|
[x]
Posted via EE Mobile
|
||
Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again. |
||
| 08/07/2009 at 09:46AM PDT, ID: 24635309 |
|
[x]
Attachment Details
|
||
|
[x]
The Solution Rating System
|
||
With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.
Your Input Matters If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support. Thank you! |
||
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265: 266: 267: 268: 269: 270: 271: |
ASA Version 8.0(2) ! hostname Pix domain-name domain.local enable password eG56nUAWGSXNN2V2 encrypted names dns-guard ! interface Ethernet0/0 nameif outside security-level 0 ip address 1.1.1.114 255.255.255.248 ospf cost 10 ! interface Ethernet0/1 nameif inside security-level 100 ip address 10.0.0.1 255.255.255.0 ospf cost 10 ! interface Ethernet0/2 nameif dmz security-level 50 ip address 192.168.0.1 255.255.255.0 ospf cost 10 ! interface Ethernet0/3 shutdown no nameif no security-level no ip address ! interface Management0/0 nameif management security-level 100 ip address 192.168.1.1 255.255.255.0 ospf cost 10 management-only ! passwd 1iRgd9K.fBsxQKzA encrypted boot system disk0:/asa802-k8.bin ftp mode passive clock timezone Central -6 clock summer-time -6 recurring dns server-group DefaultDNS domain-name domain.local object-group service RDP tcp-udp port-object eq 3389 object-group protocol TCPUDP protocol-object udp protocol-object tcp access-list outside_in extended permit tcp 216.17.3.0 255.255.255.0 interface ou tside eq smtp access-list outside_in extended permit tcp 204.11.209.64 255.255.255.192 interfa ce outside eq smtp access-list outside_in extended permit tcp any interface outside eq https access-list outside_in extended permit tcp any host 1.1.1.115 eq https access-list outside_in extended permit tcp any host 1.1.1.116 eq www access-list outside_in extended permit icmp any host 1.1.1.114 echo-reply access-list outside_in extended permit icmp any host 1.1.1.114 source-quenc h access-list outside_in extended permit icmp any host 1.1.1.114 unreachable access-list outside_in extended permit icmp any host 1.1.1.114 time-exceede d access-list outside_in extended permit ip 172.16.10.0 255.255.255.0 interface dm z access-list outside_in extended permit tcp any host 1.1.1.114 eq 3389 access-list NoNat extended permit ip 10.0.0.0 255.255.255.0 172.16.0.0 255.255.0 .0 access-list NoNat extended permit ip 10.0.0.0 255.255.255.0 192.168.0.0 255.255. 255.0 access-list NoNat extended permit ip 192.168.0.0 255.255.255.0 172.16.100.0 255. 255.255.0 access-list NoNat extended permit ip 172.16.100.0 255.255.255.0 192.168.0.0 255. 255.255.0 access-list NoNat extended permit ip 10.0.0.0 255.255.255.0 10.0.1.0 255.255.255 .0 access-list SplTunnel extended permit ip 10.0.0.0 255.255.255.0 172.16.0.0 255.2 55.0.0 access-list SplTunnel extended permit ip 192.168.0.0 255.255.255.0 172.16.100.0 255.255.255.0 access-list dmz_access_in extended permit tcp host 192.168.0.10 host 10.0.0.234 eq 1433 inactive access-list dmz_access_in extended permit tcp host 192.168.0.10 host 10.0.0.234 eq 135 inactive access-list dmz_access_in extended permit tcp host 192.168.0.10 host 10.0.0.234 eq 8080 inactive access-list dmz_access_in extended permit tcp host 192.168.0.10 host 10.0.0.234 range 4000 4020 inactive access-list dmz_access_in extended permit udp host 192.168.0.10 host 10.0.0.234 eq 135 inactive access-list dmz_access_in extended permit tcp host 192.168.0.10 host 10.0.0.231 eq 8080 access-list dmz_access_in extended permit tcp host 192.168.0.10 host 10.0.0.231 eq 4343 access-list dmz_access_in extended deny ip 192.168.0.0 255.255.255.0 10.0.0.0 25 5.255.255.0 access-list dmz_access_in extended permit ip any any access-list dmz_nat0_outbound extended permit ip 192.168.0.0 255.255.255.0 10.0. 0.0 255.255.255.0 access-list dmz_nat0_outbound extended permit ip 192.168.0.0 255.255.255.0 172.1 6.100.0 255.255.255.0 access-list outside_nat0_outbound extended permit ip 172.16.100.0 255.255.255.0 interface dmz access-list captout extended permit tcp any interface outside eq smtp access-list captout extended permit tcp interface outside eq smtp any access-list capin extended permit tcp any host 10.0.0.231 eq smtp access-list capin extended permit tcp host 10.0.0.231 eq smtp any access-list outside_cryptomap extended permit ip 10.0.0.0 255.255.255.0 10.0.1.0 255.255.255.0 pager lines 24 logging enable logging timestamp logging monitor debugging logging buffered errors logging trap notifications logging asdm informational logging host inside 10.0.0.230 mtu outside 1500 mtu inside 1500 mtu dmz 1500 mtu management 1500 ip local pool Ippool 172.16.100.1-172.16.100.100 mask 255.255.255.0 ip audit name outside_attack attack action alarm drop reset ip audit interface outside outside_attack ip audit attack action alarm drop reset icmp unreachable rate-limit 1 burst-size 1 asdm image disk0:/asdm-602.bin asdm location 172.16.0.0 255.255.0.0 outside asdm location 1.1.1.114 255.255.255.255 inside asdm location 1.1.1.115 255.255.255.255 inside no asdm history enable arp timeout 14400 nat-control global (outside) 1 interface nat (outside) 0 access-list outside_nat0_outbound nat (inside) 0 access-list NoNat nat (inside) 1 10.0.0.0 255.0.0.0 nat (dmz) 0 access-list dmz_nat0_outbound nat (dmz) 1 192.168.0.0 255.255.255.0 static (inside,outside) tcp 1.1.1.115 https 10.0.0.233 https netmask 255.25 5.255.255 static (inside,outside) tcp interface smtp 10.0.0.231 smtp netmask 255.255.255.2 55 static (dmz,outside) tcp 1.1.1.116 www 192.168.0.10 www netmask 255.255.255 .255 static (inside,outside) tcp interface https 10.0.0.231 https netmask 255.255.255 .255 static (inside,outside) tcp 1.1.1.114 3389 10.0.0.233 3389 netmask 255.255. 255.255 access-group outside_in in interface outside access-group dmz_access_in in interface dmz route outside 0.0.0.0 0.0.0.0 64.122.228.113 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout uauth 0:05:00 absolute dynamic-access-policy-record DfltAccessPolicy aaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa-server AuthRadius protocol radius aaa-server AuthRadius host 10.0.0.230 key R@diu5## http server enable http 172.16.100.0 255.255.255.0 inside http 192.168.1.0 255.255.255.0 management http 10.0.0.0 255.255.255.0 inside no snmp-server location no snmp-server contact snmp-server community public snmp-server enable traps snmp authentication linkup linkdown coldstart crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac crypto ipsec transform-set myset esp-aes esp-sha-hmac crypto ipsec transform-set myset1 esp-3des esp-md5-hmac crypto dynamic-map dynmap 50 set transform-set myset crypto map mymap 20 match address outside_cryptomap crypto map mymap 20 set peer 74.0.249.154 crypto map mymap 20 set transform-set myset1 crypto map mymap 50 ipsec-isakmp dynamic dynmap crypto map mymap interface outside crypto isakmp identity address crypto isakmp enable outside crypto isakmp policy 10 authentication pre-share encryption 3des hash md5 group 2 lifetime 86400 no crypto isakmp nat-traversal telnet 172.16.100.0 255.255.255.0 outside telnet 10.0.0.0 255.255.0.0 inside telnet timeout 5 ssh 0.0.0.0 0.0.0.0 outside ssh 0.0.0.0 0.0.0.0 inside ssh timeout 60 console timeout 0 management-access inside dhcpd address 192.168.1.2-192.168.1.254 management dhcpd enable management ! threat-detection basic-threat threat-detection statistics ! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns migrated_dns_map_1 parameters message-length maximum 1024 policy-map global_policy class inspection_default inspect dns migrated_dns_map_1 inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp inspect icmp inspect icmp error ! service-policy global_policy global ntp server 204.34.198.41 source outside tftp-server inside 10.0.0.99 tftp-server group-policy vpn internal group-policy vpn attributes wins-server value 10.0.0.230 dns-server value 10.0.0.230 10.0.0.231 split-tunnel-policy tunnelspecified split-tunnel-network-list value SplTunnel default-domain value domain.local username wipfli password qsNufYu/02WyCx2l encrypted username wipfli attributes vpn-group-policy vpn tunnel-group DefaultL2LGroup ipsec-attributes isakmp keepalive threshold 60 retry 2 tunnel-group DefaultRAGroup ipsec-attributes isakmp keepalive threshold 10 retry 2 tunnel-group DefaultWEBVPNGroup ipsec-attributes isakmp keepalive threshold 60 retry 2 tunnel-group ReeveClient type remote-access tunnel-group ReeveClient general-attributes address-pool ippool authentication-server-group AuthRadius default-group-policy vpn tunnel-group ReeveClient ipsec-attributes pre-shared-key * isakmp keepalive threshold 60 retry 2 tunnel-group 74.0.249.154 type ipsec-l2l tunnel-group 74.0.249.154 ipsec-attributes pre-shared-key * isakmp keepalive threshold 60 retry 2 prompt hostname context Cryptochecksum:82aac90548c8143d2610d33bedd747e2 |
Advertisement