Files
fwbuilder/test/pix/firewall14.fw.orig
T
Vadim Kurland 4d6302a4cc * CompilerDriver_pix_run.cpp (pixNetworkZoneChecks): see SF bug
3213019 "FWSM Network zone and IPv6". Currently we do not support
ipv6 with PIX/ASA and FWSM. If user creates a group to be used as
network zone object and places ipv6 address in it, this address
should be ignored while compiling the policy but this should not
be an error.
2011-04-07 11:05:46 -07:00

105 lines
1.8 KiB
Plaintext
Executable File

!
! This is automatically generated file. DO NOT MODIFY !
!
! Firewall Builder fwb_pix v4.2.0.3519
!
! Generated Thu Apr 7 10:50:14 2011 PDT by vadim
!
! Compiled for pix 6.3
! Outbound ACLs: not supported
! Emulate outbound ACLs: yes
! Generating outbound ACLs: no
! Assume firewall is part of any: no
!
!# files: * firewall14.fw
!
! testing dual NAT per user's request
!
! Prolog script:
!
!
! End of prolog script:
!
nameif eth0 outside security0
nameif eth2 inside security100
no logging buffered
no logging console
no logging timestamp
no logging on
timeout xlate 3:0:0
timeout conn 1:0:0
timeout udp 0:2:0
timeout rpc 0:10:0
timeout h323 0:5:0
timeout sip 0:30:0
timeout sip_media 0:2:0
timeout uauth 2:0:0 absolute
telnet timeout 5
clear ssh
aaa authentication ssh console LOCAL
ssh timeout 5
no snmp-server enable traps
no service resetinbound
no service resetoutside
no sysopt connection timewait
no sysopt nodnsalias inbound
no sysopt nodnsalias outbound
floodguard enable
!################
!
! Rule 0 (global)
access-list inside_acl_in permit ip 10.1.2.0 255.255.255.0 any
!
! Rule 1 (global)
access-list outside_acl_in deny ip any any
access-list inside_acl_in deny ip any any
access-group inside_acl_in in interface inside
access-group outside_acl_in in interface outside
!
! Rule 0 (NAT)
global (outside) 1 interface
access-list id3FA74FDE.0 permit ip host 10.1.2.27 any
nat (inside) 1 access-list id3FA74FDE.0 0 0
!
! Rule 1 (NAT)
access-list id3FA74FCE.0 permit ip host 209.165.201.11 any
static (outside,inside) interface access-list id3FA74FCE.0 0 0
!
! Rule 2 (NAT)
access-list id3FA7502F.0 permit ip host 10.1.2.27 any
static (inside,outside) interface access-list id3FA7502F.0 0 0
!
! Epilog script:
!
! End of epilog script:
!