1 | unset key protection enable
|
---|
2 | set clock timezone 0
|
---|
3 | set vrouter trust-vr sharable
|
---|
4 | set vrouter "untrust-vr"
|
---|
5 | exit
|
---|
6 | set vrouter "trust-vr"
|
---|
7 | unset auto-route-export
|
---|
8 | exit
|
---|
9 | set alg appleichat enable
|
---|
10 | unset alg appleichat re-assembly enable
|
---|
11 | set alg sctp enable
|
---|
12 | set auth-server "Local" id 0
|
---|
13 | set auth-server "Local" server-name "Local"
|
---|
14 | set auth default auth server "Local"
|
---|
15 | set auth radius accounting port 1646
|
---|
16 | set admin name "netscreen"
|
---|
17 | set admin password "nKVUM2rwMUzPcrkG5sWIHdCtqkAibn"
|
---|
18 | set admin auth web timeout 10
|
---|
19 | set admin auth dial-in timeout 3
|
---|
20 | set admin auth server "Local"
|
---|
21 | set admin format dos
|
---|
22 | set zone "Trust" vrouter "trust-vr"
|
---|
23 | set zone "Untrust" vrouter "trust-vr"
|
---|
24 | set zone "DMZ" vrouter "trust-vr"
|
---|
25 | set zone "VLAN" vrouter "trust-vr"
|
---|
26 | set zone "Untrust-Tun" vrouter "trust-vr"
|
---|
27 | set zone "Trust" tcp-rst
|
---|
28 | set zone "Untrust" block
|
---|
29 | unset zone "Untrust" tcp-rst
|
---|
30 | set zone "MGT" block
|
---|
31 | unset zone "V1-Trust" tcp-rst
|
---|
32 | unset zone "V1-Untrust" tcp-rst
|
---|
33 | set zone "DMZ" tcp-rst
|
---|
34 | unset zone "V1-DMZ" tcp-rst
|
---|
35 | unset zone "VLAN" tcp-rst
|
---|
36 | set zone "Untrust" screen tear-drop
|
---|
37 | set zone "Untrust" screen syn-flood
|
---|
38 | set zone "Untrust" screen ping-death
|
---|
39 | set zone "Untrust" screen ip-filter-src
|
---|
40 | set zone "Untrust" screen land
|
---|
41 | set zone "V1-Untrust" screen tear-drop
|
---|
42 | set zone "V1-Untrust" screen syn-flood
|
---|
43 | set zone "V1-Untrust" screen ping-death
|
---|
44 | set zone "V1-Untrust" screen ip-filter-src
|
---|
45 | set zone "V1-Untrust" screen land
|
---|
46 | set interface "ethernet0/0" zone "Untrust"
|
---|
47 | set interface "ethernet0/1" zone "V1-Trust"
|
---|
48 | set interface "ethernet0/2" zone "V1-Untrust"
|
---|
49 | set interface "bgroup0" zone "Trust"
|
---|
50 | set interface bgroup0 port ethernet0/3
|
---|
51 | set interface bgroup0 port ethernet0/4
|
---|
52 | set interface vlan1 ip 28.5.254.8/30
|
---|
53 | set interface ethernet0/0 ip 4.11.100.36/28
|
---|
54 | set interface ethernet0/0 route
|
---|
55 | set interface bgroup0 ip 192.168.1.1/24
|
---|
56 | set interface bgroup0 nat
|
---|
57 | unset interface vlan1 bypass-others-ipsec
|
---|
58 | unset interface vlan1 bypass-non-ip
|
---|
59 | unset interface vlan1 bypass-ipv6-others-ipsec
|
---|
60 | set interface vlan1 bypass-icmpv6-ndp
|
---|
61 | set interface vlan1 bypass-icmpv6-mld
|
---|
62 | unset interface vlan1 bypass-icmpv6-mrd
|
---|
63 | unset interface vlan1 bypass-icmpv6-msp
|
---|
64 | set interface vlan1 bypass-icmpv6-snd
|
---|
65 | set interface vlan1 ip manageable
|
---|
66 | set interface ethernet0/0 ip manageable
|
---|
67 | set interface bgroup0 ip manageable
|
---|
68 | set interface ethernet0/0 manage ping
|
---|
69 | set interface ethernet0/0 manage ssh
|
---|
70 | set interface ethernet0/0 manage telnet
|
---|
71 | set interface ethernet0/0 manage snmp
|
---|
72 | set interface ethernet0/0 manage ssl
|
---|
73 | set interface ethernet0/0 manage web
|
---|
74 | set interface ethernet0/0 manage mtrace
|
---|
75 | set interface bgroup0 dhcp server service
|
---|
76 | set interface bgroup0 dhcp server auto
|
---|
77 | set interface bgroup0 dhcp server option gateway 192.168.1.1
|
---|
78 | set interface bgroup0 dhcp server option netmask 255.255.255.0
|
---|
79 | set interface bgroup0 dhcp server ip 192.168.1.33 to 192.168.1.126
|
---|
80 | unset interface bgroup0 dhcp server config next-server-ip
|
---|
81 | set interface "serial0/0" modem settings "USR" init "AT&F"
|
---|
82 | set interface "serial0/0" modem settings "USR" active
|
---|
83 | set interface "serial0/0" modem speed 115200
|
---|
84 | set interface "serial0/0" modem retry 3
|
---|
85 | set interface "serial0/0" modem interval 10
|
---|
86 | set interface "serial0/0" modem idle-time 10
|
---|
87 | set flow tcp-mss
|
---|
88 | unset flow no-tcp-seq-check
|
---|
89 | set flow tcp-syn-check
|
---|
90 | unset flow tcp-syn-bit-check
|
---|
91 | set flow reverse-route clear-text prefer
|
---|
92 | set flow reverse-route tunnel always
|
---|
93 | set pki authority default scep mode "auto"
|
---|
94 | set pki x509 default cert-path partial
|
---|
95 | set crypto-policy
|
---|
96 | exit
|
---|
97 | set ike respond-bad-spi 1
|
---|
98 | set ike ikev2 ike-sa-soft-lifetime 60
|
---|
99 | unset ike ikeid-enumeration
|
---|
100 | unset ike dos-protection
|
---|
101 | unset ipsec access-session enable
|
---|
102 | set ipsec access-session maximum 5000
|
---|
103 | set ipsec access-session upper-threshold 0
|
---|
104 | set ipsec access-session lower-threshold 0
|
---|
105 | set ipsec access-session dead-p2-sa-timeout 0
|
---|
106 | unset ipsec access-session log-error
|
---|
107 | unset ipsec access-session info-exch-connected
|
---|
108 | unset ipsec access-session use-error-log
|
---|
109 | set vrouter "untrust-vr"
|
---|
110 | exit
|
---|
111 | set vrouter "trust-vr"
|
---|
112 | exit
|
---|
113 | set url protocol websense
|
---|
114 | exit
|
---|
115 | set policy id 1 from "Trust" to "Untrust" "Any-IPv4" "Any-IPv4" "ANY" permit
|
---|
116 | set policy id 1
|
---|
117 | exit
|
---|
118 | set policy id 2 from "V1-Trust" to "V1-Untrust" "Any-IPv4" "Any-IPv4" "ANY" permit
|
---|
119 | set policy id 2
|
---|
120 | exit
|
---|
121 | set policy id 3 from "V1-Untrust" to "V1-Trust" "Any-IPv4" "Any-IPv4" "ANY" permit
|
---|
122 | set policy id 3
|
---|
123 | exit
|
---|
124 | set policy id 4 from "V1-Trust" to "V1-Untrust" "Any-IPv6" "Any-IPv6" "ANY" permit
|
---|
125 | set policy id 4
|
---|
126 | exit
|
---|
127 | set policy id 5 from "V1-Untrust" to "V1-Trust" "Any-IPv6" "Any-IPv6" "ANY" permit
|
---|
128 | set policy id 5
|
---|
129 | exit
|
---|
130 | set nsmgmt bulkcli reboot-timeout 60
|
---|
131 | set ssh version v2
|
---|
132 | set config lock timeout 5
|
---|
133 | set license-key auto-update
|
---|
134 | set telnet client enable
|
---|
135 | set snmp community "public" Read-Only Trap-on traffic version any
|
---|
136 | set snmp community "test" Read-Write Trap-on traffic version v1
|
---|
137 | set snmp location "Paris"
|
---|
138 | set snmp contact "Olivier Fourmaux"
|
---|
139 | set snmp name "firewall1"
|
---|
140 | unset snmp auth-trap enable
|
---|
141 | set snmp port listen 161
|
---|
142 | set snmp port trap 162
|
---|
143 | set vrouter "untrust-vr"
|
---|
144 | exit
|
---|
145 | set vrouter "trust-vr"
|
---|
146 | unset add-default-route
|
---|
147 | set route 4.11.100.0/2 interface vlan1 gateway 28.5.254.10
|
---|
148 | set route 0.0.0.0/0 interface vlan1 gateway 28.5.254.9
|
---|
149 | exit
|
---|
150 | set vrouter "untrust-vr"
|
---|
151 | exit
|
---|
152 | set vrouter "trust-vr"
|
---|
153 | exit
|
---|