Using 8998 out of 262136 bytes ! ! Last configuration change at 09:15:23 GMT Tue Jan 23 2024 by admin ! NVRAM config last updated at 09:15:41 GMT Tue Jan 23 2024 by admin ! NVRAM config last updated at 09:15:41 GMT Tue Jan 23 2024 by admin version 15.1 no service pad service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname COKP-CISCO881 ! boot-start-marker boot-end-marker ! ! ! aaa new-model ! ! aaa authentication login default local aaa authentication enable default enable aaa authentication ppp default local aaa authorization exec default local aaa authorization network default local ! ! ! ! ! aaa session-id common ! clock timezone GMT 7 0 clock calendar-valid no ip source-route ! ! ! ip dhcp excluded-address 192.168.1.1 192.168.1.50 ! ip dhcp pool Office Network network 192.168.1.0 255.255.255.0 default-router 192.168.1.1 dns-server 172.16.1.29 172.16.111.28 109.194.32.1 5.3.3.3 option 150 ip 192.168.1.3 192.168.1.4 domain-name admin.local option 42 ip 192.168.1.1 option 4 ip 192.168.1.1 ! ip dhcp pool Static Office Network origin file flash:StaticON.txt ! ip dhcp pool COKPdisk host 192.168.1.251 255.255.255.0 hardware-address 9009.d019.e465 default-router 192.168.1.1 dns-server 172.16.1.29 172.16.111.28 domain-name admin.local ! ip dhcp pool TP_LINK_COKP2 host 192.168.1.248 255.255.255.0 hardware-address 84d8.1ba6.cfbe default-router 192.168.1.1 dns-server 172.16.1.29 172.16.111.28 domain-name admin.local ! ! ip cef ip domain name admin.local ip name-server 172.16.1.29 ip name-server 172.16.111.28 ip name-server 109.194.32.1 ip name-server 5.3.3.3 no ipv6 cef ! ! ! ! multilink bundle-name authenticated vpdn enable ! vpdn-group 1 ! Default PPTP VPDN group accept-dialin protocol pptp virtual-template 1 l2tp tunnel timeout no-session 15 ! ! ! ! voice service voip dtmf-interworking rtp-nte allow-connections h323 to sip allow-connections sip to h323 allow-connections sip to sip sip ! voice class codec 1 codec preference 1 g711alaw codec preference 2 g729r8 ! ! ! ! voice translation-rule 1 rule 1 /^282905/ /195/ rule 2 /^282906/ /196/ ! voice translation-rule 2 rule 1 /.*/ /282905/ ! ! voice translation-profile Incoming translate called 1 ! voice translation-profile Outgoing translate calling 2 translate redirect-called 2 ! ! crypto pki token default removal timeout 0 ! ! license udi pid C881-CUBE-K9 sn FCZ1705C455 ! ! ! ! ip ftp username CiscoRouter ip ftp password ip ssh authentication-retries 2 ip ssh version 2 l2 router-id 192.168.1.1 ! ! ! ! ! interface Loopback0 ip address 192.168.2.1 255.255.255.0 ! interface FastEthernet0 description Switchport for Office Network switchport access vlan 10 no ip address ! interface FastEthernet1 description Switchport for TABLO switchport access vlan 40 no ip address ! interface FastEthernet2 description Switchport for DMZ switchport access vlan 20 no ip address ! interface FastEthernet3 description Switchport for ADMIN switchport access vlan 30 no ip address ! interface FastEthernet4 description Interface for Internet mac-address 0000.0000.0000.0000 ip address __.172.0.44 255.255.255.128 ip access-group FROM_INTERNET in ip access-group TO_INTERNET out ip nat outside ip virtual-reassembly in duplex auto speed auto ! interface Virtual-Template1 ip unnumbered Loopback0 peer default ip address pool TUNNEL no keepalive ppp authentication pap ! interface Vlan1 no ip address shutdown ! interface Vlan10 description Interface for Office Network ip address 192.168.1.1 255.255.255.0 ip access-group FROM_OFFICE in ip access-group TO_OFFICE out ip nat inside ip virtual-reassembly in ! interface Vlan20 description Interface for DMZ ip address 213.183.104.177 255.255.255.248 ! interface Vlan30 description Interface for ADMIN ip address dhcp ip access-group FROM_ADMIN in ip access-group TO_ADMIN out ip nat outside ip virtual-reassembly in ! interface Vlan40 description Interface for TABLO ip address 192.168.17.1 255.255.255.0 ip nat outside ip virtual-reassembly in ! ip local pool TUNNEL 192.168.2.15 192.168.2.16 ip forward-protocol nd no ip http server no ip http secure-server ! ! ip dns server ip nat inside source route-map ROUTE_TO_ADMIN interface Vlan30 overload ip nat inside source route-map ROUTE_TO_INTERNET interface FastEthernet4 overload ip nat inside source static tcp 192.168.1.50 1717 192.168.17.1 1717 extendable ip route 0.0.0.0 0.0.0.0 __.172.0.1 ip route 172.16.0.0 255.255.0.0 dhcp ! ip access-list extended FROM_ADMIN evaluate RESPONSE_FROM_ADMIN permit udp 172.16.0.0 0.0.255.255 eq bootps any eq bootpc permit icmp 172.16.0.0 0.0.255.255 any echo-reply permit icmp 172.16.0.0 0.0.255.255 any time-exceeded deny ip any any ip access-list extended FROM_INTERNET evaluate RESPONSE_FROM_INTERNET permit udp host __.172.4.3 eq 5060 any permit udp host __.172.4.3 any eq 5060 permit tcp any host 213.183.104.180 eq www permit tcp any host 213.183.104.178 eq 1717 permit tcp any host 213.183.104.178 eq 1718 permit tcp any host 213.183.104.178 eq www permit tcp any host 213.183.104.178 eq 443 permit tcp any host 213.183.104.178 eq 42222 permit tcp any host 213.183.104.180 eq domain permit udp any host 213.183.104.180 eq domain permit tcp any host 213.183.104.178 eq ftp permit tcp any host 213.183.104.178 range 9900 10000 permit ip any host 213.183.104.179 permit tcp any host 213.183.104.180 eq 13022 permit tcp any host 213.183.104.180 eq 13306 permit tcp any host __.172.0.44 eq 22 permit tcp any host __.172.0.44 eq 1723 permit gre any host __.172.0.44 permit udp any host __.172.0.44 eq isakmp permit icmp any host 213.183.104.178 echo permit icmp any any echo-reply permit icmp any any time-exceeded permit tcp host 109.123.141.84 host __.172.0.44 eq 5432 permit tcp host 109.123.141.84 host 213.183.104.178 eq 44223 deny ip any any ip access-list extended FROM_OFFICE permit ip any any reflect RESPONSE_TO_OFFICE timeout 300 ip access-list extended TO_ADMIN permit ip 192.168.1.0 0.0.0.255 172.16.0.0 0.0.255.255 reflect RESPONSE_FROM_ADMIN timeout 300 permit ip 172.16.0.0 0.0.255.255 172.16.0.0 0.0.255.255 reflect RESPONSE_FROM_ADMIN timeout 300 deny ip any any ip access-list extended TO_INTERNET permit ip any any reflect RESPONSE_FROM_INTERNET timeout 300 permit icmp host 213.183.104.178 any echo-reply ip access-list extended TO_OFFICE evaluate RESPONSE_TO_OFFICE permit tcp host 213.183.104.178 host 192.168.1.11 eq 5432 permit tcp host 109.123.141.84 host 192.168.1.11 eq 5432 permit tcp host 192.168.17.100 host 192.168.1.50 eq 1717 permit tcp host 192.168.17.100 host 192.168.1.50 eq 1718 permit icmp any any echo-reply permit icmp any any time-exceeded permit ip host 192.168.2.15 192.168.1.0 0.0.0.255 permit ip host 192.168.2.16 192.168.1.0 0.0.0.255 deny ip any any ! access-list 1 remark --==NTP Servers==-- access-list 1 permit 91.226.136.155 access-list 1 permit 88.147.254.232 access-list 1 permit 88.147.254.235 access-list 1 permit 88.147.254.234 access-list 1 deny any access-list 2 remark --==NTP Clients==-- access-list 2 permit 192.168.1.0 0.0.0.255 access-list 2 permit 213.183.104.176 0.0.0.7 access-list 2 deny any ! ! ! ! route-map ROUTE_TO_ADMIN permit 10 match ip address TO_ADMIN match interface Vlan30 ! route-map ROUTE_TO_INTERNET permit 10 match ip address TO_INTERNET match interface FastEthernet4 ! ! ! ! control-plane ! ! ! ! mgcp profile default ! ! dial-peer voice 2000 voip description SIP trunk to Tomline destination-pattern .T redirect ip2ip session protocol sipv2 session target ipv4:__.172.4.3 session transport udp voice-class codec 1 dtmf-relay sip-notify rtp-nte h245-alphanumeric ! dial-peer voice 1000 voip description Incoming from Tomline translation-profile incoming Incoming session protocol sipv2 session target ipv4:192.168.1.3 incoming called-number 28290[56] voice-class codec 1 dtmf-relay sip-notify rtp-nte h245-alphanumeric ! dial-peer voice 1500 voip destination-pattern 1.. session protocol sipv2 session target ipv4:192.168.1.3 voice-class codec 1 dtmf-relay sip-notify rtp-nte h245-alphanumeric ! ! sip-ua credentials number 282905 username 282905 password 7 realm @__.172.4.3 credentials number 282906 username 282906 password 7 realm @__.172.4.3 registrar ipv4:__.172.4.3 expires 3600 sip-server ipv4:__.172.4.3 connection-reuse host-registrar ! ! line con 0 logging synchronous line aux 0 line vty 0 4 exec-timeout 30 0 logging synchronous transport input ssh ! ntp access-group peer 1 ntp access-group serve 2 ntp master 3 ntp update-calendar ntp server 91.226.136.155 ntp server 88.147.254.232 ntp server 88.147.254.234 ntp server 88.147.254.235 end