Configuration commentée du PIX
!
! version du IOS
PIX Version 7.2(1)
!
!
!nom reseau du cisco
hostname kamelott
!
!domaine du cisco
domain-name chateaufort.net
!
! mot de passe enable
enable password toto encrypted
!
! décalaration des adresses / IP
names
! serveur principal (pour le moment) de mon réseau
name 192.168.1.56 caradoc
!
! paramétrage interface ethernet (branché sur le "modem" ADSL)
interface Ethernet0
! branchement sur l'exterieur niveau de confiance 0
! adresse ip négociée par pppoe avec le provider
nameif outside
security-level 0
ip address pppoe setroute
!
! deuxième interface réseau (réseau privé)
interface Ethernet1
! niveau de confiance maximum
! adresse 192.168.1.254/24
nameif inside
security-level 100
ip address 192.168.1.254 255.255.255.0
!
passwd toto encrypted
ftp mode passive
dns server-group DefaultDNS
domain-name chateaufort.net
access-list from-outside extended deny ip any any log
access-list from-inside extended permit tcp any any eq www
access-list from-inside extended permit tcp any host 193.252.19.3 eq domain
access-list from-inside extended permit tcp any host 193.252.19.4 eq domain
access-list from-inside extended permit tcp any any eq https
access-list from-inside extended permit udp any host 193.252.19.3 eq domain
access-list from-inside extended permit udp any host 193.252.19.4 eq domain
access-list from-inside extended permit tcp any any eq 6901
access-list from-inside extended permit tcp any any eq 1863
access-list from-inside extended permit tcp any any range 6891 6900
access-list from-inside extended permit udp any any eq 6901
access-list from-inside extended permit udp any any eq 22
access-list from-inside extended permit tcp any any eq ssh
access-list from-inside extended permit tcp any host 217.12.6.29 eq pop3
access-list from-inside extended permit tcp any host 217.12.10.100 eq pop3
access-list from-inside extended permit tcp any host 217.12.11.6 eq smtp
access-list from-inside extended deny ip any any log
pager lines 24
logging enable
logging timestamp
logging standby
logging trap notifications
logging facility 19
logging host inside caradoc
logging permit-hostdown
mtu outside 1500
mtu inside 1500
no failover
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
access-group from-outside in interface outside
access-group from-inside in interface inside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
username mon_utilisateur password mon_mot_de_passe encrypted privilege 0
http server enable
http 192.168.1.0 255.255.255.0 inside
http 192.168.1.20 255.255.255.255 inside
snmp-server host inside caradoc community macommunautée
snmp-server location kamelott, france
no snmp-server contact
snmp-server community macommunautée
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh scopy enable
ssh 192.168.1.0 255.255.255.0 inside
ssh timeout 5
ssh version 1
console timeout 0
vpdn group ISP request dialout pppoe
vpdn group ISP localname fti/mon_utilisateur@fti
vpdn group ISP ppp authentication pap
vpdn username fti/mon_utilisateur@fti password mon_mot_de_passe
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
!
service-policy global_policy global
tftp-server inside caradoc kamelott/config
prompt hostname context
Cryptochecksum:b15469323ced6963c1ef9bdb98b394c3
: end
Commentaires