: Saved : Written by root at 23:07:31.514 UTC Sun Sep 19 2010 ! ASA Version 8.3(2) ! hostname ciscoasa enable password ###### encrypted passwd ###### encrypted names ! interface Vlan1 nameif inside security-level 100 ip address 10.1.0.1 255.255.255.0 ! interface Vlan2 nameif outside security-level 0 ip address 1.1.1.2 255.255.255.252 ! interface Vlan3 no forward interface Vlan2 nameif dmz security-level 50 ip address 192.168.1.1 255.255.255.0 ! interface Ethernet0/0 switchport access vlan 2 ! interface Ethernet0/1 ! interface Ethernet0/2 ! interface Ethernet0/3 ! interface Ethernet0/4 ! interface Ethernet0/5 switchport access vlan 3 ! interface Ethernet0/6 ! interface Ethernet0/7 ! ftp mode passive object network obj_any subnet 0.0.0.0 0.0.0.0 object network remote subnet 10.2.0.0 255.255.255.0 object network local subnet 10.1.0.0 255.255.255.0 access-list acl_cryptomap extended permit ip object local object remote access-list acl_tunnel extended permit ip object local object remote access-list acl_tunnel extended permit ip object remote object local access-list acl_local_to_remote extended permit ip object local object remote access-list acl_local_to_remote extended permit ip object remote object local access-list acl_remote_to_local extended permit ip object remote object local access-list inside_access_in extended permit ip object local any pager lines 24 logging enable logging buffer-size 16384 logging buffered informational mtu inside 1500 mtu outside 1500 mtu dmz 1500 icmp unreachable rate-limit 1 burst-size 1 no asdm history enable arp timeout 14400 nat (any,any) source static local local destination static remote remote ! object network obj_any nat (inside,outside) dynamic interface access-group inside_access_in in interface inside access-group acl_remote_to_local out interface inside access-group acl_local_to_remote in interface outside access-group acl_tunnel out interface outside route outside 0.0.0.0 0.0.0.0 1.1.1.1 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:01:00 dynamic-access-policy-record DfltAccessPolicy aaa authentication ssh console LOCAL aaa authentication enable console LOCAL http server enable http 0.0.0.0 0.0.0.0 dmz no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart no sysopt connection permit-vpn crypto ipsec transform-set esp-3des-sha esp-3des esp-sha-hmac crypto ipsec security-association lifetime seconds 28800 crypto ipsec security-association lifetime kilobytes 4608000 crypto map site01 10 match address acl_cryptomap crypto map site01 10 set peer 2.2.2.2 crypto map site01 10 set transform-set esp-3des-sha crypto map site01 interface outside crypto isakmp enable outside crypto isakmp policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 28800 telnet timeout 5 ssh scopy enable ssh 0.0.0.0 0.0.0.0 dmz ssh timeout 60 ssh version 2 console timeout 0 management-access inside dhcpd address 10.1.0.10-10.1.0.20 inside dhcpd enable inside ! threat-detection basic-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept ntp server 192.168.1.10 source dmz webvpn group-policy vpn01 internal group-policy vpn01 attributes vpn-idle-timeout 30 vpn-filter value acl_tunnel ipv6-vpn-filter none vpn-tunnel-protocol IPSec username root password ###### encrypted privilege 15 tunnel-group 2.2.2.2 type ipsec-l2l tunnel-group 2.2.2.2 general-attributes default-group-policy vpn01 tunnel-group 2.2.2.2 ipsec-attributes pre-shared-key password ! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum client auto message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp inspect ip-options ! service-policy global_policy global prompt hostname context Cryptochecksum:ccfaf043b0087806ce6b5c6f829adeea : end