Primary-FW/act# sh run : Saved : : Serial Number: JMX1203L0NN : Hardware: ASA5520, 1024 MB RAM, CPU Pentium II 1000 MHz : ASA Version 9.1(5)16 ! hostname Primary-FW enable password 8Ry2YjIyt7RRXU24 encrypted xlate per-session deny tcp any4 any4 xlate per-session deny tcp any4 any6 xlate per-session deny tcp any6 any4 xlate per-session deny tcp any6 any6 xlate per-session deny udp any4 any4 eq domain xlate per-session deny udp any4 any6 eq domain xlate per-session deny udp any6 any4 eq domain xlate per-session deny udp any6 any6 eq domain names ! interface Ethernet0 description LAN/STATE Failover Interface ! interface Ethernet1 description Connect to Core_Switch no nameif no security-level no ip address ! interface Ethernet2 description Connect to BANet_Firewall nameif outside security-level 0 ip address 10.66.244.2 255.255.255.248 standby 10.66.244.3 ! interface Ethernet3 no nameif no security-level no ip address ! interface Ethernet4 shutdown no nameif no security-level no ip address ! interface Ethernet5 shutdown no nameif no security-level no ip address ! interface Ethernet6 shutdown no nameif no security-level no ip address ! interface Ethernet7 nameif internet security-level 0 ip address 10.10.100.200 255.255.255.0 standby 10.10.100.201 ! interface Redundant1 member-interface Ethernet1 member-interface Ethernet3 nameif inside security-level 100 ip address 192.168.100.1 255.255.255.248 standby 192.168.100.5 ! ftp mode passive access-list OTI extended permit ip any any access-list OTI extended permit tcp any any pager lines 24 mtu outside 1500 mtu internet 1500 mtu inside 1500 failover failover lan unit primary failover lan interface FOLink Ethernet0 failover key ***** failover link FOLink Ethernet0 failover interface ip FOLink 192.168.99.1 255.255.255.252 standby 192.168.99.2 icmp unreachable rate-limit 1 burst-size 1 icmp permit 10.66.244.0 255.255.255.248 outside icmp permit 192.168.100.0 255.255.255.248 outside no asdm history enable arp timeout 14400 no arp permit-nonconnected access-group OTI in interface outside route outside 0.0.0.0 0.0.0.0 10.66.244.1 1 route outside 10.66.29.0 255.255.255.0 10.66.244.1 1 route inside 10.66.253.0 255.255.255.0 192.168.100.2 1 timeout xlate 3:00:00 timeout pat-xlate 0:00:30 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:01:00 timeout floating-conn 0:00:00 dynamic-access-policy-record DfltAccessPolicy user-identity default-domain LOCAL http server enable http 10.10.100.0 255.255.255.0 internet no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart crypto ipsec security-association pmtu-aging infinite crypto ca trustpool policy telnet timeout 5 ssh stricthostkeycheck ssh timeout 5 ssh key-exchange group dh-group1-sha1 console timeout 0 threat-detection basic-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept ssl encryption rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1 webvpn anyconnect-essentials username admin password f3UhLvUj1QsXsuK7 encrypted ! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum client auto message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect ip-options inspect netbios inspect rsh inspect rtsp inspect skinny inspect esmtp inspect sqlnet inspect sunrpc inspect tftp inspect sip inspect xdmcp inspect icmp ! service-policy global_policy global prompt hostname state no call-home reporting anonymous call-home profile CiscoTAC-1 no active destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address email callhome@cisco.com destination transport-method http subscribe-to-alert-group diagnostic subscribe-to-alert-group environment subscribe-to-alert-group inventory periodic monthly subscribe-to-alert-group configuration periodic monthly subscribe-to-alert-group telemetry periodic daily crashinfo save disable Cryptochecksum:b3eb36abfb39dd956b608b59dd41c9b8 : end Primary-FW/act#