Realisations/2006-2007/Projet/Entreprise2/Firewall1: config_SSG20_2007-03-30.cfg

File config_SSG20_2007-03-30.cfg, 6.3 KB (added by alladoum, 18 years ago)
Line 
1set clock ntp
2set clock timezone 1
3set vrouter trust-vr sharable
4set vrouter "untrust-vr"
5set protocol rip
6set enable
7exit
8exit
9set vrouter "trust-vr"
10unset auto-route-export
11set protocol rip
12set enable
13set reject-default-route
14exit
15set preference ebgp 250
16set preference ibgp 40
17exit
18set auth-server "Local" id 0
19set auth-server "Local" server-name "Local"
20set auth default auth server "Local"
21set auth radius accounting port 1646
22set admin name "netscreen"
23set admin password "nI2aKIrXMqTJcydDVslDSvJtm4Jubn"
24set admin user "christophe" password "nMc9KxrRNSZMcnmIAsIIfUHtdRJPwn" privilege "all"
25set admin user "geraldine" password "nC2ALar7NXGBcfaLzsYG1qKtwMP8pn" privilege "all"
26set admin manager-ip 10.0.0.0 255.0.0.0
27set admin http redirect
28set admin mail alert
29set admin mail server-name "10.40.0.9"
30set admin mail mail-addr1 "root@serveur1.ent2"
31set admin mail mail-addr2 "alladoum@tibre"
32set admin mail traffic-log
33set admin auth timeout 10
34set admin auth server "Local"
35set admin auth banner telnet login "Bienvenue sur FIREWALL1.ENT2 (ssg20)"
36set admin format dos
37set zone "Trust" vrouter "trust-vr"
38set zone "Untrust" vrouter "trust-vr"
39set zone "DMZ" vrouter "trust-vr"
40set zone "VLAN" vrouter "trust-vr"
41set zone "Untrust-Tun" vrouter "trust-vr"
42set zone "Trust" tcp-rst
43set zone "Untrust" block
44unset zone "Untrust" tcp-rst
45set zone "DMZ" tcp-rst
46set zone "VLAN" block
47unset zone "VLAN" tcp-rst
48set zone "Untrust" screen alarm-without-drop
49set zone "Untrust" screen icmp-flood
50set zone "Untrust" screen udp-flood
51set zone "Untrust" screen winnuke
52set zone "Untrust" screen port-scan
53set zone "Untrust" screen ip-sweep
54set zone "Untrust" screen tear-drop
55set zone "Untrust" screen syn-flood
56set zone "Untrust" screen ip-spoofing
57set zone "Untrust" screen ping-death
58set zone "Untrust" screen ip-filter-src
59set zone "Untrust" screen land
60set zone "Untrust" screen syn-frag
61set zone "Untrust" screen tcp-no-flag
62set zone "Untrust" screen unknown-protocol
63set zone "Untrust" screen ip-bad-option
64set zone "Untrust" screen ip-record-route
65set zone "Untrust" screen ip-timestamp-opt
66set zone "Untrust" screen ip-security-opt
67set zone "Untrust" screen ip-loose-src-route
68set zone "Untrust" screen ip-strict-src-route
69set zone "Untrust" screen ip-stream-opt
70set zone "Untrust" screen icmp-fragment
71set zone "Untrust" screen icmp-large
72set zone "Untrust" screen syn-fin
73set zone "Untrust" screen fin-no-ack
74set zone "Untrust" screen limit-session source-ip-based
75set zone "Untrust" screen syn-ack-ack-proxy
76set zone "Untrust" screen block-frag
77set zone "Untrust" screen limit-session destination-ip-based
78set zone "Untrust" screen component-block zip
79set zone "Untrust" screen component-block jar
80set zone "Untrust" screen component-block exe
81set zone "Untrust" screen component-block activex
82set zone "Untrust" screen icmp-id
83set zone "Untrust" screen ip-spoofing drop-no-rpf-route
84set zone "V1-Untrust" screen tear-drop
85set zone "V1-Untrust" screen syn-flood
86set zone "V1-Untrust" screen ping-death
87set zone "V1-Untrust" screen ip-filter-src
88set zone "V1-Untrust" screen land
89set interface "ethernet0/0" zone "Untrust"
90set interface "ethernet0/1" zone "DMZ"
91set interface "bgroup0" zone "Trust"
92set interface bgroup0 port ethernet0/2
93set interface bgroup0 port ethernet0/3
94set interface bgroup0 port ethernet0/4
95unset interface vlan1 ip
96set interface ethernet0/0 ip 10.40.0.1/30
97set interface ethernet0/0 route
98set interface bgroup0 ip 10.40.0.14/30
99set interface bgroup0 route
100set interface ethernet0/0 gateway 10.40.0.2
101unset interface vlan1 bypass-others-ipsec
102unset interface vlan1 bypass-non-ip
103set interface ethernet0/0 ip manageable
104set interface bgroup0 ip manageable
105set interface ethernet0/0 manage ping
106set interface ethernet0/0 manage ssh
107set interface ethernet0/0 manage ssl
108unset interface bgroup0 manage telnet
109unset interface bgroup0 manage web
110set interface bgroup0 manage mtrace
111set interface ethernet0/1 dhcp client enable
112set interface "serial0/0" modem settings "USR" init "AT&F"
113set interface "serial0/0" modem settings "USR" active
114set interface "serial0/0" modem speed 115200
115set interface "serial0/0" modem retry 3
116set interface "serial0/0" modem interval 10
117set interface "serial0/0" modem idle-time 10
118set flow tcp-mss
119unset flow tcp-syn-check
120set pki authority default scep mode "auto"
121set pki x509 default cert-path partial
122set ike respond-bad-spi 1
123unset ike ikeid-enumeration
124unset ipsec access-session enable
125set ipsec access-session maximum 5000
126set ipsec access-session upper-threshold 0
127set ipsec access-session lower-threshold 0
128set ipsec access-session dead-p2-sa-timeout 0
129unset ipsec access-session log-error
130unset ipsec access-session info-exch-connected
131unset ipsec access-session use-error-log
132set url protocol websense
133exit
134set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" permit
135set policy id 1
136exit
137set policy id 2 from "Untrust" to "Trust"  "Any" "Any" "ANY" permit
138set policy id 2
139exit
140set monitor cpu 100
141set global-pro policy-manager primary outgoing-interface ethernet0/0
142set global-pro policy-manager secondary outgoing-interface ethernet0/0
143set nsmgmt bulkcli reboot-timeout 60
144set ssh version v2
145set ssh enable
146set scp enable
147set config lock timeout 5
148set ssl encrypt 3des sha-1
149set ntp server "10.40.253.10"
150set ntp server src-interface "ethernet0/0"
151set ntp server backup1 "0.0.0.0"
152set ntp server backup2 "0.0.0.0"
153set snmp community "entreprise2" Read-Write Trap-on  traffic version any
154set snmp location "LIP6"
155set snmp contact "Geraldine,Christophe"
156set snmp name "FIREWALL1.ENT2"
157set snmp port listen 161
158set snmp port trap 162
159set vrouter "untrust-vr"
160exit
161set vrouter "trust-vr"
162unset add-default-route
163exit
164set interface bgroup0 protocol rip
165set interface bgroup0 protocol rip enable
166set interface bgroup0 protocol rip split-horizon poison-reverse
167set interface bgroup0 protocol rip send-version v1v2
168set interface bgroup0 protocol rip receive-version v1v2
169set interface ethernet0/0 protocol rip
170set interface ethernet0/0 protocol rip enable
171set interface ethernet0/0 protocol rip split-horizon poison-reverse
172set interface ethernet0/0 protocol rip send-version v1v2
173set interface ethernet0/0 protocol rip receive-version v1v2
174set vrouter "untrust-vr"
175exit
176set vrouter "trust-vr"
177exit