Pages

Sunday, March 6, 2016

Check Point R80 Management Installation - Part 1 - Basic Installation

Check Point finally announced their R80 Security Management from their website and also by email. Here is the email I got on March 2nd.
Check Point homeOne Step Ahead
Banner
Discover R80
We are very excited to announce R80 Security Management. This platform, a culmination of many years of research and development, was built to anticipate the challenges facing security teams during a time of massive transition in enterprise security. Growing networks, disruptive technologies, and the proliferation of interconnected devices make managing security increasingly complex. We believe the key to managing this complexity is through security consolidation – bringing all security protections and functions under one umbrella.  With R80, this is fully realized:
  • A single platform to manage your entire IT infrastructure.
  • Streamlined interface and task-oriented features (concurrent admin, integrated logs) to help you work faster, smarter.
  • Unified policy management, so you can create and monitor policies harmoniously and efficiently.
  • An extensible platform so you can align security to IT processes & technologies.
  • Integrated threat management to give you better visibility and help speed incidence response.
To learn more about R80, please join our new Exchange Point community where users can ask questions, share API scripts and interact with peers & Check Point experts. As you upgrade to R80, we are committed to partnering with you every step of the way to ensure a successful deployment!
CUSTOMER SPOTLIGHT
Talisys, an innovator in financial securities processing software, leverages R80 to reduce security management complexity and align processes.
Follow Us    ©2016 Check Point Software Technologies Ltd. (Nasdaq: CHKP) All rights reserved. If you no longer wish to receive email from us, please unsubscribe or write: 959 Skyway Rd, Suite 300, San Carlos, CA 94070. Check Point's Privacy Policy



Through Check Point Early Availability program, we were able to have a test this new exciting Security Management R80. What's new in Check Point R80 Management:
  • Unified Console
  • Concurrent administrators work
  • Layered policy approach
  • Threat prevention policy
  • Policy Apps (for example: logs by rules)
  • Next generation SmartLog and SmartEvent
  • Web services and APIs
 
Early Availability Download Page
 
Check Point R80 Web Page
The installation of R80 Security Management is similar as previous version. This post will use Vmware ESXi as platform to present the installation steps again.

Note: It also works on Vmware Workstation 10 which is the one I tested.

1. Create a new VM









  
 
2. Boot VM with Downloaded R80 ISO
 
After created the VM, start the installation by booting from mounted ISO file - Check_Point_R80_Gaia_R80_Public_EA_EA3_3.iso, downloaded from Check Point Early Availability Program.
 
\

 



 
   
















 



 







 




 

3. First Time Configuration Wizard
Using browser to open URL https://192.168.2.252, which is the management interface (eth0) ip address we configured in the previous step.


                           


                            




 















       


 
 










 

Note: During installation, I got an error which told me Cannot install Check Point Security Management Server. It is because of incompatible hardware at least 2 CPUs required. If you see this message, you will have to re-create your vm with at least 2 CPUs and re-do all steps.



Youtube Video: Check Point R80 Management Installation in Vmware Part 1 - Step by Step









Reference:  

Saturday, March 5, 2016

Website and Tools for Bloggers

During working on this "Network Security Memo" blog, there are some helpful websites or tools being used but not listed in previous posts. This post will mostly focus on blog related tools. Hopefully this will help some other beginners when they are trying to set their blog site up.

1. Website Speed Test and Monitoring Tools



2. Webmaster Tools


3. Website Analytics Tools


4. Making Money by adding ads


5. Buying Ads from advertiser





9. Free Image Hosting and Sharing Sites

a. Photobucket.com Not good anymore. They changed their service on June 2017 and charge too much for their hosting service.
b. Poco.cn
c. www.niupic.com
d. Postimage
e. TinyPic - Free Image Hosting, Photo Sharing & Video Hosting


10. Check if Your Website Blocked by GFW in China Mainland

a. Test if any website is blocked in china http://www.blockedinchina.net/
b. 网站被墙了吗? http://www.hostucan.cn/site-block-checker
c. Test website from China

11. Website Submission
Find list of best free URL submission and website submission sites. Submit your websites to 100's of Sites including search engines.
PingMyLink.com
Free search engine submission and Ping Service. Free URL submission tool will automatically add your URL to several hundreds of different websites that automatically provide free backlinks for you. Each of these sites has been collected in one comprehensive list, and our free tool automates the entire process for you.

FreeWebSubmission.com
Free Web Submission is the source for free search engine submission. Provides webmasters and site owners with free manual and auto submission to the highest-rated, free internet search engines and directories.

LinkStation
Free Autoubmit URL to 8000 FFA links pages.

Pingmyurl.com
Free Submit Your URL to 1,374 Different Websites.

Global Search Engine Submitter
Autoubmit Your Web Site to 65 Major Search Engines.

SubmitExpress
Free Search engine autosubmitter to 70+ search engines and directories.

Submitx.com
Free website submission to 636 search engines and directories.

AddMe
Website submission & registration with 25 search engines.

Site-submit.netne.net
Submit a URL to Over 130 Search Engines for Free. Free and easy site URL submission to more than 130 search engines.

MultiLinks
Submit URL to 200 classified ad sites and 1000 FFA links pages.



12. Google Test Tools


  • Google Adsense Sandbox : You can use this tool to determine if a domain is banned in the AdSense program. Put the website URL in the input box and if you see no ads, Google may have disabled ad-serving for that domain.



13. SEO Tools

SEO = Search Engine Optimization.” It is the optimized process of getting traffic from all kinds of search engines such as google, bing, yahoo.
  • SerpStat is a all-in-one SEO tool that consists of five different modules:Position Tracking, Backlink Analysis, Keyword Research, Site Audit, Competitor Research
  • Moz Open Site Explorer: This free version of Open Site Explorer gives you a limit times to have quick but full look of link analysis.
  • QuickSprout tells you how to make those important changes on your website that will grow your traffic. 
  • Similarweb : FREE version will provide 5 Results Per Metric,  1 Month of Mobile App Data and 3 Months of Web Traffic Data .
  • SeoSiteCheckup runs through a fast audit of your site, checking for proper tags and surfacing any errors that might come up.







Installing Cisco Cloud Services Router CSR 1000V in Vmware

The Cisco CSR 1000V Series lowers the barriers to enterprise adoption of a hybrid cloud model by extending the enterprise WAN to provider-hosted clouds.
Primary features include:
  • Flexible virtual form factor designed for multi-tenant, provider-hosted clouds
  • Complete, hypervisor-isolated, multi-service router instance for each tenant
  • Proven, familiar, enterprise-class Cisco IOS Software networking services
  • Feature and operational consistency with Cisco physical form-factor routers
  • Component of end-to-end WAN architecture with Cisco Integrated Services Routers and Cisco Aggregation Services Routers
Primary use cases include:
  • Secure VPN gateway
  • MPLS WAN termination
  • Data center network extension
  • Control and traffic redirection
Primary Benefits:
  • Direct connectivity improves the response time of cloud-hosted applications
  • Private WAN integration improves security, performance, and predictability
  • Enterprise control, visibility, and policy consistency reduce security risks
  • Feature consistency and product familiarity improve operational efficiency
  • Extension of the data center network to a cloud simplifies application on-boarding

1. Download CSR 1000v Software:
you can start to download either one of following package from this page (Cisco IOS XE Software Link)

  • csr1000v-universalk9.03.12.00.S.154-2.S-std.ova
  • csr1000v-universalk9.03.12.00.S.154-2.S-std.iso

Keep this in mind, CSR1000v itself comes with a 60 day license for 50Mbps throughput. After that expires it drops to 2.5Mbps.



2. Creating VM
Serial connection has to be redirected to named pipe when loading into Vmware workstation. Also four Interface has been added into VM.


3. Start VM 
Using Secure CRT to set up telnet port 4002 to connect to VM's serial port, you will get following output:


Press any key to continue.


    GNU GRUB  version 0.97  (638K lower / 2619328K upper memory)

 +-------------------------------------------------------------------------+
 | CSR1000v - packages.conf                                    | 
 | CSR1000v - GOLDEN IMAGE                             |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         | 
 +-------------------------------------------------------------------------+
      Use the ^ and v keys to select which entry is highlighted.
      Press enter to boot the selected OS, or 'c' for a command-line.



   The highlighted entry will be booted automatically in 1 seconds.   

  Booting 'CSR1000v - packages.conf'

root (hd0,0)
 Filesystem type is ext2fs, partition type 0x83
kernel /packages.conf rw quiet root=/dev/ram console= max_loop=64 HARDWARE=virt
ual SR_BOOT=bootflash:packages.conf
Calculating SHA-1 hash...done
SHA-1 hash:
        calculated   514e2831:94ee1441:2404193c:f37dac1e:4c196e19
        expected     514e2831:94ee1441:2404193c:f37dac1e:4c196e19
package header rev 1 structure detected
Calculating SHA-1 hash...done
SHA-1 hash:
        calculated   134e1e2e:319d85c6:34a4d2b3:965dcb75:dc20afef
        expected     134e1e2e:319d85c6:34a4d2b3:965dcb75:dc20afef
Package type:0x7531, flags:0x0
   [Linux-bzImage, setup=0x2e00, size=0xd1c0720]
   [isord @ 0x743b2000, 0xbc3d000 bytes]

%IOSXEBOOT-4-WATCHDOG_DISABLED: (rp/0): Hardware watchdog timer disabled: watchdog device not found
%IOSXEBOOT-4-BOOT_SRC: (rp/0): TarFilePath:
%IOSXEBOOT-4-EUSB_PROVISIONING: (rp/0): Unsupported low capacity eUSB detected in VXE board

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706



Cisco IOS Software, CSR1000V Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.4(2)S, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Wed 26-Mar-14 21:09 by mcpre



Cisco IOS-XE software, Copyright (c) 2005-2014 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


% failed to initialize nvram

IOSXE-WATCHDOG: Process = Init
-Traceback= 1#62109d0bf854130ed331df92a9947d53  c:7FB687C6F000+B8AC7 :400000+10A9C9 :400000+1FF18CC :400000+101846D :400000+101024E :400000+268CFD3 :400000+22E715 :400000+43400AC :400000+433FF4C :400000+433FE81 :400000+1FFA814 :400000+1FF96C2
Writing crashinfo to bootflash:crashinfo_RP_00_00_20140518-212501-UTCMay 18 21:25:45.831 R0/0: %PMAN-3-PROCHOLDDOWN: The process linux_iosd-image has been helddown (rc 142)
May 18 21:25:46.505 R0/0: %PMAN-0-PROCFAILCRIT: A critical process linux_iosd_image has failed (rc 142)
May 18 21:25:46.757 R0/0: %PMAN-3-RELOAD_RP_SB_NOT_READY: Reloading: Fault on Active RP bay but Standby RP bay is not ready
Press any key to continue.
Press any key to continue.
Press any key to continue.


    GNU GRUB  version 0.97  (638K lower / 2619328K upper memory)

 +-------------------------------------------------------------------------+
 | CSR1000v - packages.conf                                    | 
 | CSR1000v - GOLDEN IMAGE                             |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         |
 |                                                                         | 
 +-------------------------------------------------------------------------+
      Use the ^ and v keys to select which entry is highlighted.
      Press enter to boot the selected OS, or 'c' for a command-line.



     
  Booting 'CSR1000v - packages.conf'

root (hd0,0)
 Filesystem type is ext2fs, partition type 0x83
kernel /packages.conf rw quiet root=/dev/ram console= max_loop=64 HARDWARE=virt
ual SR_BOOT=bootflash:packages.conf
Calculating SHA-1 hash...done
SHA-1 hash:
        calculated   514e2831:94ee1441:2404193c:f37dac1e:4c196e19
        expected     514e2831:94ee1441:2404193c:f37dac1e:4c196e19
package header rev 1 structure detected
Calculating SHA-1 hash...done
SHA-1 hash:
        calculated   134e1e2e:319d85c6:34a4d2b3:965dcb75:dc20afef
        expected     134e1e2e:319d85c6:34a4d2b3:965dcb75:dc20afef
Package type:0x7531, flags:0x0
   [Linux-bzImage, setup=0x2e00, size=0xd1c0720]
   [isord @ 0x743b2000, 0xbc3d000 bytes]

%IOSXEBOOT-4-WATCHDOG_DISABLED: (rp/0): Hardware watchdog timer disabled: watchdog device not found
%IOSXEBOOT-4-BOOT_SRC: (rp/0): TarFilePath:
%IOSXEBOOT-4-EUSB_PROVISIONING: (rp/0): Unsupported low capacity eUSB detected in VXE board

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706



Cisco IOS Software, CSR1000V Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.4(2)S, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Wed 26-Mar-14 21:09 by mcpre



Cisco IOS-XE software, Copyright (c) 2005-2014 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


% failed to initialize nvram

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco CSR1000V (VXE) processor with 804580K/6147K bytes of memory.
Processor board ID 9JHR8EUL1ZL
4 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
3145728K bytes of physical memory.
7774207K bytes of virtual hard disk at bootflash:.


         --- System Configuration Dialog ---

Would you like to enter the initial configuration dialog? [yes/no]: n
lrl:Critical software exception, check bootflash:crashinfo_RP_00_00_20140518-212501-UTC

.....
.....
.....

4. Log into router and check Router's configuration
Router>en
Router#sh ip int brie
Interface              IP-Address      OK? Method Status                Protocol
GigabitEthernet1       unassigned      YES unset  administratively down down   
GigabitEthernet2       unassigned      YES unset  administratively down down   
GigabitEthernet3       unassigned      YES unset  administratively down down   
GigabitEthernet4       unassigned      YES unset  administratively down down    


Router#sh ver
Cisco IOS XE Software, Version 03.12.00.S - Standard Support Release
Cisco IOS Software, CSR1000V Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.4(2)S, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Wed 26-Mar-14 21:09 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2014 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON

Router uptime is 12 minutes
Uptime for this control processor is 13 minutes
System returned to ROM by reload
System image file is "bootflash:packages.conf"
Last reload reason: Critical software exception, check bootflash:crashinfo_RP_00_00_20140518-212501-UTC


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

License Level: limited
License Type: Default. No valid license found.
Next reload license Level: limited


cisco CSR1000V (VXE) processor with 804580K/6147K bytes of memory.
Processor board ID 9JHR8EUL1ZL
4 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
3145728K bytes of physical memory.
7774207K bytes of virtual hard disk at bootflash:.

Configuration register is 0x2102



Router#sh run
Building configuration...

Current configuration : 993 bytes
!
! Last configuration change at 01:39:18 UTC Mon May 19 2014
!
version 15.4
service timestamps debug datetime msec
service timestamps log datetime msec
no platform punt-keepalive disable-kernel-core
platform console serial
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
!
no aaa new-model
!
!

subscriber templating
multilink bundle-name authenticated
!
!
license udi pid CSR1000V sn 9JHR8EUL1ZL
!        
!
redundancy
 mode none
!
!
interface GigabitEthernet1
 no ip address
 shutdown
 negotiation auto
!
interface GigabitEthernet2
 no ip address
 shutdown
 negotiation auto
!
interface GigabitEthernet3
 no ip address
 shutdown
 negotiation auto
!
interface GigabitEthernet4
 no ip address
 shutdown
 negotiation auto
!
!
virtual-service csr_mgmt
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
!
!
!
control-plane
!
!
line con 0
 stopbits 1
line vty 0
 login
line vty 1
 login
 length 0
line vty 2 4
 login
!
!
end





Cisco ASAv 9.5.1 200 and ASDM 7.5.1 in Workstation / ESXi

I were keeping testing Cisco ASA in Vmware environment for my own studying purpose. Recently I got ASAv 9.5.1 and installed into Vmware workstation 10 and ESXi 5.5.

Here are all related posts in this blog:
More configuration posts:
1. Download Software from Cisco Software Website:

The latest is 9.5.2 200. I am using 9.5.1 200 as an example for this post.




After downloaded the package, unzipped it and you will get 7 files.

asav-esxi.ovf will be used for esxi and workstation environment.

2. Import into Vmware ESXi or Workstation

2.1 in ESXi 5.5

Choose Menu File -> Deploy OVF Template...
 Follow screen instruction to click next:
 Network Mapping will be very straightforward since all interface are listing with mapping name in the ASAv.
Management0-0 is first interface. 




2.2 in Vmware Workstation 10
Choose Open from File menu:
 Following screen , click import:
After import done, you will get a new Virtual Machine:
Network Adapter 1 is first interface which is Management0/0 in ASAv. 

Booting Screen:



3. Verify



ASAv-Pri#   show version

Cisco Adaptive Security Appliance Software Version 9.5(1)200
Device Manager Version 7.5(1)

Compiled on Fri 28-Aug-15 15:56 PDT by builders
System image file is "boot:/asa951-200-smp-k8.bin"
Config file at boot was "startup-config"

ASAv-Pri up 1 hour 5 mins
failover cluster up 15 hours 54 mins

Hardware:   ASAv, 1024 MB RAM, CPU Xeon 5500 series 2294 MHz,
Model Id:   ASAv5
Internal ATA Compact Flash, 256MB
Slot 1: ATA Compact Flash, 8192MB
BIOS Flash Firmware Hub @ 0x0, 0KB


 0: Ext: Management0/0       : address is 000c.291a.f3fd, irq 10
 1: Ext: GigabitEthernet0/0  : address is 000c.291a.f307, irq 5
 2: Ext: GigabitEthernet0/1  : address is 000c.291a.f311, irq 9
 3: Ext: GigabitEthernet0/2  : address is 000c.291a.f31b, irq 11
 4: Ext: GigabitEthernet0/3  : address is 000c.291a.f325, irq 10
 5: Ext: GigabitEthernet0/4  : address is 000c.291a.f32f, irq 5
 6: Ext: GigabitEthernet0/5  : address is 000c.291a.f339, irq 9
 7: Ext: GigabitEthernet0/6  : address is 000c.291a.f343, irq 11
 8: Ext: GigabitEthernet0/7  : address is 000c.291a.f34d, irq 10
 9: Ext: GigabitEthernet0/8  : address is 000c.291a.f357, irq 5

License mode: Smart Licensing
ASAv Platform License State: Unlicensed
No active entitlement: no feature tier and no throughput level configured
*Memory resource allocation is more than the permitted limit.

Licensed features for this platform:
Maximum Physical Interfaces       : 10
Maximum VLANs                     : 25
Inside Hosts                      : Unlimited
Failover                          : Active/Standby
Encryption-DES                    : Enabled
Encryption-3DES-AES               : Enabled
Security Contexts                 : 0
GTP/GPRS                          : Disabled
AnyConnect Premium Peers          : 2
AnyConnect Essentials             : Disabled
Other VPN Peers                   : 50
Total VPN Peers                   : 50
Shared License                    : Disabled
AnyConnect for Mobile             : Disabled
AnyConnect for Cisco VPN Phone    : Disabled
Advanced Endpoint Assessment      : Disabled
Total UC Proxy Sessions           : 2
Botnet Traffic Filter             : Enabled
Cluster                           : Disabled


License mode: Smart Licensing

Failover cluster licensed features for this platform:
Maximum Physical Interfaces       : 10
Maximum VLANs                     : 25
Inside Hosts                      : Unlimited
Failover                          : Active/Standby
Encryption-DES                    : Enabled
Encryption-3DES-AES               : Enabled
Security Contexts                 : 0
GTP/GPRS                          : Disabled
AnyConnect Premium Peers          : 2
AnyConnect Essentials             : Disabled
Other VPN Peers                   : 50
Total VPN Peers                   : 50
Shared License                    : Disabled
AnyConnect for Mobile             : Disabled
AnyConnect for Cisco VPN Phone    : Disabled
Advanced Endpoint Assessment      : Disabled
Total UC Proxy Sessions           : 2
Botnet Traffic Filter             : Enabled
Cluster                           : Disabled

Licensing mode is Smart Licensing

Serial Number: 9ALU3EW6LDF

Image type          : Release
Key version         : A

Configuration last modified by enable_1 at 17:02:38.079 UTC Wed Jan 27 2016
ASAv-Pri#

ASAv-Pri# sh run
: Saved

:
: Serial Number: 9ALU3EW6LDF
: Hardware:   ASAv, 1024 MB RAM, CPU Xeon 5500 series 2294 MHz
:
ASA Version 9.5(1)200
!
hostname ASAv-Pri
enable password 8Ry2YjIyt7RRXU24 encrypted
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
names
!
interface GigabitEthernet0/0
 nameif EXT
 security-level 0
 ip address 172.17.3.11 255.255.255.0 standby 172.17.3.12
!
interface GigabitEthernet0/1
 description test
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/2
 nameif INT
 security-level 100
 ip address 10.94.2.11 255.255.255.0 standby 10.94.2.12
!
interface GigabitEthernet0/3
 shutdown
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/4
 shutdown
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/5
 shutdown
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/6
 shutdown
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/7
 shutdown
 no nameif
 no security-level
 no ip address
!
interface GigabitEthernet0/8
 description LAN/STATE Failover Interface
!
interface Management0/0
 management-only
 nameif mgmt
 security-level 0
 ip address 192.168.2.11 255.255.255.0 standby 192.168.2.12
!
ftp mode passive
pager lines 23
logging enable
logging asdm informational
mtu EXT 1500
mtu INT 1500
mtu mgmt 1500
failover
failover lan unit secondary
failover lan interface LANFAIL GigabitEthernet0/8
failover key *****
failover link LANFAIL GigabitEthernet0/8
failover interface ip LANFAIL 10.10.1.1 255.255.255.0 standby 10.10.1.2
no monitor-interface mgmt
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
user-identity default-domain LOCAL
aaa authentication ssh console LOCAL
http server enable
http 192.168.2.0 255.255.255.0 mgmt
no snmp-server location
no snmp-server contact
crypto ipsec security-association pmtu-aging infinite
crypto ca trustpoint _SmartCallHome_ServerCA
 no validation-usage
 crl configure
crypto ca trustpool policy
crypto ca certificate chain _SmartCallHome_ServerCA
 certificate ca 6ecc7aa5a7032009b8cebcf4e952d491
    308205ec 308204d4 a0030201 0202106e cc7aa5a7 032009b8 cebcf4e9 52d49130
 .......
    6119b5dd cdb50b26 058ec36e c4c875b8 46cfe218 065ea9ae a8819a47 16de0c28
    6c2527b9 deb78458 c61f381e a4c4cb66
  quit
telnet timeout 5
ssh stricthostkeycheck
ssh 192.168.2.0 255.255.255.0 mgmt
ssh timeout 5
ssh key-exchange group dh-group1-sha1
console timeout 0
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
dynamic-access-policy-record DfltAccessPolicy
username test password P4ttSyrm33SV8TYp encrypted
!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum client auto
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect ip-options
  inspect netbios
  inspect rtsp
  inspect sunrpc
  inspect tftp
  inspect xdmcp
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect esmtp
  inspect sqlnet
  inspect sip
  inspect skinny
policy-map type inspect dns migrated_dns_map_1
 parameters
  message-length maximum client auto
  message-length maximum 512
!
service-policy global_policy global
prompt hostname context
call-home reporting anonymous prompt 2
call-home
 profile License
  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
  destination transport-method http
 profile CiscoTAC-1
  no active
  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
  destination address email callhome@cisco.com
  destination transport-method http
  subscribe-to-alert-group diagnostic
  subscribe-to-alert-group environment
  subscribe-to-alert-group inventory periodic monthly
  subscribe-to-alert-group configuration periodic monthly
  subscribe-to-alert-group telemetry periodic daily
Cryptochecksum:deb136269827f21fc1c142fac079704b
: end

ASAv-Pri#