isakmp policy 10 authentication pre-share isakmp policy 10 encryption aes-192 isakmp policy 10 hash md5 isakmp policy 10 group 2 isakmp policy 10 lifetime 14400 isakmp enable outside crypto ipsec transform-set AESset-192 esp-aes-192 esp-md5-hmac crypto map NEW_MAP 100 match address PVL1202 crypto map NEW_MAP 100 set peer y.y.y.y crypto map NEW_MAP 100 set transform-set AESset-192 crypto map NEW_MAP_ALMATY interface outside access-list PVL1202 line 1 extended permit ip 172.16.0.0 255.255.128.0 192.168.223.0 255.255.255.0 access-list PVL1202 line 2 extended permit ip 192.168.105.0 255.255.255.0 192.168.223.0 255.255.255.0 access-list PVL1202 line 3 extended permit ip 192.168.3.0 255.255.255.0 192.168.223.0 255.255.255.0 interface GigabitEthernet0/0 nameif outside security-level 0 ip address x.x.x.x 255.255.255.192 interface GigabitEthernet0/1 nameif inside security-level 100 ip address 192.168.1.2 255.255.255.252 nat (inside) 0 172.16.0.0 255.255.0.0 nat (inside) 0 192.168.105.0 255.255.255.0 nat (inside) 0 192.168.3.0 255.255.255.0 nat (inside) 1 0.0.0.0 0.0.0.0