Sunteți pe pagina 1din 35

-------------------------------------------------------------------------

<Zambia Weights and Measures Agency>


<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------

User Access Verification

Username: Zwma
Password:
ZWMA#show run
Building configuration...

Current configuration : 5985 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31323339
33345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BFA8F66 F0E385A6 37104C9F 794655BD BAD2BD78 A33752E2 4FE02CD5 B0292DDD
8D3043E3 A01F94FA A16EB265 C8A11688 A206BA47 D9059710 E4D06E90 6F222BDF
E55B2D69 EF4A93F8 F4876291 1D040D92 923DFFCF FE9DF0D9 36969F4A 6AE08C3B
A3508C9E 97FF1EFA C5214944 0EA8ED2B 90F26B33 15FE5544 8AF85841 DF70655C
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 808
1
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 808
2
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 338
9
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
--More--

ZWMA con0 is now available

Press RETURN to get started.

-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------

User Access Verification

Username:
Username: Zwma
Password:
ZWMA#show ip access-lists 150
Extended IP access list 150
10 permit ip 192.168.1.0 0.0.0.255 any (6231 matches)
ZWMA#config terminal
Enter configuration commands, one per line. End with CNTL/Z.
ZWMA(config)#ip dhcp pool internal
ZWMA(dhcp-config)#network 192.168.1.0 255.255.255.0
ZWMA(dhcp-config)#dns-server 196.12.12.65 196.12.12.66
ZWMA(dhcp-config)#default-router 41.222.21.111
ZWMA(dhcp-config)#exit
ZWMA(config)#do show run
Building configuration...

Current configuration : 6096 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
default-router 41.222.21.111
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31323339
33345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BFA8F66 F0E385A6 37104C9F 794655BD BAD2BD78 A33752E2 4FE02CD5 B0292DDD
8D3043E3 A01F94FA A16EB265 C8A11688 A206BA47 D9059710 E4D06E90 6F222BDF
E55B2D69 EF4A93F8 F4876291 1D040D92 923DFFCF FE9DF0D9 36969F4A 6AE08C3B
A3508C9E 97FF1EFA C5214944 0EA8ED2B 90F26B33 15FE5544 8AF85841 DF70655C
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA(config)#copy running-config startup-config


^
% Invalid input detected at '^' marker.

ZWMA(config)#do copy running-config startup-config


Destination filename [startup-config]?
Building configuration...
[OK]
ZWMA(config)#ip dhcp pool internal
ZWMA(dhcp-config)#no default-router 41.222.21.111
ZWMA(dhcp-config)#exit
ZWMA(config)#do show run
Building configuration...

Current configuration : 6063 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31323339
33345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BFA8F66 F0E385A6 37104C9F 794655BD BAD2BD78 A33752E2 4FE02CD5 B0292DDD
8D3043E3 A01F94FA A16EB265 C8A11688 A206BA47 D9059710 E4D06E90 6F222BDF
E55B2D69 EF4A93F8 F4876291 1D040D92 923DFFCF FE9DF0D9 36969F4A 6AE08C3B
A3508C9E 97FF1EFA C5214944 0EA8ED2B 90F26B33 15FE5544 8AF85841 DF70655C
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA(config)#ip dhcp pool internal


ZWMA(dhcp-config)#domain-name write
ZWMA(dhcp-config)#default-router 41.222.21.111
ZWMA(dhcp-config)#exit
ZWMA(config)#do show run
Building configuration...

Current configuration : 6117 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
domain-name write
default-router 41.222.21.111
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31323339
33345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BFA8F66 F0E385A6 37104C9F 794655BD BAD2BD78 A33752E2 4FE02CD5 B0292DDD
8D3043E3 A01F94FA A16EB265 C8A11688 A206BA47 D9059710 E4D06E90 6F222BDF
E55B2D69 EF4A93F8 F4876291 1D040D92 923DFFCF FE9DF0D9 36969F4A 6AE08C3B
A3508C9E 97FF1EFA C5214944 0EA8ED2B 90F26B33 15FE5544 8AF85841 DF70655C
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA(config)#exit
ZWMA#r
000029: *Apr 5 13:18:20.713 UTC: %SYS-5-CONFIG_I: Configured from console by Zwma
on console
ZWMA#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
ZWMA#reload
Proceed with reload? [confirm]

000030: *Apr 5 13:18:56.210 UTC: %SYS-5-RELOAD: Reload requested by Zwma on


console. Reload Reason: Reload Command.
System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 2006 by cisco Systems, Inc.
PLD version 0x10
GIO ASIC version 0x127
c1841 platform with 262144 Kbytes of main memory
Main memory is configured to 64 bit mode with parity disabled

Readonly ROMMON initialized


program load complete, entry point: 0x8000f000, size: 0xcb80
program load complete, entry point: 0x8000f000, size: 0xcb80

program load complete, entry point: 0x8000f000, size: 0x22a365c


Self decompressing the image :
###################################################################################
###################################################################################
########### [OK]

Smart Init is enabled


smart init is sizing iomem
ID MEMORY_REQ TYPE
0X003AA110 public buffer pools
0X00211000 public particle pools
0X00020000 Crypto module pools
0X000021B8 Onboard USB

If any of the above Memory Requirements are


"UNKNOWN", you may be using an unsupported
configuration or there is a software problem and
system operation may be compromised.

Allocating additional 16716967 bytes to IO Memory.


PMem allocated: 243269632 bytes; IOMem allocated: 25165824 bytes

Restricted Rights Legend

Use, duplication, or disclosure by the Government is


subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

cisco Systems, Inc.


170 West Tasman Drive
San Jose, California 95134-1706

Cisco IOS Software, 1841 Software (C1841-ADVENTERPRISEK9-M), Version 12.4(15)T12,


RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Fri 22-Jan-10 00:35 by prod_rel_team
Image text-base: 0x60086DA0, data-base: 0x62A00F50

This product contains cryptographic features and is subject to United


States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to


export@cisco.com.

Installed image archive


Cisco 1841 (revision 7.0) with 237568K/24576K bytes of memory.
Processor board ID FGL154422JV
2 FastEthernet interfaces
1 Virtual Private Network (VPN) Module
DRAM configuration is 64 bits wide with parity disabled.
191K bytes of NVRAM.
63808K bytes of ATA CompactFlash (Read/Write)

Logging of %SNMP-3-AUTHFAIL is enabled

Press RETURN to get started!

*Apr 5 13:20:29.843: %VPN_HW-6-INFO_LOC: Crypto engine: onboard 0 State changed


to: Initialized
*Apr 5 13:20:29.847: %VPN_HW-6-INFO_LOC: Crypto engine: onboard 0 State changed
to: Enabled
*Apr 5 13:20:31.327: %LINEPROTO-5-UPDOWN: Line protocol on Interface IPv6-mpls,
changed state to up
*Apr 5 13:20:32.327: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/0, changed state to up
*Apr 5 13:20:32.327: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/1, changed state to up
000017: *Apr 5 13:20:34.755 UTC: %LINEPROTO-5-UPDOWN: Line protocol on Interface
NVI0, changed state to up
000018: *Apr 5 13:20:54.123 UTC: %SYS-5-CONFIG_I: Configured from memory by
console
000019: *Apr 5 13:20:54.663 UTC: %SYS-5-RESTART: System restarted --
Cisco IOS Software, 1841 Software (C1841-ADVENTERPRISEK9-M), Version 12.4(15)T12,
RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Fri 22-Jan-10 00:35 by prod_rel_team
000020: *Apr 5 13:20:54.663 UTC: %SNMP-5-COLDSTART: SNMP agent on host ZWMA is
undergoing a cold start
000021: *Apr 5 13:20:54.727 UTC: %SSH-5-ENABLED: SSH 2.0 has been enabled
000022: *Apr 5 13:20:54.891 UTC: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
000023: *Apr 5 13:20:54.891 UTC: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
000024: *Apr 5 13:20:54.891 UTC: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
000025: *Apr 5 13:20:54.891 UTC: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
000026: *Apr 5 13:20:55.931 UTC: %SYS-6-BOOTTIME: Time taken to reboot after
reload = 118 seconds
000027: *Apr 5 13:21:14.850 UTC: %PKI-6-AUTOSAVE: Running configuration saved to
NVRAM
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------

User Access Verification

Username: Zwma
Password:
ZWMA#show run
Building configuration...

000028: *Apr 5 13:22:58.461 UTC: %DHCPD-4-PING_CONFLICT: DHCP address conflict:


server pinged 192.168.1.2.
000029: *Apr 5 13:22:59.960 UTC: %DHCPD-4-PING_CONFLICT: DHCP address conflict:
server pinged 192.168.1.3.
Current configuration : 6117 bytes
!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
domain-name write
default-router 41.222.21.111
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self- signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31333231
31345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BCDBE6B 710917ED 9A0D7283 EB61FB51 CA342408 6A2DBF3F 8758E07B 53A945CA
8B6F0C0D BCB42F2A F3E1EDFD AC623470 6E638D8F 100D1E08 E2B3590E 49382F37
887572F3 66D67F91 5AC6BEAE 0DEBE020 01F3FEC8 40D8DE75 75A7CA07 64B8543D
275E32DE AADAC18E 617F9FF2 022227D1 5D339A74 3EA2F94D 4E694377 3934A8BF
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA#

ZWMA con0 is now available

Press RETURN to get started.


000030: *Apr 5 14:40:56.245 UTC: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/0, changed state to down
03:06:38: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/3, changed
state to down
03:06:42: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/3, changed
state to up
03:09:13: %LINK-3-UPDOWN: Interface FastEthernet0/19, changed state to up
03:09:15: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/19, changed
state to up
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------

User Access Verification

Username: Zwma
Password:
ZWMA#show run
Building configuration...

Current configuration : 6117 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
domain-name write
default-router 41.222.21.111
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31333231
31345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BCDBE6B 710917ED 9A0D7283 EB61FB51 CA342408 6A2DBF3F 8758E07B 53A945CA
8B6F0C0D BCB42F2A F3E1EDFD AC623470 6E638D8F 100D1E08 E2B3590E 49382F37
887572F3 66D67F91 5AC6BEAE 0DEBE020 01F3FEC8 40D8DE75 75A7CA07 64B8543D
275E32DE AADAC18E 617F9FF2 022227D1 5D339A74 3EA2F94D 4E694377 3934A8BF
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA#config terminal
Enter configuration commands, one per line. End with CNTL/Z.
ZWMA(config)#deny access-list 35 41.222.21.111
^
% Invalid input detected at '^' marker.

ZWMA(config)#access-list 35 deny 41.222.21.111


ZWMA(config)#do show run
Building configuration...

Current configuration : 6117 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
domain-name write
default-router 41.222.21.111
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31333231
31345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BCDBE6B 710917ED 9A0D7283 EB61FB51 CA342408 6A2DBF3F 8758E07B 53A945CA
8B6F0C0D BCB42F2A F3E1EDFD AC623470 6E638D8F 100D1E08 E2B3590E 49382F37
887572F3 66D67F91 5AC6BEAE 0DEBE020 01F3FEC8 40D8DE75 75A7CA07 64B8543D
275E32DE AADAC18E 617F9FF2 022227D1 5D339A74 3EA2F94D 4E694377 3934A8BF
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 35 permit 41.222.21.111
access-list 35 deny 41.222.21.111
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA(config)#access-list 35 no 41.222.21.111
^
% Invalid input detected at '^' marker.

ZWMA(config)#no access-list 35 41.222.21.111


ZWMA(config)#do show run
Building configuration...

Current configuration : 6045 bytes


!
version 12.4
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname ZWMA
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 5 log
logging snmp-authfail
logging userinfo
logging buffered 16384
enable secret 5 $1$PzLJ$5M0RNwAAg3/HM3DSB33Mr.
enable password 7 070C285F4D064B55464A
!
no aaa new-model
dot11 syslog
no ip source-route
ip cef
!
!
no ip dhcp use vrf connected
!
ip dhcp pool binding
!
ip dhcp pool internal
network 192.168.1.0 255.255.255.0
dns-server 196.12.12.65 196.12.12.66
domain-name write
default-router 41.222.21.111
!
!
no ip bootp server
no ip domain lookup
!
multilink bundle-name authenticated
!
crypto pki trustpoint TP-self-signed-1439690677
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1439690677
revocation-check none
rsakeypair TP-self-signed-1439690677
!
!
crypto pki certificate chain TP-self-signed-1439690677
certificate self-signed 01
3082023C 308201A5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31343339 36393036 3737301E 170D3138 30343035 31333231
31345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 34333936
39303637 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100ACE9 0A7EA208 737F5E81 471ADA7C 1278C5F0 83D2391C F13D0CA0 4CE58928
3C8FD2DF 55A76F66 11E5A940 6B1AFACE E409D8AE 6D3E66EF 8C9C2455 8CECF565
7528A055 F4019DC5 C3289542 F91F2B7C 76627064 4CEA106B BFAAE157 DF0C6269
947F9014 EF8B6976 D3437B78 0694E818 46777DD0 B761586E 02C02F5D 0424C30D
9B010203 010001A3 64306230 0F060355 1D130101 FF040530 030101FF 300F0603
551D1104 08300682 045A574D 41301F06 03551D23 04183016 80142080 C65C100F
6445829E 70147A67 B2C86E47 D4E2301D 0603551D 0E041604 142080C6 5C100F64
45829E70 147A67B2 C86E47D4 E2300D06 092A8648 86F70D01 01040500 03818100
1BCDBE6B 710917ED 9A0D7283 EB61FB51 CA342408 6A2DBF3F 8758E07B 53A945CA
8B6F0C0D BCB42F2A F3E1EDFD AC623470 6E638D8F 100D1E08 E2B3590E 49382F37
887572F3 66D67F91 5AC6BEAE 0DEBE020 01F3FEC8 40D8DE75 75A7CA07 64B8543D
275E32DE AADAC18E 617F9FF2 022227D1 5D339A74 3EA2F94D 4E694377 3934A8BF
quit
!
!
username Zwma privilege 15 secret 5 $1$AUZg$PHj/BZcQ06R7vbG/a5qVF.
archive
log config
hidekeys
!
!
!
!
ip tcp path-mtu-discovery
ip ssh maxstartups 5
ip ssh authentication-retries 5
ip ssh logging events
ip ssh version 2
bridge irb
!
!
!
interface FastEthernet0/0
description POINT TO POINT
ip address 41.222.21.111 255.255.255.0
ip access-group 35 in
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
no cdp enable
!
interface FastEthernet0/1
description Facing My LAN
ip address 192.168.1.1 255.255.255.0
ip verify unicast reverse-path
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 41.222.21.254
!
ip flow-top-talkers
top 50
sort-by bytes
match input-interface FastEthernet0/0
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 150 interface FastEthernet0/0 overload
ip nat inside source static tcp 41.222.21.111 8081 interface FastEthernet0/0 8081
ip nat inside source static tcp 41.222.21.111 8082 interface FastEthernet0/0 8082
ip nat inside source static tcp 41.222.21.111 3389 interface FastEthernet0/0 3389
ip nat inside source static tcp 41.222.21.111 80 interface FastEthernet0/0 80
ip nat inside source static tcp 41.222.21.111 443 interface FastEthernet0/0 443
ip nat inside source static tcp 41.222.21.111 25 interface FastEthernet0/0 25
ip nat inside source static tcp 41.222.21.111 110 interface FastEthernet0/0 110
ip nat inside source static tcp 41.222.21.111 143 interface FastEthernet0/0 143
ip nat inside source static 192.168.1.2 41.222.21.111
!
logging trap debugging
logging facility local5
access-list 10 deny 172.16.0.1
access-list 12 deny 10.1.1.4
access-list 15 permit 192.43.244.18
access-list 15 remark NTP peers
access-list 15 permit 196.12.12.231
access-list 20 remark SNMP ACL
access-list 20 remark AfC-UK Range
access-list 20 permit 195.206.163.177
access-list 20 remark AfC-TZ Range
access-list 20 permit 41.222.63.0 0.0.0.128
access-list 20 remark iConnect Range
access-list 20 permit 196.12.12.64 0.0.0.63
access-list 20 permit 196.12.12.128 0.0.0.63
access-list 20 permit 192.168.1.0 0.0.0.255
access-list 150 permit ip 192.168.1.0 0.0.0.255 any
snmp-server community afr1! RO 20
snmp-server enable traps tty
no cdp run
!
!
!
!
!
!
control-plane
!
!
banner login ^C
-------------------------------------------------------------------------
<Zambia Weights and Measures Agency>
<Lusaka>

Access to this device or the attached networks is prohibited


without express written permission.

Violators may face both criminal and civil lawsuits.

PLEASE LOG OFF IMMEDIATELY IF YOU HAPPEN TO BE HERE ACCIDENTALLY


-------------------------------------------------------------------------^C
!
line con 0
exec-timeout 15 0
password 7 020B0B58
logging synchronous
login local
transport preferred none
line aux 0
exec-timeout 15 0
login
transport input all
line vty 0 4
exec-timeout 15 0
privilege level 15
password 7 082C434D
logging synchronous
login local
transport preferred none
transport input telnet ssh
!
scheduler allocate 20000 1000
ntp clock-period 17178357
ntp access-group peer 15
ntp update-calendar
ntp server 192.43.244.18
ntp server 196.12.12.231 prefer
end

ZWMA(config)#

S-ar putea să vă placă și