
我在浏览器上想使用PDM,但是却出现以下讯息,不知道谁可以救救我…。
' m- J# P# m# |- \3 G# V- {) C============================================" {+ \5 m, [: O. M( ^
PDM has encountered a firewall configuration command statement that PDM does not support.
" b0 r! x5 Q3 {7 z( W' h0 Xconfiguration parsing has been stopped. 4 ~5 [: e8 x5 |
PDM access is now limited to the Home and Monitoring views during the current session.1 r1 e7 E2 Q7 a% G) ?! Q4 D
To regain access to the rest of PDM, use the command line inte**ce windows to fix unsupported command statement and then refresh PDM with the modified firewall configuration.* J7 G5 @% y+ \% {& r! _( a
4 _& r, J5 t- N* k
0 j" i' ^! g; T; A
, K. q6 }5 g# q
: ], L; @+ `) E- X
Access control list 100 is applied to inte**ce inside for outbound nat 0 and VPN client group vpn3000 for split tunneling.7 A3 V8 \, w* ^: R
PDM does not support multiple uses of a given Access Control List.
4 X: D/ u/ Q# J3 n7 h8 e% i3 V% f. H6 _9 r$ P0 z" }7 d$ v# s& Q, ]
============================================
( G+ ]/ W8 L# s I& ?. l- t1 L" o; v O& i% f" J2 g7 W6 _# L
# [0 D6 N* s" k$ {5 n0 {6 ]: T3 u) J0 l0 W6 Y6 \. H# f1 }
以下是PIX 515设定- \! I! X# l2 A
====================================================6 O% _( K0 K! a6 d8 q3 t
: Saved6 L% c! X) n8 r& R0 U+ `
:" I- ^, f6 o. q( x7 u
PIX Version 6.3(5)
4 }' w3 q7 G3 D- T5 f5 \inte**ce ethernet0 auto
- l4 m' n" ?4 Y/ d* Ginte**ce ethernet1 auto& I" R" ?$ y) a
inte**ce ethernet2 auto1 y5 l' j* I+ n" a6 D
nameif ethernet0 outside security0
6 J2 w$ o i2 k9 u% \5 z Ynameif ethernet1 inside security100
, y% s% _) U' s8 x: l4 A. jnameif ethernet2 dmz security50
, s1 F/ s2 H1 b# h. Zenable 1234 3ftJIzCjh533nBez encrypted8 R% y& k2 h( ], X4 z U
passwd 1234 encrypted
' e9 b' m! o; V. ?! Ihostname YK-PIX
& q% Q! e6 `3 A8 @0 I( Q6 tdomain-name abc.com" K1 _" Y/ l$ Z5 r8 ~* E' ?
fixup protocol dns maximum-length 512; ~. K, o7 \1 f
fixup protocol ftp 21
2 b6 G6 \, h( M% Q/ p( tfixup protocol h323 h225 1720! |6 \) T v1 r C0 I9 A
fixup protocol h323 ras 1718-1719
6 A& p$ v3 r4 E1 |* ^fixup protocol http 80
$ t" z6 F: ~5 r7 z9 @fixup protocol rsh 514" o5 |2 g1 M" y- R
fixup protocol rtsp 554
& `, K6 k' d: k* e2 Mfixup protocol sip 5060/ h; {4 Y/ J, S+ p1 s- Y* G
fixup protocol sip udp 5060& p( G) N9 ~" f+ J N
fixup protocol skinny 2000' s& ~( D$ I8 b; u/ k! Q' G
no fixup protocol smtp 25. E& L9 c) I1 m8 {8 e
fixup protocol sqlnet 1521: c0 p; ]! q1 I
fixup protocol tftp 69
+ `! e% T) O; I, X% P; d2 ?names( ] h3 s8 e7 b7 [& f+ O
access-list 100 permit ip 172.16.128.0 255.255.224.0 172.16.160.0 255.255.224.0 . b3 z X- x( t' M |2 r e8 ~9 B
access-list 100 permit ip 192.168.2.0 255.255.255.0 172.16.160.0 255.255.224.0 2 D5 r& t" D# B7 J8 e, f
access-list 100 permit ip 172.16.128.0 255.255.224.0 192.168.101.0 255.255.255.0 7 T5 i7 U0 M( u" K7 g8 L
access-list 100 permit ip 192.168.2.0 255.255.255.0 192.168.101.0 255.255.255.0
2 [" I' I; x+ y7 _ }" faccess-list 100 permit ip 172.16.64.0 255.255.224.0 192.168.101.0 255.255.255.0 4 t6 V! d. _; p( p4 d$ q/ r) F" r/ d( e
access-list 100 permit ip 172.16.160.0 255.255.224.0 192.168.101.0 255.255.255.0
" g% ?3 _8 o4 O( `9 Uaccess-list 100 permit ip 172.16.128.0 255.255.224.0 172.16.64.0 255.255.224.0
: x3 V' y f \2 G4 m# Laccess-list 100 permit ip 192.168.2.0 255.255.255.0 172.17.128.0 255.255.224.0
/ X( _7 U8 ]; X+ y5 |# R: P; B/ Naccess-list 100 permit ip 192.168.1.0 255.255.255.0 192.168.101.0 255.255.255.0 ' o9 u) o/ g( @6 F! I$ H
access-list 100 permit ip 192.168.2.0 255.255.255.0 172.16.64.0 255.255.224.0 / `4 r* L# [2 F: |
access-list 100 permit ip host 61.66.237.6 host 194.117.106.129
$ g% u% H6 k* E7 \access-list 100 permit ip 192.168.4.0 255.255.255.0 192.168.101.0 255.255.255.0 $ q# d: R1 a0 f6 j8 g/ @9 l, j
access-list 100 permit ip 172.16.160.0 255.255.224.0 172.18.0.0 255.255.0.0
! V/ R" X1 L, o1 ? qaccess-list 100 permit ip 172.16.128.0 255.255.224.0 172.18.0.0 255.255.0.0 , r5 t$ B5 [) Q) `2 t$ q$ C
access-list 100 permit ip 172.16.100.0 255.255.252.0 192.168.101.0 255.255.255.0
t9 p& S; f2 c. b: a7 N+ Saccess-list 100 permit ip 172.16.100.0 255.255.252.0 172.18.0.0 255.255.0.0 : M$ g# i3 o& O1 a( b
access-list 120 permit ip 172.16.128.0 255.255.224.0 172.16.160.0 255.255.224.0 2 t. N# o, O5 f( Q9 P( F" G
access-list 120 permit ip 192.168.2.0 255.255.255.0 172.16.160.0 255.255.224.0
7 A% y% V% W2 raccess-list 170 permit ip host 61.66.237.6 host 194.117.106.129
( H/ {- @; e* r5 t; yaccess-list 200 permit ip 172.16.128.0 255.255.224.0 172.16.64.0 255.255.224.0
" U, z' e0 h* ~$ Z) o/ Waccess-list outside_acl permit tcp any host 61.66.237.95 eq smtp 9 g$ i' G; Z0 r% H' z* b
access-list outside_acl permit tcp any host 192.168.4.25 eq smtp
4 b7 p% U2 {' Raccess-list outside_acl permit tcp any host 61.66.237.36 eq www
9 Y9 P. M" J' Raccess-list outside_acl permit tcp any host 61.66.237.36 eq ftp
' X" }$ I s& p$ ?( Qaccess-list outside_acl permit tcp any host 61.66.237.111 eq www
9 L1 o8 }. a- ~6 |% k3 E6 P0 aaccess-list outside_acl permit tcp any host 61.66.237.96 eq www - F% P% ~+ U: |2 I& \% I7 y
access-list outside_acl permit tcp any host 61.66.237.80 eq www
3 C) r- t, f9 Paccess-list outside_acl permit tcp any host 61.66.237.21 eq ftp
3 Z& ^- o- U' m' c7 M8 e/ ]0 Paccess-list outside_acl permit tcp any host 61.66.237.34 eq www 8 r7 L/ L3 W: p$ \9 [
access-list outside_acl permit tcp any host 61.66.237.97 eq www ) t) `3 P: W w; q H
access-list outside_acl permit tcp any host 61.66.237.97 eq domain , p2 P+ ~: b7 @0 }0 L
access-list outside_acl permit udp any host 61.66.237.97 eq domain
# a2 @& q n4 m2 jaccess-list outside_acl permit tcp any host 61.66.237.84 eq www 5 Y E3 k* E) W6 K' h: K2 b
access-list outside_acl permit tcp any host 61.66.237.96 eq https ' S. @1 `* I" p7 `* x
access-list outside_acl permit tcp any host 61.66.237.97 eq https , X/ v. c" U' c5 m
access-list outside_acl permit tcp any host 61.66.237.85 eq www 5 X! i4 n9 _" [3 k7 K
access-list outside_acl permit icmp any 61.66.237.0 255.255.255.0 echo-reply
8 v6 H" V) E0 @, g' {1 N3 b- iaccess-list outside_acl permit icmp any 61.66.237.0 255.255.255.0 time-exceeded
: f- k0 B! }" ]* G. w3 a( {access-list outside_acl permit icmp any host 192.168.4.25 time-exceeded # W8 v8 G5 u! z P% ]9 p+ g
access-list outside_acl permit tcp any host 61.66.237.39 eq www
" i5 _- `) n. m8 o" ]* daccess-list outside_acl permit tcp any host 61.66.237.89 eq www ( } U6 g }% @8 k4 K
access-list outside_acl permit tcp any host 61.66.237.17 eq www
- M: O' u$ \# P# R" d8 l( Saccess-list outside_acl permit tcp any host 61.66.237.17 eq https : x; j/ q6 _9 }
access-list outside_acl permit tcp any host 61.66.237.76 eq www 0 n, k+ o# P% y# Z$ Z
access-list outside_acl permit tcp host 58.240.224.3 host 61.66.237.55 * f. L- ?. E( P
access-list outside_acl permit tcp 221.224.140.160 255.255.255.240 host 61.66.237.55 ; M7 _4 J2 u c6 j# t/ a6 O
access-list outside_acl permit tcp host 211.21.10.210 host 61.66.237.249 & B3 z" e5 |4 m' P
access-list outside_acl permit tcp any host 61.66.237.96 eq domain
1 i( s8 {( W! q$ B3 X0 B* Kaccess-list outside_acl permit udp any host 61.66.237.96 eq domain 4 L. A3 C- \$ h4 y% Q
access-list outside_acl permit tcp any host 61.66.237.17 eq ssh $ ^* M$ a M+ J# i
access-list outside_acl permit tcp any host 192.168.4.17 eq smtp
- U, Q) G+ R0 Q+ j: T2 W" Q* kaccess-list outside_acl permit icmp any host 192.168.4.17 time-exceeded 9 r# [' u. s1 V N* H( Y
access-list dmz_acl permit tcp host 192.168.4.21 host 192.168.4.11 eq smtp ' |& f7 g7 U W9 c# w1 u
access-list dmz_acl permit icmp 192.168.4.0 255.255.255.0 any echo 8 g! h8 ?# r( d) e- s. h) c+ O
access-list dmz_acl permit icmp any 192.168.4.0 255.255.255.0 echo-reply ! T4 F, Y) X; o" o8 F5 `3 w c( [/ ~
access-list dmz_acl permit tcp 192.168.4.0 255.255.255.0 any eq www
4 p, G8 h d" E5 yaccess-list dmz_acl permit tcp 192.168.4.0 255.255.255.0 any eq https 5 Z9 [1 N4 m. x0 M2 i
access-list dmz_acl permit tcp host 192.168.4.22 host 192.168.4.11 eq smtp 6 i1 t6 n( Y# q ~
access-list dmz_acl permit tcp host 192.168.4.22 host 192.168.4.15 eq smtp ) j; U# v+ n7 C( L S) p6 K- E$ @
access-list dmz_acl permit tcp host 192.168.4.25 host 192.168.4.11 eq smtp / m, Z! S( K" K, S. c W$ L
access-list dmz_acl permit tcp host 192.168.4.25 host 192.168.4.15 eq smtp . U; c/ O& z3 y' w2 x
access-list dmz_acl permit tcp host 192.168.4.22 host 192.168.4.15 eq ldap
" H$ E% X# F& |3 }2 E3 haccess-list dmz_acl permit tcp host 192.168.4.25 host 192.168.4.15 eq ldap + M5 _+ f' m) z. U4 s5 z& ~; ?
access-list dmz_acl permit tcp host 192.168.4.22 host 192.168.4.10 eq smtp
& m b$ \; d3 ?5 m! w3 naccess-list dmz_acl permit tcp host 192.168.4.25 host 192.168.4.10 eq smtp
, V( B0 T: k+ @2 y. k- H$ a7 Naccess-list dmz_acl permit tcp host 192.168.4.22 host 192.168.4.18 eq smtp 6 J" R3 c0 A9 ~5 {3 A0 S- k
access-list dmz_acl permit tcp host 192.168.4.25 host 192.168.4.18 eq smtp
& ]: |8 }# ?8 x7 b- z# a' y' @access-list dmz_acl permit tcp host 192.168.4.22 host 192.168.4.19 eq smtp 8 n4 q M# j" Q( L. N7 V& u( B) U
access-list dmz_acl permit udp 192.168.4.0 255.255.255.0 any eq ntp
3 G6 B' [. Q# L( W1 Y8 `access-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.10 eq smtp
% u( a$ g/ |' z" ~3 R4 C8 m9 B/ z/ waccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.19 eq smtp
4 b. z4 Q/ ]! }! ]access-list dmz_acl permit tcp host 192.168.4.17 any eq smtp
. w& U8 X- i W# `3 N1 Qaccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.15 eq ldap
- u" a6 o" R# Q) o+ H. `7 Kaccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.10 eq ldap
7 g! l" B& G8 `5 L) f% p3 [/ ]access-list dmz_acl permit udp 192.168.4.0 255.255.255.0 any eq domain # r; C" M! A: [7 `- F) `/ N. v' K6 U
access-list dmz_acl permit ip 172.16.140.0 255.255.255.0 host 192.168.4.17
8 J0 y; g* Q5 O, n# N; B9 @9 z* D' laccess-list dmz_acl permit tcp any host 192.168.4.17 eq ssh
4 u2 A. Q- J) u M q7 `& n3 paccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.11 eq smtp
W) {9 D, w3 l4 L/ Jaccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.15 eq smtp
" M0 L- E. X0 ?( \+ _- \, Haccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.18 eq smtp
3 _, @3 @$ \# P6 N+ p6 Caccess-list dmz_acl permit tcp host 192.168.4.17 host 192.168.4.19 4 h% B3 {& k3 N+ T
access-list inside_acl permit ip 172.16.64.0 255.255.224.0 any
7 h8 X$ L/ w, t# P' ]0 K/ [. ~4 N& k: paccess-list inside_acl permit ip 172.16.160.0 255.255.224.0 any
5 h' @; l; A3 B8 |* t ]access-list inside_acl permit ip 172.16.100.0 255.255.252.0 any
0 M! \% \* @4 ?5 u- iaccess-list inside_acl permit ip 192.168.2.0 255.255.255.0 any
k* [3 J8 ^( c2 Eaccess-list inside_acl permit ip 192.168.102.0 255.255.255.0 any
. J4 P0 H8 X) m: a! t2 H! aaccess-list inside_acl permit ip host 61.66.237.6 host 194.117.106.129
5 X) Y; A! S0 Naccess-list inside_acl permit ip 172.16.128.0 255.255.254.0 any
- _7 _4 x" a8 } {" x: l( s$ Vaccess-list inside_acl permit ip 172.16.140.224 255.255.255.240 any
6 t7 P5 A; v9 c! c7 h! _1 gaccess-list dmz_nonat permit ip 192.168.4.0 255.255.255.0 192.168.101.0 255.255.255.0 + h+ q/ {- i. l) Y+ W9 h
access-list dmz_nonat permit ip host 192.168.4.17 172.18.0.0 255.255.0.0
- o+ A4 F# Q# y" X2 t' N# saccess-list dmz_nonat permit ip 192.168.4.0 255.255.255.0 172.16.0.0 255.255.224.0
, N/ e' V# r; {/ Gaccess-list 210 permit ip 172.16.160.0 255.255.224.0 172.18.0.0 255.255.0.0
0 C9 a/ [ f7 g7 f4 N2 N2 o1 gaccess-list 210 permit ip 172.16.128.0 255.255.224.0 172.18.0.0 255.255.0.0 3 n5 [. x/ @8 ^# h; k
access-list 210 permit ip 192.168.4.0 255.255.255.0 172.18.0.0 255.255.0.0
4 s! j* w2 @* x& O- J8 P8 J- iaccess-list 210 permit ip 172.16.100.0 255.255.252.0 172.18.0.0 255.255.0.0
( K: S$ `* e- ~) Y9 T: P+ ppager lines 24
* S- y2 O" C. d. [' llogging on
8 d' P$ K- d3 N6 ^4 @logging times**p# h, {: q# B# ?. x( X
logging standby. e3 x7 R8 a' N2 p! u
logging buffered warnings
`! R/ M* L5 R. Ilogging trap warnings0 O' J( N" y3 B" m% Z& V: T
logging history debugging9 {2 G4 E& v* _" r4 X. d; S# a. q- l
logging host inside 172.16.129.78 17/45000
& U9 U5 A. n7 ^3 glogging host inside 172.16.134.586 e6 J3 ^/ V1 w: k# a, J
mtu outside 1500
3 @) d6 l1 K. o4 |2 Pmtu inside 1500/ B; Q+ y0 g( h0 H
mtu dmz 1500
* w! M8 @, t* S: l! Xip address outside 61.66.237.253 255.255.255.0
W3 z8 ]$ p# r0 X# K. p& mip address inside 172.16.128.2 255.255.254.05 h; m' w2 k% O% U' W
ip address dmz 192.168.4.1 255.255.255.04 d7 ~& n1 G: p* \2 ^5 p+ y6 x
ip audit info action alarm
2 n/ A' Z! b `ip audit attack action alarm
- I4 W' y8 Z, i$ A4 s$ Eip local pool ippool 192.168.101.1-192.168.101.2546 W4 k) q3 G( Q/ U- F* i' C5 H! H
pdm location 172.16.128.0 255.255.254.0 inside$ H f( X+ R9 G/ h) M+ _
pdm history enable
# O& h+ O/ B j1 jarp timeout 14400
& U3 u2 n: O' X7 C, V: Mglobal (outside) 1 61.66.237.124
: r+ r& y+ E, Y kglobal (dmz) 1 inte**ce* Z% m4 f' W9 m/ K' R! \: ?
nat (inside) 0 access-list 100
( O I( F* y* \: i) |' ~! O- jnat (inside) 1 192.168.102.0 255.255.255.0 0 06 g. \8 N$ g& F& n# ]
nat (inside) 1 172.16.64.0 255.255.224.0 0 0
) B% J- p7 C7 Rnat (inside) 1 172.16.128.0 255.255.224.0 0 0
' t& P: B% ?: L% Enat (inside) 1 172.16.160.0 255.255.224.0 0 0( b* [8 l7 r8 z( ?
nat (dmz) 0 access-list dmz_nonat, ^6 i$ I1 C. U, H4 l- `; J
nat (dmz) 1 192.168.4.0 255.255.255.0 0 0
3 m8 ]! O+ q5 x& k" X0 M! ~: e) W& {static (inside,dmz) 192.168.4.11 172.16.129.11 netmask 255.255.255.255 0 0 5 o, i8 f' T" ^% W# i
static (inside,dmz) 192.168.4.15 172.16.129.13 netmask 255.255.255.255 0 0 ) ~- T# E. G8 l. b
static (inside,outside) 61.66.237.6 61.66.237.6 netmask 255.255.255.255 0 0
A, d- d7 {+ n- c ^static (dmz,outside) 61.66.237.111 192.168.4.111 netmask 255.255.255.255 0 0 f) U6 ~! W% I ~, |4 T4 e) F
static (inside,outside) 61.66.237.96 172.16.129.21 netmask 255.255.255.255 0 0
+ v6 }- Y' f( |% {% {, Dstatic (dmz,outside) 61.66.237.80 192.168.4.80 netmask 255.255.255.255 0 0 ) d- n" D: t2 y6 S2 {
static (inside,outside) 61.66.237.97 172.16.129.18 netmask 255.255.255.255 0 0 4 l/ Z" L7 f( h, r" Q: r, N3 e
static (dmz,outside) 61.66.237.21 192.168.4.21 netmask 255.255.255.255 0 0 2 }/ j, T$ h: R$ U8 B
static (inside,outside) 61.66.237.34 172.16.129.173 netmask 255.255.255.255 0 0
3 X5 b4 E% A/ n8 p: O" w* ~& g; Wstatic (inside,outside) 61.66.237.36 172.16.129.175 netmask 255.255.255.255 0 0
- ~/ f, n" m& [$ x9 k4 ~static (inside,outside) 61.66.237.5 61.66.237.5 netmask 255.255.255.255 0 0 2 H3 S8 x! b" N5 g) I
static (dmz,outside) 61.66.237.85 192.168.4.85 netmask 255.255.255.255 0 0
3 [: e( N2 @" Y+ n* B$ ? } p* ` bstatic (inside,dmz) 192.168.4.18 172.16.129.18 netmask 255.255.255.255 0 0
9 c! U$ c# ~, s, F. Y% Bstatic (inside,outside) 61.66.237.39 172.16.129.169 netmask 255.255.255.255 0 0
8 V- i% \6 E( |. z1 _( t) C2 e3 Astatic (inside,dmz) 192.168.4.19 172.16.129.21 netmask 255.255.255.255 0 0 & |0 Q) w# H: d& y. o
static (dmz,outside) 61.66.237.84 192.168.4.84 netmask 255.255.255.255 0 0
Q( M# l" v5 t- Vstatic (dmz,outside) 61.66.237.89 192.168.4.89 netmask 255.255.255.255 0 0 & ]' A/ G6 h( j5 U, h7 b( Q2 `) i* R! S
static (inside,outside) 61.66.237.57 172.16.129.57 netmask 255.255.255.255 0 0
% ~/ t) i& N" M7 L' Xstatic (inside,dmz) 192.168.4.10 172.16.129.23 netmask 255.255.255.255 0 0
8 x7 V( p: K( {8 _; M. Lstatic (inside,outside) 61.66.237.249 172.16.129.249 netmask 255.255.255.255 0 0
0 S3 n: l- X, Q6 q/ a! Bstatic (inside,outside) 61.66.237.55 172.16.129.55 netmask 255.255.255.255 0 0
( s2 @* ]5 ^$ T2 g& { @2 ^static (dmz,outside) 61.66.237.17 192.168.4.16 netmask 255.255.255.255 0 0
& P' E& x8 Z% F1 H2 ^0 e! j% zstatic (dmz,outside) 61.66.237.95 192.168.4.17 netmask 255.255.255.255 0 0
3 f V5 L( m- j1 Q3 v& Xaccess-group outside_acl in inte**ce outside" t* Y" x! d7 B# @
access-group inside_acl in inte**ce inside
2 w* L! ^: h' v! Baccess-group dmz_acl in inte**ce dmz
7 |0 A5 ^& \" @router ospf 1
& C- E! T. W6 M network 172.16.128.0 255.255.224.0 area 0
6 O+ _" }- L- a% X" M* S' I log-adj-changes
$ \8 F1 F1 j5 Z& K, groute outside 0.0.0.0 0.0.0.0 61.66.237.254 1) _7 Q" h, C+ C: k" V
timeout xlate 3:00:00
$ S9 V/ l& s2 ~. h: itimeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
% w+ v. [5 x- o1 V9 d# Ptimeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00, e) h( n3 p4 f9 u' ~4 w
timeout sip-disconnect 0:02:00 sip-invite 0:03:007 u D; o+ ]% J7 h4 l
timeout uauth 0:05:00 absolute& W$ H, x+ ~6 [ f+ e8 k
aaa-server TACACS+ protocol tacacs+
/ a( G7 D) Z6 b: A, Qaaa-server TACACS+ max-failed-attempts 3
8 v( w$ _5 W4 ?) taaa-server TACACS+ deadtime 10
9 Q( X3 v7 A! s" Z. Waaa-server RADIUS protocol radius + y: D1 M( |# g; [! M
aaa-server RADIUS max-failed-attempts 3 + K% e7 [5 H' v
aaa-server RADIUS deadtime 10 9 a% r4 n& U2 Q. }$ _; {( T
aaa-server LOCAL protocol local
& Z9 ?( M# t% V# s) E# |( R% A" a# laaa-server authme protocol tacacs+
( o2 p0 O4 n7 Y; e4 U# T2 H0 \aaa-server authme max-failed-attempts 3 / V# j/ [" C3 ]. i* A- ]# v
aaa-server authme deadtime 10
- j" f$ Y6 O; y& N) t/ |' aaaa-server authme (inside) host 172.16.129.76 cisco1234 timeout 10
8 r. _" y" E N' H- Z* E1 Ghttp server enable
. Y6 t" x P0 z' ~http 0.0.0.0 0.0.0.0 inside2 ]2 l! e0 {! u1 J: q3 m
snmp-server host inside 172.16.129.27, X, W. ?1 j7 N, |. D5 g
no snmp-server location) P1 l+ Q5 V" ~' [& m' X) F
no snmp-server contact% s: P) g4 {9 u
snmp-server community public
" M+ t6 q* M% \! ?0 N3 p+ ?- j; Zno snmp-server enable traps9 {/ u% }2 \# `3 g: D2 y8 v
floodguard enable
1 ~2 c; h6 I# s" T# fsysopt connection permit-ipsec$ T& A2 {2 J0 H& s d
crypto ipsec transform-set myset esp-3des esp-md5-hmac
`9 U3 J% c, q$ icrypto dynamic-map dynmap 40 set transform-set myset3 Y+ d1 @6 w/ ?* o6 |# a. }& f
crypto map mymap 10 ipsec-isakmp
7 f/ M1 w2 y% D% s# ^, gcrypto map mymap 10 match address 2001 ~* f, x0 ~) X9 U
crypto map mymap 10 set peer 220.128.108.26
; t4 o% l- R8 C7 ~$ D/ S/ j" Wcrypto map mymap 10 set transform-set myset
! Z! }. x1 A9 E4 Q4 w# Mcrypto map mymap 20 ipsec-isakmp
/ Y: F4 {3 _. j& P# xcrypto map mymap 20 match address 120
+ t. g; a y4 {, h8 _0 lcrypto map mymap 20 set peer 61.155.20.58. m1 k9 g1 R4 q/ v) h, r) p" x2 g1 B
crypto map mymap 20 set transform-set myset
6 A1 s# R- ?& t2 f% i, r+ s1 K( vcrypto map mymap 40 ipsec-isakmp dynamic dynmap# Q7 l0 y0 O& j: |8 ~# ]
crypto map mymap 60 ipsec-isakmp; _+ \" z* [8 p
crypto map mymap 60 match address 170- a# t5 k1 A* y6 }: ?
crypto map mymap 60 set peer 194.39.131.166* j7 K9 ~# ~2 m' `
crypto map mymap 60 set transform-set myset$ h9 W$ E* G4 _% `
crypto map mymap 100 ipsec-isakmp5 s' ~% p" s# W1 ^0 Z' ?) t
crypto map mymap 100 match address 210 M* @$ n% @: _$ G: Q* ^
crypto map mymap 100 set peer 211.20.227.38
6 ~" i3 g7 I/ @5 Y& E) gcrypto map mymap 100 set transform-set myset/ k# H8 n: {% z) T. U1 x8 z
crypto map mymap client configuration address initiate9 w' c1 k4 J, A+ S, n5 w W- |
crypto map mymap client configuration address respond: U4 h+ ?9 J% x# D5 K
crypto map mymap client authentication authme
3 }) V5 g8 O+ u- m5 N( W# o4 Acrypto map mymap inte**ce outside' j2 W# b4 n6 r1 E+ o
isakmp enable outside, C: {" l7 L4 j6 I; r% D7 C( w! c' o
isakmp key ******** address 61.155.20.58 netmask 255.255.255.255 6 L A" h, z1 i3 K, l7 J9 m
isakmp key ******** address 194.39.131.166 netmask 255.255.255.255 7 u2 X9 m* O: n) K& E
isakmp key ******** address 211.20.227.38 netmask 255.255.255.255 no-xauth no-config-mode
5 F+ {' T; C6 }+ uisakmp key ******** address 220.128.108.26 netmask 255.255.255.255 2 S6 Y, H9 p2 J8 J
isakmp identity address+ w" C( W- q" C* W6 F! K
isakmp client configuration address-pool local ippool outside- A. S7 r1 ^" ~* u8 \& f
isakmp nat-traversal 10
, O/ U8 b f( Gisakmp policy 10 authentication pre-share
9 y) _# N" A( ]9 W* P$ E) _/ eisakmp policy 10 encryption 3des
8 q! y9 Y" ]" k5 _/ Z1 g$ i% J. d! ?isakmp policy 10 hash md5
. R* X3 d% T& G$ \isakmp policy 10 group 2
8 b, \! N% s* @% {# Zisakmp policy 10 lifetime 86400. }& f. ]: E9 @0 z2 `! N
vpngroup vpn3000 address-pool ippool, C$ Q. D- Y& P$ R) L4 ]
vpngroup vpn3000 dns-server 172.16.129.20$ m5 Z; r2 J( q7 P
vpngroup vpn3000 wins-server 172.16.129.31
' N( ~6 ~8 n" Qvpngroup vpn3000 default-domain arima.com.tw. ^7 Y: S7 X" d4 h& `
vpngroup vpn3000 split-tunnel 100
! @' W# ^" E) G& H( n, N, c9 Mvpngroup vpn3000 idle-time 18004 w2 y2 i2 U+ p& C
vpngroup vpn3000 password ********
, B% X$ O" G+ F# k* W9 N$ r/ [telnet 172.16.128.0 255.255.254.0 inside5 [; l. a* u3 w) V0 ^5 H( A2 L2 h
telnet 172.16.100.0 255.255.252.0 inside
6 t: e( H3 F4 M$ t6 S4 x3 ?. t4 itelnet 192.168.1.0 255.255.255.0 inside1 [( a/ U( {7 }) Z
telnet timeout 60
8 ]* U/ Y2 r2 e& B4 l2 |8 Bssh 0.0.0.0 0.0.0.0 outside5 G* E; d/ ?: l7 u; J6 m/ w; Q
ssh timeout 5& T/ E0 j, Z, \% u. `! m; h1 @9 w5 U
c**ole timeout 0
1 n( ]- R7 J' F# ]4 L, ausername abcd password 1234 encrypted privilege 2 q& y* ]. D$ ]1 |+ v, Y3 Q3 A/ c
terminal width 80
) Z4 I& v% N) F' v' R! ^8 M, j7 L7 YCryptochecksum:340de3230898696e8ef4fa2a4f86c075% Y9 b. S+ Y3 {+ i4 O% ~7 v: @! A
: end& N; t' s8 t, e
2 D6 o0 O& s6 N0 v- G5 P
7 M7 }4 Q$ u/ h: h4 o @' K) |
================================================ |
|