: Saved : Written by gsmith at 11:06:25.400 EDT Sat Sep 1 2007 PIX Version 6.3(5) interface ethernet0 100full interface ethernet1 100full nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password *************** encrypted passwd *************.2KYOU encrypted hostname ric-fwl-01 domain-name domain.com clock timezone EST -5 clock summer-time EDT recurring fixup protocol dns maximum-length 512 fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 no fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names name 66.101.xxx.xxx ric-ns-01_out name 66.101.xxx.xxx ric-mst-01_out name 66.101.xxx.xxx ric-mx-02_out name 66.101.xxx.xxx ric-mx-01_out name 172.16.20.13 ric-mst-01_in name 172.16.20.12 ric-mx-02_in name 172.16.20.11 ric-mx-01_in name 172.16.20.10 ric-ns-01_in name 216.54.xxx.xxx pluto_out name 172.16.20.101 mx01-ilo name 172.16.20.102 mx2-ilo name 172.16.20.103 ric-mst-01-ilo name 172.16.20.100 ns3_ilo name 172.16.20.15 moon-in name 209.96.xxx.xxx widomaker_out name 216.54.xxx.xxx per02-out name 172.16.20.14 ric-mst-02_in name 66.101.xxx.xxx ric-im-01_out name 66.101.xxx.xxx ric-crm-01_out name 66.101.xxx.xxx ric-mst-02_out name 66.101.xxx.xxx postoffice_out name 66.101.xxx.xxx moon-out name 172.16.20.18 postoffice_in name 172.16.20.17 ric-im-01_in name 172.16.20.16 ric-crm-01_in name 216.54.xxx.xxx zimbra-perc-out name 66.101.xxx.xxx tenacity_IM name 66.92.xxx.xxx bryan_zimbra name 216.188.xxx.xxx zclicentfailure name 70.88.xxx.xxx zimbradenyjason name 172.16.20.20 nrc_in name 172.16.20.19 readynas_in name 172.16.20.22 ric-dev-01_in name 172.16.20.25 ricvm01-new-in object-group service ZimbraServices tcp port-object range 7071 7071 port-object eq imap4 port-object eq smtp port-object range 995 995 port-object eq pop3 port-object range 993 993 port-object eq www port-object eq https port-object eq ldap object-group network PercAdmin network-object 70.169.xxx.xxx 255.255.255.255 network-object 70.169.xxx.xxx 255.255.255.255 network-object pluto_out 255.255.255.255 network-object per02-out 255.255.255.255 network-object zimbra-perc-out 255.255.255.255 network-object bryan_zimbra 255.255.255.255 object-group network PerAdmn-in network-object ric-mx-01_in 255.255.255.255 network-object ric-mst-01_in 255.255.255.255 network-object ric-mx-02_in 255.255.255.255 network-object ric-ns-01_in 255.255.255.255 network-object mx01-ilo 255.255.255.255 network-object mx2-ilo 255.255.255.255 network-object ric-mst-01-ilo 255.255.255.255 network-object ns3_ilo 255.255.255.255 network-object moon-in 255.255.255.255 network-object ric-mst-02_in 255.255.255.255 network-object ric-crm-01_in 255.255.255.255 network-object ric-im-01_in 255.255.255.255 network-object postoffice_in 255.255.255.255 network-object readynas_in 255.255.255.255 network-object ric-dev-01_in 255.255.255.255 network-object nrc_in 255.255.255.255 network-object ricvm01-new-in 255.255.255.255 object-group service DNS tcp-udp port-object eq domain object-group service Moon tcp port-object eq www port-object eq ssh port-object eq https object-group service ns1-web tcp-udp description D group-object DNS port-object eq www object-group service web tcp port-object eq www port-object eq https object-group network DNS-IN network-object ric-ns-01_in 255.255.255.255 network-object moon-in 255.255.255.255 object-group network DNS-IN_ref network-object ric-ns-01_out 255.255.255.255 network-object moon-out 255.255.255.255 object-group service ldapauth tcp port-object range ldap ldap object-group service ALTSMTP1 tcp-udp port-object range 587 587 object-group network PerAdmn-in_ref_1 network-object ric-mx-01_out 255.255.255.255 network-object ric-mst-01_out 255.255.255.255 network-object ric-mx-02_out 255.255.255.255 network-object ric-ns-01_out 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object moon-out 255.255.255.255 network-object ric-mst-02_out 255.255.255.255 network-object ric-crm-01_out 255.255.255.255 network-object ric-im-01_out 255.255.255.255 network-object postoffice_out 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 network-object 66.101.xxx.xxx 255.255.255.255 access-list domain_splitTunnelAcl permit ip any any access-list inside_outbound_nat0_acl permit ip any 172.16.25.0 255.255.255.240 access-list outside_cryptomap_dyn_20 permit ip any 172.16.25.0 255.255.255.240 access-list outside_access_in deny tcp host zimbradenyjason host ric-mst-01_out access-list outside_access_in deny tcp host zclicentfailure host ric-mst-01_out access-list outside_access_in permit tcp any host ric-mst-01_out object-group ZimbraServices access-list outside_access_in permit tcp any host ric-mx-01_out object-group ZimbraServices access-list outside_access_in permit tcp any host ric-mx-02_out object-group ZimbraServices access-list outside_access_in permit udp any object-group DNS-IN_ref object-group DNS access-list outside_access_in permit tcp object-group PercAdmin object-group PerAdmn-in_ref_1 access-list outside_access_in permit icmp object-group PercAdmin object-group PerAdmn-in_ref_1 access-list outside_access_in permit tcp any host ric-ns-01_out object-group web access-list outside_access_in permit tcp any object-group DNS-IN_ref object-group DNS access-list outside_access_in permit tcp any host ric-mst-02_out object-group ZimbraServices access-list outside_access_in permit tcp any host postoffice_out object-group ZimbraServices access-list outside_access_in permit tcp any host ric-crm-01_out object-group web access-list outside_access_in permit tcp any host ric-im-01_out access-list outside_access_in permit tcp host tenacity_IM host postoffice_out object-group ldapauth access-list outside_access_in permit tcp any host 66.101.xxx.xxx object-group ZimbraServices access-list outside_access_in permit tcp any host 66.101.xxx.xxx eq 7993 access-list outside_access_in permit tcp any host 66.101.xxx.xxx eq 587 access-list domain_splitTunnelAcl_1 permit ip any any access-list outside_cryptomap_dyn_20_1 permit ip any 172.16.25.0 255.255.255.240 pager lines 24 logging on logging trap warnings logging host inside ric-ns-01_in icmp permit host 70.169.xxx.xxx outside icmp permit host 70.169.xxx.xxx outside mtu outside 1500 mtu inside 1500 ip address outside 66.101.xxx.xxx 255.255.255.248 ip address inside 172.16.20.1 255.255.255.0 ip audit info action alarm ip audit attack action alarm ip local pool domain-admin 172.16.25.5-172.16.25.15 pdm location ric-ns-01_out 255.255.255.255 outside pdm location 70.169.xxx.xxx 255.255.255.255 outside pdm location 70.169.xxx.xxx 255.255.255.255 outside pdm location ric-ns-01_in 255.255.255.255 inside pdm location ric-mx-01_in 255.255.255.255 inside pdm location ric-mx-02_in 255.255.255.255 inside pdm location ric-mst-01_in 255.255.255.255 inside pdm location ric-mx-01_out 255.255.255.255 outside pdm location ric-mx-02_out 255.255.255.255 outside pdm location ric-mst-01_out 255.255.255.255 outside pdm location pluto_out 255.255.255.255 outside pdm location mx01-ilo 255.255.255.255 inside pdm location mx2-ilo 255.255.255.255 inside pdm location ric-mst-01-ilo 255.255.255.255 inside pdm location ns3_ilo 255.255.255.255 inside pdm location moon-in 255.255.255.255 inside pdm location 10.0.1.0 255.255.255.0 outside pdm location widomaker_out 255.255.255.255 outside pdm location per02-out 255.255.255.255 outside pdm location ric-mst-02_in 255.255.255.255 inside pdm location ric-crm-01_in 255.255.255.255 inside pdm location ric-im-01_in 255.255.255.255 inside pdm location postoffice_in 255.255.255.255 inside pdm location moon-out 255.255.255.255 outside pdm location ric-mst-02_out 255.255.255.255 outside pdm location ric-crm-01_out 255.255.255.255 outside pdm location ric-im-01_out 255.255.255.255 outside pdm location postoffice_out 255.255.255.255 outside pdm location zimbra-perc-out 255.255.255.255 outside pdm location tenacity_IM 255.255.255.255 outside pdm location bryan_zimbra 255.255.255.255 outside pdm location zclicentfailure 255.255.255.255 outside pdm location zimbradenyjason 255.255.255.255 outside pdm location nrc_in 255.255.255.255 inside pdm location readynas_in 255.255.255.255 inside pdm location 172.16.25.0 255.255.255.240 outside pdm location ric-dev-01_in 255.255.255.255 inside pdm location ricvm01-new-in 255.255.255.255 inside pdm location 8.7.xxx.xxx 255.255.255.255 outside pdm group PercAdmin outside pdm group PerAdmn-in inside pdm group DNS-IN inside pdm group DNS-IN_ref outside reference DNS-IN pdm group PerAdmn-in_ref_1 outside reference PerAdmn-in pdm logging informational 100 pdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 0 access-list inside_outbound_nat0_acl nat (inside) 1 0.0.0.0 0.0.0.0 0 0 static (inside,outside) ric-ns-01_out ric-ns-01_in netmask 255.255.255.255 0 0 static (inside,outside) ric-mx-01_out ric-mx-01_in netmask 255.255.255.255 0 0 static (inside,outside) ric-mx-02_out ric-mx-02_in netmask 255.255.255.255 0 0 static (inside,outside) ric-mst-01_out ric-mst-01_in netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx mx01-ilo netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx mx2-ilo netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx ric-mst-01-ilo netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx ns3_ilo netmask 255.255.255.255 0 0 static (inside,outside) moon-out moon-in netmask 255.255.255.255 0 0 static (inside,outside) ric-mst-02_out ric-mst-02_in netmask 255.255.255.255 0 0 static (inside,outside) ric-crm-01_out ric-crm-01_in netmask 255.255.255.255 0 0 static (inside,outside) ric-im-01_out ric-im-01_in netmask 255.255.255.255 0 0 static (inside,outside) postoffice_out postoffice_in netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx nrc_in netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx readynas_in netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx ric-dev-01_in netmask 255.255.255.255 0 0 static (inside,outside) 66.101.xxx.xxx ricvm01-new-in netmask 255.255.255.255 0 0 access-group outside_access_in in interface outside route outside 0.0.0.0 0.0.0.0 66.101.xxx.xxx 1 timeout xlate 0:05:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout sip-disconnect 0:02:00 sip-invite 0:03:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server TACACS+ max-failed-attempts 3 aaa-server TACACS+ deadtime 10 aaa-server RADIUS protocol radius aaa-server RADIUS max-failed-attempts 3 aaa-server RADIUS deadtime 10 aaa-server LOCAL protocol local aaa authentication ssh console LOCAL ntp server 17.254.0.28 source outside ntp server 17.254.0.31 source outside http server enable http 70.169.xxx.xxx 255.255.255.255 outside http 70.169.xxx.xxx 255.255.255.255 outside http 172.16.20.0 255.255.255.0 inside snmp-server host inside moon-in snmp-server location XXXXXXXXX snmp-server contact XXXXXXXXXXXX snmp-server community domain no snmp-server enable traps floodguard enable sysopt connection permit-ipsec crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac crypto ipsec transform-set sha-set esp-des esp-sha-hmac crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20 crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5 crypto dynamic-map outside_dyn_map_1 20 match address outside_cryptomap_dyn_20_1 crypto dynamic-map outside_dyn_map_1 20 set transform-set ESP-3DES-MD5 crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map crypto map outside_map client authentication LOCAL crypto map outside_map_1 65535 ipsec-isakmp dynamic outside_dyn_map_1 crypto map outside_map_1 client authentication LOCAL crypto map outside_map_1 interface outside isakmp enable outside isakmp identity address isakmp policy 20 authentication pre-share isakmp policy 20 encryption 3des isakmp policy 20 hash md5 isakmp policy 20 group 2 isakmp policy 20 lifetime 86400 vpngroup domain address-pool domain-admin vpngroup domain dns-server 8.7.xxx.xxx 8.7.xxx.xxx vpngroup domain default-domain domain.com vpngroup domain split-tunnel domain_splitTunnelAcl_1 vpngroup domain idle-time 1800 vpngroup domain password ******** telnet timeout 5 ssh 70.169.xxx.xxx 255.255.255.255 outside ssh 70.169.xxx.xxx 255.255.255.255 outside ssh 8.7.xxx.xxx 255.255.255.255 outside ssh 172.16.20.0 255.255.255.0 inside ssh timeout 5 console timeout 0 dhcpd address 172.16.20.220-172.16.20.235 inside dhcpd dns 8.7.xxx.xxx 8.7.xxx.xxx dhcpd lease 3600 dhcpd ping_timeout 750 dhcpd domain domain.com dhcpd auto_config outside dhcpd enable inside username gsmith password ***************** encrypted privilege 15 terminal width 80 Cryptochecksum:e189f20d8f07a082eabdcc77b31f497d