PIX Version 6.3(3) interface ethernet0 auto interface ethernet1 auto nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password encrypted passwd encrypted hostname PIX506e domain-name domain.local fixup protocol dns maximum-length 512 fixup protocol ftp 21 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol http 80 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol sip 5060 fixup protocol sip udp 5060 fixup protocol skinny 2000 fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names access-list acl_out permit icmp any any echo access-list acl_out permit icmp any any echo-reply access-list acl_out permit tcp any host 65.x.x.77 eq www access-list acl_out permit tcp any host 65.x.x.77 eq https access-list acl_out permit tcp any host 65.x.x.77 eq 6060 access-list acl_out permit tcp any host 65.x.x.77 eq 3389 access-list acl_out permit tcp any host 65.x.x.77 eq 32004 access-list acl_out permit tcp any host 65.x.x.77 eq ftp access-list acl_out permit tcp any host 65.x.x.187 eq 3389 access-list acl_out permit tcp any host 65.x.x.187 eq pop3 access-list acl_out permit tcp any host 65.x.x.187 eq smtp access-list acl_out permit tcp any host 65.x.x.187 eq www access-list acl_out permit tcp any host 65.x.x.187 eq https access-list nonat permit ip 172.16.10.0 255.255.255.0 172.16.11.0 255.255.255.0 access-list nonat permit ip 10.2.29.0 255.255.255.0 10.1.29.0 255.255.255.0 access-list 101 permit ip 172.16.10.0 255.255.255.0 172.16.11.0 255.255.255.0 access-list 102 permit ip 10.2.29.0 255.255.255.0 10.1.29.0 255.255.255.0 pager lines 24 mtu outside 1500 mtu inside 1500 ip address outside 65.x.x.78 255.255.255.248 ip address inside 172.16.1.1 255.255.255.0 ip audit info action alarm ip audit attack action alarm ip local pool vpnpool 10.0.1.10-10.0.1.12 pdm history enable arp timeout 14400 global (outside) 1 interface global (outside) 10 65.x.x.76 global (outside) 52 65.x.x.187 nat (inside) 0 access-list nonat nat (inside) 52 10.2.29.101 255.255.255.255 0 0 nat (inside) 10 172.16.10.101 255.255.255.255 0 0 nat (inside) 1 172.16.1.0 255.255.255.0 0 0 static (inside,outside) tcp 65.x.x.76 www 172.16.10.101 www netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.76 3389 172.16.10.101 3389 netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.76 smtp 172.16.10.101 smtp netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.76 imap4 172.16.10.101 imap4 netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.76 pop3 172.16.10.101 pop3 netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.76 https 172.16.10.101 https netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.76 3101 172.16.10.101 3101 netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.187 3389 10.2.29.101 3389 netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.187 pop3 10.2.29.101 pop3 netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.187 smtp 10.2.29.101 smtp netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.187 www 10.2.29.101 www netmask 255.255.255.255 0 0 static (inside,outside) tcp 65.x.x.187 https 10.2.29.101 https netmask 255.255.255.255 0 0 access-group acl_out in interface outside route outside 0.0.0.0 0.0.0.0 65.x.x.73 1 route inside 10.1.29.0 255.255.255.0 172.16.1.2 1 route inside 10.2.29.0 255.255.255.0 172.16.1.2 1 route inside 172.16.10.0 255.255.255.0 172.16.1.2 1 route inside 172.16.11.0 255.255.255.0 172.16.1.2 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00 timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa-server LOCAL protocol local no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps floodguard enable sysopt connection permit-ipsec crypto ipsec transform-set pixtopix esp-3des esp-md5-hmac crypto ipsec transform-set vpnclient esp-des esp-md5-hmac crypto ipsec transform-set asatopix esp-des esp-md5-hmac crypto dynamic-map dynmap 30 set transform-set vpnclient crypto map vpnmap 1 ipsec-isakmp crypto map vpnmap 1 match address 101 crypto map vpnmap 1 set peer 99.x.x.30 crypto map vpnmap 1 set transform-set pixtopix crypto map vpnmap 2 ipsec-isakmp crypto map vpnmap 2 match address 102 crypto map vpnmap 2 set peer 69.x.x.218 crypto map vpnmap 2 set transform-set asatopix crypto map vpnmap 30 ipsec-isakmp dynamic dynmap crypto map vpnmap interface outside isakmp enable outside isakmp key ******** address 99.x.x.30 netmask 255.255.255.255 isakmp key ******** address 69.x.x.218 netmask 255.255.255.255 isakmp identity address isakmp nat-traversal 20 isakmp policy 1 authentication pre-share isakmp policy 1 encryption 3des isakmp policy 1 hash md5 isakmp policy 1 group 2 isakmp policy 1 lifetime 86400 isakmp policy 10 authentication pre-share isakmp policy 10 encryption des isakmp policy 10 hash md5 isakmp policy 10 group 2 isakmp policy 10 lifetime 86400 telnet 172.16.0.0 255.255.0.0 inside telnet timeout 15 ssh timeout 5 console timeout 0 terminal width 80 Cryptochecksum:2b331a8e310e22c1b35c638e6326f462 : end