Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- =~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2016.08.01 23:24:00 =~=~=~=~=~=~=~=~=~=~=~=
- sh run
- : Saved
- :
- : Serial Number: 9AW4MCWVJ39
- : Hardware: ASAv, 2048 MB RAM, CPU Xeon 5500 series 2400 MHz
- :
- ASA Version 9.3(1)
- !
- hostname CISCOASA1
- enable password DPo8KMYgWczwBY00 encrypted
- xlate per-session deny tcp any4 any4
- xlate per-session deny tcp any4 any6
- xlate per-session deny tcp any6 any4
- xlate per-session deny tcp any6 any6
- xlate per-session deny udp any4 any4 eq domain
- xlate per-session deny udp any4 any6 eq domain
- xlate per-session deny udp any6 any4 eq domain
- xlate per-session deny udp any6 any6 eq domain
- names
- !
- interface GigabitEthernet0/0
- nameif outside
- security-level 0
- ip address dhcp setroute
- !
- <--- More --->
- interface GigabitEthernet0/1
- nameif inside
- security-level 100
- ip address 10.0.250.254 255.255.255.0
- !
- interface GigabitEthernet0/1.2
- vlan 2
- nameif LANMANAGEMENT
- security-level 100
- ip address 10.0.2.254 255.255.255.0
- !
- interface GigabitEthernet0/1.20
- vlan 20
- nameif ISCSI_VLAN20
- security-level 100
- ip address 10.0.20.254 255.255.255.0
- !
- interface GigabitEthernet0/1.30
- vlan 30
- nameif VMOTION_VLAN30
- security-level 100
- ip address 10.0.30.254 255.255.255.0
- !
- <--- More --->
- interface GigabitEthernet0/1.50
- vlan 50
- nameif PROD_VLAN50
- security-level 100
- ip address 10.0.50.254 255.255.255.0
- !
- interface GigabitEthernet0/1.66
- vlan 66
- nameif TESTING_VLAN66
- security-level 100
- ip address 10.0.66.254 255.255.255.0
- !
- interface GigabitEthernet0/1.100
- vlan 100
- nameif WIRELESS_VLAN100
- security-level 100
- ip address 10.0.100.254 255.255.255.0
- !
- interface GigabitEthernet0/1.660
- vlan 660
- nameif PUBLIC_VLAN660
- security-level 0
- ip address 10.66.0.254 255.255.255.0
- <--- More --->
- !
- interface GigabitEthernet0/2
- shutdown
- no nameif
- no security-level
- no ip address
- !
- interface GigabitEthernet0/3
- shutdown
- no nameif
- no security-level
- no ip address
- !
- interface GigabitEthernet0/4
- shutdown
- no nameif
- no security-level
- no ip address
- !
- interface GigabitEthernet0/5
- shutdown
- no nameif
- no security-level
- <--- More --->
- no ip address
- !
- interface GigabitEthernet0/6
- shutdown
- no nameif
- no security-level
- no ip address
- !
- interface GigabitEthernet0/7
- shutdown
- no nameif
- no security-level
- no ip address
- !
- interface GigabitEthernet0/8
- shutdown
- no nameif
- no security-level
- no ip address
- !
- interface Management0/0
- management-only
- shutdown
- <--- More --->
- nameif management
- security-level 0
- ip address 10.0.254.1 255.255.255.0
- !
- ftp mode passive
- clock timezone EST -5
- clock summer-time EDT recurring
- dns domain-lookup inside
- dns server-group DefaultDNS
- name-server 8.8.8.8
- name-server 4.2.2.2
- same-security-traffic permit inter-interface
- same-security-traffic permit intra-interface
- object network OBJ-0.0.0.0
- subnet 0.0.0.0 0.0.0.0
- object network INETACCESS
- subnet 0.0.0.0 0.0.0.0
- object network OBJ-RDP
- host 10.0.250.211
- description RDP
- object service RDP-3389
- service tcp destination eq 3389
- description Microsoft RDP
- <--- More --->
- object service RDP-Service
- service tcp source eq 3389
- object-group protocol TCPUDP
- protocol-object udp
- protocol-object tcp
- access-list outside_access_in extended permit object RDP-3389 any object OBJ-RDP
- pager lines 23
- logging enable
- logging asdm informational
- mtu outside 1500
- mtu inside 1500
- mtu LANMANAGEMENT 1500
- mtu ISCSI_VLAN20 1500
- mtu VMOTION_VLAN30 1500
- mtu PROD_VLAN50 1500
- mtu TESTING_VLAN66 1500
- mtu WIRELESS_VLAN100 1500
- mtu PUBLIC_VLAN660 1500
- mtu management 1500
- no failover
- icmp unreachable rate-limit 1 burst-size 1
- no asdm history enable
- arp timeout 14400
- <--- More --->
- no arp permit-nonconnected
- nat (inside,outside) source static OBJ-RDP interface service any RDP-Service
- !
- object network INETACCESS
- nat (any,outside) dynamic interface
- access-group outside_access_in in interface outside
- timeout xlate 3:00:00
- timeout pat-xlate 0:00:30
- timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
- timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
- timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
- timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
- timeout tcp-proxy-reassembly 0:01:00
- timeout floating-conn 0:00:00
- user-identity default-domain LOCAL
- aaa authentication ssh console LOCAL
- http server enable
- http 10.0.250.0 255.255.255.0 management
- http 0.0.0.0 0.0.0.0 inside
- no snmp-server location
- no snmp-server contact
- crypto ipsec security-association pmtu-aging infinite
- crypto ca trustpool policy
- <--- More --->
- telnet timeout 5
- ssh stricthostkeycheck
- ssh 0.0.0.0 0.0.0.0 inside
- ssh 10.0.250.0 255.255.255.0 management
- ssh timeout 5
- ssh key-exchange group dh-group1-sha1
- console timeout 0
- dhcp-client client-id interface outside
- dhcpd update dns both override
- !
- dhcpd address 10.0.250.100-10.0.250.200 inside
- dhcpd dns 10.0.250.211 4.2.2.2 interface inside
- dhcpd enable inside
- !
- !
- tls-proxy maximum-session 500
- !
- threat-detection basic-threat
- threat-detection statistics access-list
- no threat-detection statistics tcp-intercept
- webvpn
- anyconnect-essentials
- error-recovery disable
- <--- More --->
- dynamic-access-policy-record DfltAccessPolicy
- username cisco password XXXXXXXXXXXX encrypted
- !
- class-map inspection_default
- match default-inspection-traffic
- !
- !
- policy-map type inspect dns preset_dns_map
- parameters
- message-length maximum client auto
- message-length maximum 512
- policy-map global_policy
- class inspection_default
- inspect rtsp
- inspect sunrpc
- inspect xdmcp
- inspect netbios
- inspect tftp
- inspect ip-options
- inspect dns preset_dns_map
- inspect ftp
- inspect h323 h225
- inspect h323 ras
- <--- More --->
- inspect rsh
- inspect esmtp
- inspect sqlnet
- inspect sip
- inspect skinny
- !
- service-policy global_policy global
- prompt hostname context
- no call-home reporting anonymous
- call-home
- profile CiscoTAC-1
- no active
- destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
- destination address email [email protected]
- destination transport-method http
- subscribe-to-alert-group diagnostic
- subscribe-to-alert-group environment
- subscribe-to-alert-group inventory periodic monthly 5
- subscribe-to-alert-group configuration periodic monthly 5
- subscribe-to-alert-group telemetry periodic daily
- Cryptochecksum:6732bfe6b0799e0020a3dacaee21
- : end
- CISCOASA1(config-if)#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement