1
1
: Saved
2
2
3
3
:
4
- : Serial Number: 9AFH30Q99A3
4
+ : Serial Number: 9A1GJWWR10F
5
5
: Hardware: ASAv, 2048 MB RAM, CPU Xeon 4100 /6100 /8100 series 2500 MHz
6
6
:
7
7
ASA Version 9.16 (4 )57
@@ -20,7 +20,7 @@ no mac-address auto
20
20
interface GigabitEthernet0/0
21
21
description fw -> int [external]
22
22
nameif GigabitEthernet0/0
23
- security-level 0
23
+ security-level 100
24
24
ip address 172.16.1.1 255.255.255.0
25
25
!
26
26
interface GigabitEthernet0/1
@@ -38,9 +38,11 @@ interface Management0/0
38
38
ftp mode passive
39
39
dns server-group DefaultDNS
40
40
domain-name lab.local
41
+ access-list ALLOW_INTERNAL extended permit ip 172.16.0.0 255.255.0.0 any log
41
42
pager lines 23
42
- mtu inside 1500
43
- mtu outside 1500
43
+ logging monitor debugging
44
+ mtu GigabitEthernet0/0 1500
45
+ mtu GigabitEthernet0/1 1500
44
46
mtu management 1500
45
47
no failover
46
48
no failover wait-disable
@@ -50,6 +52,7 @@ no asdm history enable
50
52
arp timeout 14400
51
53
no arp permit-nonconnected
52
54
arp rate-limit 8192
55
+ access-group ALLOW_INTERNAL in interface GigabitEthernet0/0
53
56
router bgp 65000
54
57
bgp log-neighbor-changes
55
58
bgp router-id 10.0.0.1
@@ -233,6 +236,7 @@ policy-map global_policy
233
236
inspect sqlnet
234
237
inspect sip
235
238
inspect skinny
239
+ inspect icmp
236
240
policy-map type inspect dns migrated_dns_map_2
237
241
parameters
238
242
message-length maximum client auto
@@ -261,5 +265,5 @@ call-home
261
265
profile License
262
266
destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
263
267
destination transport-method http
264
- Cryptochecksum:177 ef40ec20b04cf3290eb46285d28d1
268
+ Cryptochecksum:ebb3cddc78118910421126ac82742707
265
269
: end
0 commit comments