{~@iUc{d@4dW#z*LaU?-Qjr53_C}&b z@!4)0`Pnj&9M^~d_;R<+qPT_?Nrz`k{jZ3mKax3wI`Kbh0hnI1DkcitYrx}X%vDa4 za^0N=Anp_DE-0XO6)@Fwb^hF_<4-LUh@0|ODH>#3O2cpR*4^E`&;!7Bxx3~sfdTzr zWbJJ+RMM{_yzc>h2j-*27VUO*wk9)sgQ~x{(Osvo4lv41*w&4_bu08=dql;C6gc-W z!1BM_)HQ?J9M2CoPUd`Yr+Z7K=zn})gfW1xYPX7MfuR5{V&1;Ri`vi79n)}9T)UZn z4eEeft>pm`86>U-172a$G!13jMp}v{27olw{H2&uirC%;C7YDh*0=rx0!lPs_lAXm z06)o6fj;(`J~!UCoZk`BX`-H&!U#_l?esVKN`ltU9$k#PEp^D&F*OG=eI&?y#K!LX zG{hQyO>yG>G7>NT(voe3`xX%rXM+h?!nC+iIBpkL$I3GE6o`O%rpGPnLRnU}=-+%d z*8pbU_sI_vxRld&T3d_Oa4sFG%_H0|c0O0^Xz>Ykh7Yz#CST35`cq1vT!nw;|Hcp3TH$ymvBl75HXA@)p<-7%*vO z*A-yK_wJnrOVrT0%34H|)$}{h?Kg8ot9xw$mWj}dKdKGK&LYn+ZX~al z^aS8192zlWkSVp;xv~;~qg>MzboknvalqiW)b%lKwov6A@7=$+E4eiFJ-|BIep*NJ z#QCYPurY!*rpASvn5REpoL?tY65GN;jc8zi&hB=vIh>0L_mav-TL75zSnR(*LY#Js z)U4|?5IbZmdM7~$x3ytEt!;~2n_}IXIyIK(Zw?u#8o{wVt{n_lLwiw0XZm0q7kD3B zc{$joeb7`K;e9c((sT|RSP@>u?Nf%g;AjXzpyzknEvWBf>iO7|q0uyHqB}jWAR25w zOGsPtP;GC=vGD=8Qx5_0h`xsh;zF^;#Zh+6i;Lk6^kw6k(3cIFkr*daQ@d|j@4o%G z6N=A(J9h&7}DTy8EE>O4X;ws+Of({*8wJUZiRh&vRMM5Mv0_Txocl?LZ@HNz>AZTmB9&&IP4r}O#7&%+7Y4mwd+>@G26 z@xFD$vX8*1M4$4kwyU(O-$Ft~z53WV z&oGBNCy2qVAJuu+98unHdvcMx$pF*Gw)<>@)tCl@V>U=33eHZ;bobV*h#%qnKQ`iHuc$H?2#rsYZR|(+k<+dr<<8bKp^wbm- z3Psnfr2>@iPpukgaA&a#$xdEa;Q0$twxPf=PC7wFCEF-9ve$>KZ4195q!;Gq#U-{Wv!z|r$Hn##(zb6-xu9R#6l=HexL*seajWA* zC5s!5xUu=83^lsLuNmlKuMKY^yP$1XMX*`d@gim`15l75GaFl6bTp@4y$I3^&$p2~ z+|FWt(P>B6r}W5Th4>-oKj3;hyA2*zdHc&nw%~`CPgN=GmllWhJr7nd_36*eKHnPA zAPC?iVPXf44V@?jJZVmh<2o_6k34sa~{i z?zfpHngCv8-ckgD_lg>zFgbfmoj#`v!JhU6nX&(h^#Rm20vui3U3Bk1BqPAi0z3qE zsWYMz@ODIk-j}Ca#dX$w@z1YaMla#NxrpGCYh3&P%5pTz8X(+FHFXQcfroD(kQ(f} zK-{1j-(;x2>{niGKY3U#G^eIMu|Hos6CH^GNYb}k01bX&pH{4s$O6b5o&%JOA_O2? z%}mxCB|VL?6jS4+!0OnTwtRq<&JDPK5V=Pz(MPWMla*DftUKHDxXt$m?5aJ z-c4ozhvn#ZzVBE7LW@jGHDKCPS=0-fb?r9FD%SeFjJb$8IO6h)`_86j_IsSzZ=c;h z=q)bLIsY?EhuHY;RKq@{wmNfH^F-e8>U^|Ee6}k>0GV1l?iuI<%jMuG&#L7!O^12v zT8HWb;<5-Bpy&RM$ghVV?K>SI=_g5iXfIw_sH%0HuuF{EF93LF(*)3WslSS+Rkhmt6zko-!BaD`k zfq`Kw98|3X&|^a}yTwASU(6nENA+23-!F0xX*P`8KfOO6Zr6 z(iD@Zq|3j#mu+hu&3RJNS-xd1Tanw({D-!H@{?)xvWwMNyZDxm8yjSo1~|Kx)~gA9OK&aciI!V_xXJ%Hv(e^wdPzC-<+ zOkH9t;c{KZtaSS^?`;(Dgarl$>XP3=g5;h6OZL=!m($*r83Kg!_cY|+!8oTrYz-to z33S%z#ePmze1a(#FB6XWoX^;iLMWGhfoako2JrhI;A*xq!8@|fCpq`xiY`h4wzM+w zz!uR(()gjMMtO>2m$PtSR_9aH(@G*DM;!Jf_+>iA2X_HXI*7#AlJw7L=wxwB9e%G> zzj$=RaL!a*z4>5k*F3zUYpA}XNrFE|_l6vuzo4%Qpuzl6U)`R`(0z~>7RA5?iBz5O zZW6C&{HU^9n9A8*p5o;JNNw)6TugV263TUFk5bvosgsF7^BJc9%7%QsAy99r95l9aYWv2bri3}V8`K?XBur=-z3W%C`YyUjec1bqF z79NG(>(CPv@++eNZliNABee+ei1czA1|Rcw%wZb#vlCwNbn!l3zD_kEBG?)?ODl?B)(rWE%O{O?jATSV_T9Ou=T=c_4Z=0eEgeR4f_s zMd07XvkX^e+vD3&_x(vpFTf&0mB%G>IBNvbPxodSgS&{fxbq3=IRA{d&vy>vtU5pz z1Cb~mmK}XRA)^nw6hS{+b7`uZubb1gJsEcw5IJ27K#`lf2o9u}DI_EmZKAw_e#^|_ z2eYZtsczZ5dKG(v<2EC)81Wl`p3W-Zr%dynUXvsaS&UW(l1EG2=kj;{c6%wBVRmmt zk5uUqhQ6I_+q}Cp;X~~Xu-QTHNZen=SixU)^^`Jnl_rK z51D{od12$%HZnNI>ELXw5}7%4ox@&pW?x4Q4Gxxcl}eTQNpf9FE5wwdiQ}hnrnPa} zXZUua1u$3|pRqhpC7iaB=D82?^1`BA=IBC{2qnV9@{(Sg;eGfus*)w>eN{~e($UJ$ zxDVYuDh%x^59{x;o0ZTTK5_v&YMcH_wLR!h0VC1-tHpb-3+>LFNhQE z&1Zzq!&P(DzG)7ZrS1~rIRQv-y7K#$fOrOEhbQaYkzpXp-#~2w5aKw3fkI<8rDQ6D z09#Qt1XD?QbGO=bf#LNYo8JLP42TkP2)R2jIAwoDP$)e6g-;)x`RmiV*DW_J{$gU5KBqULC3!-9#GzWTjV%_bvcG(x63@L_0c&$q#TK zuCLHT2fse}Z3{qT5FRT&J^%_2$2>Z9k`CH1KK1A{bMQWlYyaeB7w? z7`Zgbiv@HgT%gXS{3Jb4t)j7ue;SiITJxzx2HhX>P*ehnYUs;0$x~O2YvLkW(ds}H-k83wOHeVmhx-4 zPDZsP`^9k$!J~+TUhI`21y5iit)TJo??R%DPYUJ2+Y@ws4t6y7AZ}`vMxLdKBua^+ z(e0`Ny)%Rh_;meiM_AqQx%iqGrqS)C3s@B>i_kz=S-P=YNkDGv!=Kj3Gq%hi%gs)2 zo{;#YJ=<&?Vn*mf*WkM>crxmBy&QEH#|c0^YN{^Y2}x4buPzQVEMq6xNluKrvte&$ z!H0_Bf*HZ2VIgiUuyNR23VR-M>Ei||rmb=cqkbZ@a$Kw{1+1TPCFHgn@k4i-te`-$ z2vkGfALA{Zdz0NH>^j)(t=TEy+o^YVMSj#v#un`%&}WRb!W-DpmLLAITWxi5UXwXc zKb}{y%-Wk2f)ymrq5zswX8xW#(4lcbSi}J6~{%SO(W4^{*Q&vI&Y%6O%0T6XtVR$SQBt}1+9vzQimPntRFA>dXh@!O zWoQ?S3gk=m9dKvdHh#KN?85!5?ET#Ofc{*7drvRPExJC{$5BJS^N0wZJz?pFHjwqp zbog1l^3$=H@#nnu7-?CZO%-G~bduYxVD9$7`%Hms<+fFV;pOti8xKTlgKF7a!lb78 z;_3iQE&kB|By2SUsGBGR@@SktqoW2)J8p}kB!NVpWRdS2$N8j zuRM8XZ2eD!`Ls0x4m)`tjOnD{zVH@Nt4z%xKr3G9jZ+ZGhlpXy1m5Y}ujt|mPmZsm zOmAw_ENktQ$?9!P-q5BoM&wM;fNa?TFa7Y1fqmOr7&AbBa z8Fo0MO8S#6P6|)z-`B0qAfC7F=yP@U?CzFr_X@>uI=ZQI+ZV>!>lRCesSW4+t`*Jd zqcH1`v9230A6|$7wu)|=wf!4Rvn8=bYCz^Yr<m61zO<-%om6 zqYMRpa1?hBkbjS6irmHRm%D%j)BuW1dK+-34+X*QQo>T(D86|+3bUh}(S9IJ;LN%T ztVp(4=Ts42z76dyQ1kAqz1ioWjIP*|b+_45-ieuC#TQS<(EB~9V(b&czdB;O%9^=h zt^DVjZ11!vYODat6nCei2=6etXNo?d2-c}Hbz3=a}10rvU0C94}~N zeMtG=LD4nEs6F4bD@Ehqp-uC4XGH1(MY2BtCO}1VRdU0(<=uZ>H5EMt5#I=C@wzxp zk@BiV>~j=Xf10W=yU+Ue8wBS2bbkKk!1s~m>!dK};NYO`QkXC+8{3KI6`(8#2nh70 zN{X{K;Ai*-Fo>`zMfKhmeBw*kc)Az@#Hu4$KsiX0aI^O%-RwzL%5}h|4s?3-Bwq`N zZJy^pVS}3Mv}j~=VD)?e&VO4IvpmtcE*w4bSvjFRw=6y7ndhTW{LdE6_*Pa{`Xm{+ zIA7>-{YGzB*Si&3E&*jgdMc~^Lk)G{h~??uEutA_$oLNn zIcClz#rg-5Ht(NdXKSeU8&pi&M@+ej3JY~kq<=iPzz<^WxCyp>PPJ$@%);VS=J?C_ zA4oz(fC|7FUg@G}rHr!%>aDDUJZ+9?fBtiJ+ryiI>dGEgTzGO40E{TGQB2>k`UOxL zab1)$84n|TeokV$dm<9=@d%!-;huIA_SKzkmLPQb=#tgzn|>xi=4h($vlu&!)k0Ri zsTXDmyv*SkyR&ibxUNTaB{B$9g0yNJA4*p8?sp-jD|XyQazksXvPnc9-`$tg$YEKD ziHTWJ;LDm>1eiNeJ(5dt=5Grb$?pF6D|OjY}woHz3Q?^eRAWNIXb?MjT(9BnY9vxg9^l|v`)H{{PgY|{6w z$MSh?5CF5OtEl}laX=%0N{~qM^n$*Rp<+8~^;qYgyGN&#G3PDeB=20c#_?G)$)D4x z#~dzZe=AZby(jKPiyYex0b77OiJSdU-muZ3b9g_HD+a1A${|ksmdredd1dxF*7Bk| zej4L|&lG-*szA6lQECL_iWSpV7QHj>foy$Ovj&8pXU z;)ILB&m@?nDQON9o^_pX_B)yNfB{b@tll2b9VFwv&e}ljLpb7;;utkgE30J4vz&`g zBsF5MuC1aKbLJuoddk-HYIbJgay%X$A4oZ0Z}FDKz%J-YFNx=Lq4 z5^G757SV*6_pkftG_HHH!s9b3&@a_X+E%@pU*OI;aj+lcWzW6+mV~_um81es-(IQh z5wDvSZi?IT%&)s*GJ>4d-i%e3;#yOSY_Svt217a=QFt@XWEp0Eo)xNN8uV?P%8k-< zmy*0>Bzh)L$uvUjcWCy?mi>54fd%KZrp}r44|nWJ4X;aEJ}}AANm~_%5AZ3s>y@LF zQ2Ln9oLu^1y2E8XpF}lel|U;}x;2LuOp``Bp#LrR$23Gc&uG8emvDDtE0u3;b#&l7 z;#%8<^>djfaq9D-AUN|wWSK^%lG#mthy+jrO)JY z#F?a2ih@FEK3f>X%RL1ujDZr(|C82O?Lxx)_TP{X0%cxTN#@+T-$?N{p*9qlcn4sB z&49K4YSU*!`f)yhT z*|crloar8;BaC)17OSg}2cQ+c&8E z*OOV>?j1hl+<&XLq@UW&7XG0N=}UOcR{&pwr*Y)NACon+d!Yf;ApidDD1!3Ag$o9FX+>IpiH>7|B#4q}s`wlQDpaKM_Xe216v8-Y4jup}r z8+`PBwPYCYj>mKHQ`2g!_sOmhVaE2S)6kL{pfcjFPi!y#!B^08iiwpdFLd8-k_o`r zROU&8nr@sx8X1Gz7V=`uB~uFMQm1Ta4<#AD3hZ9UmN>+) z4OT|kdJxvS&`i?ap+nvD`6XcASI~)Q`GNo1?6Ie+tGS0IrBo1ceak?m?rm2{e@2+3C!Wmpu4vgr>#qXNl+zLE zP6R}HqWP#K2CF?tO*ubHw~#|Is@z+{;7mqR=pP=P<%xya_lrHz(R|Y^Hb>em3HjDt zPIct2&SSNey#RMhC^M_!c(?hjUQnU`NuW`ng)_$WdD{w^8}XymE?NtRcZ}LbUymeD z6^4ndHWMW?J2Qz88G))mor1JV=GH~px9GPndd*9=jzqiObNMI5Rp_~D1T|&hZ|k2Z zuR2Aj$*X}z!&rBMHG%Ds&(g=+2@O|dByfSQMoZRU%s=TsjzC&fbr?w4pYz~Omm;n! zn#wH!X=J)MC{_kLE+BMr^>8{?WAWr-{OvL4k7&2g0|Osq9DqP|K5<9>x}-!})4lV5 z)dC#gO^#SD*bsz}RRd-CS7WAJX$40je+y|Yut_t=2X5)o`b@UFI1cTbtby8SRC~JvzcN^nqB*NQlU^o}c(*_*4^VasdnSfWKqerwoLMi= zRZ?BG)MyJ28zTjZ<*gQ;-x_}zr+6Elyu&3hG5oadBAxoS4L(U5A;V=^_T<>$y=aPk z>qF8;KNNP^{v@h*dp2gx&Puvk>KWo;0@h$X>>}B2;hP#({T&pj%`tWX_gUT+(N_^w ztmXEMHrL-zUg457Hi7GsiaQ6x-p=>W*#nuV|2NwqEqS5Al>$_lpx;7(9xp$=?Za;6 zVxyJH-VLbInj4zSyAw?~FYE|du<+y!6yPrjw@Fayx+>GV z9ilE)zhEatN&~ZUi>O6Xask?S+*Y!YN3%4i$ms#SQxVTIdskx@n5GHOlpQ>`d_{6& zw)A&bx?qwT0%;9Ur;7~6V2!dm`yDZldi0#gGOBuZfr7 zmACp{rkfkZz|bSGgMi$DGpnK)?*7pU>$(4}p^lD%h z9s2dIk%+arx;htQ^=7iir+%c7tT%5|+dhlt8r;W}`mG@h&T5gpeRco~rwSB@(cqcAHlOmF9 zD2Cu1AFGITcF&KtG+=sTUU|o?za;OIE6X!meWAart&H7$>;fUK@PB#8<9-Q!{Rg?UU^}egAy?l9Ph%}g zW73haBCR%Xb35Cau5!}Pr$(R>IiF%Th6$%LWjnMb#eW4Jf7o3^Q`_e^y}q62;Sebu zC&E&(pIzlV((G$UQt^o_)j|JRURntJhR(C8QgTbMqP?K_CqxFE$Qd~!sryP?#p^?* z>Ec4S{{d$BJhrH_t$p?`H4Res)#y-#&D5kE?Q=%mMNZ%B+oaAaufy;#Jwy*U9Gv?N zxU-cmMSoA$egoV0l z%5m87r9||zr;(?5qt$w19~)%Xf82T+d9daQ&Q)z%X4KV_l*$U}`uq_q3cXVI{{1Gc z!bVKO&3yFRjaQ$!v&rJZVPRBvHL-RFkmx!=%{$q-n_lAL%h1iAUlP-|%34%*2h8JH z8PmD~sl_ya}IhmyozHp5i5GqmmS)=5`5*b!LBnya%BTG7L5Ec<0%{t=m^{ zQ#R}8xk{rT2@{>l?L2J<{0h00c^E@?$6x~@Y|QuM%Mw%KH{cq%nt9H*O1)LUwHH@u zp<*|whW^A`j~XOi$WmsnC3h}ey!xE}CFC_N!`Q3nE61~Vjtw=H6h!u@q3(u@l7Y_I z#DHX;M=dGzH!rn1@c#vZ9q;aN^c!vM?OG~th~%m+yl3Actucs>*e7TxyQyZC`0d-b z=XErO;FV2%kyTY-WraRb1sQre<(IVG5B^qSO}ZWQaxbqd@xv`;1L1~qe?SKEazasjuYtUV=#RmNQem5iIRA6x!Ss)%PM#(lHw~)JMV^! zzABR}uMxf8PU&GZOL%Nin~8O~A>W=?sDA64t*TT=5+7n!($JsxeGeCMep{)LjVC-SmlVx6@byIlHhbw*k^)bX?6U7QK;3xX6D#YSL-x+u`~Uo&XYZ5AY+Ya) z$eTEYCTFF6=ly^h;3$!z1_yjyVeoh4NzO%PJ z+-0N#>-XOD@4?9?4pf>(ozy{g)IF5p1OtOAjiatHA0-Z1e&OXuUD}YzbcjXB42=aIhY<8{^pT72Hd0LgC|5}OMusi zZxYNOSYxvBsPhzF`RM3i4Jb~pU#W^@GYhY~ok#em-J}JnFBtwTOWyZi3#ZcF(trHp zk0SSv^=fZSyq=A^(UM#(4;cN09=bDA)HhG^`ie+>;AQ}Hjwj@c6bb(>`0odSQVgQ4|F(y>5p{CT^VUx3p@Jhv8gl$Di{NaWyN7+91` z-g~PVY)NXzJTfYO;u~feKk2r*DjE0q$NTLri-fq-UaydRwtWp}{bX5*HLfn+kU1BE z=bdXio^kc&TW^ku7@3&ZJ2)Wq(rRj`I2e&?w-pkKFea4^&Wt?sS5@7DB|=69i>v%6 zpbRXhSVx38n~{|2EFM4a#pQt>)dTUp@~g=+XMClvh5j6ynYdFp{xGT!aqEdJ%=9y! zFRHb>DX^jG0Vt9bfe?!+Y7dH+(cDoI^9;IWiyCEr(Lfw7u!L$OS$nED87<-g*_vS& z*Wdeo}zAji(b@0DS`{jaDqi4LJy)Lt4|-XZxFxU?!OYLJ$SImqOM`KV*=b1#hlmMo^C=QDMag%9HqOfr|QyDuu-xgBz zl%=Rb;`?Q0joaR}RtnKrg}QM8lb11~C%>GG(_nR8YVolYTk>%lK0#g<2YU4i2vj#| z$wl6mdFrxq#;Ilh;{{>g#B1@VnXLu2cygD1tpQy%LuqQfne)InZxF?=TpdVcA%Azh zqXKlkN7CdgtbJ2^)Bc4EiNJo!tBgxQ^F!r6RwlI)8m=)Rv1@Uz4i>kE?STxKFZfkY z{we>c4FL)zYVvc2odrv%!f#p3o@;Gd<5bx39LXrY3vrhjL-!am)Qk0vh8e9vvaHoH z8!YOygR3jNTZ?;hCOK+i>zE%Nb^8m0GMiW;?!I+T+`@cenOKq1pq-T5cpQ*+B&^Ry zc`5x4Rn}``H(~c3%FV;!V{*-!&+BLgL!;)yQD0u9A-K0nRx!bP-g<0`)a(_>oIJe0 zmWZ8WtpQqe85;xoZ0ROLIRxX7O~z;;ZcF&nT6~3;0f$6ac9#FMGwVmdu~ELXW3P5% zR>xfWX0d}k%S$h=k?hx{Ig=D3z=Ol9KBk1Z~{(09tx;zJs>1g!sN_P2#ZO; z?B2I=lVK;WF!CwF?+@RU;YF5v$5Y+~pDn;8iyramj#*CoOmTq)-l^DjhCj+jJfBq) zoFK~|!8bEW^L@v2s}wL}24lnOIEw`EhNCYXUgtn~Pa36_P05y`P+gfd@8$04FTfQ3A|RDN=GilcLty5& z=}s`Nb|efQ_gA3!QcNdCnj$cs-IiMg7>1{7%iT=GDop1#yv3bh$Iz{8WK&+Y8SO|s zdTt@e9e!;hDtW+Eu27=L;fjsgTAk=VuS7+qP4H9JhF~0G)8a^m=W~3yFu`|lY2WB> z`;YLwG(+4wciFOiME2x6%H}tzomyY;VOLA0954g;12d`vx32Xi^88!JFL(3Qq7GAe zA;c5KyOUt5P$E~|;P^rI%w7N9^cl3AlH@bVyLJJAg+wwUQ1O(>}z+#^!!! z;goUPTI|iaw>BRt5W2m6iWLHx*$uhvAt@=&TU4uHqs}2Aid0Ft<{@W-*1ZFo^9U$x5R*TSuGdgZfua4t^J(+K6w!6n(Olqgyy($(G13Yf78b>DJ zK5!Qt{NO*97o%~)dB2_8sEc~35n4@>A$nj$M|1`Qbt&F_Lx!aJe2D#u%KF%6Bj?n# z4c`^tEkn)Yq_aT9_ieUFu%yO?x%*3rCO_YM-PfIaKoD&+F0a#4*%EvUwO@HVRW30Z zd(?B|*g#7av=B$Dvu!Us%o0P^R^2)BOzD|c;OovMPE5y$X@8=!7HwVBf8yNoC$EL~ zsk`96$%n0@gP-^n0RY8o-u~ZF90!mo!uU~&wkLT(V{mV}F$4!JLOSyq0K%;~!w*S)&rW~5XxsA+ zhD|vl;C1JZe)N~|@=|hh3*@ck%gFrK@p>huu0~fqP0#sFT^rG|`$`E@1Vr4GKj^y+ zJz!d?7Fi{0+8lUsE+Eg2YnKnZOVdh578ZU7JB~kM*(1VGo+TTRsWNhTmYl;?kYEt- zavbj&PfpE*hBOD1H%~Dzf24lmi?1=l@0VO3ZS|})V}^$ZD|#X7#ZHyot@C}IbRJ>o zOVUdhLr&&b^v0+eOz7#&Sx_F0wL4arecg9@EMiP{HvIq)vOxN`ZZ!uMM$(ns4Gi#X zx%Zhf%cB;2(9gv-Gxl=PIh}8pPcuwBE~~w8*!J@0l$kwr%kZc9i0;SsXtrp@@RUu( zr`y^>5s=Ds_T;uD7eeY+?;_ib{>ECE>G|eemu=6)+`c%a7BkfdqU(GmCVhRGr20U^ zBc3EMFjSwvxu=;|cW=6A&9qT0T*qK*I+{h*aX<{<)=2#d9dIH*p1tr-Dx+fGCsz)f z@rL0k(BbV${kuuZP!Jl%`N4-n=WOw=BPg;GS;Zfjdpt7E?Ao^tX481S%BOb>_UoazH9!Z`sl?t4buc%cfhv!Q=ti#8FaVet1+v#)tpxU9#Q zgCkb~5-Mjef1bSQm7Xf%v>E&3{<1PhP z6EqUYPbDO%SABVRM5aIZ$OlQ?O31A}??p#%B9fh>v_$y+aJRx%t$w!mJ5v{6-Hh-} zqBrN`Tt|0p71DHwVmLNlwmk)CLL7RdH&rHm83Iw|@ol>SNg~U)&yna45^kY(41VN#{V+SWleK~l zHMoWH=^OvNpu1d{A8~mW&AS|N@!g}w;YVzhP@I`6r=QuY8#oHrv)cwff-{UlSy;K?@iLl~u6$r`G8F z*XVan;~h*V=&WFSmD(nQWC5#-!k`a%S{#t}_SKWS3Y)KG$}S%YE$BXAoM$+PS+}jR zx8Kh+)$Q@F&e`QB1hyuepT>jBV)+6XFL56e8#K8+iQ(2xc=n*jsH#VFjTIeYEyL zKVh|ttS85>?p(H~RY=W*Jz#5I?B6P+jO^tH-JBw5n4_6VxrjD$j=?|}g_5!dj62+G zaluPOANu2<4YTDzzK~#jpwYHC^z#^es6oDK}8Oz$n#wdy6xw8_Y~nYd(035 z3pRA7i#5!nOLlns*nFUOFt>EmbM)ccmm-*m^?lqS-A>?2Mq7QB^*N^ODpYE=YWB@^ z{ec`{I7Omv%L&ap+%wV$wT%-*uhjPGHf9&b(VP%~xnm_XIn8(JE>`pvya_QdhwDHU zxx!F)1}USeGGd5y-;F{OndH9YAvuV9fhv(~`#YwunTMvgl*+i`$;`sS!j2xvfcL-+ z^TS>$KE4xK_w#71t8v6zE%c68`h0?rHiR@PxTUSeZ?PT;KV zwOIWSHi%tqU3JJt!g++VrwQiZ@{Oq<)|VK+YTqh_cm3$^Fh=0iiK*sOh8o8XnB=e5 z=L^YamJfI`UF8V~(9z%&+?{E9UW{YP8OaVV>$w$S}ZaT|AlX= z82D@Bg==y9#OYJcPo*cA@u2vJtRR=oRE!Icjq`~PFeB+YhW3%E``fvO1A9PvgSeJXgG;GKR z$MTA^C5vd3M(J^v@O}ixsFM!Dke$-ulHu(Ap#ahfSM_}ba$egXazX40Ra(u z#5WY%s-`eP7?;OQoc``)BT>{Izr;+4sfrHG8@8t--KDYlmB>y+bHo~RCAW}r5%1SB zopeZR#~9G|An6OCrIB^s1=va?vEE{1-AO6Ek&x$=@)a#u#NM8K(LaZR$4wa3Tr`@G z+?)?$gm>te(pTT(##G_~%=U=SFm|aP=lF}(+#ZPifrbgEsWGQ5qQv_Fn6yXu0anEG zT)ZATYM&hXGcCM6N&m{BO`0CPUu2Jw;+&23yllT@X4;X@OeWNEh}NcG7e4{CX{5q! zw$eF-M)GbJ6xhMK*q%KfmDK3Ra$TVE@t)kFuUo57Q4CG+CC zcEzM5z1U-k9{-H!H}VVoP@X_+$@BfGX>my3otyY0?y2>fY3u_C#Lp%ghpcT$R$&uz zAa-}?5It`F)+q~P^Jh(QzJxTNI5W`gtWJ)94!Oe*c`0?VRH6uxda*q$24$EowO9Pg z9n@8sa3|4nMRt*i50D*qVmXb$_ ztXW@W8`fIEMEUEF{fewyWRN%Tv82ncY~M^}IliQ5q_>T%{@Uu}XbV$6fn?vA@3D8C0pt93jBt^lK@zX;eaNqa{-l+cd(SU;f! zUP+G;Q*RZz!W-kKk0^k9A#J8ZPN-Yd;`zM~EZQapn_(|X_0nf1%4kY{)Tp)iwym(p zC#k5(cV3b27x+$8I7ry_dAZk5#vUq=*Pysl06@-su#gvmJQ5e(d`Nlg(|ch9Fam5I zMTM`*@nlNfC}ahKFmQsL*Jj!W1rrO4e0G@IVh>=_5lLTIPHp$W9t?LaZYVLV0(6Aq zVF;>vlOO*hx*#DUZkX3IPxQBoAcDfdU{;;8*l(bX5Xm}iizmv@rT0YrIaQhYyo1j8 zyV=joRb_4l^JVZ14TIHDDBC9s?V>R+2}ocy5lp5uW4eiBnTa<+viH8+-4oT%^z3G8 zqycngow@?}i-Y0{g& zCw|fxz_P@Pk8m_Jyj>iCqnyFV@QjP)v_}*CmDT+TAixv^y!-zs{i}j}9$U6^6)=dv z;Y)+EEAzN6;CaA-lS8v7geUCss+92FW)Vb>#^IuW&idF&KsWk$A!S@Y@0GVeKd9*y zg?&&wON+6N$G$&}X?Z*4Ot~6hK9u9o)Ngg~?90g^kxKV70gSYp=$5Exo$o=}s@elV z&tTw318Ql%5dfW~x!-`~UV7=bWjj0Tq}iMn!7(6+zbkSAmh0p>T)NEOdr3STWg7K{ z7O4K7;LQz$jzWXYnuY5>xiX5y>d#8tm0vyg-Mt#C(JWuD*KE2R*D$CALh{wVY>FEK zAzGm4{6IQBTJ2Y~tLP`xmF|SNqZ`lSIoQ!{X7-MqE$&DSm;sgaqAUx0_E*t7Wx%A8 zYu+tFsfZYhTwQ=Kyu1BT3W(2?puL$L=ogP)n$)_VV$5EzVGMqpena)Td+vBbPRGeK zxxL0Xy3w+C@@c>`f|RN(1=J^I9$ZBJQUi!uf%JD^+9f2#Gu)Al;VR0X?k{I1pyrZV zvx=wNYwM4O_%)=oqd3dBSa5#E?P+>Z(*sv2Us-8Qwn*92Z@Lk1yzz1?df+-JQbgE_ z=mIr(Athh};R1nxKusBrRZyIZVib}e_>hbTzM#}SECiC|Dz7SNP$JkpbLO0FWqJ-f znwE*$wl#|6f)62(RNvYi4mysfO*!>wlsv29%?=I)VaL-XQ>Ol>^adl3VZRBhq?~_r zv!ei3bYo79Smg9q;8Z$`OOgk&rrn`)?&duS?G^22s!W-h5qH#>O%q%07tK_ZaT(HN zl#MT)EfYAfE#=q{#lL>zdxD3B{bc} zy+wAY-F1X{-BO)XjYSzX2e#hqN~)T|5Jp(68B-%{xs2_oh40XyqGY*=_G-GgLh4jO z?oxPR7-Q;|!B?gNV#mS{rxo4qQ$e_#QJf&1+0yQ{zjYYkUV14-An#vGB< ztT@Q0VcRo6(BJh6z DCO1$@ literal 0 HcmV?d00001