ASA Version 7.2(4) ! hostname gw1 names ! interface GigabitEthernet0/0 nameif inside security-level 100 ip address 10.10.10.2 255.255.255.252 ! interface GigabitEthernet0/1 nameif outside security-level 0 ip address 10.23.26.6 255.255.255.252 ! interface GigabitEthernet0/2 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/3 shutdown no nameif no security-level no ip address ! interface Management0/0 shutdown nameif management security-level 100 no ip address ! boot system disk0:/asa724-k8.bin ftp mode passive clock timezone IRKST 8 clock summer-time IRKDT recurring last Sun Mar 2:00 last Sun Oct 3:00 same-security-traffic permit intra-interface access-list inside_access_in extended permit ip 192.168.10.0 255.255.255.0 any log disable access-list inside_nat0_outbound extended permit ip 192.168.10.0 255.255.255.0 172.16.16.0 255.255.255.0 access-list outside_2_cryptomap extended permit ip 192.168.10.0 255.255.255.0 172.16.16.0 255.255.255.0 pager lines 24 logging enable logging console debugging logging asdm informational mtu inside 1500 mtu outside 1500 mtu management 1500 no failover icmp unreachable rate-limit 1 burst-size 1 icmp permit any inside icmp permit any outside asdm image disk0:/asdm-524.bin no asdm history enable arp timeout 14400 global (outside) 23 interface nat (inside) 0 access-list inside_nat0_outbound route inside 192.168.10.0 255.255.255.0 10.10.10.1 1 route outside 0.0.0.0 0.0.0.0 10.23.26.5 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute aaa authentication enable console LOCAL aaa authentication http console LOCAL aaa authentication serial console LOCAL aaa authentication ssh console LOCAL aaa authorization command LOCAL http server enable http 10.100.8.2 255.255.255.255 outside http 192.168.10.0 255.255.255.0 inside http 10.3.10.0 255.255.255.0 inside no snmp-server location no snmp-server contact sysopt connection tcpmss 1300 crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto ipsec fragmentation after-encryption outside crypto ipsec df-bit clear-df outside crypto map outside_map 2 match address outside_2_cryptomap crypto map outside_map 2 set peer 10.23.26.2 crypto map outside_map 2 set transform-set ESP-DES-MD5 crypto map outside_map 2 set reverse-route crypto map outside_map interface outside crypto isakmp identity address crypto isakmp enable outside crypto isakmp policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 86400 crypto isakmp policy 30 authentication pre-share encryption des hash md5 group 2 lifetime 86400 crypto isakmp nat-traversal 20 vpn-sessiondb max-session-limit 750 telnet timeout 60 ssh scopy enable ssh 192.168.10.0 255.255.255.0 inside ssh 10.100.8.2 255.255.255.255 outside ssh timeout 60 ssh version 2 console timeout 60 management-access inside tunnel-group 10.23.26.2 type ipsec-l2l tunnel-group 10.23.26.2 ipsec-attributes pre-shared-key * ! class-map global-class match default-inspection-traffic ! prompt hostname context