ASA Version 9.0(2) ! hostname WDC-ASA xlate per-session deny tcp any4 any4 xlate per-session deny tcp any4 any6 xlate per-session deny tcp any6 any4 xlate per-session deny tcp any6 any6 xlate per-session deny udp any4 any4 eq domain xlate per-session deny udp any4 any6 eq domain xlate per-session deny udp any6 any4 eq domain xlate per-session deny udp any6 any6 eq domain names ip local pool RemoteClientPool 172.16.1.1-172.16.1.15 mask 255.255.255.0 ! interface Ethernet0/0 switchport access vlan 2 ! interface Ethernet0/1 ! interface Ethernet0/2 ! interface Ethernet0/3 ! interface Ethernet0/4 ! interface Ethernet0/5 ! interface Ethernet0/6 ! interface Ethernet0/7 switchport trunk allowed vlan 1,3 switchport trunk native vlan 1 switchport mode trunk ! interface Vlan1 nameif inside security-level 100 ip address 10.1.1.250 255.255.255.0 ! interface Vlan2 nameif outside security-level 0 ip address (IP omitted) ! interface Vlan3 nameif guest security-level 50 ip address 192.168.1.254 255.255.255.0 ! boot system disk0:/asa902-k8.bin ftp mode passive clock timezone EST -5 clock summer-time EDT recurring dns server-group DefaultDNS domain-name object network obj_any subnet 0.0.0.0 0.0.0.0 object network obj-172.16.1.0 subnet 172.16.1.0 255.255.255.0 object network guest subnet 0.0.0.0 0.0.0.0 access-list NO-NAT extended permit ip any 172.16.1.0 255.255.255.0 access-list Inbound extended permit icmp any any echo-reply access-list Inbound extended permit icmp any any time-exceeded access-list Inbound extended permit tcp any object (object omitted) access-list Inbound extended permit tcp any object (object omitted) access-list Inbound extended permit tcp any object (object omitted) access-list Outbound extended permit tcp host 10.1.1.2 any eq smtp access-list Outbound extended deny tcp any any eq smtp access-list Outbound extended permit ip any any access-list Outbound-Guest extended deny tcp any any eq smtp access-list Outbound-Guest extended permit ip any any pager lines 24 logging enable logging asdm informational mtu inside 1500 mtu outside 1500 mtu guest 1500 no failover icmp unreachable rate-limit 1 burst-size 1 icmp deny any outside asdm image disk0:/asdm-713.bin no asdm history enable arp timeout 14400 no arp permit-nonconnected nat (inside,any) source static any any destination static obj-172.16.1.0 obj-172.16.1.0 no-proxy-arp ! object network obj_any nat (inside,outside) dynamic interface object network guest nat (guest,outside) dynamic interface access-group Outbound in interface inside access-group Inbound in interface outside access-group Outbound-Guest in interface guest route outside 0.0.0.0 0.0.0.0 (IP omitted) timeout xlate 3:00:00 timeout pat-xlate 0:00:30 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:01:00 timeout floating-conn 0:00:00 dynamic-access-policy-record DfltAccessPolicy user-identity default-domain LOCAL aaa authentication ssh console LOCAL http server enable http 172.16.1.0 255.255.255.0 inside http 10.1.1.0 255.255.255.0 inside no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart telnet 10.1.1.0 255.255.255.0 inside telnet timeout 15 console timeout 0 management-access inside dhcpd dns 75.75.75.75 75.75.76.76 ! dhcpd address 192.168.1.100-192.168.1.125 guest dhcpd dns 75.75.75.75 75.75.76.76 interface guest dhcpd enable guest ! threat-detection basic-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept ssl encryption des-sha1 ! class-map inspection_default match default-inspection-traffic class-map inspect ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp inspect ip-options class inspect ! service-policy global_policy global prompt hostname context no call-home reporting anonymous call-home profile CiscoTAC-1 no active destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address email callhome@cisco.com destination transport-method http subscribe-to-alert-group diagnostic subscribe-to-alert-group environment subscribe-to-alert-group inventory periodic monthly subscribe-to-alert-group configuration periodic monthly subscribe-to-alert-group telemetry periodic daily