Realisations/2006-2007/Projet/Entreprise2/Firewall1: config_SSG20_2007-01-19.cfg

File config_SSG20_2007-01-19.cfg, 3.5 KB (added by alladoum, 18 years ago)
Line 
1# saved_cfg_timestamp:317141427 ##############################################################################################
2set clock dst-off
3set clock timezone 1
4set vrouter trust-vr sharable
5set vrouter "untrust-vr"
6exit
7set vrouter "trust-vr"
8unset auto-route-export
9exit
10set auth-server "Local" id 0
11set auth-server "Local" server-name "Local"
12set auth default auth server "Local"
13set auth radius accounting port 1646
14set admin name "netscreen"
15set admin password "nKVUM2rwMUzPcrkG5sWIHdCtqkAibn"
16set admin auth timeout 10
17set admin auth server "Local"
18set admin format dos
19set zone "Trust" vrouter "trust-vr"
20set zone "Untrust" vrouter "trust-vr"
21set zone "DMZ" vrouter "trust-vr"
22set zone "VLAN" vrouter "trust-vr"
23set zone "Untrust-Tun" vrouter "trust-vr"
24set zone "Trust" tcp-rst
25set zone "Untrust" block
26unset zone "Untrust" tcp-rst
27set zone "DMZ" tcp-rst
28set zone "VLAN" block
29unset zone "VLAN" tcp-rst
30set zone "Untrust" screen tear-drop
31set zone "Untrust" screen syn-flood
32set zone "Untrust" screen ping-death
33set zone "Untrust" screen ip-filter-src
34set zone "Untrust" screen land
35set zone "V1-Untrust" screen tear-drop
36set zone "V1-Untrust" screen syn-flood
37set zone "V1-Untrust" screen ping-death
38set zone "V1-Untrust" screen ip-filter-src
39set zone "V1-Untrust" screen land
40set interface "ethernet0/0" zone "Untrust"
41set interface "ethernet0/1" zone "DMZ"
42set interface "bgroup0" zone "Trust"
43set interface bgroup0 port ethernet0/2
44set interface bgroup0 port ethernet0/3
45set interface bgroup0 port ethernet0/4
46unset interface vlan1 ip
47set interface ethernet0/0 ip 10.40.0.1/30
48set interface ethernet0/0 route
49set interface bgroup0 ip 10.40.0.14/30
50set interface bgroup0 nat
51set interface ethernet0/0 gateway 10.40.0.2
52unset interface vlan1 bypass-others-ipsec
53unset interface vlan1 bypass-non-ip
54set interface ethernet0/0 ip manageable
55set interface bgroup0 ip manageable
56set interface bgroup0 manage mtrace
57set interface ethernet0/1 dhcp client enable
58set interface "serial0/0" modem settings "USR" init "AT&F"
59set interface "serial0/0" modem settings "USR" active
60set interface "serial0/0" modem speed 115200
61set interface "serial0/0" modem retry 3
62set interface "serial0/0" modem interval 10
63set interface "serial0/0" modem idle-time 10
64set flow tcp-mss
65unset flow tcp-syn-check
66set pki authority default scep mode "auto"
67set pki x509 default cert-path partial
68set ike respond-bad-spi 1
69unset ike ikeid-enumeration
70unset ipsec access-session enable
71set ipsec access-session maximum 5000
72set ipsec access-session upper-threshold 0
73set ipsec access-session lower-threshold 0
74set ipsec access-session dead-p2-sa-timeout 0
75unset ipsec access-session log-error
76unset ipsec access-session info-exch-connected
77unset ipsec access-session use-error-log
78set url protocol websense
79exit
80set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" permit
81set policy id 1
82exit
83set policy id 2 from "Untrust" to "Trust"  "Any" "Any" "ANY" permit
84set policy id 2
85exit
86set monitor cpu 100
87set global-pro policy-manager primary outgoing-interface ethernet0/0
88set global-pro policy-manager secondary outgoing-interface ethernet0/0
89set nsmgmt bulkcli reboot-timeout 60
90set ssh version v2
91set config lock timeout 5
92set ntp server "10.40.0.13"
93set ntp server backup1 "0.0.0.0"
94set ntp server backup2 "0.0.0.0"
95set snmp port listen 161
96set snmp port trap 162
97set vrouter "untrust-vr"
98exit
99set vrouter "trust-vr"
100unset add-default-route
101exit
102set vrouter "untrust-vr"
103exit
104set vrouter "trust-vr"
105exit