PIX Version 6.3(5) interface ethernet0 100full interface ethernet1 100full nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password 8Ry2YjIyt7RRXU24 encrypted passwd 2KFQnbNIdI.2KYOU encrypted hostname nkpix domain-name ciscopix.com fixup protocol dns maximum-length 512 fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names name 10.1.1.1 inside name x.x.x.x outside name 10.1.2.0 client access-list in_outside permit icmp any any access-list 101 permit ip 10.1.1.0 255.255.255.0 192.168.11.0 255.255.255.0 access-list test permit ip 10.1.1.0 255.255.255.0 192.168.11.0 255.255.255.0 access-list test permit ip any client 255.255.255.0 access-list outside_cryptomap_dyn_20 permit ip any client 255.255.255.0 pager lines 24 mtu outside 1500 mtu inside 1500 ip address outside outside 255.255.255.248 ip address inside inside 255.255.255.0 ip audit info action alarm ip audit attack action alarm ip local pool CSB_LAN 10.1.2.1-10.1.2.2 mask 255.255.255.0 pdm location 192.168.11.0 255.255.255.0 outside pdm location 10.1.1.200 255.255.255.254 outside pdm location client 255.255.255.0 outside pdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 0 access-list test nat (inside) 1 0.0.0.0 0.0.0.0 0 0 access-group in_outside in interface outside route outside 0.0.0.0 0.0.0.0 203.177.60.49 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout sip-disconnect 0:02:00 sip-invite 0:03:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server TACACS+ max-failed-attempts 3 aaa-server TACACS+ deadtime 10 aaa-server RADIUS protocol radius aaa-server RADIUS max-failed-attempts 3 aaa-server RADIUS deadtime 10 aaa-server LOCAL protocol local aaa authentication ssh console LOCAL http server enable http 10.1.1.0 255.255.255.0 inside no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps floodguard enable sysopt connection permit-ipsec crypto ipsec transform-set CSB esp-des esp-md5-hmac crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20 crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5 crypto map transam 1 ipsec-isakmp crypto map transam 1 match address 101 crypto map transam 1 set peer x.x.x.x crypto map transam 1 set transform-set CSB ESP-DES-MD5 ESP-3DES-SHA ESP-DES-SHA ESP-3DES-MD5 ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 crypto map transam 65535 ipsec-isakmp dynamic outside_dyn_map crypto map transam client authentication LOCAL crypto map transam interface outside isakmp enable outside isakmp key ******** address x.x.x.x netmask 255.255.255.255 no-xauth no-config-mode isakmp identity address isakmp policy 1 authentication pre-share isakmp policy 1 encryption des isakmp policy 1 hash md5 isakmp policy 1 group 1 isakmp policy 1 lifetime 1000 isakmp policy 21 authentication pre-share isakmp policy 21 encryption des isakmp policy 21 hash md5 isakmp policy 21 group 2 isakmp policy 21 lifetime 86400 vpngroup CSB_IT address-pool CSB_LAN vpngroup CSB_IT dns-server 4.2.2.2 vpngroup CSB_IT default-domain nk.net vpngroup CSB_IT idle-time 1800 vpngroup CSB_IT password ******** telnet 10.1.1.0 255.255.255.0 inside telnet timeout 5 ssh timeout 5 console timeout 0 dhcpd address 10.1.1.2-10.1.1.10 inside dhcpd dns 4.2.2.2 dhcpd lease 3600 dhcpd ping_timeout 750 dhcpd enable inside username test password P4ttSyrm33SV8TYp encrypted privilege 15 terminal width 80 Cryptochecksum:c30688b649172bc8f5fefdef87aec3cc : end nkpix#