Realisations/2006-2007/Projet/Entreprise2/Firewall1: config_SSG20_2007-05-19.cfg

File config_SSG20_2007-05-19.cfg, 8.6 KB (added by alladoum, 18 years ago)
Line 
1set clock ntp
2set clock timezone 1
3set vrouter trust-vr sharable
4set vrouter "untrust-vr"
5exit
6set vrouter "trust-vr"
7unset auto-route-export
8set protocol rip
9set enable
10set reject-default-route
11set no-source-validation
12set summary-ip 10.40.254.0/24 metric 2
13exit
14set preference ebgp 250
15set preference ibgp 40
16exit
17set service "NetPerf_sortant" protocol tcp src-port 10987-10987 dst-port 0-65535
18set service "NetPerf_sortant" + tcp src-port 10985-10985 dst-port 0-65535
19set service "NetPerf_entrant" protocol tcp src-port 0-65535 dst-port 10987-10987
20set service "NetPerf_entrant" + tcp src-port 0-65535 dst-port 10985-10985
21set service "OpenVPN_sortant" protocol tcp src-port 1194-1194 dst-port 0-65535
22set service "OpenVPN_entrant" protocol tcp src-port 0-65535 dst-port 1194-1194
23set service "Iperf_sortant" protocol udp src-port 10985-10989 dst-port 0-65535
24set service "Iperf_entrant" protocol udp src-port 0-65535 dst-port 10985-10989
25set service "zabbix_entrant" protocol tcp src-port 0-65535 dst-port 10050-10051
26set service "zabbix_sortant" protocol tcp src-port 10050-10051 dst-port 0-65535
27set service "QoS_DITG_entrant" protocol udp src-port 0-65535 dst-port 10000-10010
28set service "QoS_DITG_entrant_2" protocol tcp src-port 0-65535 dst-port 9000-9000
29set auth-server "Local" id 0
30set auth-server "Local" server-name "Local"
31set auth default auth server "Local"
32set auth radius accounting port 1646
33set admin name "netscreen"
34set admin password "nI2aKIrXMqTJcydDVslDSvJtm4Jubn"
35set admin user "geraldine" password "nC2ALar7NXGBcfaLzsYG1qKtwMP8pn" privilege "all"
36set admin user "christophe" password "nMc9KxrRNSZMcnmIAsIIfUHtdRJPwn" privilege "all"
37set admin http redirect
38set admin mail server-name "132.227.74.2"
39set admin mail mail-addr1 "andre@tibre"
40set admin mail mail-addr2 "alladoum@tibre"
41set admin mail traffic-log
42set admin auth timeout 10
43set admin auth server "Local"
44set admin auth banner telnet login "Bienvenue sur FIREWALL1.ENT2"
45set admin auth banner console login "Bienvenue sur FIREWALL1.ENT2"
46set admin privilege read-write
47set admin format dos
48set zone "Trust" vrouter "trust-vr"
49set zone "Untrust" vrouter "trust-vr"
50set zone "DMZ" vrouter "trust-vr"
51set zone "VLAN" vrouter "trust-vr"
52set zone "Untrust-Tun" vrouter "trust-vr"
53set zone "Trust" tcp-rst
54set zone "Untrust" block
55unset zone "Untrust" tcp-rst
56set zone "DMZ" tcp-rst
57set zone "VLAN" block
58unset zone "VLAN" tcp-rst
59set zone "Trust" screen icmp-flood
60set zone "Trust" screen udp-flood
61set zone "Trust" screen winnuke
62set zone "Trust" screen port-scan
63set zone "Trust" screen syn-flood
64set zone "Trust" screen ping-death
65set zone "Untrust" screen tear-drop
66set zone "Untrust" screen syn-flood
67set zone "Untrust" screen ping-death
68set zone "Untrust" screen ip-filter-src
69set zone "Untrust" screen land
70set zone "V1-Untrust" screen tear-drop
71set zone "V1-Untrust" screen syn-flood
72set zone "V1-Untrust" screen ping-death
73set zone "V1-Untrust" screen ip-filter-src
74set zone "V1-Untrust" screen land
75set interface "ethernet0/0" zone "Untrust"
76set interface "ethernet0/1" zone "DMZ"
77set interface "bgroup0" zone "Trust"
78set interface bgroup0 port ethernet0/2
79set interface bgroup0 port ethernet0/3
80set interface bgroup0 port ethernet0/4
81unset interface vlan1 ip
82set interface ethernet0/0 ip 10.40.0.1/30
83set interface "ethernet0/0" ipv6 mode "router"
84set interface "ethernet0/0" ipv6 interface-id 0000000000000002
85set interface "ethernet0/0" ipv6 ip 2001:db8:4:10::1/64
86set interface "ethernet0/0" ipv6 enable
87set interface ethernet0/0 route
88set interface bgroup0 ip 10.40.0.14/30
89set interface "bgroup0" ipv6 mode "router"
90set interface "bgroup0" ipv6 ip 2001:db8:4:11::1/64
91set interface "bgroup0" ipv6 enable
92set interface bgroup0 route
93unset interface vlan1 bypass-others-ipsec
94unset interface vlan1 bypass-non-ip
95set interface ethernet0/0 ip manageable
96set interface bgroup0 ip manageable
97set interface ethernet0/0 manage ping
98set interface ethernet0/0 manage ssh
99set interface ethernet0/0 manage telnet
100set interface ethernet0/0 manage snmp
101set interface ethernet0/0 manage ssl
102set interface ethernet0/0 manage web
103set interface bgroup0 manage mtrace
104set interface ethernet0/0 ipv6 ra link-mtu
105set interface ethernet0/0 ipv6 ra link-address
106set interface ethernet0/0 ipv6 ra transmit
107set interface bgroup0 ipv6 ra link-mtu
108set interface bgroup0 ipv6 ra link-address
109set interface bgroup0 ipv6 ra retransmit-time
110set interface bgroup0 ipv6 ra reachable-time
111set interface bgroup0 ipv6 ra transmit
112set interface ethernet0/0 ipv6 nd nud
113set interface bgroup0 ipv6 nd nud
114set interface ethernet0/1 dhcp client enable
115set interface "serial0/0" modem settings "USR" init "AT&F"
116set interface "serial0/0" modem settings "USR" active
117set interface "serial0/0" modem speed 115200
118set interface "serial0/0" modem retry 3
119set interface "serial0/0" modem interval 10
120set interface "serial0/0" modem idle-time 10
121set flow tcp-mss
122unset flow tcp-syn-check
123set domain ent2.p6
124set hostname firewall1
125set pki authority default scep mode "auto"
126set pki x509 default cert-path partial
127set dns host dns1 10.40.0.9 src-interface ethernet0/0
128set dns host dns2 0.0.0.0
129set dns host dns3 0.0.0.0
130set address "Trust" "10.40.0.5/32" 10.40.0.5 255.255.255.255
131set address "Trust" "10.40.0.9/32" 10.40.0.9 255.255.255.255
132set address "Trust" "10.40.253.1/32" 10.40.253.1 255.255.255.255
133set address "Untrust" "10.10.0.0/16" 10.10.0.0 255.255.0.0
134set address "Untrust" "10.40.0.5/32" 10.40.0.5 255.255.255.255
135set address "Untrust" "10.40.0.9/32" 10.40.0.9 255.255.255.255
136set address "Untrust" "10.40.253.1/32" 10.40.253.1 255.255.255.255
137set address "Untrust" "10.40.253.10/32" 10.40.253.10 255.255.255.255
138set user "christophe" uid 1
139set user "christophe" type  auth
140set user "christophe" hash-password "02PrIj9I081CRLVmc/8B+TNYdSf22msniLh6s="
141set user "christophe" "enable"
142set ike respond-bad-spi 1
143unset ike ikeid-enumeration
144unset ipsec access-session enable
145set ipsec access-session maximum 5000
146set ipsec access-session upper-threshold 0
147set ipsec access-session lower-threshold 0
148set ipsec access-session dead-p2-sa-timeout 0
149unset ipsec access-session log-error
150unset ipsec access-session info-exch-connected
151unset ipsec access-session use-error-log
152set url protocol websense
153exit
154set policy id 20 from "Trust" to "Untrust"  "Any-IPv6" "Any-IPv6" "ANY" permit
155set policy id 20
156exit
157set policy id 22 from "Untrust" to "Trust"  "Any-IPv6" "Any-IPv6" "ANY" permit
158set policy id 22
159exit
160set policy id 13 from "Untrust" to "Trust"  "Any-IPv4" "Any-IPv4" "ANY" permit
161set policy id 13
162exit
163set policy id 14 from "Trust" to "Untrust"  "Any-IPv4" "Any-IPv4" "ANY" permit
164set policy id 14
165exit
166set monitor cpu 100
167unset log module system level emergency destination NSM
168unset log module system level alert destination NSM
169unset log module system level critical destination NSM
170unset log module system level error destination NSM
171unset log module system level warning destination NSM
172unset log module system level notification destination NSM
173unset log module system level information destination NSM
174unset log module system level debugging destination NSM
175set global-pro policy-manager primary outgoing-interface ethernet0/0
176set global-pro policy-manager secondary outgoing-interface ethernet0/0
177set nsmgmt bulkcli reboot-timeout 60
178set ssh version v2
179set ssh enable
180set scp enable
181set config lock timeout 5
182set ntp server "10.40.253.10"
183set ntp server backup1 "0.0.0.0"
184set ntp server backup2 "0.0.0.0"
185set snmp community "entreprise2" Read-Only Trap-on  version v1
186set snmp location "LIP6"
187set snmp contact "Geraldine,Christophe"
188set snmp name "FIREWALL2.ENT2"
189set snmp port listen 161
190set snmp port trap 162
191set vrouter "untrust-vr"
192exit
193set vrouter "trust-vr"
194set adv-inact-interface
195set access-list 20
196set access-list 20 permit ip 10.40.254.0/24 1
197set route-map name "vpnmap" permit 1
198set match ip 20
199exit
200unset add-default-route
201set protocol rip
202set redistribute route-map "vpnmap" protocol static
203exit
204set protocol ripng
205set enable
206set reject-default-route
207exit
208exit
209set interface ethernet0/0 protocol rip
210set interface ethernet0/0 protocol rip enable
211set interface ethernet0/0 protocol rip send-version v2
212set interface ethernet0/0 protocol rip receive-version v2
213set interface ethernet0/0 protocol rip summary-enable
214set interface bgroup0 protocol rip
215set interface bgroup0 protocol rip enable
216set interface bgroup0 protocol rip send-version v2
217set interface bgroup0 protocol rip receive-version v2
218set interface bgroup0 protocol rip summary-enable
219set vrouter "untrust-vr"
220exit
221set vrouter "trust-vr"
222exit