|
[x]
Posted via EE Mobile
|
||
Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again. |
||
| Question |
|
[x]
Attachment Details
|
||
|
[x]
The Solution Rating System
|
||
With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.
Your Input Matters If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support. Thank you! |
||
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265: 266: 267: 268: 269: 270: 271: 272: 273: 274: 275: 276: 277: 278: 279: 280: 281: 282: 283: 284: 285: 286: |
: Saved : ASA Version 7.2(3) ! hostname MainFirewall domain-name shrun enable password *** encrypted names ! interface Ethernet0/0 nameif outside security-level 0 ip address *** 255.255.255.224 ospf cost 10 ! interface Ethernet0/1 nameif inside security-level 100 ip address 192.168.6.13 255.255.255.0 ospf cost 10 ! interface Ethernet0/2 shutdown no nameif no security-level no ip address ! interface Ethernet0/3 shutdown no nameif no security-level no ip address ! interface Management0/0 nameif management security-level 100 ip address 10.1.1.1 255.255.255.0 ospf cost 10 management-only ! passwd jDUXMyqeIzxQIVgK encrypted boot system disk0:/asa723-k8.bin ftp mode passive clock timezone CST -6 clock summer-time CDT recurring dns domain-lookup inside dns server-group DefaultDNS name-server 192.168.6.34 name-server 192.168.6.10 domain-name shrun same-security-traffic permit intra-interface access-list split-tunnel extended permit ip 192.168.75.0 255.255.255.0 any access-list split-tunnel extended permit ip 192.168.6.0 255.255.255.0 any access-list vpntunnel extended permit ip 192.168.6.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.1.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.2.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.3.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.4.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.5.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.7.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.8.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.9.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.11.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.10.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.12.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.60.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.101.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.102.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.107.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.108.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.110.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.111.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 172.16.25.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list vpntunnel extended permit ip 192.168.75.0 255.255.255.0 host 192.168.6.254 access-list nonat extended permit ip 192.168.6.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.2.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.3.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.4.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.5.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.7.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.8.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.9.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.11.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.12.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.60.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.101.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.102.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.107.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.108.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.110.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.111.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 172.16.25.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list nonat extended permit ip 192.168.6.0 255.255.255.0 192.168.6.128 255.255.255.128 access-list nonat extended permit ip 192.168.75.0 255.255.255.0 172.16.25.0 255.255.255.0 access-list nonat extended permit ip 192.168.6.0 255.255.255.0 172.16.25.0 255.255.255.0 access-list ping_acl extended permit icmp any any access-list everything extended permit ip any any access-list everything extended permit ip 192.168.75.0 255.255.255.0 192.168.6.0 255.255.255.0 access-list everything extended permit ip 172.16.25.0 255.255.255.0 192.168.6.0 255.255.255.0 access-list everything extended permit icmp 172.16.25.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list wbnash_splitTunnelAcl standard permit 192.168.6.0 255.255.255.0 access-list wbnash_splitTunnelAcl standard permit 192.168.3.0 255.255.255.0 access-list wbnash_splitTunnelAcl standard permit 192.168.2.0 255.255.255.0 access-list wbnash_splitTunnelAcl standard permit 192.168.75.0 255.255.255.0 access-list inside_access_out extended permit ip 172.16.25.0 255.255.255.0 192.168.6.0 255.255.255.0 access-list inside_access_out extended permit icmp 172.16.25.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list inside_access_out extended permit ip 192.168.6.0 255.255.255.0 192.168.75.0 255.255.255.0 access-list inside_access_out extended permit ip host 192.168.6.13 192.168.75.0 255.255.255.0 pager lines 24 logging enable logging asdm informational mtu outside 1500 mtu inside 1500 mtu management 1500 ip local pool wbnash 172.16.25.1-172.16.25.100 mask 255.255.255.0 icmp unreachable rate-limit 1 burst-size 1 asdm image disk0:/asdm-523.bin no asdm history enable arp timeout 14400 nat-control global (outside) 2 interface global (outside) 1 192.168.3.0 netmask 255.255.255.0 global (outside) 1 192.168.4.0 netmask 255.255.255.0 global (outside) 3 172.16.25.0 netmask 255.255.0.0 nat (inside) 0 access-list nonat nat (inside) 1 192.168.1.0 255.255.255.0 nat (inside) 1 192.168.10.0 255.255.255.0 nat (management) 0 0.0.0.0 0.0.0.0 access-group everything in interface outside access-group everything in interface inside access-group inside_access_out out interface inside route outside 0.0.0.0 0.0.0.0 *** 1 route inside 192.168.1.0 255.255.255.0 192.168.6.254 1 route inside 192.168.2.0 255.255.255.0 192.168.6.254 1 route inside 192.168.3.0 255.255.255.0 192.168.6.254 1 route inside 192.168.4.0 255.255.255.0 192.168.6.254 1 route inside 192.168.5.0 255.255.255.0 192.168.6.254 1 route inside 192.168.7.0 255.255.255.0 192.168.6.254 1 route inside 192.168.8.0 255.255.255.0 192.168.6.254 1 route inside 192.168.9.0 255.255.255.0 192.168.6.254 1 route inside 192.168.10.0 255.255.255.0 192.168.6.254 1 route inside 192.168.11.0 255.255.255.0 192.168.6.254 1 route inside 192.168.12.0 255.255.255.0 192.168.6.254 1 route inside 192.168.60.0 255.255.255.0 192.168.6.254 1 route inside 192.168.101.0 255.255.255.0 192.168.6.254 1 route inside 192.168.102.0 255.255.255.0 192.168.6.254 1 route inside 192.168.107.0 255.255.255.0 192.168.6.254 1 route inside 192.168.108.0 255.255.255.0 192.168.6.254 1 route inside 192.168.110.0 255.255.255.0 192.168.6.254 1 route inside 192.168.111.0 255.255.255.0 192.168.6.254 1 route inside 192.168.160.0 255.255.255.0 192.168.6.254 1 route inside 192.168.253.0 255.255.255.0 192.168.6.254 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout uauth 0:05:00 absolute aaa-server RADIUS protocol radius aaa-server TACACS+ protocol tacacs+ aaa authentication ssh console LOCAL http server enable http 172.16.25.0 255.255.255.0 inside http 172.16.25.0 255.255.255.0 outside http 192.168.6.0 255.255.255.0 inside http 10.1.1.0 255.255.255.0 management no snmp-server location no snmp-server contact snmp-server community public snmp-server enable traps snmp authentication linkup linkdown coldstart crypto ipsec transform-set transformset esp-3des esp-sha-hmac crypto ipsec security-association lifetime seconds 3600 crypto dynamic-map dynmap 10 set transform-set transformset crypto dynamic-map dynmap 30 set pfs crypto dynamic-map dynmap 30 set transform-set transformset crypto dynamic-map dynmap 50 set pfs crypto dynamic-map dynmap 50 set transform-set transformset crypto dynamic-map dynmap 70 set pfs crypto dynamic-map dynmap 70 set transform-set transformset crypto dynamic-map inside_dyn_map 20 set pfs crypto dynamic-map inside_dyn_map 20 set transform-set transformset crypto map mymap 10 match address vpntunnel crypto map mymap 10 set pfs crypto map mymap 10 set peer <vpn tunnel external IP> crypto map mymap 10 set transform-set transformset crypto map mymap 10 set security-association lifetime seconds 28800 crypto map mymap 20 ipsec-isakmp dynamic dynmap crypto map mymap interface outside crypto map inside_map 65535 ipsec-isakmp dynamic inside_dyn_map crypto map inside_map interface inside crypto isakmp identity address crypto isakmp enable outside crypto isakmp policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 28800 crypto isakmp nat-traversal 20 telnet timeout 5 ssh 172.16.25.0 255.255.255.0 outside ssh 192.168.6.0 255.255.255.0 inside ssh 172.16.25.0 255.255.255.0 inside ssh 10.1.1.0 255.255.255.0 management ssh timeout 5 console timeout 0 management-access inside dhcpd address 10.1.1.100-10.1.1.110 management ! ! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp inspect http ! service-policy global_policy global group-policy wbnash internal group-policy wbnash attributes wins-server value 192.168.6.34 192.168.6.10 dns-server value 192.168.6.34 192.168.6.10 vpn-tunnel-protocol IPSec group-lock value wbnash split-tunnel-policy tunnelspecified split-tunnel-network-list value wbnash_splitTunnelAcl nac-default-acl value split-tunnel group-policy **redacted** internal group-policy **redacted** attributes wins-server value 192.168.6.10 192.168.6.34 dns-server value 192.168.6.10 192.168.6.34 vpn-tunnel-protocol IPSec l2tp-ipsec ip-comp enable re-xauth enable group-lock value **redacted** pfs enable split-tunnel-policy tunnelspecified split-tunnel-network-list value wbnash_splitTunnelAcl username admin password fbFbxQS63ePiLd41 encrypted privilege 15 username **main vpn user** password pw-encryptedbutredacted encrypted username **main vpn user** attributes vpn-group-policy wbnash group-lock value wbnash username **redacted** password Onn6/Ve2g7kOcQtX encrypted username **redacted** attributes vpn-group-policy **redacted** group-lock value **redacted** tunnel-group **redacted** type ipsec-ra tunnel-group **redacted** general-attributes address-pool wbnash default-group-policy **redacted** tunnel-group **redacted** ipsec-attributes pre-shared-key * tunnel-group <vpn tunnel external IP> type ipsec-l2l tunnel-group <vpn tunnel external IP> ipsec-attributes pre-shared-key * tunnel-group wbnash type ipsec-ra tunnel-group wbnash general-attributes address-pool wbnash default-group-policy wbnash strip-group tunnel-group wbnash ipsec-attributes pre-shared-key * tunnel-group-map default-group **redacted** prompt hostname context Cryptochecksum:a018b90fd1f6ca192ad75d5e61997482 : end asdm image disk0:/asdm-523.bin no asdm history enable |
Advertisement
| Hall of Fame |