Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- !
- class-map type inspect match-all INSIDE-TO-OUTSIDE-CLASS
- match access-group name INSIDE-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-INSIDE-CLASS
- match access-group name OUTSIDE-TO-INSIDE
- class-map type inspect match-all V80-TO-OUTSIDE-CLASS
- match access-group name V80-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V80-CLASS
- match access-group name OUTSIDE-TO-V80
- class-map type inspect match-all V30-TO-OUTSIDE-CLASS
- match access-group name V30-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V30-CLASS
- match access-group name OUTSIDE-TO-V30
- class-map type inspect match-all V20-TO-OUTSIDE-CLASS
- match access-group name V20-TO-OUTSIDE
- match access-group name ip620-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V20-CLASS
- match access-group name OUTSIDE-TO-V20
- match access-group name OUTSIDE-TO-ip620
- class-map type inspect match-all V70-TO-OUTSIDE-CLASS
- match access-group name V70-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V70-CLASS
- match access-group name OUTSIDE-TO-V70
- class-map type inspect match-all V60-TO-OUTSIDE-CLASS
- match access-group name V60-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V60-CLASS
- match access-group name OUTSIDE-TO-V60
- class-map type inspect match-all V50-TO-OUTSIDE-CLASS
- match access-group name V50-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V50-CLASS
- match access-group name OUTSIDE-TO-V50
- class-map type inspect match-all V40-TO-OUTSIDE-CLASS
- match access-group name V40-TO-OUTSIDE
- class-map type inspect match-all OUTSIDE-TO-V40-CLASS
- match access-group name OUTSIDE-TO-V40
- !
- policy-map type inspect V60-TO-OUTSIDE-POLICY
- class type inspect V60-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect V40-TO-OUTSIDE-POLICY
- class type inspect V40-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect OUTSIDE-TO-V60-POLICY
- class type inspect OUTSIDE-TO-V60-CLASS
- drop
- class class-default
- drop
- policy-map type inspect V20-TO-OUTSIDE-POLICY
- class type inspect V20-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect V70-TO-OUTSIDE-POLICY
- class type inspect V70-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect OUTSIDE-TO-V40-POLICY
- class type inspect OUTSIDE-TO-V40-CLASS
- drop
- class class-default
- drop
- policy-map type inspect V30-TO-OUTSIDE-POLICY
- class type inspect V30-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect OUTSIDE-TO-V80-POLICY
- class type inspect OUTSIDE-TO-V80-CLASS
- drop
- class class-default
- drop
- policy-map type inspect OUTSIDE-TO-V30-POLICY
- class type inspect OUTSIDE-TO-V30-CLASS
- drop
- class class-default
- drop
- policy-map type inspect OUTSIDE-TO-V50-POLICY
- class type inspect OUTSIDE-TO-V50-CLASS
- drop
- class class-default
- drop
- policy-map type inspect INSIDE-TO-OUTSIDE-POLICY
- class type inspect INSIDE-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect V50-TO-OUTSIDE-POLICY
- class type inspect V50-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect OUTSIDE-TO-V20-POLICY
- class type inspect OUTSIDE-TO-V20-CLASS
- drop
- class class-default
- drop
- policy-map type inspect OUTSIDE-TO-INSIDE-POLICY
- class type inspect OUTSIDE-TO-INSIDE-CLASS
- drop
- class class-default
- drop
- policy-map type inspect V80-TO-OUTSIDE-POLICY
- class type inspect V80-TO-OUTSIDE-CLASS
- inspect
- class class-default
- pass
- policy-map type inspect OUTSIDE-TO-V70-POLICY
- class type inspect OUTSIDE-TO-V70-CLASS
- drop
- class class-default
- drop
- !
- zone security INSIDE
- zone security OUTSIDE
- zone security vlan20
- zone security vlan30
- zone security vlan40
- zone security vlan50
- zone security vlan60
- zone security vlan70
- zone security vlan80
- zone-pair security IN-TO-OUT source INSIDE destination OUTSIDE
- service-policy type inspect INSIDE-TO-OUTSIDE-POLICY
- zone-pair security OUT-TO-IN source OUTSIDE destination INSIDE
- service-policy type inspect OUTSIDE-TO-INSIDE-POLICY
- zone-pair security 20-TO-OUT source vlan20 destination OUTSIDE
- service-policy type inspect V20-TO-OUTSIDE-POLICY
- zone-pair security 30-TO-OUT source vlan30 destination OUTSIDE
- service-policy type inspect V30-TO-OUTSIDE-POLICY
- zone-pair security 40-TO-OUT source vlan40 destination OUTSIDE
- service-policy type inspect V40-TO-OUTSIDE-POLICY
- zone-pair security 50-TO-OUT source vlan50 destination OUTSIDE
- service-policy type inspect V50-TO-OUTSIDE-POLICY
- zone-pair security 60-TO-OUT source vlan60 destination OUTSIDE
- service-policy type inspect V60-TO-OUTSIDE-POLICY
- zone-pair security 70-TO-OUT source vlan70 destination OUTSIDE
- service-policy type inspect V70-TO-OUTSIDE-POLICY
- zone-pair security 80-TO-OUT source vlan80 destination OUTSIDE
- service-policy type inspect V80-TO-OUTSIDE-POLICY
- zone-pair security OUT-TO-20 source OUTSIDE destination vlan20
- service-policy type inspect OUTSIDE-TO-V20-POLICY
- zone-pair security OUT-TO-30 source OUTSIDE destination vlan30
- service-policy type inspect OUTSIDE-TO-V30-POLICY
- zone-pair security OUT-TO-40 source OUTSIDE destination vlan40
- service-policy type inspect OUTSIDE-TO-V40-POLICY
- zone-pair security OUT-TO-50 source OUTSIDE destination vlan50
- service-policy type inspect OUTSIDE-TO-V50-POLICY
- zone-pair security OUT-TO-60 source OUTSIDE destination vlan60
- service-policy type inspect OUTSIDE-TO-V60-POLICY
- zone-pair security OUT-TO-70 source OUTSIDE destination vlan70
- service-policy type inspect OUTSIDE-TO-V70-POLICY
- zone-pair security OUT-TO-80 source OUTSIDE destination vlan80
- service-policy type inspect OUTSIDE-TO-V80-POLICY
- !
- !
- ip access-list extended INSIDE-TO-OUTSIDE
- ip access-list extended OUTSIDE-TO-INSIDE
- ip access-list extended OUTSIDE-TO-V20
- ip access-list extended OUTSIDE-TO-V30
- ip access-list extended OUTSIDE-TO-V40
- ip access-list extended OUTSIDE-TO-V50
- ip access-list extended OUTSIDE-TO-V60
- ip access-list extended OUTSIDE-TO-V70
- ip access-list extended OUTSIDE-TO-V80
- ip access-list extended V20-TO-OUTSIDE
- permit ip 192.168.20.0 0.0.0.255 any
- ip access-list extended V30-TO-OUTSIDE
- permit ip 192.168.30.0 0.0.0.255 any
- ip access-list extended V40-TO-OUTSIDE
- permit ip 192.168.40.0 0.0.0.255 any
- ip access-list extended V50-TO-OUTSIDE
- permit ip 192.168.50.0 0.0.0.255 any
- ip access-list extended V60-TO-OUTSIDE
- permit ip 192.168.60.0 0.0.0.255 any
- ip access-list extended V70-TO-OUTSIDE
- permit ip 192.168.70.0 0.0.0.255 any
- ip access-list extended V80-TO-OUTSIDE
- permit ip 192.168.80.0 0.0.0.255 any
- ! show run
- ipv6 route ::/0 Tunnel0
- ipv6 ioam timestamp
- !
- !
- access-list 1 permit 192.168.20.0 0.0.0.255
- access-list 1 permit 192.168.30.0 0.0.0.255
- access-list 1 permit 192.168.40.0 0.0.0.255
- access-list 1 permit 192.168.50.0 0.0.0.255
- access-list 1 permit 192.168.60.0 0.0.0.255
- access-list 1 permit 192.168.70.0 0.0.0.255
- access-list 1 permit 192.168.80.0 0.0.0.255
- access-list 1 permit 192.168.2.0 0.0.0.255
- !
- !
- !
- ipv6 access-list OUTSIDE-TO-ip620
- permit icmp any any unreachable
- permit icmp any any packet-too-big
- permit icmp any 2001:470:1F19:AB:2000::/68
- permit icmp any any reassembly-timeout
- permit icmp any any header
- permit icmp any any next-header
- permit icmp any any parameter-option
- permit icmp any any echo-request
- permit icmp any any echo-reply
- permit icmp any any dhaad-request
- permit icmp any any dhaad-reply
- permit icmp any any mpd-solicitation
- permit icmp any any mpd-advertisement
- permit icmp any any nd-na
- permit icmp any any nd-ns
- !
- ipv6 access-list ip620-TO-OUTSIDE
- permit ipv6 2001:470:1F19:AB:2000::/68 any
- sequence 30 permit icmp any 2001:470:1F19:AB:2000::/68
- control-plane host
- !
- !
- control-plane
- !
- My zone based firewall config.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement