<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Confused with this ASA - VPN config issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013291#M438277</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network VPNPOOL&lt;/P&gt;&lt;P&gt;network-object 192.168.238.0&amp;nbsp; 255.255.255.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;//below command is to allow vpn devices to inside network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public_Internet,Private_ODATA) source static VPNPOOL VPNPOOL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;//below command is to allow vpn devices to access internet&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public_Internet,Public_Internet) source dynamic VPNPOOL interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;let me know how this goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Sep 2012 20:32:07 GMT</pubDate>
    <dc:creator>Harish Balakrishnan</dc:creator>
    <dc:date>2012-09-25T20:32:07Z</dc:date>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013288#M438272</link>
      <description>&lt;P&gt;Hello. Can anyone help me here? I am new to the ASA config and commands. Everything works well, enough, on this ASA except the VPN. A client can connect but cannot access anything inside or outside. Here is the config. Can someone please take a look and tell me why VPN is not working? I don't want to set up split-tunneling, I would prefer everything to go through the firewall. Also, if you see something else wrong (or have a better implementation) then please let me know.&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;BR /&gt;!&lt;BR /&gt;hostname FIREWALL_NAME&lt;BR /&gt;enable password Some_X's_here encrypted&lt;BR /&gt;passwd Some_X's_here encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0.22&lt;BR /&gt;description Public Internet space via VLAN 22&lt;BR /&gt;vlan 22&lt;BR /&gt;nameif Public_Internet&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 1.3.3.7 255.255.255.248 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1.42&lt;BR /&gt;description Private LAN space via VLAN 42&lt;BR /&gt;shutdown&lt;BR /&gt;vlan 42&lt;BR /&gt;nameif Private_CDATA&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.30.136.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1.69&lt;BR /&gt;description Private LAN space via VLAN 69&lt;BR /&gt;vlan 69&lt;BR /&gt;nameif Private_ODATA&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.30.133.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1.95&lt;BR /&gt;description Private LAN space via VLAN 95&lt;BR /&gt;shutdown&lt;BR /&gt;vlan 95&lt;BR /&gt;nameif Private_OVOICE&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.102.254 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1.96&lt;BR /&gt;description Private LAN space via VLAN 96&lt;BR /&gt;shutdown&lt;BR /&gt;vlan 96&lt;BR /&gt;nameif Private_CVOICE&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.91.254 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1.3610&lt;BR /&gt;description Private LAN subnet via VLAN 3610&lt;BR /&gt;shutdown&lt;BR /&gt;vlan 3610&lt;BR /&gt;nameif Private_CeDATA&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.100.18 255.255.255.240 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1.3611&lt;BR /&gt;description Private LAN space via VLAN 3611&lt;BR /&gt;shutdown&lt;BR /&gt;vlan 3611&lt;BR /&gt;nameif Private_CeVOICE&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.100.66 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;security-level 0&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.69.1 255.255.255.0 &lt;BR /&gt;management-only&lt;BR /&gt;!&lt;BR /&gt;banner exec WARNING!! Access to this device is restricted to those individuals with specific permissions. If you are not an authorized user, disconnect now. Any attempts to gain unauthorized access will be prosecuted to the fullest &lt;/P&gt;&lt;P&gt;extent of the law.&lt;BR /&gt;banner exec&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .';&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .-'` .'&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,`.-'-.`\&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ; /&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '-'&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | \&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,-,&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&amp;nbsp; '-.__&amp;nbsp;&amp;nbsp; )_`'._&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \|/&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ```&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ``'--._[]--------------*&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .-' ,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; `'-.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /|\&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '-'`-._&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ((&amp;nbsp;&amp;nbsp; o&amp;nbsp;&amp;nbsp; )&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; `'--....(`- ,__..--'&lt;BR /&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '-'`&lt;BR /&gt;banner exec&lt;BR /&gt;banner exec frickin' sharks with frickin' laser beams attached to their frickin' heads&lt;BR /&gt;banner login WARNING!! Access to this device is restricted to those individuals with specific permissions. If you are not an authorized user, disconnect now. Any attempts to gain unauthorized access will be prosecuted to the fullest &lt;/P&gt;&lt;P&gt;extent of the law.&lt;BR /&gt;banner asdm WARNING!! Access to this device is restricted to those individuals with specific permissions. If you are not an authorized user, disconnect now. Any attempts to gain unauthorized access will be prosecuted to the fullest &lt;/P&gt;&lt;P&gt;extent of the law.&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network CD_3610-GW&lt;BR /&gt;host 10.10.100.17&lt;BR /&gt;description First hop to 3610&lt;BR /&gt;object network CV_3611-GW&lt;BR /&gt;host 10.10.100.65&lt;BR /&gt;description First hop to 3611&lt;BR /&gt;object network GW_22-EXT&lt;BR /&gt;host 1.3.3.6&lt;BR /&gt;description First hop to 22&lt;BR /&gt;object service MS-RDC&lt;BR /&gt;service tcp source range 1024 65535 destination eq 3389 &lt;BR /&gt;description Microsoft Remote Desktop Connection&lt;BR /&gt;object network HDC-LAN&lt;BR /&gt;subnet 192.168.200.0 255.255.255.0&lt;BR /&gt;description DC LAN subnet&lt;BR /&gt;object network HAM-LAN&lt;BR /&gt;subnet 192.168.110.0 255.255.255.0&lt;BR /&gt;description HAM LAN subnet&lt;BR /&gt;object service MSN&lt;BR /&gt;service tcp source range 1 65535 destination eq 1863 &lt;BR /&gt;description MSN Messenger&lt;BR /&gt;object network BCCs&lt;BR /&gt;host 2.1.8.1&lt;BR /&gt;description BCCs server access&lt;BR /&gt;object network ODLW-EXT&lt;BR /&gt;host 7.1.1.5&lt;BR /&gt;description OTTDl&lt;BR /&gt;object network SWINDS-INT&lt;BR /&gt;host 10.30.133.67&lt;BR /&gt;description SWINDS server&lt;BR /&gt;object network SWINDS(192.x.x.x)-INT&lt;BR /&gt;host 192.168.100.67&lt;BR /&gt;description SWINDS server&lt;BR /&gt;object service YMSG&lt;BR /&gt;service tcp source range 1 65535 destination eq 5050 &lt;BR /&gt;description Yahoo Messenger&lt;BR /&gt;object service c.b.ca1&lt;BR /&gt;service tcp source range 1 65535 destination eq citrix-ica &lt;BR /&gt;description Connections to the bc portal.&lt;BR /&gt;object service c.b.ca2&lt;BR /&gt;service tcp source range 1 65535 destination eq 2598 &lt;BR /&gt;description Connections to the bc portal.&lt;BR /&gt;object service HTTP-EXT(7001)&lt;BR /&gt;service tcp source range 1 65535 destination eq 7001 &lt;BR /&gt;description HTTP Extended on port 7001.&lt;BR /&gt;object service HTTP-EXT(8000-8001)&lt;BR /&gt;service tcp source range 1 65535 destination range 8000 8001 &lt;BR /&gt;description HTTP Extended on ports 8000-8001.&lt;BR /&gt;object service HTTP-EXT(8080-8081)&lt;BR /&gt;service tcp source range 1 65535 destination range 8080 8081 &lt;BR /&gt;description HTTP Extended on ports 8080-8081.&lt;BR /&gt;object service HTTP-EXT(8100)&lt;BR /&gt;service tcp source range 1 65535 destination eq 8100 &lt;BR /&gt;description HTTP Extended on port 8100.&lt;BR /&gt;object service HTTP-EXT(8200)&lt;BR /&gt;service tcp source range 1 65535 destination eq 8200 &lt;BR /&gt;description HTTP Extended on port 8200.&lt;BR /&gt;object service HTTP-EXT(8888)&lt;BR /&gt;service tcp source range 1 65535 destination eq 8888 &lt;BR /&gt;description HTTP Extended on port 8888.&lt;BR /&gt;object service HTTP-EXT(9080)&lt;BR /&gt;service tcp source range 1 65535 destination eq 9080 &lt;BR /&gt;description HTTP Extended on port 9080.&lt;BR /&gt;object service ntp&lt;BR /&gt;service tcp source range 1 65535 destination eq 123 &lt;BR /&gt;description TCP NTP on port 123.&lt;BR /&gt;object network Pl-EXT&lt;BR /&gt;host 7.1.1.2&lt;BR /&gt;description OPl box.&lt;BR /&gt;object service Pl-Admin&lt;BR /&gt;service tcp source range 1 65535 destination eq 8443 &lt;BR /&gt;description Pl Admin portal&lt;BR /&gt;object network FW-EXT&lt;BR /&gt;host 1.3.3.7&lt;BR /&gt;description External/Public interface IP address of firewall.&lt;BR /&gt;object network Rs-EXT&lt;BR /&gt;host 7.1.1.8&lt;BR /&gt;description Rs web portal External/Public IP.&lt;BR /&gt;object network DWDM-EXT&lt;BR /&gt;host 2.1.2.1&lt;BR /&gt;description DWDM.&lt;BR /&gt;object network HM_VPN-EXT&lt;BR /&gt;host 6.2.9.7&lt;BR /&gt;description HAM Man.&lt;BR /&gt;object network SIM_MGMT&lt;BR /&gt;host 2.1.1.1&lt;BR /&gt;description SIM Man.&lt;BR /&gt;object network TS_MGMT&lt;BR /&gt;host 2.1.1.4&lt;BR /&gt;description TS Man.&lt;BR /&gt;object network TS_MGMT&lt;BR /&gt;host 2.1.2.2&lt;BR /&gt;description TS Man.&lt;BR /&gt;object service VPN-TCP(1723)&lt;BR /&gt;service tcp source range 1 65535 destination eq pptp &lt;BR /&gt;description For PPTP control path.&lt;BR /&gt;object service VPN-UDP(4500)&lt;BR /&gt;service udp source range 1 65535 destination eq 4500 &lt;BR /&gt;description For L2TP(IKEv1) and IKEv2.&lt;BR /&gt;object service VPN-TCP(443)&lt;BR /&gt;service tcp source range 1 65535 destination eq https &lt;BR /&gt;description For SSTP control and data path.&lt;BR /&gt;object service VPN-UDP(500)&lt;BR /&gt;service udp source range 1 65535 destination eq isakmp &lt;BR /&gt;description For L2TP(IKEv1) and IKEv2.&lt;BR /&gt;object network RCM&lt;BR /&gt;host 6.1.8.2&lt;BR /&gt;description RCM&lt;BR /&gt;object network RCM_Y&lt;BR /&gt;host 6.1.8.9&lt;BR /&gt;description RCM Y&lt;BR /&gt;object network r.r.r.c163&lt;BR /&gt;host 2.1.2.63&lt;BR /&gt;description RCV IP.&lt;BR /&gt;object network r.r.r.c227&lt;BR /&gt;host 2.1.2.27&lt;BR /&gt;description RCV IP.&lt;BR /&gt;object network v.t.c-EXT&lt;BR /&gt;host 2.5.1.2&lt;BR /&gt;description RTICR&lt;BR /&gt;object service VPN-TCP(10000)&lt;BR /&gt;service tcp source range 1 65535 destination eq 10000 &lt;BR /&gt;description For TCP VPN over port 1000.&lt;BR /&gt;object service BGP-JY&lt;BR /&gt;service tcp source range 1 65535 destination eq 21174 &lt;BR /&gt;description BPG&lt;BR /&gt;object network KooL&lt;BR /&gt;host 192.168.100.100&lt;BR /&gt;description KooL&lt;BR /&gt;object network FW_Test&lt;BR /&gt;host 1.3.3.7&lt;BR /&gt;description Testing other External IP&lt;BR /&gt;object network AO_10-30-133-0-LAN&lt;BR /&gt;range 10.30.133.0 10.30.133.229&lt;BR /&gt;description OLS 10.30.133.0/24&lt;BR /&gt;object network AC_10-30-136-0-LAN&lt;BR /&gt;subnet 10.30.136.0 255.255.255.0&lt;BR /&gt;description CLS 10.30.136.0/24&lt;BR /&gt;object network NETWORK_OBJ_192.168.238.0_27&lt;BR /&gt;subnet 192.168.238.0 255.255.255.224&lt;BR /&gt;object-group network All_Private_Interfaces&lt;BR /&gt;description All private interfaces&lt;BR /&gt;network-object 10.30.133.0 255.255.255.0&lt;BR /&gt;network-object 10.30.136.0 255.255.255.0&lt;BR /&gt;network-object 10.10.100.16 255.255.255.240&lt;BR /&gt;network-object 10.10.100.64 255.255.255.252&lt;BR /&gt;network-object 192.168.102.0 255.255.255.0&lt;BR /&gt;network-object 192.168.91.0 255.255.255.0&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt;protocol-object udp&lt;BR /&gt;protocol-object tcp&lt;BR /&gt;object-group service cb.ca&lt;BR /&gt;description All ports required for cb.ca connections.&lt;BR /&gt;service-object object c.b.ca1 &lt;BR /&gt;service-object object c.b.ca2 &lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt;service-object tcp destination eq https &lt;BR /&gt;service-object udp destination eq snmp &lt;BR /&gt;object-group service FTP&lt;BR /&gt;description All FTP ports (20 + 21)&lt;BR /&gt;service-object tcp destination eq ftp &lt;BR /&gt;service-object tcp destination eq ftp-data &lt;BR /&gt;object-group service HTTP-EXT&lt;BR /&gt;description HTTP Extended port ranges.&lt;BR /&gt;service-object object HTTP-EXT(7001) &lt;BR /&gt;service-object object HTTP-EXT(8000-8001) &lt;BR /&gt;service-object object HTTP-EXT(8080-8081) &lt;BR /&gt;service-object object HTTP-EXT(8100) &lt;BR /&gt;service-object object HTTP-EXT(8200) &lt;BR /&gt;service-object object HTTP-EXT(8888) &lt;BR /&gt;service-object object HTTP-EXT(9080) &lt;BR /&gt;object-group service ICMP_Any&lt;BR /&gt;description ICMP: Any Type, Any Code&lt;BR /&gt;service-object icmp alternate-address&lt;BR /&gt;service-object icmp conversion-error&lt;BR /&gt;service-object icmp echo&lt;BR /&gt;service-object icmp echo-reply&lt;BR /&gt;service-object icmp information-reply&lt;BR /&gt;service-object icmp information-request&lt;BR /&gt;service-object icmp mask-reply&lt;BR /&gt;service-object icmp mask-request&lt;BR /&gt;service-object icmp mobile-redirect&lt;BR /&gt;service-object icmp parameter-problem&lt;BR /&gt;service-object icmp redirect&lt;BR /&gt;service-object icmp router-advertisement&lt;BR /&gt;service-object icmp router-solicitation&lt;BR /&gt;service-object icmp source-quench&lt;BR /&gt;service-object icmp time-exceeded&lt;BR /&gt;service-object icmp timestamp-reply&lt;BR /&gt;service-object icmp timestamp-request&lt;BR /&gt;service-object icmp traceroute&lt;BR /&gt;service-object icmp unreachable&lt;BR /&gt;service-object icmp6 echo&lt;BR /&gt;service-object icmp6 echo-reply&lt;BR /&gt;service-object icmp6 membership-query&lt;BR /&gt;service-object icmp6 membership-reduction&lt;BR /&gt;service-object icmp6 membership-report&lt;BR /&gt;service-object icmp6 neighbor-advertisement&lt;BR /&gt;service-object icmp6 neighbor-redirect&lt;BR /&gt;service-object icmp6 neighbor-solicitation&lt;BR /&gt;service-object icmp6 packet-too-big&lt;BR /&gt;service-object icmp6 parameter-problem&lt;BR /&gt;service-object icmp6 router-advertisement&lt;BR /&gt;service-object icmp6 router-renumbering&lt;BR /&gt;service-object icmp6 router-solicitation&lt;BR /&gt;service-object icmp6 time-exceeded&lt;BR /&gt;service-object icmp6 unreachable&lt;BR /&gt;service-object icmp &lt;BR /&gt;object-group service NTP&lt;BR /&gt;description TCP and UPD NTP protocol&lt;BR /&gt;service-object object ntp &lt;BR /&gt;service-object udp destination eq ntp &lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt;group-object FTP&lt;BR /&gt;group-object HTTP-EXT&lt;BR /&gt;group-object ICMP_Any&lt;BR /&gt;group-object NTP&lt;BR /&gt;service-object tcp-udp destination eq domain &lt;BR /&gt;service-object tcp-udp destination eq www &lt;BR /&gt;service-object tcp destination eq https &lt;BR /&gt;service-object tcp destination eq ssh &lt;BR /&gt;service-object ip &lt;BR /&gt;object-group service DM_INLINE_SERVICE_4&lt;BR /&gt;group-object NTP&lt;BR /&gt;service-object tcp destination eq daytime &lt;BR /&gt;object-group network SWINDS&lt;BR /&gt;description Both Internal IP addresses (192 + 10)&lt;BR /&gt;network-object object SWINDS-INT&lt;BR /&gt;network-object object SWINDS(192.x.x.x)-INT&lt;BR /&gt;object-group service IM_Types&lt;BR /&gt;description All messenger type applications&lt;BR /&gt;service-object object MSN &lt;BR /&gt;service-object object YMSG &lt;BR /&gt;service-object tcp-udp destination eq talk &lt;BR /&gt;service-object tcp destination eq aol &lt;BR /&gt;service-object tcp destination eq irc &lt;BR /&gt;object-group service SNMP&lt;BR /&gt;description Both poll and trap ports.&lt;BR /&gt;service-object udp destination eq snmp &lt;BR /&gt;service-object udp destination eq snmptrap &lt;BR /&gt;object-group service DM_INLINE_SERVICE_2&lt;BR /&gt;group-object FTP&lt;BR /&gt;service-object object MS-RDC &lt;BR /&gt;service-object object Pl-Admin &lt;BR /&gt;group-object SNMP&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;network-object object FW-EXT&lt;BR /&gt;network-object object Rs-EXT&lt;BR /&gt;object-group network AMV&lt;BR /&gt;description connections for legacy AM&lt;BR /&gt;network-object object DWDM-EXT&lt;BR /&gt;network-object object HAM_MGMT&lt;BR /&gt;network-object object SIM_MGMT&lt;BR /&gt;network-object object TS_MGMT&lt;BR /&gt;network-object object TS_MGMT&lt;BR /&gt;object-group service IKEv2_L2TP&lt;BR /&gt;description IKEv2 and L2TP VPN configurations&lt;BR /&gt;service-object esp &lt;BR /&gt;service-object object VPN-UDP(4500) &lt;BR /&gt;service-object object VPN-UDP(500) &lt;BR /&gt;object-group service PPTP&lt;BR /&gt;description PPTP VPN configuration&lt;BR /&gt;service-object gre &lt;BR /&gt;service-object object VPN-TCP(1723) &lt;BR /&gt;object-group service SSTP&lt;BR /&gt;description SSTP VPN configuration&lt;BR /&gt;service-object object VPN-TCP(443) &lt;BR /&gt;object-group network RvIPs&lt;BR /&gt;description Rv IP addresses&lt;BR /&gt;network-object object RCM&lt;BR /&gt;network-object object RCM_Y&lt;BR /&gt;network-object object r.r.r.c163&lt;BR /&gt;network-object object r.r.r.c227&lt;BR /&gt;network-object object v.t.c-EXT&lt;BR /&gt;object-group service Rvs&lt;BR /&gt;description Rv configuration.&lt;BR /&gt;service-object object VPN-TCP(10000) &lt;BR /&gt;service-object object VPN-UDP(500) &lt;BR /&gt;object-group service DM_INLINE_SERVICE_5&lt;BR /&gt;service-object object BGP-JY &lt;BR /&gt;service-object tcp destination eq bgp &lt;BR /&gt;object-group network Local_Private_Subnets&lt;BR /&gt;description OandCl DATA&lt;BR /&gt;network-object 10.30.133.0 255.255.255.0&lt;BR /&gt;network-object 10.30.136.0 255.255.255.0&lt;BR /&gt;access-list Public/Internet_access_out remark Block all IM traffic out.&lt;BR /&gt;access-list Public/Internet_access_out extended deny object-group IM_Types object-group Local_Private_Subnets any &lt;BR /&gt;access-list Public/Internet_access_out remark Access from SWINDS to DLM portal&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_1 object-group SWINDS object ODLW-EXT &lt;BR /&gt;access-list Public/Internet_access_out remark Allow access to BMC portal&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group cb.ca object-group Local_Private_Subnets object BCCs &lt;BR /&gt;access-list Public/Internet_access_out remark Allow basic services out.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_3 object-group Local_Private_Subnets any &lt;BR /&gt;access-list Public/Internet_access_out remark Allow WhoIS traffic out.&lt;BR /&gt;access-list Public/Internet_access_out extended permit tcp object-group Local_Private_Subnets any eq whois &lt;BR /&gt;access-list Public/Internet_access_out remark Allow Network Time protocols out.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_4 object-group Local_Private_Subnets any &lt;BR /&gt;access-list Public/Internet_access_out remark Allow all IP based monitoring traffic to Pl.&lt;BR /&gt;access-list Public/Internet_access_out extended permit ip object-group SWINDS object Pl-EXT &lt;BR /&gt;access-list Public/Internet_access_out remark Allow Management traffic to Pl-JY.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_2 object-group Local_Private_Subnets object Pl-EXT &lt;BR /&gt;access-list Public/Internet_access_out remark Allow FTP traffic to Grimlock and RS FTP.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group FTP object-group Local_Private_Subnets object-group DM_INLINE_NETWORK_1 &lt;BR /&gt;access-list Public/Internet_access_out remark Allow VPN traffic to AM-JY.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group IKEv2_L2TP object-group Local_Private_Subnets object-group AMV &lt;BR /&gt;access-list Public/Internet_access_out remark Allow VPN traffic to RCm devices.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group Rvs object-group Local_Private_Subnets object-group RvIPs &lt;BR /&gt;access-list Public/Internet_access_out remark Allow BPG traffic out.&lt;BR /&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_5 object-group Local_Private_Subnets any &lt;BR /&gt;access-list Public/Internet_access_out remark Allow Kool server out.&lt;BR /&gt;access-list Public/Internet_access_out extended permit ip object KooL any &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging history informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging mail notifications&lt;BR /&gt;logging from-address &lt;A href="mailto:thisemail@address.local" target="_blank"&gt;thisemail@address.local&lt;/A&gt;&lt;BR /&gt;logging recipient-address &lt;A href="mailto:sendhere@address.com" target="_blank"&gt;sendhere@address.com&lt;/A&gt; level errors&lt;BR /&gt;mtu Public_Internet 1500&lt;BR /&gt;mtu Private_CDATA 1500&lt;BR /&gt;mtu Private_ODATA 1500&lt;BR /&gt;mtu Private_OVOICE 1500&lt;BR /&gt;mtu Private_CVOICE 1500&lt;BR /&gt;mtu Private_CeDATA 1500&lt;BR /&gt;mtu Private_CeVOICE 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;ip local pool AO-VPN_Pool 192.168.238.2-192.168.238.30 mask 255.255.255.224&lt;BR /&gt;ip verify reverse-path interface Public_Internet&lt;BR /&gt;ip verify reverse-path interface Private_CDATA&lt;BR /&gt;ip verify reverse-path interface Private_ODATA&lt;BR /&gt;ip verify reverse-path interface Private_OVOICE&lt;BR /&gt;ip verify reverse-path interface Private_CVOICE&lt;BR /&gt;ip verify reverse-path interface Private_CeDATA&lt;BR /&gt;ip verify reverse-path interface Private_CeVOICE&lt;BR /&gt;ip verify reverse-path interface management&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp deny any Public_Internet&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (Private_ODATA,Public_Internet) source dynamic AO_10-30-133-0-LAN interface&lt;BR /&gt;nat (Private_CDATA,Public_Internet) source dynamic AC_10-30-136-0-LAN interface&lt;BR /&gt;nat (Private_ODATA,Public_Internet) source static any any destination static NETWORK_OBJ_192.168.238.0_27 NETWORK_OBJ_192.168.238.0_27 no-proxy-arp route-lookup&lt;BR /&gt;access-group Public/Internet_access_out out interface Public_Internet&lt;BR /&gt;route Public_Internet 0.0.0.0 0.0.0.0 1.3.3.6 1&lt;BR /&gt;route Private_CeDATA 10.0.0.0 255.0.0.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.1.0.0 255.255.0.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.3.0.0 255.255.0.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.5.0.0 255.255.0.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.11.106.74 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.30.128.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.30.130.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.30.131.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.30.132.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.30.134.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.30.135.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.67.31.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 10.224.0.0 255.255.0.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 4.1.1.19 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 1.1.1.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 1.1.1.13 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.11.24 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.11.27 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.17.105 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.147.64 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.147.66 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.147.110 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.19.251.57 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.21.56.105 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 172.21.57.152 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 192.168.3.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeVOICE 192.168.9.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeDATA 192.168.20.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeVOICE 192.168.21.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeDATA 192.168.30.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 192.168.31.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 192.168.40.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeVOICE 192.168.41.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeVOICE 192.168.50.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeDATA 192.168.60.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeVOICE 192.168.61.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeVOICE 192.168.70.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeVOICE 192.168.101.0 255.255.255.0 10.10.100.65 1&lt;BR /&gt;route Private_CeDATA 192.168.110.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 192.168.200.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 192.251.177.0 255.255.255.0 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 2.1.2.7 255.255.255.255 10.10.100.17 1&lt;BR /&gt;route Private_CeDATA 2.1.2.74 255.255.255.255 10.10.100.17 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa-server AD protocol nt&lt;BR /&gt;aaa-server AD (Private_ODATA) host 10.30.133.21&lt;BR /&gt;timeout 5&lt;BR /&gt;nt-auth-domain-controller Cool_Transformer_Name&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;aaa authentication telnet console LOCAL &lt;BR /&gt;aaa authentication serial console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.69.0 255.255.255.0 management&lt;BR /&gt;snmp-server host Private_ODATA 10.30.133.67 poll community Some_*s_here version 2c&lt;BR /&gt;snmp-server location OT&lt;BR /&gt;snmp-server contact &lt;A href="mailto:theseguys@address.com" target="_blank"&gt;theseguys@address.com&lt;/A&gt;&lt;BR /&gt;snmp-server community Some_*s_here&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;BR /&gt;snmp-server enable traps syslog&lt;BR /&gt;snmp-server enable traps ipsec start stop&lt;BR /&gt;snmp-server enable traps entity config-change fru-insert fru-remove&lt;BR /&gt;snmp-server enable traps memory-threshold&lt;BR /&gt;snmp-server enable traps interface-threshold&lt;BR /&gt;snmp-server enable traps remote-access session-threshold-exceeded&lt;BR /&gt;snmp-server enable traps connection-limit-reached&lt;BR /&gt;snmp-server enable traps cpu threshold rising&lt;BR /&gt;snmp-server enable traps ikev2 start stop&lt;BR /&gt;snmp-server enable traps nat packet-discard&lt;BR /&gt;sysopt noproxyarp Public_Internet&lt;BR /&gt;sysopt noproxyarp Private_CDATA&lt;BR /&gt;sysopt noproxyarp Private_ODATA&lt;BR /&gt;sysopt noproxyarp Private_OVOICE&lt;BR /&gt;sysopt noproxyarp Private_CVOICE&lt;BR /&gt;sysopt noproxyarp Private_CeDATA&lt;BR /&gt;sysopt noproxyarp Private_CeVOICE&lt;BR /&gt;sysopt noproxyarp management&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs &lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map Public_Internet_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map Public_Internet_map interface Public_Internet&lt;BR /&gt;crypto ikev1 enable Public_Internet&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;client-update enable&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 10.30.133.0 255.255.255.0 Private_ODATA&lt;BR /&gt;ssh 192.168.69.0 255.255.255.0 management&lt;BR /&gt;ssh timeout 2&lt;BR /&gt;ssh version 2&lt;BR /&gt;console timeout 5&lt;BR /&gt;dhcprelay server 10.30.133.13 Private_ODATA&lt;BR /&gt;dhcprelay enable Private_CDATA&lt;BR /&gt;dhcprelay timeout 60&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics&lt;BR /&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;BR /&gt;ntp server 10.30.133.13 prefer&lt;BR /&gt;ntp server 132.246.11.227&lt;BR /&gt;ntp server 10.30.133.21&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy AO-VPN_Tunnel internal&lt;BR /&gt;group-policy AO-VPN_Tunnel attributes&lt;BR /&gt;dns-server value 10.30.133.21 10.30.133.13&lt;BR /&gt;vpn-tunnel-protocol ikev1 &lt;BR /&gt;default-domain value ao.local&lt;BR /&gt;username helpme password Some_X's_here encrypted privilege 1&lt;BR /&gt;username helpme attributes&lt;BR /&gt;service-type nas-prompt&lt;BR /&gt;tunnel-group AO-VPN_Tunnel type remote-access&lt;BR /&gt;tunnel-group AO-VPN_Tunnel general-attributes&lt;BR /&gt;address-pool AO-VPN_Pool&lt;BR /&gt;authentication-server-group AD&lt;BR /&gt;default-group-policy AO-VPN_Tunnel&lt;BR /&gt;tunnel-group AO-VPN_Tunnel ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key Some_*s_here&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;class class-default&lt;BR /&gt;&amp;nbsp; user-statistics accounting&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;smtp-server 192.168.200.25&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013288#M438272</guid>
      <dc:creator>JBeach2007</dc:creator>
      <dc:date>2019-03-11T23:59:05Z</dc:date>
    </item>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013289#M438273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pretty long config &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;..&amp;nbsp; can you give the following and see whether the PC can access internet after connecting to VPN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public_Internet,Public_Internet) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know the results , then we will troubleshoot further&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 19:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013289#M438273</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-09-25T19:51:18Z</dc:date>
    </item>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013290#M438275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, it is a looooong read. When I try to enter that command into the CLI I get an error stating, "ERROR: % Invalid input detected at '^' marker."&amp;nbsp; The ^ marker is pointing under the start of the word "dynamic".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 20:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013290#M438275</guid>
      <dc:creator>JBeach2007</dc:creator>
      <dc:date>2012-09-25T20:19:46Z</dc:date>
    </item>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013291#M438277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network VPNPOOL&lt;/P&gt;&lt;P&gt;network-object 192.168.238.0&amp;nbsp; 255.255.255.224&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;//below command is to allow vpn devices to inside network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public_Internet,Private_ODATA) source static VPNPOOL VPNPOOL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;//below command is to allow vpn devices to access internet&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public_Internet,Public_Internet) source dynamic VPNPOOL interface&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;let me know how this goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 20:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013291#M438277</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-09-25T20:32:07Z</dc:date>
    </item>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013292#M438278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (Public_internet,Public_internet) 2 source dynamic&amp;nbsp; NETWORK_OBJ_192.168.238.0_27 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also with the configuration you have you should be able to access only the subnet behind the &lt;STRONG&gt;Private_ODATA interface that is &lt;/STRONG&gt;10.30.133.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any other question.. Sure.. Just remember to rate all of my answers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 00:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013292#M438278</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-26T00:12:35Z</dc:date>
    </item>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013293#M438279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried those commands but this started getting messy and so I looked at the current config and it was not the same as what I originally posted.&amp;nbsp; Looks like some changes were implemented but not saved so the config that I posted what slightly different.&amp;nbsp; Thank you for all your suggestions.&amp;nbsp; Here is the new config, confirmed as the current running and saved config.&amp;nbsp; Same situation as before though.&amp;nbsp; I can connect using the Cisco VPN client but can only ping myself and can't get out to the Internet or access anything internal.&amp;nbsp; If someone can take a look it would be greatly appreciated.&amp;nbsp; The main difference is the VPN pool has been set as a subset of the 10.30.133.0 network instead of using a separate subnet (VPN pool is 10.30.133.200 - 10.30.133.230).&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname FIREWALL_NAME&lt;/P&gt;&lt;P&gt;enable password Some_X's_here encrypted&lt;/P&gt;&lt;P&gt;passwd Some_X's_here encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;speed 100&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.22&lt;/P&gt;&lt;P&gt;description Public Internet space via VLAN 22&lt;/P&gt;&lt;P&gt;vlan 22&lt;/P&gt;&lt;P&gt;nameif Public_Internet&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 1.3.3.7 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;speed 100&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.42&lt;/P&gt;&lt;P&gt;description Private LAN space via VLAN 42&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;vlan 42&lt;/P&gt;&lt;P&gt;nameif Private_CDATA&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.30.136.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.69&lt;/P&gt;&lt;P&gt;description Private LAN space via VLAN 69&lt;/P&gt;&lt;P&gt;vlan 69&lt;/P&gt;&lt;P&gt;nameif Private_ODATA&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.30.133.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.95&lt;/P&gt;&lt;P&gt;description Private LAN space via VLAN 95&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;vlan 95&lt;/P&gt;&lt;P&gt;nameif Private_OVOICE&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.102.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.96&lt;/P&gt;&lt;P&gt;description Private LAN space via VLAN 96&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;vlan 96&lt;/P&gt;&lt;P&gt;nameif Private_CVOICE&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.91.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.3610&lt;/P&gt;&lt;P&gt;description Private LAN subnet via VLAN 3610&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;vlan 3610&lt;/P&gt;&lt;P&gt;nameif Private_CeDATA&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.10.100.18 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.3611&lt;/P&gt;&lt;P&gt;description Private LAN space via VLAN 3611&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;vlan 3611&lt;/P&gt;&lt;P&gt;nameif Private_CeVOICE&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.10.100.66 255.255.255.252 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;nameif management&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.69.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;banner exec WARNING!! Access to this device is restricted to those individuals with specific permissions. If you are not an authorized user, disconnect now. Any attempts to gain unauthorized access will be prosecuted to the fullest extent of the law.&lt;/P&gt;&lt;P&gt;banner exec &lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .';&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .-'` .'&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,`.-'-.`\&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ; /&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '-'&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | \&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,-,&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \&amp;nbsp; '-.__&amp;nbsp;&amp;nbsp; )_`'._&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; \|/&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ```&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ``'--._[]--------------*&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .-' ,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; `'-.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /|\ &lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '-'`-._&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ((&amp;nbsp;&amp;nbsp; o&amp;nbsp;&amp;nbsp; )&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; `'--....(`- ,__..--'&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; '-'`&lt;/P&gt;&lt;P&gt;banner exec &lt;/P&gt;&lt;P&gt;banner exec frickin' sharks with frickin' laser beams attached to their frickin' heads&lt;/P&gt;&lt;P&gt;banner login WARNING!! Access to this device is restricted to those individuals with specific permissions. If you are not an authorized user, disconnect now. Any attempts to gain unauthorized access will be prosecuted to the fullest extent of the law.&lt;/P&gt;&lt;P&gt;banner asdm WARNING!! Access to this device is restricted to those individuals with specific permissions. If you are not an authorized user, disconnect now. Any attempts to gain unauthorized access will be prosecuted to the fullest extent of the law.&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network CD_3610-GW&lt;/P&gt;&lt;P&gt;host 10.10.100.17&lt;/P&gt;&lt;P&gt;description First hop to 3610&lt;/P&gt;&lt;P&gt;object network CV_3611-GW&lt;/P&gt;&lt;P&gt;host 10.10.100.65&lt;/P&gt;&lt;P&gt;description First hop to 3611&lt;/P&gt;&lt;P&gt;object network GW_22-EXT&lt;/P&gt;&lt;P&gt;host 1.3.3.6&lt;/P&gt;&lt;P&gt;description First hop to 22&lt;/P&gt;&lt;P&gt;object network Ts-LAN&lt;/P&gt;&lt;P&gt;host 192.168.100.4&lt;/P&gt;&lt;P&gt;description TS&lt;/P&gt;&lt;P&gt;object service MS-RDC&lt;/P&gt;&lt;P&gt;service tcp source range 1024 65535 destination eq 3389 &lt;/P&gt;&lt;P&gt;description Microsoft Remote Desktop Connection&lt;/P&gt;&lt;P&gt;object network HDC-LAN&lt;/P&gt;&lt;P&gt;subnet 192.168.200.0 255.255.255.0&lt;/P&gt;&lt;P&gt;description DC LAN subnet&lt;/P&gt;&lt;P&gt;object network HAM-LAN&lt;/P&gt;&lt;P&gt;subnet 192.168.110.0 255.255.255.0&lt;/P&gt;&lt;P&gt;description HAM LAN subnet&lt;/P&gt;&lt;P&gt;object service MSN&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 1863 &lt;/P&gt;&lt;P&gt;description MSN Messenger&lt;/P&gt;&lt;P&gt;object network BCCs&lt;/P&gt;&lt;P&gt;host 2.1.8.1&lt;/P&gt;&lt;P&gt;description BCCs server access&lt;/P&gt;&lt;P&gt;object network ODLW-EXT&lt;/P&gt;&lt;P&gt;host 7.1.1.5&lt;/P&gt;&lt;P&gt;description OTTDl&lt;/P&gt;&lt;P&gt;object network SWINDS-INT&lt;/P&gt;&lt;P&gt;host 10.30.133.67&lt;/P&gt;&lt;P&gt;description SWINDS server&lt;/P&gt;&lt;P&gt;object network SWINDS(192.x.x.x)-INT&lt;/P&gt;&lt;P&gt;host 192.168.100.67&lt;/P&gt;&lt;P&gt;description SWINDS server&lt;/P&gt;&lt;P&gt;object service YMSG&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 5050 &lt;/P&gt;&lt;P&gt;description Yahoo Messenger&lt;/P&gt;&lt;P&gt;object service c.b.ca1&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq citrix-ica &lt;/P&gt;&lt;P&gt;description Connections to the bc portal.&lt;/P&gt;&lt;P&gt;object service c.b.ca2&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 2598 &lt;/P&gt;&lt;P&gt;description Connections to the bc portal.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(7001)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 7001 &lt;/P&gt;&lt;P&gt;description HTTP Extended on port 7001.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(8000-8001)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination range 8000 8001 &lt;/P&gt;&lt;P&gt;description HTTP Extended on ports 8000-8001.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(8080-8081)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination range 8080 8081 &lt;/P&gt;&lt;P&gt;description HTTP Extended on ports 8080-8081.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(8100)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 8100 &lt;/P&gt;&lt;P&gt;description HTTP Extended on port 8100.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(8200)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 8200 &lt;/P&gt;&lt;P&gt;description HTTP Extended on port 8200.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(8888)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 8888 &lt;/P&gt;&lt;P&gt;description HTTP Extended on port 8888.&lt;/P&gt;&lt;P&gt;object service HTTP-EXT(9080)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 9080 &lt;/P&gt;&lt;P&gt;description HTTP Extended on port 9080.&lt;/P&gt;&lt;P&gt;object service ntp&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 123 &lt;/P&gt;&lt;P&gt;description TCP NTP on port 123.&lt;/P&gt;&lt;P&gt;object network Pl-EXT&lt;/P&gt;&lt;P&gt;host 7.1.1.2&lt;/P&gt;&lt;P&gt;description OPl box.&lt;/P&gt;&lt;P&gt;object service Pl-Admin&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 8443 &lt;/P&gt;&lt;P&gt;description Pl Admin portal&lt;/P&gt;&lt;P&gt;object network FW-EXT&lt;/P&gt;&lt;P&gt;host 1.3.3.7&lt;/P&gt;&lt;P&gt;description External/Public interface IP address of firewall.&lt;/P&gt;&lt;P&gt;object network Rs-EXT&lt;/P&gt;&lt;P&gt;host 7.1.1.8&lt;/P&gt;&lt;P&gt;description Rs web portal External/Public IP.&lt;/P&gt;&lt;P&gt;object network DWDM-EXT&lt;/P&gt;&lt;P&gt;host 2.1.2.1&lt;/P&gt;&lt;P&gt;description DWDM.&lt;/P&gt;&lt;P&gt;object network HM_VPN-EXT&lt;/P&gt;&lt;P&gt;host 6.2.9.7&lt;/P&gt;&lt;P&gt;description HAM Man.&lt;/P&gt;&lt;P&gt;object network SIM_MGMT&lt;/P&gt;&lt;P&gt;host 2.1.1.1&lt;/P&gt;&lt;P&gt;description SIM Man.&lt;/P&gt;&lt;P&gt;object network TS_MGMT&lt;/P&gt;&lt;P&gt;host 2.1.1.4&lt;/P&gt;&lt;P&gt;description TS Man.&lt;/P&gt;&lt;P&gt;object network TS_MGMT&lt;/P&gt;&lt;P&gt;host 2.1.2.2&lt;/P&gt;&lt;P&gt;description TS Man.&lt;/P&gt;&lt;P&gt;object service VPN-TCP(1723)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq pptp &lt;/P&gt;&lt;P&gt;description For PPTP control path.&lt;/P&gt;&lt;P&gt;object service VPN-UDP(4500)&lt;/P&gt;&lt;P&gt;service udp source range 1 65535 destination eq 4500 &lt;/P&gt;&lt;P&gt;description For L2TP(IKEv1) and IKEv2.&lt;/P&gt;&lt;P&gt;object service VPN-TCP(443)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq https &lt;/P&gt;&lt;P&gt;description For SSTP control and data path.&lt;/P&gt;&lt;P&gt;object service VPN-UDP(500)&lt;/P&gt;&lt;P&gt;service udp source range 1 65535 destination eq isakmp &lt;/P&gt;&lt;P&gt;description For L2TP(IKEv1) and IKEv2.&lt;/P&gt;&lt;P&gt;object network RCM&lt;/P&gt;&lt;P&gt;host 6.1.8.2&lt;/P&gt;&lt;P&gt;description RCM&lt;/P&gt;&lt;P&gt;object network RCM_Y&lt;/P&gt;&lt;P&gt;host 6.1.8.9&lt;/P&gt;&lt;P&gt;description RCM Y&lt;/P&gt;&lt;P&gt;object network r.r.r.c163&lt;/P&gt;&lt;P&gt;host 2.1.2.63&lt;/P&gt;&lt;P&gt;description RCV IP.&lt;/P&gt;&lt;P&gt;object network r.r.r.c227&lt;/P&gt;&lt;P&gt;host 2.1.2.27&lt;/P&gt;&lt;P&gt;description RCV IP.&lt;/P&gt;&lt;P&gt;object network v.t.c-EXT&lt;/P&gt;&lt;P&gt;host 2.5.1.2&lt;/P&gt;&lt;P&gt;description RTICR&lt;/P&gt;&lt;P&gt;object service VPN-TCP(10000)&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 10000 &lt;/P&gt;&lt;P&gt;description For TCP VPN over port 1000.&lt;/P&gt;&lt;P&gt;object service BGP-JY&lt;/P&gt;&lt;P&gt;service tcp source range 1 65535 destination eq 21174 &lt;/P&gt;&lt;P&gt;description BPG&lt;/P&gt;&lt;P&gt;object network KooL&lt;/P&gt;&lt;P&gt;host 192.168.100.100&lt;/P&gt;&lt;P&gt;description KooL&lt;/P&gt;&lt;P&gt;object network FW_Test&lt;/P&gt;&lt;P&gt;host 1.3.3.7&lt;/P&gt;&lt;P&gt;description Testing other External IP&lt;/P&gt;&lt;P&gt;object network AO_10-30-133-0-LAN&lt;/P&gt;&lt;P&gt;subnet 10.30.133.0 255.255.255.0&lt;/P&gt;&lt;P&gt;description OLS 10.30.133.0/24&lt;/P&gt;&lt;P&gt;object network AC_10-30-136-0-LAN&lt;/P&gt;&lt;P&gt;subnet 10.30.136.0 255.255.255.0&lt;/P&gt;&lt;P&gt;description CLS 10.30.136.0/24&lt;/P&gt;&lt;P&gt;object-group network All_Private_Interfaces&lt;/P&gt;&lt;P&gt;description All private interfaces&lt;/P&gt;&lt;P&gt;network-object 10.30.133.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.30.136.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.10.100.16 255.255.255.240&lt;/P&gt;&lt;P&gt;network-object 10.10.100.64 255.255.255.252&lt;/P&gt;&lt;P&gt;network-object 192.168.102.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 192.168.91.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt;protocol-object udp&lt;/P&gt;&lt;P&gt;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service cb.ca&lt;/P&gt;&lt;P&gt;description All ports required for cb.ca connections.&lt;/P&gt;&lt;P&gt;service-object object c.b.ca1 &lt;/P&gt;&lt;P&gt;service-object object c.b.ca2 &lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_1&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https &lt;/P&gt;&lt;P&gt;service-object udp destination eq snmp &lt;/P&gt;&lt;P&gt;object-group service FTP&lt;/P&gt;&lt;P&gt;description All FTP ports (20 + 21)&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ftp &lt;/P&gt;&lt;P&gt;service-object tcp destination eq ftp-data &lt;/P&gt;&lt;P&gt;object-group service HTTP-EXT&lt;/P&gt;&lt;P&gt;description HTTP Extended port ranges.&lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(7001) &lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(8000-8001) &lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(8080-8081) &lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(8100) &lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(8200) &lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(8888) &lt;/P&gt;&lt;P&gt;service-object object HTTP-EXT(9080) &lt;/P&gt;&lt;P&gt;object-group service ICMP_Any&lt;/P&gt;&lt;P&gt;description ICMP: Any Type, Any Code&lt;/P&gt;&lt;P&gt;service-object icmp alternate-address&lt;/P&gt;&lt;P&gt;service-object icmp conversion-error&lt;/P&gt;&lt;P&gt;service-object icmp echo&lt;/P&gt;&lt;P&gt;service-object icmp echo-reply&lt;/P&gt;&lt;P&gt;service-object icmp information-reply&lt;/P&gt;&lt;P&gt;service-object icmp information-request&lt;/P&gt;&lt;P&gt;service-object icmp mask-reply&lt;/P&gt;&lt;P&gt;service-object icmp mask-request&lt;/P&gt;&lt;P&gt;service-object icmp mobile-redirect&lt;/P&gt;&lt;P&gt;service-object icmp parameter-problem&lt;/P&gt;&lt;P&gt;service-object icmp redirect&lt;/P&gt;&lt;P&gt;service-object icmp router-advertisement&lt;/P&gt;&lt;P&gt;service-object icmp router-solicitation&lt;/P&gt;&lt;P&gt;service-object icmp source-quench&lt;/P&gt;&lt;P&gt;service-object icmp time-exceeded&lt;/P&gt;&lt;P&gt;service-object icmp timestamp-reply&lt;/P&gt;&lt;P&gt;service-object icmp timestamp-request&lt;/P&gt;&lt;P&gt;service-object icmp traceroute&lt;/P&gt;&lt;P&gt;service-object icmp unreachable&lt;/P&gt;&lt;P&gt;service-object icmp6 echo&lt;/P&gt;&lt;P&gt;service-object icmp6 echo-reply&lt;/P&gt;&lt;P&gt;service-object icmp6 membership-query&lt;/P&gt;&lt;P&gt;service-object icmp6 membership-reduction&lt;/P&gt;&lt;P&gt;service-object icmp6 membership-report&lt;/P&gt;&lt;P&gt;service-object icmp6 neighbor-advertisement&lt;/P&gt;&lt;P&gt;service-object icmp6 neighbor-redirect&lt;/P&gt;&lt;P&gt;service-object icmp6 neighbor-solicitation&lt;/P&gt;&lt;P&gt;service-object icmp6 packet-too-big&lt;/P&gt;&lt;P&gt;service-object icmp6 parameter-problem&lt;/P&gt;&lt;P&gt;service-object icmp6 router-advertisement&lt;/P&gt;&lt;P&gt;service-object icmp6 router-renumbering&lt;/P&gt;&lt;P&gt;service-object icmp6 router-solicitation&lt;/P&gt;&lt;P&gt;service-object icmp6 time-exceeded&lt;/P&gt;&lt;P&gt;service-object icmp6 unreachable&lt;/P&gt;&lt;P&gt;service-object icmp &lt;/P&gt;&lt;P&gt;object-group service NTP&lt;/P&gt;&lt;P&gt;description TCP and UPD NTP protocol&lt;/P&gt;&lt;P&gt;service-object object ntp &lt;/P&gt;&lt;P&gt;service-object udp destination eq ntp &lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_3&lt;/P&gt;&lt;P&gt;group-object FTP&lt;/P&gt;&lt;P&gt;group-object HTTP-EXT&lt;/P&gt;&lt;P&gt;group-object ICMP_Any&lt;/P&gt;&lt;P&gt;group-object NTP&lt;/P&gt;&lt;P&gt;service-object tcp-udp destination eq domain &lt;/P&gt;&lt;P&gt;service-object tcp-udp destination eq www &lt;/P&gt;&lt;P&gt;service-object tcp destination eq https &lt;/P&gt;&lt;P&gt;service-object tcp destination eq ssh &lt;/P&gt;&lt;P&gt;service-object ip &lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_4&lt;/P&gt;&lt;P&gt;group-object NTP&lt;/P&gt;&lt;P&gt;service-object tcp destination eq daytime &lt;/P&gt;&lt;P&gt;object-group network SWINDS&lt;/P&gt;&lt;P&gt;description Both Internal IP addresses (192 + 10)&lt;/P&gt;&lt;P&gt;network-object object SWINDS-INT&lt;/P&gt;&lt;P&gt;network-object object SWINDS(192.x.x.x)-INT&lt;/P&gt;&lt;P&gt;object-group service IM_Types&lt;/P&gt;&lt;P&gt;description All messenger type applications&lt;/P&gt;&lt;P&gt;service-object object MSN &lt;/P&gt;&lt;P&gt;service-object object YMSG &lt;/P&gt;&lt;P&gt;service-object tcp-udp destination eq talk &lt;/P&gt;&lt;P&gt;service-object tcp destination eq aol &lt;/P&gt;&lt;P&gt;service-object tcp destination eq irc &lt;/P&gt;&lt;P&gt;object-group service SNMP&lt;/P&gt;&lt;P&gt;description Both poll and trap ports.&lt;/P&gt;&lt;P&gt;service-object udp destination eq snmp &lt;/P&gt;&lt;P&gt;service-object udp destination eq snmptrap &lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_2&lt;/P&gt;&lt;P&gt;group-object FTP&lt;/P&gt;&lt;P&gt;service-object object MS-RDC &lt;/P&gt;&lt;P&gt;service-object object Pl-Admin &lt;/P&gt;&lt;P&gt;group-object SNMP&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt;network-object object FW-EXT&lt;/P&gt;&lt;P&gt;network-object object Rs-EXT&lt;/P&gt;&lt;P&gt;object-group network AMV&lt;/P&gt;&lt;P&gt;description connections for legacy AM&lt;/P&gt;&lt;P&gt;network-object object DWDM-EXT&lt;/P&gt;&lt;P&gt;network-object object HAM_MGMT&lt;/P&gt;&lt;P&gt;network-object object SIM_MGMT&lt;/P&gt;&lt;P&gt;network-object object TS_MGMT&lt;/P&gt;&lt;P&gt;network-object object TS_MGMT&lt;/P&gt;&lt;P&gt;object-group service IKEv2_L2TP&lt;/P&gt;&lt;P&gt;description IKEv2 and L2TP VPN configurations&lt;/P&gt;&lt;P&gt;service-object esp &lt;/P&gt;&lt;P&gt;service-object object VPN-UDP(4500) &lt;/P&gt;&lt;P&gt;service-object object VPN-UDP(500) &lt;/P&gt;&lt;P&gt;object-group service PPTP&lt;/P&gt;&lt;P&gt;description PPTP VPN configuration&lt;/P&gt;&lt;P&gt;service-object gre &lt;/P&gt;&lt;P&gt;service-object object VPN-TCP(1723) &lt;/P&gt;&lt;P&gt;object-group service SSTP&lt;/P&gt;&lt;P&gt;description SSTP VPN configuration&lt;/P&gt;&lt;P&gt;service-object object VPN-TCP(443) &lt;/P&gt;&lt;P&gt;object-group network RvIPs&lt;/P&gt;&lt;P&gt;description Rv IP addresses&lt;/P&gt;&lt;P&gt;network-object object RCM&lt;/P&gt;&lt;P&gt;network-object object RCM_Y&lt;/P&gt;&lt;P&gt;network-object object r.r.r.c163&lt;/P&gt;&lt;P&gt;network-object object r.r.r.c227&lt;/P&gt;&lt;P&gt;network-object object v.t.c-EXT&lt;/P&gt;&lt;P&gt;object-group service Rvs&lt;/P&gt;&lt;P&gt;description Rv configuration.&lt;/P&gt;&lt;P&gt;service-object object VPN-TCP(10000) &lt;/P&gt;&lt;P&gt;service-object object VPN-UDP(500) &lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_5&lt;/P&gt;&lt;P&gt;service-object object BGP-JY &lt;/P&gt;&lt;P&gt;service-object tcp destination eq bgp &lt;/P&gt;&lt;P&gt;object-group network Local_Private_Subnets&lt;/P&gt;&lt;P&gt;description OandCl DATA&lt;/P&gt;&lt;P&gt;network-object 10.30.133.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 10.30.136.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group service IPSec&lt;/P&gt;&lt;P&gt;description IPSec traffic&lt;/P&gt;&lt;P&gt;service-object object VPN-UDP(4500) &lt;/P&gt;&lt;P&gt;service-object object VPN-UDP(500) &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Block all IM traffic out.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended deny object-group IM_Types object-group Local_Private_Subnets any &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Access from SWINDS to DLM portal&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_1 object-group SWINDS object ODLW-EXT &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow access to BMC portal&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group cb.ca object-group Local_Private_Subnets object BCCs &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow basic services out.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_3 object-group Local_Private_Subnets any &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow WhoIS traffic out.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit tcp object-group Local_Private_Subnets any eq whois &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow Network Time protocols out.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_4 object-group Local_Private_Subnets any &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow all IP based monitoring traffic to Pl.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit ip object-group SWINDS object Pl-EXT &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow Management traffic to Pl-JY.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_2 object-group Local_Private_Subnets object Pl-EXT &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow FTP traffic to Grimlock and RS FTP.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group FTP object-group Local_Private_Subnets object-group DM_INLINE_NETWORK_1 &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow VPN traffic to AM-JY.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group IKEv2_L2TP object-group Local_Private_Subnets object-group AMV &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow VPN traffic to RCm devices.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group Rvs object-group Local_Private_Subnets object-group RvIPs &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow BPG traffic out.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit object-group DM_INLINE_SERVICE_5 object-group Local_Private_Subnets any &lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out remark Allow Kool server out.&lt;/P&gt;&lt;P&gt;access-list Public/Internet_access_out extended permit ip object KooL any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging history informational&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging mail notifications&lt;/P&gt;&lt;P&gt;logging from-address thisemail@address.local&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:sendhere@address.com"&gt;sendhere@address.com&lt;/A&gt;&lt;SPAN&gt; level errors&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;mtu Public_Internet 1500&lt;/P&gt;&lt;P&gt;mtu Private_CDATA 1500&lt;/P&gt;&lt;P&gt;mtu Private_ODATA 1500&lt;/P&gt;&lt;P&gt;mtu Private_OVOICE 1500&lt;/P&gt;&lt;P&gt;mtu Private_CVOICE 1500&lt;/P&gt;&lt;P&gt;mtu Private_CeDATA 1500&lt;/P&gt;&lt;P&gt;mtu Private_CeVOICE 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool AO-VPN_Pool 192.168.238.2-192.168.238.30 mask 255.255.255.224&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Public_Internet&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Private_CDATA&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Private_ODATA&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Private_OVOICE&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Private_CVOICE&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Private_CeDATA&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface Private_CeVOICE&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface management&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp deny any Public_Internet&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (Private_ODATA,Public_Internet) source dynamic AO_10-30-133-0-LAN interface&lt;/P&gt;&lt;P&gt;nat (Private_CDATA,Public_Internet) source dynamic AC_10-30-136-0-LAN interface&lt;/P&gt;&lt;P&gt;nat (Private_ODATA,Public_Internet) source static any any destination static NETWORK_OBJ_192.168.238.0_27 NETWORK_OBJ_192.168.238.0_27 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;access-group Public/Internet_access_out out interface Public_Internet&lt;/P&gt;&lt;P&gt;route Public_Internet 0.0.0.0 0.0.0.0 1.3.3.6 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.0.0.0 255.0.0.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.1.0.0 255.255.0.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.3.0.0 255.255.0.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.5.0.0 255.255.0.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.11.106.74 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.30.128.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.30.130.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.30.131.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.30.132.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.30.134.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.30.135.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.67.31.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 10.224.0.0 255.255.0.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 4.1.1.19 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 1.1.1.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 1.1.1.13 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.11.24 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.11.27 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.11.29 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.17.105 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.147.64 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.147.66 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.147.110 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.19.251.57 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.21.56.105 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 172.21.57.152 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.3.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.9.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.20.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.21.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.30.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.31.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.40.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.41.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.50.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.60.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.61.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.70.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeVOICE 192.168.101.0 255.255.255.0 10.10.100.65 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.110.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.168.200.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 192.251.177.0 255.255.255.0 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 2.1.2.7 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;route Private_CeDATA 2.1.2.74 255.255.255.255 10.10.100.17 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server AD protocol nt&lt;/P&gt;&lt;P&gt;aaa-server AD (Private_ODATA) host 10.30.133.21&lt;/P&gt;&lt;P&gt;timeout 5&lt;/P&gt;&lt;P&gt;nt-auth-domain-controller Cool_Transformer_Name&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication telnet console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.69.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;snmp-server host Private_ODATA 10.30.133.67 poll community Some_*s_here version 2c&lt;/P&gt;&lt;P&gt;snmp-server location OT&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;snmp-server contact &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:theseguys@address.com"&gt;theseguys@address.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;snmp-server community Some_*s_here&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;snmp-server enable traps syslog&lt;/P&gt;&lt;P&gt;snmp-server enable traps ipsec start stop&lt;/P&gt;&lt;P&gt;snmp-server enable traps entity config-change fru-insert fru-remove&lt;/P&gt;&lt;P&gt;snmp-server enable traps memory-threshold&lt;/P&gt;&lt;P&gt;snmp-server enable traps interface-threshold&lt;/P&gt;&lt;P&gt;snmp-server enable traps remote-access session-threshold-exceeded&lt;/P&gt;&lt;P&gt;snmp-server enable traps connection-limit-reached&lt;/P&gt;&lt;P&gt;snmp-server enable traps cpu threshold rising&lt;/P&gt;&lt;P&gt;snmp-server enable traps ikev2 start stop&lt;/P&gt;&lt;P&gt;snmp-server enable traps nat packet-discard&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Public_Internet&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Private_CDATA&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Private_ODATA&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Private_OVOICE&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Private_CVOICE&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Private_CeDATA&lt;/P&gt;&lt;P&gt;sysopt noproxyarp Private_CeVOICE&lt;/P&gt;&lt;P&gt;sysopt noproxyarp management&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map Public_Internet_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map Public_Internet_map interface Public_Internet&lt;/P&gt;&lt;P&gt;crypto ikev1 enable Public_Internet&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 10&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt;encryption aes-256&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 30&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt;encryption 3des&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;client-update enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.30.133.0 255.255.255.0 Private_ODATA&lt;/P&gt;&lt;P&gt;ssh 192.168.69.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;ssh timeout 2&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;console timeout 5&lt;/P&gt;&lt;P&gt;dhcprelay server 10.30.133.13 Private_ODATA&lt;/P&gt;&lt;P&gt;dhcprelay enable Private_CDATA&lt;/P&gt;&lt;P&gt;dhcprelay timeout 60&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;ntp server 10.30.133.13 prefer&lt;/P&gt;&lt;P&gt;ntp server 132.246.11.227&lt;/P&gt;&lt;P&gt;ntp server 10.30.133.21&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy AO-VPN_Tunnel internal&lt;/P&gt;&lt;P&gt;group-policy AO-VPN_Tunnel attributes&lt;/P&gt;&lt;P&gt;dns-server value 10.30.133.21 10.30.133.13&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol ikev1 &lt;/P&gt;&lt;P&gt;default-domain value ao.local&lt;/P&gt;&lt;P&gt;username helpme password Some_X's_here encrypted privilege 1&lt;/P&gt;&lt;P&gt;username helpme attributes&lt;/P&gt;&lt;P&gt;service-type nas-prompt&lt;/P&gt;&lt;P&gt;tunnel-group AO-VPN_Tunnel type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group AO-VPN_Tunnel general-attributes&lt;/P&gt;&lt;P&gt;address-pool AO-VPN_Pool&lt;/P&gt;&lt;P&gt;authentication-server-group AD&lt;/P&gt;&lt;P&gt;default-group-policy AO-VPN_Tunnel&lt;/P&gt;&lt;P&gt;tunnel-group AO-VPN_Tunnel ipsec-attributes&lt;/P&gt;&lt;P&gt;ikev1 pre-shared-key Some_*s_here&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum client auto&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;inspect ftp &lt;/P&gt;&lt;P&gt;inspect h323 h225 &lt;/P&gt;&lt;P&gt;inspect h323 ras &lt;/P&gt;&lt;P&gt;inspect rsh &lt;/P&gt;&lt;P&gt;inspect rtsp &lt;/P&gt;&lt;P&gt;inspect esmtp &lt;/P&gt;&lt;P&gt;inspect sqlnet &lt;/P&gt;&lt;P&gt;inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;inspect sunrpc &lt;/P&gt;&lt;P&gt;inspect xdmcp &lt;/P&gt;&lt;P&gt;inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;inspect netbios &lt;/P&gt;&lt;P&gt;inspect tftp &lt;/P&gt;&lt;P&gt;inspect ip-options &lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;user-statistics accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;smtp-server 192.168.200.25&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Jeff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 18:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013293#M438279</guid>
      <dc:creator>JBeach2007</dc:creator>
      <dc:date>2012-09-26T18:13:20Z</dc:date>
    </item>
    <item>
      <title>Confused with this ASA - VPN config issue</title>
      <link>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013294#M438280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just tried that and I got an error returned:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ERROR: NETWORK_OBJ_192.168.238.0_27 doesn't match an existing object or object-group"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Jeff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 20:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confused-with-this-asa-vpn-config-issue/m-p/2013294#M438280</guid>
      <dc:creator>JBeach2007</dc:creator>
      <dc:date>2012-09-27T20:11:00Z</dc:date>
    </item>
  </channel>
</rss>

