ASA# show run : Saved : : Serial Number: : Hardware: ASA5525, 8192 MB RAM, CPU Lynnfield 2394 MHz, 1 CPU (4 cores) : ASA Version 9.8(2) ! hostname ASA domain-name enable password $sha512$5000$E3LfBd2HaSsCbZcYECnuwQ==$JjeC50HCwmLFA84iFw7kQA== pbkdf2 xlate per-session deny tcp any4 any4 xlate per-session deny tcp any4 any6 xlate per-session deny tcp any6 any4 xlate per-session deny tcp any6 any6 xlate per-session deny udp any4 any4 eq domain xlate per-session deny udp any4 any6 eq domain xlate per-session deny udp any6 any4 eq domain xlate per-session deny udp any6 any6 eq domain names ! interface GigabitEthernet0/0 description to WAN nameif outside security-level 80 ip address 172.18.151.171 255.255.255.0 ! interface GigabitEthernet0/1 description to LAN nameif inside security-level 100 ip address 192.168.0.1 255.255.255.0 ! interface GigabitEthernet0/2 shutdown nameif management security-level 90 no ip address ! interface GigabitEthernet0/3 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/4 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/5 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/6 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/7 shutdown no nameif no security-level no ip address ! interface Management0/0 management-only nameif ManageASDM security-level 100 ip address 192.168.1.1 255.255.255.0 ! interface GigabitEthernet1/0 shutdown no nameif no security-level no ip address ! interface GigabitEthernet1/1 shutdown no nameif no security-level no ip address ! interface GigabitEthernet1/2 shutdown no nameif no security-level no ip address ! interface GigabitEthernet1/3 shutdown no nameif no security-level no ip address ! interface GigabitEthernet1/4 shutdown no nameif no security-level no ip address ! interface GigabitEthernet1/5 shutdown no nameif no security-level no ip address ! ftp mode passive dns server-group DefaultDNS domain-name cisco.com object-group icmp-type ping description Ping Group icmp-object echo icmp-object echo-reply access-list INBOUND extended permit icmp any any echo-reply access-list INBOUND extended permit tcp host host 172.18.151.0 eq https access-list INBOUND extended permit tcp host host 192.168.0.0 eq https access-list OUTBOUND extended permit icmp any any echo access-list OUTBOUND extended permit icmp any any time-exceeded access-list OUTBOUND extended permit tcp host 172.18.151.0 host eq https access-list OUTBOUND extended permit tcp host 192.168.0.0 host eq https pager lines 24 logging enable logging buffered debugging mtu outside 1500 mtu inside 1500 mtu management 1500 mtu ManageASDM 1500 no failover no monitor-interface service-module icmp unreachable rate-limit 1 burst-size 1 icmp permit any unreachable outside icmp permit any time-exceeded outside icmp permit any echo-reply outside asdm image disk0:/asdm-782.bin no asdm history enable arp timeout 14400 no arp permit-nonconnected arp rate-limit 16384 access-group INBOUND in interface outside access-group OUTBOUND in interface inside route outside 0.0.0.0 0.0.0.0 172.18.151.1 1 timeout xlate 3:00:00 timeout pat-xlate 0:00:30 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:01:00 timeout floating-conn 0:00:00 timeout conn-holddown 0:00:15 timeout igp stale-route 0:01:10 user-identity default-domain LOCAL aaa authentication ssh console LOCAL aaa authentication http console LOCAL aaa authentication telnet console LOCAL aaa authentication login-history http server enable http 192.168.1.0 255.255.255.0 ManageASDM http 172.18.151.0 255.255.255.0 outside http 192.168.0.0 255.255.255.0 inside no snmp-server location no snmp-server contact crypto ipsec security-association pmtu-aging infinite crypto ca trustpoint localtrust enrollment self fqdn ASA.cisco.com subject-name CN=ASA.cisco.com crl configure crypto ca trustpool policy telnet timeout 5 ssh stricthostkeycheck ssh 0.0.0.0 0.0.0.0 outside ssh timeout 5 ssh version 2 ssh key-exchange group dh-group14-sha1 console timeout 0 threat-detection basic-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept dynamic-access-policy-record DfltAccessPolicy username ASA password $sha512$5000$4YjG20+B4dG9A/AwTuNqfA==$FDk45b0FxrDlxu1MlNhMiA== pbkdf2 ! class-map icmp-class match default-inspection-traffic class-map tcp-class match port tcp eq https class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum client auto message-length maximum 512 tcp-inspection policy-map icmp_policy class icmp-class inspect icmp policy-map global_policy class inspection_default inspect ftp inspect h323 h225 inspect h323 ras inspect ip-options inspect netbios inspect rsh inspect rtsp inspect skinny inspect esmtp inspect sqlnet inspect sunrpc inspect tftp inspect sip inspect xdmcp inspect dns preset_dns_map inspect icmp inspect icmp error policy-map type inspect dns migrated_dns_map_2 parameters message-length maximum client auto message-length maximum 512 no tcp-inspection policy-map type inspect dns migrated_dns_map_1 parameters message-length maximum client auto message-length maximum 512 no tcp-inspection policy-map tcp_policy class tcp-class ! service-policy global_policy global service-policy icmp_policy interface outside prompt hostname context no call-home reporting anonymous call-home profile CiscoTAC-1 no active destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address email callhome@cisco.com destination transport-method http subscribe-to-alert-group diagnostic subscribe-to-alert-group environment subscribe-to-alert-group inventory periodic monthly subscribe-to-alert-group configuration periodic monthly subscribe-to-alert-group telemetry periodic daily Cryptochecksum:42bacd0eb6e1b807ff9433645e5c0ad9 : end ASA#