Realisations/2006-2007/Projet/Entreprise2/Firewall1: config_SSG20_2007-03-09.cfg

File config_SSG20_2007-03-09.cfg, 5.6 KB (added by alladoum, 18 years ago)
Line 
1set clock ntp
2set clock timezone 1
3set vrouter trust-vr sharable
4set vrouter "untrust-vr"
5exit
6set vrouter "trust-vr"
7unset auto-route-export
8exit
9set auth-server "Local" id 0
10set auth-server "Local" server-name "Local"
11set auth default auth server "Local"
12set auth radius accounting port 1646
13set admin name "netscreen"
14set admin password "nI2aKIrXMqTJcydDVslDSvJtm4Jubn"
15set admin user "christophe" password "nMc9KxrRNSZMcnmIAsIIfUHtdRJPwn" privilege "all"
16set admin user "geraldine" password "nC2ALar7NXGBcfaLzsYG1qKtwMP8pn" privilege "all"
17set admin manager-ip 10.0.0.0 255.0.0.0
18set admin http redirect
19set admin mail alert
20set admin mail server-name "10.40.0.9"
21set admin mail mail-addr1 "lagege1983@hotmail.com"
22set admin mail mail-addr2 "christophe.alladoum@rp.lip6.fr"
23set admin mail traffic-log
24set admin auth timeout 10
25set admin auth server "Local"
26set admin auth banner telnet login "Bienvenue sur FIREWALL1.ENT2 (ssg20)"
27set admin format dos
28set zone "Trust" vrouter "trust-vr"
29set zone "Untrust" vrouter "trust-vr"
30set zone "DMZ" vrouter "trust-vr"
31set zone "VLAN" vrouter "trust-vr"
32set zone "Untrust-Tun" vrouter "trust-vr"
33set zone "Trust" tcp-rst
34set zone "Untrust" block
35unset zone "Untrust" tcp-rst
36set zone "DMZ" tcp-rst
37set zone "VLAN" block
38unset zone "VLAN" tcp-rst
39set zone "Untrust" screen alarm-without-drop
40set zone "Untrust" screen icmp-flood
41set zone "Untrust" screen udp-flood
42set zone "Untrust" screen winnuke
43set zone "Untrust" screen port-scan
44set zone "Untrust" screen ip-sweep
45set zone "Untrust" screen tear-drop
46set zone "Untrust" screen syn-flood
47set zone "Untrust" screen ip-spoofing
48set zone "Untrust" screen ping-death
49set zone "Untrust" screen ip-filter-src
50set zone "Untrust" screen land
51set zone "Untrust" screen syn-frag
52set zone "Untrust" screen tcp-no-flag
53set zone "Untrust" screen unknown-protocol
54set zone "Untrust" screen ip-bad-option
55set zone "Untrust" screen ip-record-route
56set zone "Untrust" screen ip-timestamp-opt
57set zone "Untrust" screen ip-security-opt
58set zone "Untrust" screen ip-loose-src-route
59set zone "Untrust" screen ip-strict-src-route
60set zone "Untrust" screen ip-stream-opt
61set zone "Untrust" screen icmp-fragment
62set zone "Untrust" screen icmp-large
63set zone "Untrust" screen syn-fin
64set zone "Untrust" screen fin-no-ack
65set zone "Untrust" screen limit-session source-ip-based
66set zone "Untrust" screen syn-ack-ack-proxy
67set zone "Untrust" screen block-frag
68set zone "Untrust" screen limit-session destination-ip-based
69set zone "Untrust" screen component-block zip
70set zone "Untrust" screen component-block jar
71set zone "Untrust" screen component-block exe
72set zone "Untrust" screen component-block activex
73set zone "Untrust" screen icmp-id
74set zone "Untrust" screen ip-spoofing drop-no-rpf-route
75set zone "V1-Untrust" screen tear-drop
76set zone "V1-Untrust" screen syn-flood
77set zone "V1-Untrust" screen ping-death
78set zone "V1-Untrust" screen ip-filter-src
79set zone "V1-Untrust" screen land
80set interface "ethernet0/0" zone "Untrust"
81set interface "ethernet0/1" zone "DMZ"
82set interface "bgroup0" zone "Trust"
83set interface bgroup0 port ethernet0/2
84set interface bgroup0 port ethernet0/3
85set interface bgroup0 port ethernet0/4
86unset interface vlan1 ip
87set interface ethernet0/0 ip 10.40.0.1/30
88set interface ethernet0/0 route
89set interface bgroup0 ip 10.40.0.14/30
90set interface bgroup0 route
91set interface ethernet0/0 gateway 10.40.0.2
92unset interface vlan1 bypass-others-ipsec
93unset interface vlan1 bypass-non-ip
94set interface ethernet0/0 ip manageable
95set interface bgroup0 ip manageable
96unset interface bgroup0 manage telnet
97unset interface bgroup0 manage web
98set interface bgroup0 manage mtrace
99set interface ethernet0/1 dhcp client enable
100set interface "serial0/0" modem settings "USR" init "AT&F"
101set interface "serial0/0" modem settings "USR" active
102set interface "serial0/0" modem speed 115200
103set interface "serial0/0" modem retry 3
104set interface "serial0/0" modem interval 10
105set interface "serial0/0" modem idle-time 10
106set flow tcp-mss
107unset flow tcp-syn-check
108set pki authority default scep mode "auto"
109set pki x509 default cert-path partial
110set ike respond-bad-spi 1
111unset ike ikeid-enumeration
112unset ipsec access-session enable
113set ipsec access-session maximum 5000
114set ipsec access-session upper-threshold 0
115set ipsec access-session lower-threshold 0
116set ipsec access-session dead-p2-sa-timeout 0
117unset ipsec access-session log-error
118unset ipsec access-session info-exch-connected
119unset ipsec access-session use-error-log
120set url protocol websense
121exit
122set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" permit
123set policy id 1
124exit
125set policy id 2 from "Untrust" to "Trust"  "Any" "Any" "ANY" permit
126set policy id 2
127exit
128set monitor cpu 100
129set global-pro policy-manager primary outgoing-interface ethernet0/0
130set global-pro policy-manager secondary outgoing-interface ethernet0/0
131set nsmgmt bulkcli reboot-timeout 60
132set ssh version v2
133set ssh enable
134set scp enable
135set config lock timeout 5
136set ssl encrypt 3des sha-1
137set ntp server "10.40.253.10"
138set ntp server src-interface "ethernet0/0"
139set ntp server backup1 "0.0.0.0"
140set ntp server backup2 "0.0.0.0"
141set snmp community "entreprise2" Read-Write Trap-on  traffic version any
142set snmp location "Paris,France"
143set snmp contact "Geraldine,Christophe"
144set snmp name "FIREWALL1.ENT2"
145set snmp port listen 161
146set snmp port trap 162
147set vrouter "untrust-vr"
148exit
149set vrouter "trust-vr"
150unset add-default-route
151exit
152set vrouter "untrust-vr"
153exit
154set vrouter "trust-vr"
155exit