: Saved : Written by enable_15 at 13:25:52.348 UTC Tue Nov 6 2007 PIX Version 6.3(3) interface ethernet0 auto interface ethernet1 auto interface ethernet2 auto shutdown nameif ethernet0 outside security0 nameif ethernet1 inside security100 nameif ethernet2 old-inside security10 enable password ycBnSXkJEGXuQQ2i encrypted passwd 3bAFUWxCAWqSD0h. encrypted hostname sco-iff-sec-01a domain-name xxxxxx.xxxx fixup protocol dns maximum-length 1500 fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol ils 389 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 no fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names access-list 101 permit ip 10.10.12.0 255.255.255.0 10.10.15.0 255.255.255.0 access-list 101 permit ip 10.10.11.0 255.255.255.0 10.10.15.0 255.255.255.0 access-list 101 permit ip 10.10.101.0 255.255.255.0 10.10.15.0 255.255.255.0 access-list 101 permit ip 10.10.14.0 255.255.255.0 10.10.12.0 255.255.255.0 access-list 101 permit ip 10.10.14.0 255.255.255.0 10.10.15.0 255.255.255.0 access-list 101 permit ip 10.10.15.0 255.255.255.0 10.10.12.0 255.255.255.0 access-list 101 permit ip any host 64.xx.xx.xxx access-list inbound.conn.from.i-net permit ip any host 64.xx.xx.xxx access-list inbound.conn.from.i-net permit ip any any no pager logging on logging timestamp logging buffered notifications logging trap informational logging facility 22 logging host outside 64.xx.xx.xx mtu outside 1500 mtu inside 1500 mtu old-inside 1500 ip address outside 64.xx.xx.x 255.255.255.0 ip address inside 10.10.12.1 255.255.255.0 ip address old-inside 127.0.0.1 255.0.0.0 ip audit info action alarm ip audit attack action alarm ip local pool ippool 10.10.15.1-10.10.15.254 pdm history enable arp timeout 14400 global (outside) 1 64.xx.xx.xxx-64.xx.xx.xxx netmask 255.255.255.0 global (outside) 1 64.xx.xx.xxx netmask 255.255.255.0 nat (inside) 0 access-list 101 nat (inside) 1 0.0.0.0 0.0.0.0 0 0 nat (old-inside) 0 access-list 101 nat (old-inside) 1 0.0.0.0 0.0.0.0 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.43 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.210 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.211 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.17 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.16 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.19 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.18 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.61 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.14 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.24 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.36 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.9 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.15 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.56 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.11 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.35 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.54 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.26 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.33 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.12.12 netmask 255.255.255.255 0 0 static (inside,outside) 64.xx.xx.xxx 10.10.20.30 netmask 255.255.255.255 0 0 conduit permit icmp any any conduit permit tcp host 64.xx.xx.xxx eq telnet host 207.xxx.xxx.xxx conduit permit udp host 64.xx.xx.xxx eq pcanywhere-status host 64.xxx.xx.xx conduit permit tcp host 64.xx.xx.xxx eq pcanywhere-data host 64.xxx.xx.xx conduit permit ip host 64.xx.xx.xxx any conduit permit tcp host 64.xx.xx.xxx eq telnet host 72.xx.xx.xx conduit permit tcp host 64.xx.xx.xxx eq smtp host 64.xx.xx.xx conduit permit tcp host 64.xx.xx.xxx eq pcanywhere-data 71.xx.xx.xx 255.255.255.224 conduit permit udp host 64.xx.xx.xx eq pcanywhere-status 71.xx.xx.xx 255.255.255.224 conduit permit tcp host 64.xx.xx.xx eq pcanywhere-data host 68.xx.xx.xx conduit permit udp host 64.xx.xx.xx eq pcanywhere-status host 68.xx.xx.xx conduit permit ip host 64.xx.xx.xx host 64.xx.xx.xx conduit permit udp host 64.xx.xx.xx eq radius-acct host 64.xx.xx.xx conduit permit udp host 64.xx.xx.xx eq radius host 64.xx.xx.xx conduit permit udp host 64.xx.xx.xx eq radius host 64.xx.xx.xx conduit permit udp host 64.xx.xx.xxeq radius-acct host 64.xx.xx.xx conduit permit ip host 64.xx.xx.xx host 64.xx.xx.xx conduit permit tcp host 64.xx.xx.xx eq pcanywhere-data 69.xx.xx.xx 255.255.255.252 conduit permit udp host 64.xx.xx.xx eq pcanywhere-status 69.xx.xx.xx 255.255.255.252 conduit permit tcp host 64.xx.xx.xxeq pcanywhere-data host 24.xx.xx.xx conduit permit udp host 64.xx.xx.xx eq pcanywhere-status host 24.xx.xx.xx conduit permit tcp host 64.xx.xx.xxx eq ftp-data host 72.xx.xx.xx conduit permit tcp host 64.xx.xx.xxx eq ftp host 72.xx.xx.xx conduit permit ip host 64.xx.xx.xxx any conduit permit ip host 64.xx.xx.xxx any route outside 0.0.0.0 0.0.0.0 64.xx.xx.xx 1 route inside 10.10.14.0 255.255.255.0 10.10.12.230 1 route inside 10.10.15.0 255.255.255.0 10.10.12.230 1 route inside 10.10.20.0 255.255.255.0 10.10.12.21 1 route inside 10.10.20.0 255.255.255.0 10.10.12.27 2 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa-server LOCAL protocol local snmp-server host inside 10.10.12.29 snmp-server location Admin Bld snmp-server contact snmp.admin snmp-server community snmp.work snmp-server enable traps floodguard enable sysopt connection permit-ipsec auth-prompt prompt "Do Not Enter" crypto ipsec transform-set myset esp-des esp-md5-hmac crypto dynamic-map dynmap 10 set transform-set myset crypto map mymap 10 ipsec-isakmp dynamic dynmap crypto map mymap interface outside isakmp enable outside isakmp identity address isakmp nat-traversal 20 isakmp policy 10 authentication pre-share isakmp policy 10 encryption 3des isakmp policy 10 hash sha isakmp policy 10 group 2 isakmp policy 10 lifetime 86400 vpngroup touavpn address-pool ippool vpngroup touavpn dns-server 10.10.12.12 64.xx.xx.xx vpngroup touavpn default-domain work.net vpngroup touavpn split-tunnel 101 vpngroup touavpn idle-time 1800 vpngroup touavpn password xxxxxxxx vpngroup testvpn idle-time 1800 vpngroup touvpn idle-time 1800 telnet 10.10.11.3 255.255.255.255 inside telnet 10.10.12.200 255.255.255.255 inside telnet 10.10.12.201 255.255.255.255 inside telnet 10.10.12.14 255.255.255.255 inside telnet 10.10.11.17 255.255.255.255 inside telnet 10.10.12.121 255.255.255.255 inside telnet 10.10.12.0 255.255.255.0 inside telnet 10.10.50.0 255.255.255.0 inside telnet 10.10.15.0 255.255.255.0 inside telnet 10.10.11.41 255.255.255.255 old-inside telnet 10.10.11.3 255.255.255.255 old-inside telnet 10.10.12.43 255.255.255.255 old-inside telnet 10.10.12.246 255.255.255.255 old-inside telnet 10.10.12.200 255.255.255.255 old-inside telnet 10.10.12.201 255.255.255.255 old-inside telnet 10.10.12.14 255.255.255.255 old-inside telnet 10.10.11.30 255.255.255.255 old-inside telnet 10.10.11.25 255.255.255.255 old-inside telnet 10.10.11.17 255.255.255.255 old-inside telnet timeout 30 ssh 0.0.0.0 0.0.0.0 outside ssh timeout 5 console timeout 0 terminal width 80 Cryptochecksum:fc379aecd06ab14c560c529ae978ef60 : end