
PIX Version 6.1(4)1 O @. G) y' y$ j
nameif ethernet0 outsid security0
8 X7 z3 ]) {4 r* Lnameif ethernet1 inside security100
6 {$ _! a [# eenable password toBi7KVlAY1YlvcW encrypted4 u% m+ y* } Q" B
passwd SaeANaf1hnt0M77p encrypted) G, X7 ?7 K! y
hostname pix515E. Q4 N& h, N u' `1 `
domain-name ssh-manage.com
- ?, T+ J4 s3 ?+ b- `7 Wfixup protocol ftp 21
% S* R8 H$ _( i! T! E: vfixup protocol http 80) I6 M' m6 V0 ^
fixup protocol h323 1720
: e- p, _% B3 @7 c% ffixup protocol rsh 514
3 F: W# J6 M. \( _& h* Yfixup protocol rtsp 554
( T& r. l# g! @/ Wfixup protocol smtp 25
6 J+ _$ \# O2 Z# Jfixup protocol sqlnet 1521, s) z1 Z) G2 m) p/ T- ~
fixup protocol sip 50601 d% \& n4 m4 O! ?
fixup protocol skinny 2000
; n& ^6 ]4 m& w0 unames1 o: q& s; Y Z1 F
access-list 100 permit ip 133.0.0.0 255.0.0.0 133.54.9.192 255.255.255.240& [( Q: |9 B) x9 g3 l( M
access-list 100 permit ip 139.0.0.0 255.0.0.0 133.54.9.192 255.255.255.2405 X+ A3 T% ~7 {+ W( w) R9 m- R
access-list 100 permit ip 172.16.0.0 255.255.0.0 133.54.9.192 255.255.255.2407 o P3 r4 m* Q( Y; V
access-list 100 permit ip 10.42.0.0 255.255.0.0 133.54.9.192 255.255.255.240
0 Z& n, l4 S+ z- e8 y, haccess-list 100 permit ip 221.236.19.0 255.255.255.0 133.54.9.192 255.255.255.24
3 n9 s8 q4 w9 M8 y( D$ P) |* C1 w0
1 y8 X2 ?8 ~9 `1 {. k0 Dpager lines 24
% P' o* T) ]6 _logging on Z3 P9 C7 X% v, Q/ m! n* a9 R4 j
logging trap debugging% `/ Z) `2 e l; [* W+ ^! J' `3 P
logging history debugging/ s# \1 }" W0 r" M; e0 c
logging host inside 133.54.30.71
, ~0 `! ]9 @- d$ C8 I, B3 {$ Ointerface ethernet0 auto
% [ @2 X/ m- A% X8 b3 N* Minterface ethernet1 auto4 L: b- a! o H1 n L5 ]* j; f
mtu outsid 15007 n9 h6 d/ _9 |6 r- Z
mtu inside 1500
2 ?0 B( W# Z6 i; V; Nip address outsid 218.89.65.31 255.255.255.0; B7 D8 J6 x- m: x
ip address inside 133.54.30.2 255.255.255.0* U4 w+ w0 n7 _" ^- r1 U3 ~
ip audit info action alarm
; c1 B) H+ K; W( J4 Y& `$ U# ]ip audit attack action alarm+ l; v' J3 b$ T2 K" L$ z# j
ip local pool vpnpool2 133.54.9.192/ ]5 ?* [$ B* \# A$ ]" E
ip local pool vpnpool 133.54.9.199-133.54.9.207' p R) t. f( a e
ip local pool vpnpool3 133.54.9.193
! x8 M8 }, j/ K( q, |ip local pool vpnpool4 133.54.9.194) r/ A6 `# b8 s* @
ip local pool vpnpool5 133.54.9.1956 H" ~) S+ y. R6 f. a2 C
ip local pool vpnpool6 133.54.9.196
. _) x# s6 y( b& S" Bip local pool vpnpool7 133.54.9.197
/ u U' Y; Y6 l3 u" ?$ W( Yip local pool vpnpool8 133.54.9.198
( w7 l7 c G9 \, h; Zpdm history enable% R; C/ ^5 J, Q: }' M! V; \
arp timeout 14400* q# o( Y5 I: ]. }5 f
global (outsid) 1 interface
5 Z. f% I( W1 q: Ynat (inside) 0 access-list 100
5 B% n" u n1 Q+ @+ Hnat (inside) 2 133.54.30.103 255.255.255.255 0 0
9 y e$ |8 R" D) h* N1 x+ ^2 qnat (inside) 1 133.54.9.0 255.255.255.0 0 0( m/ O. u! L4 ]! z! i, s2 m
nat (inside) 1 133.54.30.0 255.255.255.0 0 0! k/ |' \; A, g9 U' F* b6 {9 n
static (inside,outsid) tcp 218.89.65.31 www 133.54.9.4 www netmask 255.255.255.20 ?2 ^! z$ ? w
55 0 0
; S( S4 q& v8 A# fconduit permit icmp any any0 O2 E: r" o k# @" [4 I
conduit permit udp any any
8 H% [, a! V6 p' nconduit permit tcp host 18.89.65.31 eq www any9 I% B- `: @3 Q/ N. Q9 I9 w/ r2 b
route outsid 0.0.0.0 0.0.0.0 218.89.65.1 1
X, R. b3 w3 h' _. n# Q! groute inside 10.12.0.0 255.255.0.0 133.54.30.76 1
' [+ k+ V4 y$ i: n# Aroute inside 10.42.0.0 255.255.0.0 133.54.30.76 1
. h2 m3 A2 d! O9 |$ E1 i* y, Sroute inside 133.37.0.0 255.255.0.0 133.54.9.124 12 ?2 ~6 w0 G- O" x0 ]
route inside 133.54.0.0 255.255.0.0 133.54.9.124 1: U8 P3 p3 [8 h D( \
route inside 133.57.0.0 255.255.0.0 133.54.30.1 1
: r3 E. _2 ? b: X, a7 n y. |route inside 139.54.5.0 255.255.255.0 133.54.30.1 1
! K6 e. M) W6 ]6 k. j4 w& M: U( Eroute inside 172.16.0.0 255.255.0.0 133.54.30.76 1' x: w7 }+ l% J7 m! U# `
route inside 172.16.5.0 255.255.255.0 133.54.30.76 1
0 E! P. ?3 R* E9 X6 [, W, Eroute inside 172.16.51.0 255.255.255.0 133.54.30.76 1( S3 U1 x1 i" I p" R3 }
route inside 172.16.52.0 255.255.255.0 133.54.30.76 17 E) n# C7 H- c6 u9 N- u5 s
route inside 202.98.107.0 255.255.255.0 133.54.30.76 17 t' R2 Z1 W' u8 r% a
route inside 221.236.19.0 255.255.255.0 133.54.30.76 1
8 [9 `. Y9 N, n4 X# b3 ~0 utimeout xlate 3:00:00
! {- y+ c4 ^2 wtimeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si9 q4 H- h7 |1 E7 E
p 0:30:00 sip_media 0:02:00
- i# F l% u( ]timeout uauth 0:05:00 absolute- t, {' W% q0 G! r$ X
aaa-server TACACS+ protocol tacacs+
' ^7 ?6 ]" z* L% Iaaa-server RADIUS protocol radius0 ~/ L7 E+ O! e; v7 S# v* ?) g
snmp-server host outsid 61.188.201.771 r+ ]5 R8 A* q9 |3 \2 A9 a
snmp-server location idc
2 z7 e$ g( G% o$ Qsnmp-server contact lijie4 @0 i; T" c v# n
snmp-server community ybdxitzczx
1 N4 h! M3 ~. Q+ X% Z8 x/ C5 Osnmp-server enable traps7 x& t" I( E" h- q# ]1 D+ S* z
floodguard enable" m y' t2 O) ]" Y& T) q# a
sysopt connection permit-ipsec) A8 e2 y. f7 }" a- H. s; j0 w
sysopt connection permit-pptp
* t3 Z7 K/ k i( s8 `5 ?) ~no sysopt route dnat
" s7 g. Z) R0 U- ucrypto ipsec transform-set gyset esp-des esp-md5-hmac) B3 L( o0 [0 K; ?
crypto dynamic-map dynmap 20 set transform-set gyset: N. G: [. ?9 M) H# Y+ H& x
crypto map ipsecmap 10 ipsec-isakmp dynamic dynmap* T6 ] K! ?/ r7 m% H8 _
crypto map ipsecmap interface outsid
) n. i# c$ R3 P$ O- Z% V- B; Y) visakmp enable outsid
+ ^/ E' r6 ?6 R3 iisakmp key ******** address 0.0.0.0 netmask 0.0.0.0
# T# ~# K) d$ nisakmp identity address
6 B( G& S F _& \9 E' o$ Hisakmp policy 10 authentication pre-share
0 W U1 j* N3 }) Uisakmp policy 10 encryption des& g% d4 J- ~6 c: N3 x
isakmp policy 10 hash md5) r0 S! ^" m* @* C+ ^4 t! Z: Z
isakmp policy 10 group 2
" e+ Q) h, T: I0 ]$ {$ f) sisakmp policy 10 lifetime 86400
8 K9 n& l; a" c+ x0 Htelnet 133.54.9.4 255.255.255.255 inside' _: l4 v+ r0 i: g# y; B
telnet timeout 50; t5 w9 ]5 L5 I9 w+ Q) q0 Z) l* e
ssh timeout 53 ?& q1 P p& h7 [( F
vpdn group PPTP-VPDN-GROUP accept dialin pptp
' p0 S4 n, W: ?/ V7 H1 H# Gvpdn group PPTP-VPDN-GROUP ppp authentication mschap
0 o5 e6 X+ A' }vpdn group PPTP-VPDN-GROUP ppp encryption mppe 40; n0 }0 x; g) v% `8 f5 }
vpdn group PPTP-VPDN-GROUP client configuration address local vpnpool7 ^; W- l* I+ V- c' i+ a2 z
vpdn group PPTP-VPDN-GROUP pptp echo 60/ C' v8 S" E+ b
vpdn group PPTP-VPDN-GROUP client authentication local. y* P0 S) z+ n; w# b: e$ @
vpdn enable outsid
! b6 ]3 T9 j, _) _9 S6 f6 Yterminal width 80
: e3 Z: I* }7 L t) GCryptochecksum:659329c159244656b60a5b569fb4a904 |
|