Advertisement
Guest User

Untitled

a guest
Jun 8th, 2010
266
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.52 KB | None | 0 0
  1. Result of the command: "show running-config"
  2.  
  3. : Saved
  4. :
  5. ASA Version 8.2(1)
  6. !
  7. hostname ciscoasa
  8. names
  9. dns-guard
  10. !
  11. interface Vlan1
  12. nameif inside
  13. security-level 100
  14. ip address dhcp
  15. !
  16. interface Vlan2
  17. nameif outside
  18. security-level 0
  19. ip address 100.10.20.235 255.255.255.0
  20. !
  21. interface Ethernet0/0
  22. switchport access vlan 2
  23. !
  24.  
  25. same-security-traffic permit inter-interface
  26. access-list no-nat extended permit ip 172.16.1.0 255.255.255.0 10.10.0.0 255.255.255.0
  27. access-list VPN_splitunnelacl standard permit 172.16.1.0 255.255.255.0
  28.  
  29. mtu inside 1500
  30. mtu outside 1500
  31. ip local pool VPN 10.10.0.1-10.10.0.10 mask 255.255.255.252
  32. icmp unreachable rate-limit 1 burst-size 1
  33. no asdm history enable
  34. arp timeout 14400
  35. global (inside) 2 interface
  36. global (outside) 1 interface
  37. nat (inside) 0 access-list no-nat
  38. nat (inside) 1 0.0.0.0 0.0.0.0
  39. route outside 0.0.0.0 0.0.0.0 100.10.20.1 1
  40. route inside 172.16.1.0 255.255.255.255 172.16.1.254 1
  41. route outside 0.0.0.0 0.0.0.0 172.16.1.254 tunneled
  42.  
  43. dynamic-access-policy-record DfltAccessPolicy
  44. http server enable
  45. http 172.16.1.0 255.255.255.0 inside
  46. no snmp-server location
  47. no snmp-server contact
  48. snmp-server enable traps snmp authentication linkup linkdown coldstart
  49. crypto ipsec transform-set TRANS_ESP_3DES_SHA esp-3des esp-sha-hmac
  50. crypto ipsec transform-set TRANS_ESP_3DES_SHA mode transport
  51. crypto ipsec transform-set TRANS_ESP_3DES_MD5 esp-3des esp-md5-hmac
  52. crypto ipsec transform-set TRANS_ESP_3DES_MD5 mode transport
  53. crypto ipsec security-association lifetime seconds 28800
  54. crypto ipsec security-association lifetime kilobytes 4608000
  55. crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
  56. crypto dynamic-map outside_dyn_map 20 set transform-set TRANS_ESP_3DES_SHA TRANS_ESP_3DES_MD5
  57. crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
  58. crypto map outside_map interface outside
  59. crypto isakmp enable outside
  60. crypto isakmp policy 10
  61. authentication pre-share
  62. encryption 3des
  63. hash sha
  64. group 2
  65. lifetime 86400
  66. telnet timeout 5
  67. ssh timeout 5
  68. console timeout 0
  69. dhcpd auto_config outside
  70. !
  71. dhcpd address 172.16.1.10-172.16.1.41 inside
  72. !
  73.  
  74. threat-detection basic-threat
  75. threat-detection statistics access-list
  76. no threat-detection statistics tcp-intercept
  77. webvpn
  78. group-policy DefaultRAGroup internal
  79. group-policy DefaultRAGroup attributes
  80. dns-server value 172.16.1.1 172.16.1.254
  81. vpn-tunnel-protocol l2tp-ipsec
  82. split-tunnel-policy tunnelspecified
  83. split-tunnel-network-list value VPN_splitunnelacl
  84.  
  85. vpn-group-policy DefaultRAGroup
  86. tunnel-group DefaultRAGroup general-attributes
  87. address-pool VPN
  88. default-group-policy DefaultRAGroup
  89. tunnel-group DefaultRAGroup ipsec-attributes
  90. pre-shared-key *
  91. tunnel-group DefaultRAGroup ppp-attributes
  92. no authentication chap
  93. authentication ms-chap-v2
  94. !
  95. class-map inspection_default
  96. match default-inspection-traffic
  97. !
  98. !
  99. policy-map type inspect dns preset_dns_map
  100. parameters
  101. message-length maximum 512
  102. policy-map global_policy
  103. class inspection_default
  104. inspect dns preset_dns_map
  105. inspect ftp
  106. inspect h323 h225
  107. inspect h323 ras
  108. inspect rsh
  109. inspect rtsp
  110. inspect esmtp
  111. inspect sqlnet
  112. inspect skinny
  113. inspect sunrpc
  114. inspect xdmcp
  115. inspect sip
  116. inspect netbios
  117. inspect tftp
  118. !
  119. service-policy global_policy global
  120. prompt hostname context
  121. Cryptochecksum:a1417758a0b191120cdd7021f8eb5fbc
  122. : end
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement