|
[x]
Posted via EE Mobile
|
||
Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again. |
||
| Question |
|
[x]
Attachment Details
|
||
|
[x]
The Solution Rating System
|
||
With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.
Your Input Matters If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support. Thank you! |
||
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265: 266: 267: 268: 269: 270: 271: 272: 273: 274: 275: 276: 277: 278: 279: 280: 281: 282: 283: 284: 285: 286: 287: 288: 289: 290: 291: 292: 293: 294: 295: 296: 297: 298: 299: 300: 301: 302: 303: 304: 305: 306: 307: 308: 309: 310: 311: 312: 313: 314: 315: 316: 317: 318: 319: 320: 321: 322: 323: 324: 325: 326: 327: 328: 329: 330: 331: 332: 333: 334: 335: 336: 337: 338: 339: 340: 341: 342: 343: 344: 345: 346: 347: 348: 349: 350: 351: 352: 353: 354: 355: 356: 357: 358: 359: 360: 361: 362: 363: 364: 365: 366: 367: 368: 369: 370: 371: 372: 373: 374: 375: 376: 377: 378: 379: 380: 381: 382: 383: 384: 385: 386: 387: 388: 389: 390: 391: 392: 393: 394: 395: 396: 397: 398: 399: 400: 401: 402: 403: 404: 405: 406: 407: 408: 409: 410: 411: 412: 413: 414: 415: 416: 417: 418: 419: 420: 421: 422: 423: 424: 425: 426: 427: 428: 429: 430: 431: 432: 433: 434: 435: 436: 437: 438: 439: 440: 441: 442: 443: 444: 445: 446: 447: 448: 449: 450: 451: 452: 453: 454: 455: 456: 457: 458: 459: 460: 461: 462: 463: 464: 465: 466: 467: 468: 469: 470: 471: 472: 473: 474: 475: 476: 477: 478: 479: 480: 481: 482: 483: 484: 485: 486: 487: 488: 489: 490: 491: 492: 493: 494: 495: 496: 497: 498: 499: 500: 501: 502: 503: 504: 505: 506: 507: 508: 509: 510: 511: 512: 513: 514: 515: 516: 517: 518: 519: 520: 521: 522: 523: 524: 525: 526: 527: 528: 529: 530: 531: 532: 533: 534: 535: 536: 537: 538: 539: 540: 541: 542: 543: 544: 545: 546: 547: 548: 549: 550: 551: 552: 553: 554: 555: 556: 557: 558: 559: 560: 561: 562: 563: 564: 565: 566: 567: 568: 569: 570: 571: 572: 573: 574: 575: 576: 577: 578: 579: 580: 581: 582: 583: 584: 585: 586: 587: 588: 589: 590: 591: 592: 593: 594: 595: 596: 597: 598: 599: 600: 601: 602: 603: 604: 605: 606: 607: 608: 609: 610: 611: 612: 613: 614: 615: 616: 617: 618: 619: 620: 621: 622: 623: 624: 625: 626: 627: 628: 629: 630: 631: 632: 633: 634: 635: 636: 637: 638: 639: 640: 641: 642: 643: 644: 645: 646: 647: 648: 649: 650: 651: 652: 653: 654: 655: 656: 657: 658: 659: 660: 661: 662: 663: 664: 665: 666: 667: 668: 669: 670: 671: 672: 673: 674: 675: 676: 677: 678: 679: 680: 681: 682: 683: 684: 685: 686: 687: 688: 689: 690: 691: 692: 693: 694: 695: 696: 697: 698: 699: 700: 701: 702: 703: 704: 705: 706: 707: 708: 709: 710: 711: 712: 713: 714: 715: 716: 717: 718: 719: 720: 721: 722: 723: 724: 725: 726: 727: 728: |
: Saved : Written by user at 20:44:36.628 UTC Sat Jan 17 2009 ! ASA Version 8.0(4) ! hostname asa enable password xxxxxxxxxxxxxx encrypted passwd xxxxxxxxxxxxxx encrypted names ! interface Ethernet0/0 nameif Outside security-level 0 ip address 63.236.xxx.xxx 255.255.255.224 ! interface Ethernet0/1 nameif Inside security-level 100 ip address 192.168.75.1 255.255.255.0 ! interface Ethernet0/2 shutdown no nameif no security-level no ip address ! interface Ethernet0/3 shutdown no nameif no security-level no ip address ! interface Management0/0 shutdown no nameif no security-level no ip address ! ftp mode passive same-security-traffic permit inter-interface same-security-traffic permit intra-interface access-list Outside extended permit ip 68.167.49.24 255.255.255.248 any access-list Outside extended permit ip 65.114.139.224 255.255.255.224 any access-list Outside extended permit tcp any host 63.236.13.200 eq smtp access-list Outside extended permit tcp any host 63.236.13.201 eq www access-list Outside extended permit tcp any host 63.236.13.201 eq https access-list Citizant_VPN_splitTunnelAcl standard permit 192.168.75.0 255.255.255.0 access-list Inside_nat0_outbound extended permit ip 192.168.75.0 255.255.255.0 192.168.75.192 255.255.255.192 access-list Inside_nat0_outbound extended permit ip 192.168.75.0 255.255.255.0 192.168.50.0 255.255.255.0 access-list Inside_cryptomap extended permit ip 192.168.75.0 255.255.255.0 192.168.50.0 255.255.255.0 access-list citizant_vpn_splitTunnelAcl standard permit 192.168.75.0 255.255.255.0 access-list Outside_cryptomap extended permit ip 192.168.75.0 255.255.255.0 192.168.50.0 255.255.255.0 pager lines 20 logging enable logging buffered debugging logging asdm informational mtu Outside 1500 mtu Inside 1500 ip local pool VPN_POOL 192.168.75.200-192.168.75.249 mask 255.255.255.0 no failover icmp unreachable rate-limit 1 burst-size 1 icmp permit any Inside asdm image disk0:/asdm-615.bin no asdm history enable arp timeout 14400 global (Outside) 101 interface nat (Inside) 0 access-list Inside_nat0_outbound nat (Inside) 101 0.0.0.0 0.0.0.0 static (Inside,Outside) 63.236.xxx.xxx 192.168.75.20 netmask 255.255.255.255 static (Inside,Outside) 63.236.xxx.xxx 192.168.75.22 netmask 255.255.255.255 access-group Outside in interface Outside route Outside 0.0.0.0 0.0.0.0 63.236.13.193 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute dynamic-access-policy-record DfltAccessPolicy aaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa authentication enable console LOCAL aaa authentication serial console LOCAL aaa authentication ssh console LOCAL aaa authentication telnet console LOCAL aaa authentication http console LOCAL http server enable http 192.168.75.0 255.255.255.0 Inside http 0.0.0.0 0.0.0.0 Outside no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec security-association lifetime seconds 28800 crypto ipsec security-association lifetime kilobytes 4608000 crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1 crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5 crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set security-association lifetime seconds 28800 crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set security-association lifetime kilobytes 4608000 crypto map Outside_map 1 match address Outside_cryptomap crypto map Outside_map 1 set peer 65.114.xxx.xxx crypto map Outside_map 1 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5 crypto map Outside_map 1 set security-association lifetime seconds 28800 crypto map Outside_map 1 set security-association lifetime kilobytes 4608000 crypto map Outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP crypto map Outside_map interface Outside crypto map Inside_map0 1 match address Inside_cryptomap crypto map Inside_map0 1 set peer 65.114.xxx.xxx crypto map Inside_map0 1 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5 crypto map Inside_map0 1 set security-association lifetime seconds 28800 crypto map Inside_map0 1 set security-association lifetime kilobytes 4608000 crypto map Inside_map0 interface Inside crypto isakmp enable Outside crypto isakmp enable Inside crypto isakmp policy 5 authentication pre-share encryption 3des hash sha group 2 lifetime 86400 crypto isakmp policy 10 authentication pre-share encryption des hash sha group 2 lifetime 86400 telnet timeout 5 ssh 0.0.0.0 0.0.0.0 Outside ssh 65.114.xxx.xxx 255.255.255.224 Outside ssh 192.168.75.254 255.255.255.255 Inside ssh timeout 5 console timeout 0 management-access Inside threat-detection basic-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept webvpn enable Outside username howesieg password lWHcdh1VLcmmaNA6 encrypted privilege 15 username citadmin password kjr51D6niJIL7md0 encrypted privilege 15 tunnel-group 65.114.xxx.xxx type ipsec-l2l tunnel-group 65.114.xxx.xxx ipsec-attributes pre-shared-key * ! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp ! service-policy global_policy global prompt hostname context Cryptochecksum:0688fbcf8d159641a7467124eb8df851 ----------- Building configuration... Current configuration : 15392 bytes ! version 12.4 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption service sequence-numbers ! hostname 1812_router ! boot-start-marker boot-end-marker ! security authentication failure rate 3 log security passwords min-length 6 logging buffered 51200 logging console critical enable secret 5 $1$oI6p$JlAxbdLccUrZ5wphDNfqs0 enable password 7 060A1C251844194F0F ! aaa new-model ! ! aaa authentication login local_authen local aaa authorization exec local_author local ! ! aaa session-id common ! crypto pki trustpoint TP-self-signed-2311851175 enrollment selfsigned subject-name cn=IOS-Self-Signed-Certificate-2311851175 revocation-check none rsakeypair TP-self-signed-2311851175 ! ! crypto pki certificate chain TP-self-signed-2311851175 certificate self-signed 01 30820248 308201B1 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 69666963 6174652D 32333131 38353131 3735301E 170D3039 30313137 31383139 33305A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 33313138 35313137 3530819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 8100E311 14B0DECD E0C4F201 75EE740B B4EE7E8A 164F3D9A 021819C9 15F58FAA 548FE9EB 0F5E0E23 42112395 0D495515 8683156C 93DF8663 9EAF44A4 7C5C53E1 61D07DF9 227A8B39 8193F015 8791FAE3 747B25AF DB7AC1C9 043EEC43 946224CF CA4E1614 148C6423 97102A4A 43AFDAD0 E1791A64 83C0AB5C 66B53C9E E9C2B9E1 F9AB0203 010001A3 70306E30 0F060355 1D130101 FF040530 030101FF 301B0603 551D1104 14301282 10636861 6E74696C 6C795F72 6F757465 72301F06 03551D23 04183016 80141CB6 C3130051 43D38751 43E81D3A 232D0CD4 2CAA301D 0603551D 0E041604 141CB6C3 13005143 D3875143 E81D3A23 2D0CD42C AA300D06 092A8648 86F70D01 01040500 03818100 7AEFF102 E7467DD0 EF9DDA38 95FFE407 8A0F3E41 E36BA48B B601378A 9AC5E19F 01DBFE96 85682E77 AE9F6227 1AE16581 6D0F50E4 76CF8858 1907B680 415267C2 F9604E09 D8A91FBF 6F5EFE78 12EB5B9F A685DC5D CDF8F99D E615D4CF 9D8F3BF5 EBF3915E 3214AA8C 5E4F2185 E419421A 5406A365 971BB3CE 832B6333 E508F359 quit ! ! crypto isakmp policy 1 encr 3des authentication pre-share group 2 crypto isakmp key xxxxxx address 63.236.xxx.xxx ! ! crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac ! crypto map SDM_CMAP_1 1 ipsec-isakmp description Tunnel to63.236.xxx.xxx set peer 63.236.xxx.xxx set transform-set ESP-3DES-SHA match address 102 ! no ip source-route no ip routing ! ! ! ! no ip cef no ip bootp server ip name-server 205.171.3.65 ip name-server 205.171.2.65 ! no ipv6 cef multilink bundle-name authenticated parameter-map type protocol-info msn-servers server name messenger.hotmail.com server name gateway.messenger.hotmail.com server name webmessenger.msn.com parameter-map type protocol-info aol-servers server name login.oscar.aol.com server name toc.oscar.aol.com server name oam-d09a.blue.aol.com parameter-map type protocol-info yahoo-servers server name scs.msg.yahoo.com server name scsa.msg.yahoo.com server name scsb.msg.yahoo.com server name scsc.msg.yahoo.com server name scsd.msg.yahoo.com server name cs16.msg.dcn.yahoo.com server name cs19.msg.dcn.yahoo.com server name cs42.msg.dcn.yahoo.com server name cs53.msg.dcn.yahoo.com server name cs54.msg.dcn.yahoo.com server name ads1.vip.scd.yahoo.com server name radio1.launch.vip.dal.yahoo.com server name in1.msg.vip.re2.yahoo.com server name data1.my.vip.sc5.yahoo.com server name address1.pim.vip.mud.yahoo.com server name edit.messenger.yahoo.com server name messenger.yahoo.com server name http.pager.yahoo.com server name privacy.yahoo.com server name csa.yahoo.com server name csb.yahoo.com server name csc.yahoo.com ! ! archive log config hidekeys ! ! ! class-map type inspect match-all sdm-cls-VPNOutsideToInside-1 match access-group 104 class-map type inspect match-any SDM_HTTPS match access-group name SDM_HTTPS class-map type inspect match-any SDM_SSH match access-group name SDM_SSH class-map type inspect match-any SDM_SHELL match access-group name SDM_SHELL class-map type inspect match-any sdm-cls-access match class-map SDM_HTTPS match class-map SDM_SSH match class-map SDM_SHELL class-map type inspect match-any SDM_AH match access-group name SDM_AH class-map type inspect imap match-any sdm-app-imap match invalid-command class-map type inspect match-any sdm-cls-protocol-p2p match protocol edonkey signature match protocol gnutella signature match protocol kazaa2 signature match protocol fasttrack signature match protocol bittorrent signature class-map type inspect match-any sdm-cls-insp-traffic match protocol cuseeme match protocol dns match protocol ftp match protocol h323 match protocol https match protocol icmp match protocol imap match protocol pop3 match protocol netshow match protocol shell match protocol realmedia match protocol rtsp match protocol smtp extended match protocol sql-net match protocol streamworks match protocol tftp match protocol vdolive match protocol tcp match protocol udp class-map type inspect match-all sdm-insp-traffic match class-map sdm-cls-insp-traffic class-map type inspect match-any SDM_ESP match access-group name SDM_ESP class-map type inspect match-any SDM_VPN_TRAFFIC match protocol isakmp match protocol ipsec-msft match class-map SDM_AH match class-map SDM_ESP class-map type inspect match-all SDM_VPN_PT match access-group 103 match class-map SDM_VPN_TRAFFIC class-map type inspect gnutella match-any sdm-app-gnutella match file-transfer class-map type inspect match-any SDM-Voice-permit match protocol h323 match protocol skinny match protocol sip class-map type inspect msnmsgr match-any sdm-app-msn-otherservices match service any class-map type inspect ymsgr match-any sdm-app-yahoo-otherservices match service any class-map type inspect match-all sdm-protocol-pop3 match protocol pop3 class-map type inspect match-any sdm-cls-icmp-access match protocol icmp match protocol tcp match protocol udp class-map type inspect match-any sdm-cls-protocol-im match protocol ymsgr yahoo-servers match protocol msnmsgr msn-servers match protocol aol aol-servers class-map type inspect aol match-any sdm-app-aol-otherservices match service any class-map type inspect pop3 match-any sdm-app-pop3 match invalid-command class-map type inspect match-all sdm-access match class-map sdm-cls-access match access-group 101 class-map type inspect kazaa2 match-any sdm-app-kazaa2 match file-transfer class-map type inspect match-all sdm-protocol-p2p match class-map sdm-cls-protocol-p2p class-map type inspect http match-any sdm-http-blockparam match request port-misuse im match request port-misuse p2p match req-resp protocol-violation class-map type inspect match-all sdm-protocol-im match class-map sdm-cls-protocol-im class-map type inspect match-all sdm-icmp-access match class-map sdm-cls-icmp-access class-map type inspect match-all sdm-invalid-src match access-group 100 class-map type inspect ymsgr match-any sdm-app-yahoo match service text-chat class-map type inspect msnmsgr match-any sdm-app-msn match service text-chat class-map type inspect edonkey match-any sdm-app-edonkey match file-transfer match text-chat match search-file-name class-map type inspect http match-any sdm-app-httpmethods match request method bcopy match request method bdelete match request method bmove match request method bpropfind match request method bproppatch match request method connect match request method copy match request method delete match request method edit match request method getattribute match request method getattributenames match request method getproperties match request method index match request method lock match request method mkcol match request method mkdir match request method move match request method notify match request method options match request method poll match request method propfind match request method proppatch match request method put match request method revadd match request method revlabel match request method revlog match request method revnum match request method save match request method search match request method setattribute match request method startrev match request method stoprev match request method subscribe match request method trace match request method unedit match request method unlock match request method unsubscribe class-map type inspect edonkey match-any sdm-app-edonkeychat match search-file-name match text-chat class-map type inspect fasttrack match-any sdm-app-fasttrack match file-transfer class-map type inspect http match-any sdm-http-allowparam match request port-misuse tunneling class-map type inspect match-all sdm-protocol-http match protocol http class-map type inspect edonkey match-any sdm-app-edonkeydownload match file-transfer class-map type inspect match-all sdm-protocol-imap match protocol imap class-map type inspect aol match-any sdm-app-aol match service text-chat ! ! policy-map type inspect sdm-permit-icmpreply class type inspect sdm-icmp-access inspect class class-default pass policy-map type inspect sdm-pol-VPNOutsideToInside-1 class type inspect sdm-cls-VPNOutsideToInside-1 inspect class class-default policy-map type inspect p2p sdm-action-app-p2p class type inspect edonkey sdm-app-edonkeychat log allow class type inspect edonkey sdm-app-edonkeydownload log allow class type inspect fasttrack sdm-app-fasttrack log allow class type inspect gnutella sdm-app-gnutella log allow class type inspect kazaa2 sdm-app-kazaa2 log allow class class-default policy-map type inspect http sdm-action-app-http class type inspect http sdm-http-blockparam log reset class type inspect http sdm-app-httpmethods log reset class type inspect http sdm-http-allowparam log allow class class-default policy-map type inspect imap sdm-action-imap class type inspect imap sdm-app-imap log class class-default policy-map type inspect pop3 sdm-action-pop3 class type inspect pop3 sdm-app-pop3 log class class-default policy-map type inspect im sdm-action-app-im class type inspect aol sdm-app-aol log allow class type inspect msnmsgr sdm-app-msn log allow class type inspect ymsgr sdm-app-yahoo log allow class type inspect aol sdm-app-aol-otherservices log reset class type inspect msnmsgr sdm-app-msn-otherservices log reset class type inspect ymsgr sdm-app-yahoo-otherservices log reset class class-default policy-map type inspect sdm-inspect class type inspect sdm-invalid-src drop log class type inspect sdm-protocol-http inspect service-policy http sdm-action-app-http class type inspect sdm-protocol-imap inspect service-policy imap sdm-action-imap class type inspect sdm-protocol-pop3 inspect service-policy pop3 sdm-action-pop3 class type inspect sdm-protocol-p2p inspect service-policy p2p sdm-action-app-p2p class type inspect sdm-protocol-im inspect service-policy im sdm-action-app-im class type inspect sdm-insp-traffic inspect class type inspect SDM-Voice-permit inspect class class-default pass policy-map type inspect sdm-permit class type inspect SDM_VPN_PT pass class type inspect sdm-access inspect class class-default ! zone security out-zone zone security in-zone zone-pair security sdm-zp-self-out source self destination out-zone service-policy type inspect sdm-permit-icmpreply zone-pair security sdm-zp-out-self source out-zone destination self service-policy type inspect sdm-permit zone-pair security sdm-zp-in-out source in-zone destination out-zone service-policy type inspect sdm-inspect zone-pair security sdm-zp-VPNOutsideToInside-1 source out-zone destination in-zone service-policy type inspect sdm-pol-VPNOutsideToInside-1 ! ! ! interface Null0 no ip unreachables ! interface FastEthernet0 description $ETH-WAN$$FW_OUTSIDE$ ip address 65.114.xxx.xxx 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp ip nat outside ip virtual-reassembly zone-member security out-zone no ip route-cache duplex auto speed auto crypto map SDM_CMAP_1 ! interface FastEthernet1 no ip address no ip redirects no ip unreachables no ip proxy-arp no ip route-cache duplex auto speed auto ! interface BRI0 no ip address no ip redirects no ip unreachables no ip proxy-arp encapsulation hdlc no ip route-cache shutdown ! interface FastEthernet2 ! interface FastEthernet3 ! interface FastEthernet4 ! interface FastEthernet5 ! interface FastEthernet6 ! interface FastEthernet7 ! interface FastEthernet8 ! interface FastEthernet9 ! interface Vlan1 description $FW_INSIDE$ ip address 192.168.50.1 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp ip nat inside ip virtual-reassembly zone-member security in-zone no ip route-cache ! ip forward-protocol nd ip route 0.0.0.0 0.0.0.0 65.114.xxx.xxx ! ! ip http server ip http secure-server ip nat inside source route-map SDM_RMAP_1 interface FastEthernet0 overload ! ip access-list extended SDM_AH remark SDM_ACL Category=1 permit ahp any any ip access-list extended SDM_ESP remark SDM_ACL Category=1 permit esp any any ip access-list extended SDM_HTTPS remark SDM_ACL Category=1 permit tcp any any eq 443 ip access-list extended SDM_SHELL remark SDM_ACL Category=1 permit tcp any any eq cmd ip access-list extended SDM_SSH remark SDM_ACL Category=1 permit tcp any any eq 22 ! logging trap debugging access-list 1 remark INSIDE_IF=Vlan1 access-list 1 remark SDM_ACL Category=2 access-list 1 permit 192.168.50.0 0.0.0.255 access-list 100 remark SDM_ACL Category=128 access-list 100 permit ip host 255.255.255.255 any access-list 100 permit ip 127.0.0.0 0.255.255.255 any access-list 100 permit ip 65.114.139.0 0.0.0.255 any access-list 101 remark SDM_ACL Category=128 access-list 101 permit ip host 0.0.0.0 any access-list 102 remark SDM_ACL Category=4 access-list 102 remark IPSec Rule access-list 102 permit ip 192.168.50.0 0.0.0.255 192.168.75.0 0.0.0.255 access-list 103 remark SDM_ACL Category=128 access-list 103 permit ip host 63.236.xxx.xxx any access-list 104 remark SDM_ACL Category=0 access-list 104 remark IPSec Rule access-list 104 permit ip 192.168.75.0 0.0.0.255 192.168.50.0 0.0.0.255 access-list 105 remark SDM_ACL Category=2 access-list 105 remark IPSec Rule access-list 105 deny ip 192.168.50.0 0.0.0.255 192.168.75.0 0.0.0.255 access-list 105 permit ip 192.168.50.0 0.0.0.255 any no cdp run ! ! ! route-map SDM_RMAP_1 permit 1 match ip address 105 ! ! ! ! control-plane ! banner login ^CAuthorized access only! Disconnect IMMEDIATELY if you are not an authorized user! ^C ! line con 0 login authentication local_authen line aux 0 login authentication local_authen line vty 0 4 password 7 062E0C2A781A584C44 authorization exec local_author login authentication local_authen transport input ssh ! scheduler allocate 4000 1000 scheduler interval 500 ntp update-calendar ntp server 192.43.244.18 source FastEthernet0 prefer ! webvpn cef end |
Advertisement
| Hall of Fame |