pixfirewall#show run: Y. a& T9 v3 e" q! I
: Saved+ }+ q/ L$ ^6 F/ G" a9 ^6 b
:
( r% t* B2 `7 H) uPIX Version 6.3(3)4 E4 T$ `7 K- e: G5 F
interface ethernet0 100full
; ^9 J, M% K# p2 p( b1 Binterface ethernet1 100full
: n0 q0 ]4 V+ T, I7 qnameif ethernet0 outside security0
5 m2 ~) D% f* x0 O' Unameif ethernet1 inside security1005 {7 J2 z( f6 ^( V1 n; m
enable password 8Ry2YjIyt7RRXU24 encrypted( J4 |/ v* ^ e5 x
passwd 2KFQnbNIdI.2KYOU encrypted
4 z3 O b$ _" @6 J4 phostname pixfirewall: t" X2 S: s) e, @( A' L
fixup protocol dns maximum-length 512, ~ G& H8 k& \, D
fixup protocol ftp 21
& V. M! I0 A9 \ K# Nfixup protocol h323 h225 1720
* n4 R; J+ R+ N8 [fixup protocol h323 ras 1718-1719# D0 p* [4 d( H( V, B8 k0 ]
fixup protocol http 80+ L" F0 l& j+ r# Q
fixup protocol rsh 514! ^/ J1 j5 B# L
fixup protocol rtsp 554
$ E: R; Y w$ O' _2 kfixup protocol sip 5060+ H0 I) c8 b: B0 F7 z
fixup protocol sip udp 5060
+ a$ m; d) i) F8 p& E( sfixup protocol skinny 2000
, @* [; u( L3 E# ~: `- d" Nfixup protocol smtp 25
4 A% t1 W! `- p+ V8 L. N) [9 m/ `fixup protocol sqlnet 1521! n; [8 w. g9 x+ J
fixup protocol tftp 69- b( k5 I5 {, t+ @9 ?$ M
names
/ J3 h4 \7 O! t k1 u! r& A. Y: K; B
!--- Do not use Network Address Translation (NAT) for inside-to-pool
) K/ z# m' k. M# Z h3 b# M6 h3 E; F!--- traffic. This should not go through NAT.
G& n! e; i* H4 o3 e' v+ G! b( @( j# v7 L1 k8 d! o
access-list 101 permit ip 10.89.129.128 255.255.255.240 10.89.129.192 255.255.255.240' @# A9 `5 n1 `
& I7 `6 Q7 t; v7 }!--- Permits Internet Control Message Protocol (ICMP), z8 |0 j; ]! \1 F, ~5 }
!--- Transmission Control Protocol (TCP) and User Datagram Protocol (UDP)
9 V2 M* J8 m( m8 `4 X5 ?!--- traffic from any host on the Internet (non-VPN) to the web server.
& H! ~& z# V$ U5 T( `" |
) O: D0 h) @0 e! U A* kaccess-list 120 permit icmp any host 10.89.129.131
# X7 j" J% a' q; [access-list 120 permit tcp any host 10.89.129.1312 ?& u2 y. \4 o& u* A: H8 M
access-list 120 permit udp any host 10.89.129.131& @, m- ^$ I# z; l1 P2 Z/ ]+ G3 u8 Z
# N2 e$ \5 P1 t; |7 Zpager lines 248 k1 ?) ]5 w$ G- I4 C4 h7 ^7 e& W
mtu outside 1500
2 ]0 J4 ?, m3 m3 ?0 z* dmtu inside 1500
: b% g: h0 \3 a ]ip address outside 192.168.1.1 255.255.255.0
6 |8 C2 m+ y5 a* u5 jip address inside 10.89.129.194 255.255.255.240
& \0 n! c" j; D+ Z8 hip audit info action alarm, R5 Y) ?6 o! Q# K8 o4 _
ip audit attack action alarm
4 J4 N4 ] h6 o$ g$ L# ^( ^% t4 V& j( T+ n* h
!--- Specifies the inside IP address range to be assigned9 c* a: w9 g% z- g# M( c9 X
!--- to the VPN Clients.
+ S* [& F5 ~4 c' Q
: m( y) N% N) \0 O @# lip local pool VPNpool 10.89.129.200-10.89.129.204. P0 l# o @" ]/ c9 g! h4 A0 {
no failover
, D8 u. I. c1 U% tfailover timeout 0:00:00
- V( r4 a. @7 w9 z( }( ifailover poll 15/ } U% N ~4 }5 p# \( X( K. {9 B
no failover ip address outside: ~, P- j2 U9 d# O8 T( g% Z) F* Y
no failover ip address inside
5 t1 H. o; V* [$ |( \! X' xpdm history enable+ P' Y/ }7 S _' V3 e
arp timeout 14400, G9 I. {$ t5 t* f
. B- X& ]4 L3 i0 S% N!--- Defines a pool of global addresses to be used by NAT.
; r; q( f' w: O( k, V3 p" J/ l) ?7 q
3 r, B; A/ B1 ~" V2 S4 J- lglobal (outside) 1 192.168.1.6-192.168.1.10
$ i* o8 s! w6 {# Q( U7 s1 M" s5 M5 o1 U2 h' Z5 r5 ^
nat (inside) 0 access-list 101
3 S& V4 C$ U& k8 Cnat (inside) 1 0.0.0.0 0.0.0.0 0 0
, e# s+ o, o( T1 [4 ]# ]3 C( B
! R* y0 o- ? f( w0 X: B# z: @!--- Specifies which outside IP address to apply to the web server.2 l: y: P: ^5 ]* L
0 N K6 [" D3 ?6 @static (inside,outside) 192.168.1.11 10.89.129.131 netmask 255.255.255.255 0 0( E" q6 z! ?8 T
. H: n, V' M) B y! z2 Y' Z1 l" n
!--- Apply ACL 120 to the outside interface in the inbound direction.
/ c& d- e; r& ^1 h/ r
6 R4 \0 @9 W ]& j( c4 laccess-group 120 in interface outside
. d) _' v" I) @; s; c y5 R" k8 W
!--- Defines a default route for the PIX.
{/ q6 L& c9 g! |) X) N' E/ F- o# x: K- B/ h' H( I! z
route outside 0.0.0.0 0.0.0.0 192.168.1.3 13 Z) J4 T3 |7 U$ f/ q% h! t+ z$ K
! E' q' b1 V+ S }; P* t, s!--- Defines a route for traffic within the PIX's
" Z/ p( b( n, R0 }; ]7 X$ v0 A!--- subnet to reach other inside hosts.
# E _! j; p! [ j8 d2 B9 ~! ]: G" v1 u- N7 t
route inside 10.89.129.128 255.255.255.128 10.89.129.193 1" w0 o6 R9 B# U- z0 t1 V' D. z
) I- V; R- y+ e0 m8 J6 S( J
timeout xlate 3:00:00" e' L4 ?* R# h' q. K6 l
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00( V2 \% K% g2 _- Y
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00" O1 H( R8 P" V& [+ L
timeout uauth 0:05:00 absolute
. Y/ ]2 l6 f* G4 Baaa-server TACACS+ protocol tacacs+
/ E: E' \ h* x2 g8 m6 y+ _aaa-server RADIUS protocol radius; H+ U. n$ B a
aaa-server LOCAL protocol local6 V& T6 q& F) p
0 y+ c$ c" ^5 F( M) X
!--- Authentication, authorization, and accounting (AAA)' k( q! q* n* |/ K0 K1 c/ n
!--- statements for authentication. Method AuthInbound uses TACACS+.8 a0 x& S% Z6 Y, n
! \2 T" v2 R1 {aaa-server AuthInbound protocol tacacs+3 ^2 q7 W- _5 Y; b6 J
1 F( C4 a u7 T8 N ^$ ]! n
!--- Specify the TACACS+ server and key.
3 U+ n4 P4 y" l( G7 {. `4 T1 s2 n8 Y0 f) p: D( |2 X
aaa-server AuthInbound (inside) host 10.89.129.134 <deleted> timeout 10$ q/ X; }/ g) s
2 t c! Y9 R( {. ~/ D" Q. O
!--- Authenticate HTTP, FTP, and Telnet traffic to the web server.
$ l3 Y7 I! O0 w T/ h
0 r, a+ B6 A6 M# m7 Xaaa authentication include http outside
, ]1 M1 ^5 _" p, a+ `- x5 m7 ~10.89.129.131 255.255.255.255 0.0.0.0 0.0.0.0 AuthInbound2 f% ~, x& K. Y4 @5 M* E0 r: `5 i
2 @* t; w" X6 R ^
aaa authentication include ftp outside
3 l7 `; W# r1 C. B% u 10.89.129.131 255.255.255.255 0.0.0.0 0.0.0.0 AuthInbound
: H X; t8 I1 R u# B% w* ]& H: r% u4 v, h
aaa authentication include telnet outside ' _$ d9 }4 p/ h; j/ {. ?
10.89.129.131 255.255.255.255 0.0.0.0 0.0.0.0 AuthInbound
3 m/ W8 |+ j( ^" F& u! E0 `' V- J5 D: j5 Y# L+ \
no snmp-server location2 i' R5 w+ `6 Q s
no snmp-server contact
" ^, |! E" Q! Ksnmp-server community public
" }$ |4 @( p& ]' _# Fno snmp-server enable traps
. Y& q- W# ^# Q3 ~floodguard enable8 n5 v1 P1 }3 ?* }' `* I
7 ]$ n5 J4 `/ n0 w0 ]% k* ?. k' M
!--- Trust IPSec traffic and avoid going through ACLs/NAT.
k2 O% |" t3 a
0 z4 C2 O _' @( C+ @1 W( Wsysopt connection permit-ipsec
7 ]* }5 @, m/ H' t5 a* h
$ \4 a0 v( F- [!--- IPSec and dynamic map configuration.1 ^) f h, L9 A3 S& N8 l
( z Y F |& E, A8 v) D' z. Ocrypto ipsec transform-set myset esp-des esp-md5-hmac
- D; j* S% W+ k' P4 a/ t6 A rcrypto dynamic-map dynmap 10 set transform-set myset
0 I5 W7 \' u8 W3 P% m# U! hcrypto map mymap 10 ipsec-isakmp dynamic dynmap& W: S$ R* |9 i5 [9 V5 @
7 G& T6 V$ G8 N: L" V!--- Assign IP address for VPN 1.1 Clients.( @; }6 Z% N9 ?
5 \+ E) c* z6 |" a( G/ Q, M
crypto map mymap client configuration address initiate
4 a2 Y0 o8 h: Ecrypto map mymap client configuration address respond" j2 R1 a" O! d: y
V' K$ |( q: E! |- G!--- Use the AAA server for authentication (AuthInbound). P5 Y- v, [; M3 Q2 d
$ c3 E# K5 z {0 A; z* gcrypto map mymap client authentication AuthInbound3 {* O0 Z& P2 z7 n1 }5 f( z
& c* n* ~: i" i; e3 @7 i!--- Apply the IPSec/AAA/ISAKMP configuration to the outside interface.3 U; m( n( r# K$ ~6 A5 P# u1 w) H
! W$ L$ i8 X- i2 P$ F9 |; C/ Y9 H8 pcrypto map mymap interface outside
+ j; [) z% I1 l! e2 V. fisakmp enable outside) s) O4 r1 q5 C7 a/ R" b
, m% K* U- j( ]3 M
!--- Pre-shared key for VPN 1.1 Clients./ s0 v" w$ o$ G+ F9 O
/ m+ h% M y4 K9 }# @5 k. I6 I' _
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0: F* \. ~! O! l
isakmp identity address2 S$ E9 m4 z/ G, `+ b+ A2 F) W) O
! o: P) s3 y5 v* \!--- Assign address from "VPNpool" pool for VPN 1.1 Clients.5 A7 z7 @, H: H; z% o0 q- P
' S3 b8 E |3 s8 j
isakmp client configuration address-pool local VPNpool outside# D7 h: J/ P7 r7 m7 r3 o; \
! J1 |0 n+ N0 L2 P' G$ ]!--- ISAKMP configuration for VPN Client 3.x/4.x.
' u$ w6 f; D/ T1 \' h" i8 i3 I/ k1 U# ~9 I
isakmp policy 10 authentication pre-share
; I. ?7 P9 M- z/ k5 H; Nisakmp policy 10 encryption des V5 L! M+ J0 h/ E! w4 j- G
isakmp policy 10 hash md5
2 s7 m9 T2 K" g, v) Y- w! q$ eisakmp policy 10 group 2
8 ?- L( Z& w% hisakmp policy 10 lifetime 86400/ `- r9 d3 C0 S
2 F& ?7 H% `! Q" s! i
!--- ISAKMP configuration for VPN Client 1.x.0 S4 w/ c) y" s/ _
) N' p. w8 r0 `; l7 a# @1 {
isakmp policy 20 authentication pre-share
" Q3 j% h/ [5 f6 pisakmp policy 20 encryption des. e9 I9 u& P# _1 e& d X# B
isakmp policy 20 hash md50 ~# D& Q6 X# z1 E# B: X j
isakmp policy 20 group 1- ?' a) D! ]; r4 Z7 z. p6 u X
isakmp policy 20 lifetime 86400; s$ s! [: y1 ]: X C
" C2 ?+ h" x, N6 k, ^!--- Assign addresses from "VPNpool" for VPN Client 3.x/4.x.
# r" d( r& n' _: {2 I, M& T: M4 v! _2 X! W5 w
vpngroup vpn3000 address-pool VPNpool
: P+ E% x2 f9 S3 @# I' @) v( ~. u) o" n
vpngroup vpn3000 idle-time 1800
6 V D* i- B6 k7 p& m/ s
9 L: [1 Q4 c+ J5 G, @- C$ N9 U5 b* E* {
!--- Group password for VPN Client 3.x/4.x (not shown in configuration)." t( j2 y- ~( a' H$ E6 m- k
9 Q* j8 Q% Z5 l
vpngroup vpn3000 password ********
. u, l8 D T W: V) Ctelnet timeout 5% F! U; y, i% m: r: C% w, x
ssh timeout 5
. J- s$ Q8 ]0 Y: A% D2 }# ]7 vconsole timeout 0
* v+ M- v# w5 Vterminal width 80
0 @8 A! i% n" S$ W3 ]) oCryptochecksum:ba54c063d94989cbd79076955dbfeefc
$ l/ h, s# L3 F5 ^5 r' c+ U7 o) ~: end
2 ^/ {9 a1 G/ o! Fpixfirewall# |