Realisations/2011-2012/Projet/Entreprise2: ssg202-ent2-cfg.txt

File ssg202-ent2-cfg.txt, 5.7 KB (added by bbaron, 13 years ago)
Line 
1unset key protection enable
2set clock timezone 0
3set vrouter trust-vr sharable
4set vrouter "untrust-vr"
5exit
6set vrouter "trust-vr"
7unset auto-route-export
8exit
9set alg appleichat enable
10unset alg appleichat re-assembly enable
11set alg sctp enable
12set auth-server "Local" id 0
13set auth-server "Local" server-name "Local"
14set auth default auth server "Local"
15set auth radius accounting port 1646
16set admin name "netscreen"
17set admin password "nKVUM2rwMUzPcrkG5sWIHdCtqkAibn"
18set admin telnet port 4656
19set admin auth web timeout 10
20set admin auth dial-in timeout 3
21set admin auth server "Local"
22set admin format dos
23set zone "Trust" vrouter "trust-vr"
24set zone "Untrust" vrouter "trust-vr"
25set zone "DMZ" vrouter "trust-vr"
26set zone "VLAN" vrouter "trust-vr"
27set zone "Untrust-Tun" vrouter "trust-vr"
28set zone "Trust" tcp-rst
29set zone "Untrust" block
30unset zone "Untrust" tcp-rst
31set zone "MGT" block
32unset zone "V1-Trust" tcp-rst
33unset zone "V1-Untrust" tcp-rst
34set zone "DMZ" tcp-rst
35unset zone "V1-DMZ" tcp-rst
36unset zone "VLAN" tcp-rst
37set zone "Untrust" screen tear-drop
38set zone "Untrust" screen syn-flood
39set zone "Untrust" screen ping-death
40set zone "Untrust" screen ip-filter-src
41set zone "Untrust" screen land
42set zone "V1-Untrust" screen tear-drop
43set zone "V1-Untrust" screen syn-flood
44set zone "V1-Untrust" screen ping-death
45set zone "V1-Untrust" screen ip-filter-src
46set zone "V1-Untrust" screen land
47set interface "ethernet0/0" zone "Untrust"
48set interface "ethernet0/1" zone "V1-Trust"
49set interface "ethernet0/2" zone "V1-Untrust"
50set interface "bgroup0" zone "Trust"
51set interface bgroup0 port ethernet0/3
52set interface bgroup0 port ethernet0/4
53set interface vlan1 ip 13.8.254.0/30
54set interface "vlan1" ipv6 mode "host"
55set interface "vlan1" ipv6 ip 2d05:37:0:430::/64
56set interface "vlan1" ipv6 enable
57set interface ethernet0/0 ip 4.11.100.37/28
58set interface ethernet0/0 route
59set interface bgroup0 ip 192.168.1.1/24
60set interface bgroup0 nat
61set interface vlan1 bypass-others-ipsec
62set interface vlan1 bypass-non-ip
63unset interface vlan1 bypass-ipv6-others-ipsec
64set interface vlan1 bypass-icmpv6-ndp
65set interface vlan1 bypass-icmpv6-mld
66unset interface vlan1 bypass-icmpv6-mrd
67unset interface vlan1 bypass-icmpv6-msp
68set interface vlan1 bypass-icmpv6-snd
69set interface vlan1 ip manageable
70set interface ethernet0/0 ip manageable
71set interface bgroup0 ip manageable
72set interface ethernet0/0 manage ping
73set interface ethernet0/0 manage ssh
74set interface ethernet0/0 manage telnet
75set interface ethernet0/0 manage snmp
76set interface ethernet0/0 manage ssl
77set interface ethernet0/0 manage web
78set interface ethernet0/0 manage mtrace
79set interface vlan1 ipv6 nd nud
80set interface bgroup0 dhcp server service
81set interface bgroup0 dhcp server auto
82set interface bgroup0 dhcp server option gateway 192.168.1.1
83set interface bgroup0 dhcp server option netmask 255.255.255.0
84set interface bgroup0 dhcp server ip 192.168.1.33 to 192.168.1.126
85unset interface bgroup0 dhcp server config next-server-ip
86set interface "serial0/0" modem settings "USR" init "AT&F"
87set interface "serial0/0" modem settings "USR" active
88set interface "serial0/0" modem speed 115200
89set interface "serial0/0" modem retry 3
90set interface "serial0/0" modem interval 10
91set interface "serial0/0" modem idle-time 10
92set flow tcp-mss
93unset flow no-tcp-seq-check
94set flow tcp-syn-check
95unset flow tcp-syn-bit-check
96set flow reverse-route clear-text prefer
97set flow reverse-route tunnel always
98set pki authority default scep mode "auto"
99set pki x509 default cert-path partial
100set crypto-policy
101exit
102set ike respond-bad-spi 1
103set ike ikev2 ike-sa-soft-lifetime 60
104unset ike ikeid-enumeration
105unset ike dos-protection
106unset ipsec access-session enable
107set ipsec access-session maximum 5000
108set ipsec access-session upper-threshold 0
109set ipsec access-session lower-threshold 0
110set ipsec access-session dead-p2-sa-timeout 0
111unset ipsec access-session log-error
112unset ipsec access-session info-exch-connected
113unset ipsec access-session use-error-log
114set vrouter "untrust-vr"
115exit
116set vrouter "trust-vr"
117exit
118set url protocol websense
119exit
120set policy default-permit-all
121set policy id 1 from "Trust" to "Untrust"  "Any-IPv4" "Any-IPv4" "ANY" permit
122set policy id 1
123exit
124set policy id 2 from "V1-Trust" to "V1-Untrust"  "Any-IPv4" "Any-IPv4" "ANY" permit
125set policy id 2
126exit
127set policy id 3 from "V1-Untrust" to "V1-Trust"  "Any-IPv4" "Any-IPv4" "ANY" permit
128set policy id 3
129exit
130set policy id 4 from "V1-Trust" to "V1-Untrust"  "Any-IPv6" "Any-IPv6" "ANY" permit
131set policy id 4
132exit
133set policy id 5 from "V1-Untrust" to "V1-Trust"  "Any-IPv6" "Any-IPv6" "ANY" permit
134set policy id 5
135exit
136set policy id 6 from "Trust" to "Untrust"  "Any-IPv6" "Any-IPv6" "ANY" permit
137set policy id 6
138exit
139set policy id 7 from "Untrust" to "Trust"  "Any-IPv6" "Any-IPv6" "ANY" permit
140set policy id 7
141exit
142set nsmgmt bulkcli reboot-timeout 60
143set ssh version v2
144set config lock timeout 5
145set license-key auto-update
146set telnet client enable
147set snmp community "public" Read-Only Trap-on traffic version v2c 
148set snmp location "Paris"
149set snmp contact "Olivier Fourmaux"
150set snmp name "firewall2"
151set snmp port listen 161
152set snmp port trap 162
153set vrouter "untrust-vr"
154exit
155set vrouter "trust-vr"
156unset add-default-route
157set route 0.0.0.0/0 interface vlan1 gateway 13.8.254.1
158set route 4.11.100.0/24 interface vlan1 gateway 13.8.254.2
159set route 2a00:285:42::/48 interface vlan1 gateway 2d05:13:0:420::2
160set route ::/0 interface vlan1 gateway 2d05:37:0:430::1
161set route 2a00:285:42::/64 interface vlan1 gateway 2d05:37:254:430::2
162exit
163set vrouter "untrust-vr"
164exit
165set vrouter "trust-vr"
166exit