hostname test_fw
name 192.168.10.0 net1
name 192.168.10.1 server1 description Test web server
banner motd a banner
interface Vlan2
nameif outside
security-level 0
ip address 10.2.19.8 255.255.255.248 standby 10.2.19.9
speed 100
duplex full
object network test_fw_2
host 192.168.5.219
object network internal_net
subnet 10.1.2.0 255.255.255.0
object network citrix_net
subnet 192.168.2.0 255.255.255.0
object network test_net1_range
range 10.1.2.13 10.1.2.28
object service citrix
service tcp destination eq 1494
object service web_https
service tcp source gt 1024 destination eq 443
object-group service NFS
service-object 6 source eq 2046
service-object 17 source eq 2046
object-group protocol layer4
protocol-object tcp
protocol-object udp
object-group network test_srv
network-object host server1
object-group service web tcp
port-object eq www
port-object eq https
object-group network test_net
group-object test_srv
network-object host 10.1.2.3
object-group network test_net
description test network
network-object 10.20.16.0 255.255.240.0
object-group service NFS
service-object 6 destination eq 2046
object-group network customerX
network-object 172.16.0.0 255.255.240.0
object-group service high_ports tcp-udp
port-object range 1024 65535
object-group service www tcp
group-object web
object-group network citrix_servers
network-object host 192.168.2.1
network-object host 192.168.2.2
network-object host 192.168.2.3
object-group icmp-type ping
icmp-object echo
icmp-object echo-reply
access-list outside-in remark ICMP rules
access-list outside-in extended permit tcp object-group customerX gt 1024 host server1 eq 80 log
access-list outside-in extended permit tcp host server1 eq 1024 any eq 80 log warnings inactive
access-list outside-in extended permit tcp object-group customerX object-group high_ports host server1 eq 80
access-list outside-in extended permit object-group layer4 object-group customerX object-group high_ports host server1 eq 8080
access-list outside-in extended permit object citrix any object-group citrix_servers
access-list outside-in extended permit object-group layer4 object-group customerX object-group high_ports net1 255.255.255.0 eq 50234
access-list outside-in extended permit udp any range 1024 65535 host 192.168.10.1 gt 32768
access-list outside-in extended permit object citrix object internal_net object citrix_net
access-list outside-in remark ICMP rules
access-list outside-in extended permit icmp any any object-group ping
access-list outside-in extended permit icmp any any echo
access-list outside-in extended permit icmp any any echo-reply
access-list outside-in extended permit icmp any host 192.168.10.72
access-list outside-in extended permit ip any host 192.168.10.72
access-list outside-in remark For IPSEC
access-list outside-in extended permit esp any host 192.168.10.72
access-list inside-out permit ip any any
access-group outside-in in interface outside
route inside 192.168.0.0 255.255.0.0 10.0.0.1 1 track 200 tunneled
route outside 0 0 10.0.0.2 2
logging enable
logging timestamp
logging buffered warnings
telnet timeout 5
ssh version 1
crypto map
tunnel-group
object-group protocol all
protocol-object tcp
protocol-object udp
protocol-object icmp
protocol-object eigrp
protocol-object gre
protocol-object igmp
protocol-object igrp
protocol-object ipinip
protocol-object ipsec
protocol-object nos
protocol-object ospf
protocol-object pcp
protocol-object pim
protocol-object pptp
protocol-object snp