interface ethernet0 auto interface ethernet1 100full nameif ethernet0 outside security0 nameif ethernet1 inside security100 hostname TekConPix domain-name local.local clock timezone EST -5 clock summer-time EDT recurring fixup protocol dns maximum-length 512 fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol ils 389 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names name 10.0.0.50 JetDirect name 10.0.0.4 TekConPhone name 10.0.0.3 TekConTS name 10.0.0.2 TekConApps name 10.0.0.1 TekConMain name 10.0.0.51 Phaser6115MFP name 10.0.0.5 TekconFTP name 97.86.42.142 HomePIX object-group service NetMeeting tcp port-object range 1731 1731 port-object range ldap ldap port-object range 522 522 port-object range h323 h323 port-object range 1503 1503 object-group service TomsPC tcp port-object range 5555 5555 object-group service JetDirect tcp port-object range 9100 9100 object-group service TerminalServices tcp port-object range 3389 3389 access-list outside_access_in remark OWA access-list outside_access_in permit tcp any interface outside eq https access-list outside_access_in remark Jet Direct Printing access-list outside_access_in permit tcp any interface outside object-group JetDirect access-list outside_access_in remark Phone System Ports access-list outside_access_in permit udp any eq 5060 any access-list outside_access_in remark Phone System Ports access-list outside_access_in permit udp any range 8000 9000 any access-list outside_access_in permit tcp any interface outside object-group NetMeeting access-list outside_access_in remark FTP Access access-list outside_access_in permit tcp any interface outside eq ftp access-list outside_access_in remark Terminal Server Access access-list outside_access_in permit tcp any interface outside object-group TerminalServices access-list inside_outbound_nat0_acl permit ip any 10.0.0.0 255.255.255.0 access-list tekconvpn_splitTunnelAcl permit ip 10.0.0.0 255.255.255.0 any access-list outside_cryptomap_dyn_20 permit ip any 10.0.0.0 255.255.255.0 access-list 101 permit ip 10.0.0.0 255.255.255.0 10.1.0.0 255.255.255.0 access-list NoNat permit ip 10.0.0.0 255.255.255.0 10.1.0.0 255.255.255.0 pager lines 24 logging on logging timestamp logging trap informational logging host inside TekConMain mtu outside 1500 mtu inside 1500 ip address outside 45.59.152.222 255.255.255.248 pppoe setroute ip address inside 10.0.0.250 255.255.255.0 ip audit info action alarm ip audit attack action alarm ip local pool vpnpool 10.0.0.126-10.0.0.130 pdm location TekConMain 255.255.255.255 inside pdm location TekConApps 255.255.255.255 inside pdm location JetDirect 255.255.255.255 inside pdm location TekConTS 255.255.255.255 inside pdm location 45.59.152.0 255.255.255.0 outside pdm location TekConPhone 255.255.255.255 inside pdm location Phaser6115MFP 255.255.255.255 inside pdm location TekconFTP 255.255.255.255 inside pdm location HomePIX 255.255.255.255 outside pdm location 10.1.0.0 255.255.255.0 outside pdm logging informational 100 pdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 0 access-list NoNat nat (inside) 1 0.0.0.0 0.0.0.0 0 0 static (inside,outside) tcp interface https TekConMain https netmask 255.255.255.255 0 0 static (inside,outside) tcp interface 9100 JetDirect 9100 netmask 255.255.255.255 0 0 static (inside,outside) udp interface 5060 TekConPhone 5060 netmask 255.255.255.255 0 0 static (inside,outside) tcp interface ftp TekconFTP ftp netmask 255.255.255.255 0 0 static (inside,outside) tcp interface 522 TekConTS 522 netmask 255.255.255.255 0 0 static (inside,outside) tcp interface 3389 TekConTS 3389 netmask 255.255.255.255 0 0 static (inside,outside) tcp interface ldap TekConTS ldap netmask 255.255.255.255 0 0 static (inside,outside) tcp interface 1503 TekConTS 1503 netmask 255.255.255.255 0 0 static (inside,outside) tcp interface h323 TekConTS h323 netmask 255.255.255.255 0 0 static (inside,outside) tcp interface 1731 TekConTS 1731 netmask 255.255.255.255 0 0 access-group outside_access_in in interface outside route outside 45.59.152.0 255.255.255.0 45.59.152.222 1 timeout xlate 0:05:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout sip-disconnect 0:02:00 sip-invite 0:03:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server TACACS+ max-failed-attempts 3 aaa-server TACACS+ deadtime 10 aaa-server RADIUS protocol radius aaa-server RADIUS max-failed-attempts 3 aaa-server RADIUS deadtime 10 aaa-server LOCAL protocol local ntp server TekConMain source inside prefer http server enable http 10.0.0.0 255.255.255.0 inside no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps floodguard enable sysopt connection permit-ipsec crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto ipsec transform-set TekconStS esp-des esp-md5-hmac crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20 crypto dynamic-map outside_dyn_map 20 set transform-set ESP-DES-MD5 crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map crypto map transam 1 ipsec-isakmp crypto map transam 1 match address 101 crypto map transam 1 set peer HomePIX crypto map transam 1 set transform-set TekconStS crypto map transam interface outside isakmp enable outside isakmp key ******** address HomePIX netmask 255.255.255.255 isakmp identity address isakmp nat-traversal 20 isakmp policy 1 authentication pre-share isakmp policy 1 encryption des isakmp policy 1 hash md5 isakmp policy 1 group 1 isakmp policy 1 lifetime 1000 isakmp policy 20 authentication pre-share isakmp policy 20 encryption des isakmp policy 20 hash md5 isakmp policy 20 group 2 isakmp policy 20 lifetime 86400 vpngroup tekconvpn address-pool vpnpool vpngroup tekconvpn dns-server TekConMain vpngroup tekconvpn default-domain tekconllc.local vpngroup tekconvpn split-tunnel tekconvpn_splitTunnelAcl vpngroup tekconvpn idle-time 1800 vpngroup tekconvpn password ******** telnet 10.0.0.0 255.255.255.0 inside telnet timeout 5 ssh timeout 5 management-access inside console timeout 0 vpdn group pppoe_group request dialout pppoe vpdn group pppoe_group localname xxxxxxx@xxxxxx.net vpdn group pppoe_group ppp authentication pap vpdn username xxxxxxx@xxxxxx.net password ********* store-local dhcpd address 10.0.0.111-10.0.0.125 inside dhcpd dns TekConMain dhcpd lease 3600 dhcpd ping_timeout 750 dhcpd domain local.local dhcpd auto_config outside dhcpd enable inside terminal width 80