c877W#sh run Building configuration... Current configuration : 9607 bytes ! version 15.1 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime service timestamps log datetime msec localtime no service password-encryption service disable-ip-fast-frag service sequence-numbers ! hostname c877W ! boot-start-marker boot-end-marker ! ! logging buffered 64096 logging console notifications logging monitor notifications ! no aaa new-model ! crypto pki token default removal timeout 0 ! crypto pki trustpoint TP-self-signed-3569064645 enrollment selfsigned subject-name cn=IOS-Self-Signed-Certificate-3569064645 revocation-check none rsakeypair TP-self-signed-3569064645 ! ! crypto pki certificate chain TP-self-signed-3569064645 certificate self-signed 01 3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 69666963 6174652D 33353639 30363436 3435301E 170D3039 30333235 30393234 31395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 35363930 36343634 3530819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 8100D7C9 CCB0490A 9E75CF4C E0067AB9 6521A61A B2DFB8DD 4CD6EB27 045FB9DA 63C63B14 55A45F8D C76881EC EB6B6AC6 5832FCC9 8D43B7F3 233194A5 1E1C1472 FFE88494 A5AE94F8 EE68ABF4 337D8145 E818A6E8 BED3D57C 8F683808 86450459 DE45E780 A6457E69 FDAA1608 CB9072CD 27C87651 5DA6D582 86B7945D 531ECB9D 08CD0203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603 551D2304 18301680 1462BBF6 4A0D419C 61584BE9 B12B798D 5FCD8EEE CF301D06 03551D0E 04160414 62BBF64A 0D419C61 584BE9B1 2B798D5F CD8EEECF 300D0609 2A864886 F70D0101 05050003 8181006A 058360EE 900921DD 1942BE3C 56C16E28 1C023A7C 33DCE28C DD63AFF9 EFF8EA7C 1EF5A78A B2EEE324 2238D456 6BABC481 58963052 7CEC5A62 C20B3921 B677E994 16261377 A7B7F449 F47EB230 7BE601DE 6C17F233 58034D98 669D35B5 D3CD4D00 9E9DF431 09456977 557E66A2 EF6FDFEB A4B5DA1D 71C2B1FB EEA76313 109779 quit dot11 syslog ! dot11 ssid A!t4(^@nd]+*n36C!R286!0=\lyrHe6 vlan 7 max-associations 2 authentication open authentication key-management wpa wpa-psk ascii 0 @85jGw_)$nF*Ud&!}gs*[BS@270//se ! no ip source-route no ip gratuitous-arps ip options drop ! ! ! ! ! ip cef no ip bootp server ip domain name .ru ip name-server 89.222.217.131 ip name-server 89.222.222.2 ip ips config location flash:ips retries 1 ip ips memory threshold 10 ip ips name *IPS* ! ip ips signature-category category all retired true category ios_ips advanced retired false enabled true event-action reset-tcp-connection deny-packet-inline deny-connection-inline produce-alert ! ip inspect max-incomplete low 180 ip inspect max-incomplete high 250 ip inspect udp idle-time 10 ip inspect dns-timeout 1 ip inspect tcp idle-time 120 ip inspect tcp finwait-time 3 ip inspect tcp synwait-time 7 ip inspect tcp block-non-session ip inspect tcp reassembly queue length 256 ip inspect tcp reassembly timeout 4 ip inspect tcp reassembly memory limit 4096 ip inspect name *USHT* tcp timeout 120 ip inspect name *USHT* udp timeout 10 ip inspect name *USHT* ftp timeout 60 ip inspect name *USHT* dns timeout 5 ip inspect name *USHT* tftp timeout 60 ip inspect name *USHT* ftps timeout 60 ip inspect name *USHT* icmp router-traffic timeout 5 ip inspect name *USHT* fragment maximum 200 timeout 5 ip inspect name *USHT* smtp timeout 30 ip inspect name *USHT* ntp timeout 5 ip inspect name *USHT* https timeout 60 ip inspect name *USHT* telnet timeout 60 ip inspect name *USHT* echo timeout 5 ip inspect name *USHT* bittorrent ip inspect name *USHT* telnets ip inspect name *USHT* who no ipv6 cef ! appfw policy-name 8888888 ! appfw policy-name *HTTP* application http max-header-length request 5000 response 5000 action reset alarm max-uri-length 1500 action reset alarm port-misuse default action reset alarm request-method extension default action reset alarm timeout 88 ! appfw policy-name *HTTP-partial-WORK* application http strict-http action reset alarm content-type-verification unknown-type action reset alarm max-header-length request 5000 response 5000 action reset alarm max-uri-length 1500 action reset alarm port-misuse default action reset alarm request-method extension default action reset alarm transfer-encoding type compress action reset alarm transfer-encoding type deflate action reset alarm transfer-encoding type gzip action reset alarm transfer-encoding type identity action reset alarm timeout 88 ! multilink bundle-name authenticated ! parameter-map type inspect global alert on tcp reset-PSH enable l2-transparent dhcp-passthrough disable parameter-map type inspect *MY-MAP* parameter-map type ooo global ! ! archive log config hidekeys memory reserve critical 256 object-group network DNS host 94.100.191.202 ! ! no spanning-tree vlan 1 no spanning-tree vlan 777 username lms privilege 15 password 0 works ! crypto key pubkey-chain rsa named-key realm-cisco.pub signature key-string 30820122 300D0609 2A864886 F70D0101 01050003 82010F00 3082010A 02820101 00C19E93 A8AF124A D6CC7A24 5097A975 206BE3A2 06FBA13F 6F12CB5B 4E441F16 17E630D5 C02AC252 912BE27F 37FDD9C8 11FC7AF7 DCDD81D9 43CDABC3 6007D128 B199ABCB D34ED0F9 085FADC1 359C189E F30AF10A C0EFB624 7E0764BF 3E53053E 5B2146A9 D7A5EDE3 0298AF03 DED7A5B8 9479039D 20F30663 9AC64B93 C0112A35 FE3F0C87 89BCB7BB 994AE74C FA9E481D F65875D6 85EAF974 6D9CC8E3 F0B08B85 50437722 FFBE85B9 5E4189FF CC189CB9 69C46F9C A84DFBA5 7A0AF99E AD768C36 006CF498 079F88F8 A3B3FB1F 9FB7B3CB 5539E1D1 9693CCBB 551F78D2 892356AE 2F56D826 8918EF3C 80CA4F4D 87BFCA3B BFF668E9 689782A5 CF31CB6E B4B094D3 F3020301 0001 quit ! ! ip tcp selective-ack ! ! ! ! buffers tune automatic bridge irb ! ! ! interface Loopback911 ip address 9.1.1.1 255.255.255.255 ! interface ATM0 no ip address no atm ilmi-keepalive dsl operating-mode adsl2+ pvc 1/50 oam-pvc 0 encapsulation aal5snap pppoe-client dial-pool-number 13 ! ! interface FastEthernet0 description *DMZ-fa1* no ip address spanning-tree portfast ! interface FastEthernet1 description *Trunk-To-PIX-fa1* switchport mode trunk no ip address spanning-tree portfast ! interface FastEthernet2 description *My-Lan* switchport access vlan 21 no ip address spanning-tree portfast ! interface FastEthernet3 description *Wi-Fi* switchport access vlan 7 no ip address spanning-tree portfast ! interface Dot11Radio0 no ip address ! encryption vlan 7 mode ciphers aes-ccm ! broadcast-key vlan 7 change 120 ! ! ssid A!t4(^@nd]+*n36C!R286!0=\lyrHe6 ! speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0 channel 2437 station-role root no cdp enable ! interface Dot11Radio0.7 encapsulation dot1Q 7 native no cdp enable bridge-group 7 bridge-group 7 subscriber-loop-control bridge-group 7 spanning-disabled bridge-group 7 block-unknown-source no bridge-group 7 source-learning no bridge-group 7 unicast-flooding ! interface Vlan1 description *DMZ* ip address 7.0.0.1 255.255.255.0 ip nat inside no ip virtual-reassembly in ! interface Vlan7 description *Wi-Fi* no ip address ip tcp adjust-mss 1452 bridge-group 7 bridge-group 7 spanning-disabled ! interface Vlan21 no ip address no ip redirects no ip unreachables no ip proxy-arp ip nat inside ip virtual-reassembly in ip tcp adjust-mss 1452 ! interface Dialer13 ip address negotiated ip access-group PIX in no ip redirects no ip unreachables no ip proxy-arp ip mtu 1492 ip nat outside no ip virtual-reassembly in ip verify unicast reverse-path encapsulation ppp dialer pool 13 ppp authentication chap callin ppp chap hostname SOLOVJOVA13 ppp chap password 0 133878 no cdp enable ! interface BVI7 no ip address no ip redirects no ip unreachables no ip proxy-arp ip nat inside no ip virtual-reassembly in ! no ip forward-protocol nd no ip http server no ip http secure-server ! ! ip nat translation timeout 140 ip nat translation tcp-timeout 123 ip nat translation udp-timeout 13 ip nat translation finrst-timeout 6 ip nat translation syn-timeout 10 ip nat translation dns-timeout 3 ip nat translation icmp-timeout 8 ip nat inside source list 13 interface Dialer13 overload ip route 0.0.0.0 0.0.0.0 Dialer13 33 ip route 7.7.7.0 255.255.255.0 7.0.0.253 77 ip route 7.21.3.0 255.255.255.0 7.0.0.253 77 ! ip access-list standard TELNET permit 7.0.0.0 0.0.0.255 permit 7.7.7.0 0.0.0.255 permit 7.21.3.0 0.0.0.255 ! ip access-list extended CBAC deny ip any any fragments deny ip any any deny udp any any fragments deny udp any any ip access-list extended LAN permit tcp any any permit udp any any deny ip any any ip access-list extended NIGHT permit tcp host 7.7.7.33 any permit udp host 7.7.7.33 any deny ip host 7.7.7.69 any time-range NIGHT permit tcp host 7.7.7.69 any permit udp host 7.7.7.69 any deny ip any any ip access-list extended PIX deny ip any any fragments deny tcp any any eq telnet deny tcp any any eq 22 permit tcp any any permit udp any any deny ip any any ! access-list 13 permit any no cdp run ! ! ! ! ! control-plane ! bridge 7 protocol ieee bridge 7 route ip ! line con 0 no modem enable line aux 0 line vty 0 4 access-class TELNET in exec-timeout 40 0 privilege level 15 login local transport input telnet ! scheduler max-task-time 5000 time-range NIGHT periodic daily 22:00 to 23:59 periodic daily 0:00 to 6:00 ! end c877W# *********************************************** *********************************************** *********************************************** ! Last configuration change at 21:43:09 UTC Fri Mar 13 2009 by lms version 15.1 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime service timestamps log datetime msec localtime no service password-encryption service disable-ip-fast-frag service sequence-numbers ! hostname c877W ! boot-start-marker boot-end-marker ! ! logging buffered 64096 logging console notifications logging monitor notifications ! no aaa new-model ! crypto pki token default removal timeout 0 ! crypto pki trustpoint TP-self-signed-3569064645 enrollment selfsigned subject-name cn=IOS-Self-Signed-Certificate-3569064645 revocation-check none rsakeypair TP-self-signed-3569064645 ! ! crypto pki certificate chain TP-self-signed-3569064645 certificate self-signed 01 nvram:IOS-Self-Sig#1.cer dot11 syslog ! dot11 ssid A!t4(^@nd]+*n36C!R286!0=\lyrHe6 max-associations 2 authentication open authentication key-management wpa wpa-psk ascii 0 @85jGw_)$nF*Ud&!}gs*[BS@270//se ! no ip source-route no ip gratuitous-arps ip options drop ! ! ! ! ! ip cef no ip bootp server ip domain name .ru ip name-server 89.222.217.131 ip name-server 89.222.222.2 ip ips config location flash:ips retries 1 ip ips memory threshold 10 ip ips name *IPS* ! ip ips signature-category category all retired true category ios_ips advanced retired false enabled true event-action reset-tcp-connection deny-packet-inline deny-connection-inline produce-alert ! ip inspect max-incomplete low 180 ip inspect max-incomplete high 250 ip inspect udp idle-time 10 ip inspect dns-timeout 1 ip inspect tcp idle-time 120 ip inspect tcp finwait-time 3 ip inspect tcp synwait-time 7 ip inspect tcp block-non-session ip inspect tcp reassembly queue length 256 ip inspect tcp reassembly timeout 4 ip inspect tcp reassembly memory limit 4096 ip inspect name *USHT* tcp timeout 120 ip inspect name *USHT* udp timeout 10 ip inspect name *USHT* ftp timeout 60 ip inspect name *USHT* dns timeout 5 ip inspect name *USHT* tftp timeout 60 ip inspect name *USHT* ftps timeout 60 ip inspect name *USHT* icmp router-traffic timeout 5 ip inspect name *USHT* fragment maximum 200 timeout 5 ip inspect name *USHT* smtp timeout 30 ip inspect name *USHT* ntp timeout 5 ip inspect name *USHT* https timeout 60 ip inspect name *USHT* telnet timeout 60 ip inspect name *USHT* echo timeout 5 ip inspect name *USHT* bittorrent ip inspect name *USHT* telnets ip inspect name *USHT* who no ipv6 cef ! appfw policy-name 8888888 ! appfw policy-name *HTTP* application http max-header-length request 5000 response 5000 action reset alarm max-uri-length 1500 action reset alarm port-misuse default action reset alarm request-method extension default action reset alarm timeout 88 ! appfw policy-name *HTTP-partial-WORK* application http strict-http action reset alarm content-type-verification unknown-type action reset alarm max-header-length request 5000 response 5000 action reset alarm max-uri-length 1500 action reset alarm port-misuse default action reset alarm request-method extension default action reset alarm transfer-encoding type compress action reset alarm transfer-encoding type deflate action reset alarm transfer-encoding type gzip action reset alarm transfer-encoding type identity action reset alarm timeout 88 ! multilink bundle-name authenticated ! parameter-map type inspect global alert on tcp reset-PSH enable l2-transparent dhcp-passthrough disable parameter-map type inspect *MY-MAP* parameter-map type ooo global ! ! archive log config hidekeys memory reserve critical 256 object-group network DNS host 94.100.191.202 ! ! no spanning-tree vlan 1 no spanning-tree vlan 777 username lms privilege 15 password 0 works ! crypto key pubkey-chain rsa named-key realm-cisco.pub signature key-string 30820122 300D0609 2A864886 F70D0101 01050003 82010F00 3082010A 02820101 00C19E93 A8AF124A D6CC7A24 5097A975 206BE3A2 06FBA13F 6F12CB5B 4E441F16 17E630D5 C02AC252 912BE27F 37FDD9C8 11FC7AF7 DCDD81D9 43CDABC3 6007D128 B199ABCB D34ED0F9 085FADC1 359C189E F30AF10A C0EFB624 7E0764BF 3E53053E 5B2146A9 D7A5EDE3 0298AF03 DED7A5B8 9479039D 20F30663 9AC64B93 C0112A35 FE3F0C87 89BCB7BB 994AE74C FA9E481D F65875D6 85EAF974 6D9CC8E3 F0B08B85 50437722 FFBE85B9 5E4189FF CC189CB9 69C46F9C A84DFBA5 7A0AF99E AD768C36 006CF498 079F88F8 A3B3FB1F 9FB7B3CB 5539E1D1 9693CCBB 551F78D2 892356AE 2F56D826 8918EF3C 80CA4F4D 87BFCA3B BFF668E9 689782A5 CF31CB6E B4B094D3 F3020301 0001 quit ! ! ip tcp selective-ack ! ! ! ! buffers tune automatic ! buffers tune automatic ! ! ! interface Loopback911 ip address 9.1.1.1 255.255.255.255 ! interface ATM0 no ip address no atm ilmi-keepalive dsl operating-mode adsl2+ pvc 1/50 oam-pvc 0 encapsulation aal5snap pppoe-client dial-pool-number 13 ! ! interface FastEthernet0 description *DMZ-fa1* no ip address spanning-tree portfast ! interface FastEthernet1 description *Trunk-To-PIX-fa1* switchport mode trunk no ip address spanning-tree portfast ! interface FastEthernet2 description *My-Lan* switchport access vlan 21 no ip address spanning-tree portfast ! interface FastEthernet3 description *Wi-Fi* switchport access vlan 7 no ip address spanning-tree portfast ! interface Dot11Radio0 ip address 7.7.7.254 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp ip nat inside ip virtual-reassembly in ip verify unicast reverse-path ip tcp adjust-mss 1452 ! encryption mode ciphers aes-ccm ! broadcast-key change 120 ! ! ssid A!t4(^@nd]+*n36C!R286!0=\lyrHe6 ! speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0 power local cck 3 power local ofdm 3 power client 3 channel 2437 station-role root no cdp enable ! interface Vlan1 description *DMZ* ip address 7.0.0.1 255.255.255.0 ! interface Vlan7 description *Wi-Fi* no ip address ! interface Vlan21 ip address 7.21.3.254 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp ip nat inside ip virtual-reassembly in ip verify unicast reverse-path ip tcp adjust-mss 1452 ! interface Dialer13 ip address negotiated ip access-group CBAC in no ip redirects no ip unreachables no ip proxy-arp ip mtu 1492 ip nat outside ip inspect *USHT* out ip virtual-reassembly in max-fragments 24 max-reassemblies 20 ip verify unicast reverse-path encapsulation ppp dialer pool 13 ppp authentication chap callin ppp chap hostname SOLOVJOVA13 ppp chap password 0 133878 no cdp enable ! no ip forward-protocol nd ip http server ip http authentication local ip http secure-server ip http timeout-policy idle 600 life 86400 requests 10000 ! ! ip nat translation timeout 140 ip nat translation tcp-timeout 123 ip nat translation udp-timeout 13 ip nat translation finrst-timeout 6 ip nat translation syn-timeout 10 ip nat translation dns-timeout 3 ip nat translation icmp-timeout 8 ip nat inside source list 13 interface Dialer13 overload ip route 0.0.0.0 0.0.0.0 Dialer13 ! ip access-list extended CBAC deny ip any any fragments deny ip any any deny udp any any fragments deny udp any any ip access-list extended LAN permit tcp any any permit udp any any deny ip any any ip access-list extended NIGHT permit tcp host 7.7.7.33 any permit udp host 7.7.7.33 any deny ip host 7.7.7.69 any time-range NIGHT permit tcp host 7.7.7.69 any permit udp host 7.7.7.69 any deny ip any any access-list 13 permit any no cdp run ! ! ! ! ! control-plane ! ! line con 0 no modem enable line aux 0 line vty 0 4 exec-timeout 40 0 privilege level 15 login local transport input telnet ssh ! scheduler max-task-time 5000 time-range NIGHT periodic daily 22:00 to 23:59 periodic daily 0:00 to 6:00 ! end ****************************************************8 ***************************************************** ***************************************************** PIX Version 8.0(4)28 ! hostname PIX-515E enable password 8Ry2YjIyt7RRXU24 encrypted passwd 2KFQnbNIdI.2KYOU encrypted names dns-guard ! interface Ethernet0 description *TRUNK* speed 100 duplex full no nameif security-level 0 no ip address ! interface Ethernet0.7 vlan 7 nameif *Wi-Fi* security-level 100 ip address 7.7.7.253 255.255.255.0 ! interface Ethernet0.21 vlan 21 nameif *My-Lan* security-level 100 ip address 7.21.3.253 255.255.255.0 ! interface Ethernet1 speed 100 duplex full nameif *DMZ* security-level 0 ip address 7.0.0.253 255.255.255.0 ! interface Ethernet2 shutdown nameif intf2 security-level 4 no ip address ! ! time-range NIGHT periodic daily 22:00 to 23:59 periodic daily 0:00 to 6:00 ! boot system flash:/image.bin ftp mode passive clock timezone **MYT** 4 same-security-traffic permit inter-interface access-list *LAN* extended permit tcp any any access-list *LAN* extended permit udp any any access-list *LAN* extended deny ip any any access-list *WI-FI* extended permit tcp host 7.7.7.33 any access-list *WI-FI* extended permit udp host 7.7.7.33 any access-list *WI-FI* extended deny ip host 7.7.7.69 any time-range NIGHT access-list *WI-FI* extended permit tcp host 7.7.7.69 any access-list *WI-FI* extended permit udp host 7.7.7.69 any access-list *WI-FI* extended deny ip any any ! tcp-map *NORMALIZE-TCP* check-retransmission checksum-verification reserved-bits drop syn-data drop ! pager lines 24 logging enable logging timestamp logging buffer-size 48999 logging buffered informational logging asdm informational no logging message 106023 no logging message 302015 no logging message 302014 no logging message 302013 no logging message 304001 no logging message 302016 no logging message 302021 no logging message 302020 mtu *Wi-Fi* 1500 mtu *My-Lan* 1500 mtu *DMZ* 1500 mtu intf2 1500 ip verify reverse-path interface *Wi-Fi* ip verify reverse-path interface *My-Lan* ip verify reverse-path interface *DMZ* ip audit name *USHT* attack action alarm reset ip audit name *USHT1* info action alarm reset ip audit interface *DMZ* *USHT1* ip audit interface *DMZ* *USHT* ip audit info action alarm reset ip audit attack action alarm reset icmp unreachable rate-limit 1 burst-size 1 icmp permit any *DMZ* icmp permit any *DMZ* asdm image flash:/asdm-615.bin asdm history enable arp timeout 14400 access-group *WI-FI* in interface *Wi-Fi* access-group *LAN* in interface *My-Lan* route *DMZ* 0.0.0.0 0.0.0.0 7.0.0.1 1 timeout xlate 0:05:00 timeout conn 0:05:00 half-closed 0:05:00 udp 0:01:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:00:10 dynamic-access-policy-record DfltAccessPolicy aaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa authentication telnet console LOCAL aaa authentication enable console LOCAL http server enable http 0.0.0.0 0.0.0.0 *My-Lan* http 0.0.0.0 0.0.0.0 *Wi-Fi* no snmp-server location no snmp-server contact snmp-server community ***** snmp-server enable traps snmp authentication linkup linkdown coldstart fragment chain 1 *DMZ* no sysopt connection permit-vpn service resetinbound interface *Wi-Fi* service resetinbound interface *My-Lan* service resetinbound interface *DMZ* service resetoutside crypto ipsec security-association lifetime seconds 28800 crypto ipsec security-association lifetime kilobytes 4608000 telnet 0.0.0.0 0.0.0.0 *Wi-Fi* telnet 0.0.0.0 0.0.0.0 *My-Lan* telnet timeout 10 ssh timeout 5 ssh version 2 console timeout 0 threat-detection basic-threat threat-detection scanning-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept ntp server 85.114.26.194 ssl encryption aes128-sha1 aes256-sha1 username usht password jMChuFDytyRn.007 encrypted privilege 15 ! class-map *NORMALIZE* match any class-map type inspect http match-any *HTTP* class-map inspection_default match default-inspection-traffic ! ! policy-map *NORMALIZE* class *NORMALIZE* set connection conn-max 7887 embryonic-conn-max 788 set connection timeout embryonic 0:00:07 half-closed 0:05:00 tcp 0:05:00 reset set connection advanced-options *NORMALIZE-TCP* policy-map type inspect http *HTTP* parameters protocol-violation action reset log policy-map type inspect dns *DNS* parameters message-length maximum 512 policy-map global_policy class inspection_default inspect ftp inspect h323 h225 inspect h323 ras inspect http *HTTP* inspect netbios inspect rsh inspect rtsp inspect skinny inspect esmtp inspect sqlnet inspect sunrpc inspect tftp inspect sip inspect xdmcp inspect dns *DNS* ! service-policy global_policy global service-policy *NORMALIZE* interface *DMZ* prompt hostname context Cryptochecksum:4923c8e9ce484b40c1f49e2cad44b5cf : end PIX-515E# PIX-515E up 1 day 3 hours Hardware: PIX-515E, 256 MB RAM, CPU Pentium III 796 MHz Flash E28F128J3 @ 0xfff00000, 16MB BIOS Flash AM29F400B @ 0xfffd8000, 32KB 0: Ext: Ethernet0 : address is 000e.38fb.fe5c, irq 10 1: Ext: Ethernet1 : address is 000e.38fb.fe5d, irq 11 2: Ext: Ethernet2 : address is 0002.b3e7.4059, irq 11 Licensed features for this platform: Maximum Physical Interfaces : 3 Maximum VLANs : 10 Inside Hosts : Unlimited Failover : Disabled VPN-DES : Enabled VPN-3DES-AES : Enabled Cut-through Proxy : Enabled Guards : Enabled URL Filtering : Enabled Security Contexts : 0 GTP/GPRS : Disabled VPN Peers : Unlimited This platform has a Restricted (R) license. Serial Number: 807454276 Running Activation Key: 0x7c2ba999 0x0836241c 0x2345fa2d 0x6d293bda Configuration last modified by usht at 23:37:08.453 **MYT** Fri Jul 6 2012 PIX-515E#