Kamis, 04 November 2010

Cisco Series

Router adalah sebuah peralatan yang digunakan pada jaringan WAN (World Area Network).Router menyalurkan informasi ke router lainpada jaringan yang berbeda.Pada jaringan LAN (Local Area Network) router mengunakan tabel routing atau disebut juga routing statis.Perangkat yang ada didalam router seperti halnya komputer menggunakan CPU(Central Procesing Unit).Pada Cisco router terdapat ROM,RAM,NVRAM dan FLASH yang berguna membantu kerja CPU dan beberapa interface yang dapat menghubungkan router dengan dunia luar untuk keluar masuk data.Cisco router menggunakan sistem operasi IOS (Internetwork Operating System).Memori yang digunakan oleh cisco router masing-masing mempunyai kegunaan sendiri- sendiri sebagai berikut :
• ROM berguna untuk menyimpan sistem bootstrap yang berfungsi untuk mengatur proses boot dan menjalankan Power On Self Test (POST) dan IOS image.
• RAM berguna untuk menyimpan running configuration dan dan sistem operasi IOS yang aktif.
• NVRAM berguna untuk menyimpan konfigurasi awal (start-up configuration)
• FLASH berguna untuk menyimpan IOS image. Dengan menggunakan FLASH, IOS versi baru dapat diperoleh dari TFTP server tanpa harus mengganti komponen dalam router.
Macam-macam Cisco router
Perusahaan cisco membuat router dengan berbagai seri dan model untuk berbagai kelas
atau tingkat penggunaan, seperti :
1. CISCO ROUTER TIPE FIXED TINGKAT AKSES
• Cisco router 700 series
• Cisco router 801-804
• Cisco router 805
• Cisco router 811 dan 813
• Cisco router 827
• Cisco router 1000 series
• Cisco router 2000 series
• Cisco router 2500 series
• Cisco router 3000 series
2. CISCO ROUTER TIPE MODULAR TINGKAT AKSES
• Cisco router 1600 series
• Cisco router 1720 dan 1750
• Cisco router 2500 series
• Cisco router 2600 series
• Cisco router 3600 series
• Cisco router 4000 series
3. CISCO ROUTER TIPE MODULAR TINGKAT INTI
• Cisco router 7000 series, untuk enterprise
• Cisco router 10000 dan 12000 series, untuk enterprise
Umumnya perusahaan cisco memberikan nomor model dengan angka kecil seperti cisco router model 700 untuk jaringan WAN sederhana untuk dipakai oleh perusahaan kecil. Sedangkan nomor dengan angka yang besar seperti cisco router model 12000 digunakan untuk jaringan WAN kompleks yang dipakai oleh perusahaan besar.
Cisco router tipe fixed mempunyai interface tetap yang tidak dapat diganti-ganti sesuai dengan kebutuhan pemakai. Umumnya cisco router jenis modular harganya jauh lebih mahal, tetapi lebih fleksibel dalam penggunaanya. Cisco router 2500 series tersedia dalam bentuk tipe fixed maupun modular. Setiap router biasanya mempunyai dua Synchronous Serial port DB-60 (Serial0 dan Serial1) untuk hubungan WAN, satu ethernet port DB-15 (AUI) untuk hubungan LAN, satu Console port RJ-45 untuk akses langsung ke sistem router dan satu Auxiliary Port RJ-45 (AUX) untuk akses ke sistem router dengan modem.
http://www.cisco.com/en/US/prod/routers/ps10536/3900-m.jpg

Rabu, 06 Oktober 2010

Koneksi Jaringan

 

Koneksi jaringan merupakan upaya mengkoneksikan semua peralatan jaringan dalam infrastruktur jaringan komputer. Anda harus konsentrasikan terlebih dahulu pada local area network anda sebelum anda membuat koneksi ke jaringan WAN yang menghubungkan semua remote site anda kedalam suatu system koneksi jaringan – suatu infrastruktur jaringan komputer. Hal ini bukan berarti anda tidak perlu membuat design WAN kedalam design jaringan anda sampai semua jaringan local area network anda terbentuk, akan tetapi anda kosentrasikan dulu sampai anda bisa memastikan bahwa system koneksi jaringan LAN anda sudah effisien sebelum membuat koneksi ke WAN.
Akan banyak sekali pekerjaan yang akan diselesaikan dalam koneksi jaringan ini dan tergantung seberapa besar skala design jaringan anda. Membuat koneksi jaringan dalam suatu perusahaan dimana kantornya terdiri dari beberapa site yang jauh bahkan sampai melewati batas geography, berbeda dengan koneksi jaringan dalam local area network yang menghubungkan beberapa bangunan dalam suatu area perusahaan atau mungkin hanya dalam suatu ruangan kantor yang kecil saja. Anda harus sudah menyelesaikan design jaringan anda termasuk system komputer yang bakal menggunakan system infrastruktur jaringan ini. Pekerjaan koneksi jaringan ini memang rumit tergantung seberapa besar skala jaringan anda apalagi jika anda harus juga mendesign jaringan backup in case terjadi bencana atau antisipasi adanya masalah dalam jaringan.
Diasumsikan bahwa anda sudah membuat design jaringan anda dan sebagian dari diagram sites anda seperti gambar ibawah ini, bagaimana anda membuat koneksi jaringan berdasarkan diagram sites ini?
Diagram Koneksi Jaringan
Diagram Koneksi Jaringan
Ruang server dimana beberapa server anda berada, ada di gedung HRD. ada sekitar 80 user di gedung ini. Saya katakan beberapa server – kenapa tidak semua server berada dalam satu ruangan dan dalam satu gedung yang sama? Hal ini menyangkut keamanan standard security best practice mengenai penempatan servers (artikel berikutnya). Masih ada dua bangunan lagi yang harus dihubungkan dalam koneksi jaringan:
1.       Gedung mining yang berjarak sekitar 70 meter dari gedung HRD (ada sekitar 80 user juga)
2.       Workshop yang berada dibawah lembah yang berjarak lebih dari 300 meter dari gedung HRD (ada sekitar 50 user disini)
Total user dalam jaringan ini adalah 200 (80 dalam gedung HRD + 80 di Mining + 40 di Workshop), dan belum termasuk kebutuhan IP address permanen untuk beberapa server; printer; Access Point wireless; switch; dan juga VoIP. Anda bisa memakai satu jaringan IP private katakana 192.168.100.0/24 (tersedia 254 IP addres) untuk semua user dan piranti dalam jaringan ini. Untuk itu anda bisa menggunakan 4 buah switch 24 port di cascade di kedua gedung mining dan HRD dengan standard 100BaseT Ethernet. Sementara di workshop cukup 3 switch 24 port di cascade. Terkecuali di server room anda perlu switch Gigabit 12 port jika semua server anda dilengkapi dengan Gigabit Ethernet, untuk transfer data yang sangat cepat dan akan terasa berguna sekali jika anda menggunakan satu piranti tunggal backup Autoloader untuk keperluan backup semua data server; exchange dan database anda, yang rutin dilakukan di malam hari.
Kemudian bagaimana tentang koneksi jaringan antara gedung HRD dengan Workshop? Karena letak Workshop ini berada dibawah lembah dengan jarak lebih dari 300 meter, tidak mungkin anda menggunakan koneksi kabel. Maka anda bisa memanfaatkan teknologi Wireless yang menghubungkan dua atau lebih titik access point lewat media transmisi radio dengan frequensi 2.4 GigaHz. Anda bisa mendapatkan produk semacam ini dipasaran misal Cisco Aironet. Anda bisa membangun dua tower sederhana untuk meletakkan antenna di puncak tower asal kedua antenna Access point ini bisa saling melihat tanpa halangan. Piranti Wireless ini bisa mentransmit data sampai 58 Mbps; cukup untuk link antar gedung ini dengan menggunakan media transmisi udara. Silahkan membaca artikel selanjutnya mengenai wireless local area network.
Sekarang bagaimana anda menghubungkan koneksi jaringan antara bangunan di Mining dan di HRD yang berjarak sekitar 70 meter? Hal ini akan tergantung dari kendala yang anda hadapi, jika anda harus memutuskan untuk menarik kabel bawah tanah maka gunakanlah kabel LAN outdoor UTP Cat 5e yang memang didesign khusus untuk pemakaian luar gedung dan tahan air dan support speed gigabit.  Akan tetapi untuk alasan kemanan dan kemudahan maintenance maka masukkan kabel UTP yang diameternya cukup besar ini kedalam pipa besi atau sejenisnya dan bila perlu buatkan saluran khusus semacam saluran air.
Kenapa tidak memakai jaringan wireless saja antar dua gedung ini seperti antar HRD dan workshop? Memang dengan jaringan wireless sangat praktis sekali anda tidak perlu repot-2 narik kabel bawah tanah, akan tetapi anda tahu kalau wireless sampai sekarang ini speednya paling tinggi sekitar 300 Mbps (draft 802.11n standards), sementara antar dua gedung tersebut anda memerlukan koneksi yang handal dengan kecepatan gigabit sebagai backbone dua gedung. Di Mining office juga ada beberapa server data dan aplikasi mining yang sangat besar datanya terutama data geologi dan harus di backup secara terpusat di gedung HRD. Belum lagi kendali blackspot kalau terjadi masalah dengan wireless anda, atau banyaknya halangan interferensi frequensi radio. Sementara untuk gedung workshop memang kendalanya mengharuskan kita memakai jaringan radio wireless karena antar gedung harus melewati lembah dan tidak memungkinkan menarik kabel melewati hutan yang walau hanya berjarak sekitar 300 meter. Jaringan wireless sangat diandalkan jika kedua tower antenna bisa saling melihat. Dan lagi di workshop hanya memerlukan koneksi untuk clients komputer saja.
Untuk menyelesaikan koneksi jaringan ini, anda masih perlu untuk memikirkan tentang konfigurasi jaringan dan setup jaringan untuk semua piranti dalam koneksi jaringan ini seperti IP address ke semua client PC; IP permanen untuk server; switch; printer dan sebagainya.
Selanjutnya apa? Yang perlu anda pertimbangkan adalah dokumentasi semua pekerjaan ini termasuk rencana disaster recovery – suatu rencana backup – plan B dari kemungkinan terjadinya bencana.

Senin, 20 September 2010

Konfigurasi Juniper Untuk Membatasi Akses Internet

Sekilas Tentang Juniper
Juniper/Netscreen merupakan hardware jaringan yang memiliki banyak fungsi, namun fungsi utamanya adalah sebagai gateway dan firewall. Produk Juniper terdiri atas keluarga router T-series, M-series, E-series, MX-series, dan J-series, Switch ethernet EX-series, perangkat optimasi WAN WX-series, dan perangkat Session & Resource Control (SRC).
Konfigurasi Juniper Untuk Membatasi Akses Internet
Kali ini kita akan membahas konfigurasi Juniper untuk membatasi akses internet dimana hanya User/IP tertentu saja yang ada pada suatu jaringan yang dapat mengakses internet. Berikut langkah-langkah yang diperlukan untuk Konfigurasi Juniper sebagai firewall untuk membatasi akses internet :
1. Pertama tambahkan List Address pada Trust Zone (Internal Zone) dengan cara :
  • Klik menu Object-Address-List
  • Isikan Address NameIP Address dan Netmask
  • Pilih Zone : Trust (Trust Zone merupakan Zona yang ada di jaringan internal)



2. Setelah itu buatlah Group Address List pada Trust Zone dengan cara :
  • Pilih menu Objects > Addresses > Groups
  • Pilih Zone Trust lalu klik button New
  • Isikan Group Name (misal Internet and email)
  • Pilih nama di Avialable Member di kolom sebelah kanan
  • Lalu klik tombol << “ untuk menambahkan ke Group
Member yang ada di Group ini saja yang bisa menggunakan Internet.

3. Lalu kita akan mendefinisikan Group Service untuk mengakses internet (HTTP, FTP, DNS, PING, POP3, SMTP) dengan cara :
  • Pilih menu Objects > Services > Groups
  • Klik tombol New untuk menambahkan Group
  • Isikan Group Name (misal Internet and Email)
  • Tambahkan DNS, FTP, HTTP, HTTPS, PING , POP3, dan SMTP di Group Service ini.

4. Selanjutnya membuat Policies untuk membatasi akses internet, dengan cara :
  • Pilih menu Policies
  • Pilih zone from Trust to Untrust
  • Klik tombol New
  • Pilih / Isikan Source Address dengan ” Internet and Email “ dari Address Book Entry
  • Pilih / isikan Destination Address dengan ” Any “ dari Address Book Entry
  • Pilih / Isikan Service “Internet dan Email
  • Tekan OK


Jika anda sudah mengkonfigurasikannya dengan benar maka hanya user dan IP address yang ada di group Internet and Email saja yang dapat mengakses Internet.

FORTIGATE 60 FIREWALL CLI CONFIGURATION

Configure Interface
Fortiget-60 # config system interface
edit internal
set ip 192.168.2.1 255.255.255.0
set mode static
next
edit wan1
set ip 192.168.3.1 255.255.255.0
next
edit internal
set ip 192.168.100.1 255.255.255.0
set dhcp-server-mode none (Set DHCP Server Mode Off)
next
edit wan1
set ip 192.168.1.2 255.255.255.0
show system interface (Check interface configuration)
Configure DNS
Fortiget-60 # config system dns
set primary 165.21.83.88
set secondary 165.21.100.88
end
Configure Internal Allowaccess (ping, https)
Fortiget-60 # config system interface
edit internal
unset allowaccess
set allowaccess ping
set allowaccess https
end
Configure Wan1 Allowaccess (ping)
Fortiget-60 # config system interface
edit wan1
unset allowaccess
set allowaccess ping
end
Configure Static Route
Fortiget-60 # config router static
edit 1
set device wan1
set dst 0.0.0.0 0.0.0.0
set gateway 192.168.1.1
set distance 10
Change Admin Password
Fortiget-60 # config system admin
edit admin
set password
end
Firmware Upgrade
To upgrade the FortiGate firmware from the CLI:
1 Make sure that the TFTP server is running.
2 Copy the new firmware image file to the root directory of your TFTP server.
3 Log into the CLI as the admin administrative user.
Fortiget-60 # execute restore image

How to Configure Cisco PIX Firewall Part I

How to Configure PIX Firewall.
Abstract:

Please find below a step by step process to configure the PIX Firewall from scratch. A simple scenario is given here where you have a corporate network with a PIX Firewall connected to the Internet through the Outside Interface, Internal Network through the Inside interface and DMZ through the DMZ Network. This paper would assist you in a simple step by step, near complete configuration for a PIX Firewall running a midsized corporate network

The Outside Network is connected to the internet through a Internet Router. The Inside Network is connected to a switch to the Internal Clients or Inside Hosts. The DMZ network consists of two servers, the Web server and the WEB server.
Note: An effort has been made to keep this paper as simple as possible for the newbies. Much theory is not covered as you have numerous sites on the internet from where you can read that stuff.. Referral Links are given from time to time for more detailed configuration from Cisco website for Reference purpose.

A Simple Network Diagram




The first thing in configuration is getting connected to the pix firewall. You use the console cable to connect the cable to the console port of the pix firewall. The other end goes to the serial port of your computer. You can then use a terminal emulation software to get connected to the prompt. For Windows users, HyperTerminal is a good option.
The next step is booting the Firewall.
When a non-configured PIX Firewall boots up, it prompts to preconfigure it through interactive prompts. If you press Enter to accept the default answer of yes, you are presented with a series of prompts that lead you through the basic configuration steps:
Pre-configure PIX Firewall now through
interactive prompts [yes]? Enable Password []: abc123
Clock (UTC)
Year [2002]:
Month [Aug]:
Day [2]: 12
Time [2:45:37]: 12:22:00
Inside IP address: 10.1.1.1
Inside network mask: 255.255.255.0
Host name: pixfirewall
Domain name: secmanager.com
IP address of host running
PIX Device Manager: 101.1.111
Use this configuration and write to flash? Y
The above can also be achieved by entering the setup command in privileged mode.
The pix Firewall has four modes of Operation as given below:
• Unprivileged mode: This mode provides a restricted, limited, view of PIX Firewall settings. Example : pixfirewall>
• Privileged mode: This mode enables you change the current firewall settings. Example: pixfirewall#
• Configuration mode: This mode enables you to change the system configurations of the firewall. Example pixfirewall(config)#
• Monitor mode: This mode is used to update the image over the network, perform password recovery or backup the configuration onto the TFTP server
In case you don’t want to use the setup command for the configuration, you can use the console connection and configure as follows:
Priveleged mode
The first step is to enter the privileged mode:
Pixfirewall> en
Password: (Enter or Cisco, for more information refer to the configuration manuals that came with the firewall)
Pixfirewall#
Changing password
The next step is to change the enable password on the firewall:
Pixfirewall# enable password abc123
The next step is to enter the configuration mode for changing the system configurations. To enter the config mode, enter the following command:
Pixfirewall# configure terminal (or popularly conf t)
Pixfirewall (config) #
Give a Hostname to the firewall.
You might want to give a hostname to the firewall. You can use the hostname command to do this.
Pixfirewall (config) #hostname CorpFW1
CorpFW1(config)#
To save the information, use the write memory command or simply wr mem.
CorpFW1(config)# write memory
For purposes of this document, we continue to give the firewall the name “Pixfirewall”. So let us change the name back to Pixfirewall
CorpFW1(config)# hostname Pixfirewall
Pixfirewall (config) # wr mem
Setup the console timeout:
Next, you might want to setup the console timeout for security reasons. The default timeout is 0, which means unlimited.
Pixfirewall (config) # console timeout 5
This means you have setup a console timeout of 5 minutes ( the value can be set from 0-60 minutes) which means after a idle time of 5 minutes, the session will be closed.
Setup a banner to your Pix firewall.
You can do this with the banner command:
Pixfirewall (config) # banner exec Unauthorized access will be prosecuted.
There are also two other commands available:
banner login
banner motd
To remove banner you use the no banner or clear banner commands.
Naming an Interface:
The first two interfaces would have the default names of inside and outside. While inside interface has a security level of 100, the outside interface has a default security level of 0.
Let us configure the Ethernet 2 interface as the dmz.
Pixfirewall (config) # nameif ethernet2 dmz sec60
In this example, we are assigning a security_level of 60 to the DMZ network.
Configure the Interface:
Now let us turn the interface on and configure the speeds for these interfaces:
Pixfirewall (config) # interface ethernet0 100full
Pixfirewall (config) #interface ethernet1 100full
Pixfirewall (config) #interface ethernet2 100full
Assign IP Address to the Interface:
Pixfirewall (config) # ip address outside 192.168.1.1 255.255.255.0
Pixfirewall (config) # ip address inside 10.1.1.1 255.255.255.0
Pixfirewall (config) #ip address dmz 172.16.16.1 255.255.255.0
You can use the “show ip” command to view the ip address information and “clear ip” command to remove all assigned IP addresses from all interfaces.
Route Commands:
Now let us setup the routing information on the pix firewall.
This is the default route, where we are configuring the next hop of the default route to the IP address of the Internet Router which is 192.168.1.100
Pixfirewall (config) # route outside 0.0.0.0 0.0.0.0 192.168.1.100 1
Pixfirewall (config) # route inside 10.0.0.0 255.0.0.0 10.1.1.1 1
Pixfirewall (config) # route dmz 172.16.17.0 255.255.255.0 172.16.16.1 1
So using these route commands you are telling the PIX router that route the traffic for 10.0.0.0/8 network to inside, 172.16.17.0/24 network to dmz. The default route is set for outside, which means for all other networks, route the traffic through the outside interface.

How to Configure Cisco PIX Firewall Part II

Please find below a step by step process to configure the PIX Firewall from scratch. A simple scenario is given here where you have a corporate network with a PIX Firewall connected to the Internet through the Outside Interface, Internal Network through the Inside interface and DMZ through the DMZ Network. This paper would assist you in a simple step by step, near complete configuration for a PIX Firewall running a midsized corporate network

This is part II of the How to Configure Pix Firewall, a step by step approach.
This is in continuation of the Part I of the series.
A Simple Network Diagram




Network Address Translation:
Let us take a simple scenario to explain this section. Let us say that all the computers in the inside network want internet access. NAT also allows you to keep your internal IP hidden from the outside network. To achieve this you need to implement address translation. You do this using the “nat” and “global” commands.
The NAT command:
Pixfirewall (config) # nat (inside) 1 0.0.0.0 0.0.0.0
In this example, the nat (inside) 1 10.0.0.0 255.255.255.0 command means that all outbound connections from a host within the specified network, 10.1.1.0, can pass through the PIX Firewall (with address translation).
Global command:
Pixfirewall (config) #global (outside) 1 192.168.1.10-192.168.1.50
This means that use the IP address from 192.168.1.10 to 192.168.1.50 for NATing the traffic coming from the inside interface.
There is also another simple way for allowing internet /outside access to the inside network using PAT or port address translation. What this would do is hide all the internal networks behind the outside interface of the PIX firewall and transmit traffic using Port Address Translation. One limitation to this approach is that at a time it can process only less than 64000 client computers. But in most cases, this is more than enough.
PAT using Global:
Pixfirewall (config) # global (outside) 1 interface
Now, let us configure the two servers in the dmz network, the webserver and the mailserver. The wish list is to allow traffic from anywhere to reach the webserver on http, https and ftp and traffic from anywhere to reach the mail server on the smtp port.
To do this we need to setup statics and access-lists.
Setting up Static’s:
Pixfirewall (config) #static (dmz,outside) 192.168.1.2 172.16.16.2 netmask 255.255.255.255 0 0
Pixfirewall (config) # static (dmz,outside) 192.168.1.4 172.16.16.4 netmask 255.255.255.255 0 0
Having configured the statics, now let us move on to configure the object-groups that would be used in configuring the access-list
Configuring object-groups:
Pixfirewall (config) #object-group service webservices tcp
Pixfirewall (config-service) # port-object eq http
Pixfirewall (config-service) # port-object eq https
Pixfirewall (config-service) # port-object eq ftp
Pixfirewall (config-service) # exit
Pixfirewall (config) #
Now let us configure the access-lists to allow access to the dmz networks from outside and also to the other interfaces:
Configuring Access-list:
Pixfirewall (config) # access-list external permit tcp any host 192.168.1.2 object-group webservices
Pixfirewall (config) # access-list external permit tcp any host 192.168.1.4 eq smtp.
Pixfirewall (config) #access-list external deny ip any any
(This is a any any drop rule. Place this at the end of the access-lists. This acl won’t allow any other traffic that is not explicitly allowed to get into the firewall. This is often helpful in checking the number of hits on this acl from outside for troubleshooting or analysis purposes.)
Pixfirewall (config) #access-list internal permit ip 172.16.16.0 255.255.255.0 10.1.1.0 255.255.255.0
Pixfirewall (config) # access-list internal deny ip any any
Pixfirewall (config) # access-list dmz permit ip 10.1.1.0 255.255.255.0 172.16.16.0 255.255.255.0
Pixfirewall (config) #access-list dmz deny ip any any
Now map these access-lists to access-groups for these access-lists to work properly:
Configuring Access Groups:
Pixfirewall (config) #access-group external in interface outside
Pixfirewall (config) # access-group internal in interface inside
Pixfirewall (config) #access-group dmz in interface ethernet2
With this we have configured the PIX firewall for a normal office setup.
These commands will be helpful in checking the configuration of the pix firewall and also in troubleshooting, analysis and fine tuning.
Useful Commands:
show config
show blocks
show checksum
show conn
show cpu usage
show history
show memory
show processes
show routing
show running-config
show startup-config
show tech-support
show tcpstat
show traffic
show uauth/clear uauth
show version
show xlate/clear xlate
Note: There is a lot that you can do with the PIX firewall. This document is just a simple guide for a easy setup. It covers most popular setups. In case you need any further information please refer to Cisco website at http://www.cisco.com
Further reference:
You can also refer to the Getting Started document for more detailed information from the Cisco Website:
http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172790.html
Cisco PIX Firewall Command Reference, version 6.3
http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_book09186a008017284e.html

Cisco site to site VPN Configuration Cheatsheet

Please find enclosed the cisco site to site VPN configuration in a nutshell. These basic commands would help in configuring a site to site VPN setup. This can also assist in troubleshooting vpn issues.
VPN Configuration Steps:
sysopt connection permit-ipsec
Phase I
isakmp enable outside
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
iaskmp policy 10 authentication pre-share or rsa-sig
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
isakmp key abc123 address 192.168.1.2 netmask 255.255.255.255
isakmp identity address
show isakmp policy
show isakmp
Phase 2
access-list 101 permit ip 10.0.1.0 255.255.255.0 172.16.1.0 255.255.255.0
nat (inside) 0 access-list 101
crypto ipsec transform-set customer1 esp-des esp-sha-hmac
crypto map PIX1MAP 10 ipsec-isakmp
crypto map PIX1MAP 10 match address 101
crypto map PIX1MAP 10 set peer 192.168.2.1
crypto map PIX1MAP 10 set transform-set customer1
crypto map PIX1MAP 10 set security-association lifetime seconds 28800
crypto map PIX1MAP 10 set pfs group1
crypto map PIX1MAP interface outside
crypto dynamic-map dynamic-map-name dynamic-seq-num
show crypto map
show isakmp
show isakmp policy
show access-list
show crypto ipsec transform-set
show crypto map
clear crypto ipsec sa
clear crypto isakmp sa
debug crypto ipsec
debug crypto isakmp