FastEthernet0/0 is up, line protocol is up
Hardware is Gt96k FE, address is 0017.595e.5734 (bia 0017.595e.5734)
Description: "Data Subnet"
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 2/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, 100BaseTX/FX
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/525/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 443000 bits/sec, 126 packets/sec
5 minute output rate 801000 bits/sec, 138 packets/sec
207101029 packets input, 1138306940 bytes
Received 6884281 broadcasts, 0 runts, 0 giants, 0 throttles
13378 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog
0 input packets with dribble condition detected
204491111 packets output, 830476776 bytes, 0 underruns
0 output errors, 0 collisions, 6 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
FastEthernet0/0.1 is up, line protocol is up
Hardware is Gt96k FE, address is 0017.595e.5734 (bia 0017.595e.5734)
Description: $ETH-LAN$$FW_INSIDE$
Internet address is 192.168.2.200/24
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 2/255, rxload 1/255
Encapsulation 802.1Q Virtual LAN, Vlan ID 1.
ARP type: ARPA, ARP Timeout 04:00:00
Last clearing of "show interface" counters never
FastEthernet0/0.2 is up, line protocol is up
Hardware is Gt96k FE, address is 0017.595e.5734 (bia 0017.595e.5734)
Description: $ETH-LAN$$FW_INSIDE$
Internet address is 192.168.4.1/24
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 2/255, rxload 1/255
Encapsulation 802.1Q Virtual LAN, Vlan ID 2.
ARP type: ARPA, ARP Timeout 04:00:00
Last clearing of "show interface" counters never
FastEthernet0/1 is up, line protocol is up
Hardware is Gt96k FE, address is 0017.595e.5735 (bia 0017.595e.5735)
Description: Internet$FW_OUTSIDE$$ETH-LAN$
Internet address is XXXX/29
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, 100BaseTX/FX
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/110/0 (size/max/drops/flushes); Total output drops: 109
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 720000 bits/sec, 89 packets/sec
5 minute output rate 288000 bits/sec, 73 packets/sec
111283688 packets input, 2544427114 bytes
Received 30843 broadcasts, 0 runts, 0 giants, 0 throttles
409 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog
0 input packets with dribble condition detected
102491341 packets output, 2828776774 bytes, 0 underruns
0 output errors, 0 collisions, 4 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
Serial0/0/0 is up, line protocol is up
Hardware is GT96K with integrated T1 CSU/DSU
Description: "T1 to Abbottstown"$FW_INSIDE$
Internet address is 192.168.200.1/30
MTU 1500 bytes, BW 1544 Kbit, DLY 20000 usec,
reliability 255/255, txload 14/255, rxload 2/255
Encapsulation HDLC, loopback not set
Keepalive set (10 sec)
Last input 00:00:03, output 00:00:07, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 1675
Queueing strategy: Class-based queueing
Output queue: 0/1000/64/1675 (size/max total/threshold/drops)
Conversations 0/22/256 (active/max active/max total)
Reserved Conversations 1/1 (allocated/max allocated)
Available Bandwidth 773 kilobits/sec
5 minute input rate 13000 bits/sec, 27 packets/sec
5 minute output rate 89000 bits/sec, 30 packets/sec
63436963 packets input, 2267964727 bytes, 0 no buffer
Received 278809 broadcasts, 0 runts, 0 giants, 0 throttles
1351 input errors, 1350 CRC, 499 frame, 197 overrun, 0 ignored, 741 abort
66879848 packets output, 895051379 bytes, 0 underruns
0 output errors, 0 collisions, 5 interface resets
0 output buffer failures, 0 output buffers swapped out
3 carrier transitions
DCD=up DSR=up DTR=up RTS=up CTS=up
NVI0 is up, line protocol is up
Hardware is NVI
MTU 1514 bytes, BW 10000000 Kbit, DLY 0 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation UNKNOWN, loopback not set
Last input never, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 packets output, 0 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 output buffer failures, 0 output buffers swapped out
E-town# sh access-list
Standard IP access list 1
10 permit 192.168.4.0, wildcard bits 0.0.0.255
20 permit 192.168.200.0, wildcard bits 0.0.0.3
Extended IP access list 100
10 permit ip any any (1192 matches)
Extended IP access list 101
10 deny ip 192.168.200.0 0.0.0.3 any
20 deny ip 192.168.2.0 0.0.0.255 any
30 deny ip xx.xxx.62.72 0.0.0.7 any
40 deny ip host 255.255.255.255 any
50 deny ip 127.0.0.0 0.255.255.255 any
60 permit ip any any
Extended IP access list 102
10 deny ip 192.168.4.0 0.0.0.255 any
20 deny ip 192.168.2.0 0.0.0.255 any (65 matches)
30 deny ip xx.xxx.62.72 0.0.0.7 any (706118 matches)
40 deny ip host 255.255.255.255 any
50 deny ip 127.0.0.0 0.255.255.255 any
60 permit ip any any (63001339 matches)
Extended IP access list 103
10 permit udp any host xx.xxx.62.74 eq isakmp
20 permit tcp any host xx.xxx.62.74 eq 50
30 permit udp any host xx.xxx.62.74 eq non500-isakmp
40 permit tcp any host xx.xxx.62.74 eq 443
50 permit tcp any host xx.xxx.62.74 eq www
60 permit tcp any host xx.xxx.62.73 eq 443
70 permit tcp any host xx.xxx.62.73 eq www
80 permit tcp any host xx.xxx.62.73 eq smtp
90 deny ip 192.168.200.0 0.0.0.3 any
100 deny ip 192.168.4.0 0.0.0.255 any
110 deny ip 192.168.2.0 0.0.0.255 any
120 permit udp any eq bootps any eq bootps
130 permit icmp any host xx.xxx.62.74 echo-reply
140 permit icmp any host xx.xxx.62.74 time-exceeded
150 permit icmp any host xx.xxx.62.74 unreachable
160 deny ip 10.0.0.0 0.255.255.255 any
170 deny ip 172.16.0.0 0.15.255.255 any
180 deny ip 192.168.0.0 0.0.255.255 any
190 deny ip 127.0.0.0 0.255.255.255 any
200 deny ip host 255.255.255.255 any
210 deny ip host 0.0.0.0 any
220 deny ip any any log
Extended IP access list 104
10 permit ip any host 129.35.117.246 (159296 matches)
20 permit tcp host 192.168.2.5 any eq smtp (1219189 matches)
30 deny tcp any any eq smtp (11886 matches)
40 deny ip 192.168.200.0 0.0.0.3 any
50 deny ip 192.168.4.0 0.0.0.255 any (165 matches)
60 deny ip xx.xxx.62.72 0.0.0.7 any (5958800 matches)
70 deny ip host 255.255.255.255 any
80 deny ip 127.0.0.0 0.255.255.255 any
90 permit ip any any (109050101 matches)
Extended IP access list 105
10 deny ip 192.168.200.0 0.0.0.3 any
20 deny ip 192.168.2.0 0.0.0.255 any (47 matches)
30 deny ip xx.xxx.62.72 0.0.0.7 any (97170 matches)
40 deny ip host 255.255.255.255 any
50 deny ip 127.0.0.0 0.255.255.255 any
60 permit ip any any (71787696 matches)
Extended IP access list 106
10 permit tcp any host xx.xxx.62.76 eq ftp-data
20 permit ip host 129.35.117.246 any (522 matches)
30 permit tcp any host xx.xxx.62.76 eq
matches)
40 permit tcp any host xx.xxx.62.76 eq ftp (845057 matches)
50 permit tcp any host xx.xxx.62.74 eq 1723 (60393 matches)
60 permit gre any host xx.xxx.62.74 log (561860 matches)
70 permit udp any host xx.xxx.62.74 eq isakmp (443 matches)
80 permit tcp any host xx.xxx.62.74 eq 50
90 permit udp any host xx.xxx.62.74 eq non500-isakmp
100 permit tcp any host xx.xxx.62.74 eq 443 (247824 matches)
110 permit tcp any host xx.xxx.62.74 eq
matches)
120 permit tcp any host xx.xxx.62.73 eq 443 (8 matches)
130 permit tcp any host xx.xxx.62.73 eq
matches)
140 permit tcp any host xx.xxx.62.73 eq smtp (840141 matches)
150 permit udp host 205.160.192.2 eq domain host xx.xxx.62.74 (784 matches)
160 deny ip 192.168.200.0 0.0.0.3 any
170 deny ip 192.168.4.0 0.0.0.255 any
180 deny ip 192.168.2.0 0.0.0.255 any (5 matches)
190 permit udp any eq bootps any eq bootps
200 permit icmp any host xx.xxx.62.74 echo-reply
210 permit icmp any host xx.xxx.62.74 time-exceeded (15149 matches)
220 permit icmp any host xx.xxx.62.74 unreachable (364570 matches)
230 deny ip 10.0.0.0 0.255.255.255 any (22 matches)
240 deny ip 172.16.0.0 0.15.255.255 any (25 matches)
250 deny ip 192.168.0.0 0.0.255.255 any (1157 matches)
260 deny ip 127.0.0.0 0.255.255.255 any
270 deny ip host 255.255.255.255 any
280 deny ip host 0.0.0.0 any
290 deny ip any any log (989918 matches)
Extended IP access list 107
10 deny ip 192.168.200.0 0.0.0.3 any
20 deny ip 192.168.4.0 0.0.0.255 any
30 deny ip xx.xxx.62.72 0.0.0.7 any (1184 matches)
40 deny ip host 255.255.255.255 any
50 deny ip 127.0.0.0 0.255.255.255 any
60 permit ip any any (12715 matches)
Extended IP access list ToTheInternet
10 permit ip any any (7019755 matches)
E-town#