The ippool is now set to 10.4.1.10-10.4.1.20. This should not be an overlapping subnet now.
Every host can ping the VPN clients (DMZ hosts, inside hosts), but the VPN clients can only ping hosts on the inside interface. They still cannot access anything in the DMZ. Here's the updated config.
PIX Version 6.3(1)
interface ethernet0 100full
interface ethernet1 100full
interface ethernet2 auto shutdown
interface ethernet3 100full
interface ethernet4 auto shutdown
interface ethernet5 auto shutdown
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 unused1 security10
nameif ethernet3 dmz1 security40
nameif ethernet4 unused3 security60
nameif ethernet5 VPN security10
enable password z23N8AO5Ly59fYIP encrypted
passwd Vy9CsBcpPoTrbRZb encrypted
hostname pix
domain-name essvote.com
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
names
access-list acl_outside permit tcp any host xxx.xxx.xxx.140 eq domain
access-list acl_outside permit udp any host xxx.xxx.xxx.140 eq domain
access-list acl_outside permit tcp any host xxx.xxx.xxx.143 eq ftp
access-list acl_outside permit tcp any host xxx.xxx.xxx.144 eq smtp
access-list acl_outside permit tcp any host xxx.xxx.xxx.144 eq www
access-list acl_outside permit tcp any host xxx.xxx.xxx.141 eq domain
access-list acl_outside permit udp any host xxx.xxx.xxx.141 eq domain
access-list acl_outside permit tcp any host xxx.xxx.xxx.141 eq www
access-list acl_outside permit tcp any host xxx.xxx.xxx.141 eq smtp
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq 5050
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq ftp
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq ssh
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq https
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq citrix-ica
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq 123
access-list acl_outside permit udp host xxx.xxx.xxx.191 any eq ntp
access-list acl_outside permit tcp host xxx.xxx.xxx.154 host xxx.xxx.xxx eq pptp
access-list acl_outside permit tcp host xxx.xxx.xxx host xxx.xxx.xxx.154 eq pptp
access-list acl_outside permit gre host xxx.xxx.xxx host xxx.xxx.xxx.154
access-list acl_outside permit gre host xxx.xxx.xxx.154 host xxx.xxx.xxx
access-list acl_outside deny ip host xxx.xxx.xxx.154 any
access-list acl_outside permit tcp host xxx.xxx.xxx.192 host xxx.xxx.xxx.212 eq citrix-ica
access-list acl_outside permit tcp host xxx.xxx.xxx.192 host xxx.xxx.xxx.212 eq www
access-list acl_outside permit esp xxx.xxx.xxx.0 255.255.255.0 host xxx.xxx.xxx.145
access-list acl_outside permit ah xxx.xxx.xxx.0 255.255.255.0 host xxx.xxx.xxx.145
access-list acl_outside permit ip xxx.xxx.xxx.0 255.255.255.0 host xxx.xxx.xxx.145
access-list acl_outside permit tcp xxx.xxx.xxx.0 255.255.255.0 host xxx.xxx.xxx.145
access-list acl_outside permit udp xxx.xxx.xxx.0 255.255.255.0 host xxx.xxx.xxx.145
access-list acl_outside permit esp host xxx.xxx.xxx.145 xxx.xxx.xxx.0 255.255.255.0
access-list acl_outside permit ah host xxx.xxx.xxx.145 xxx.xxx.xxx.0 255.255.255.0
access-list acl_outside permit ip host xxx.xxx.xxx.145 xxx.xxx.xxx.0 255.255.255.0
access-list acl_outside permit tcp host xxx.xxx.xxx.145 xxx.xxx.xxx.0 255.255.255.0
access-list acl_outside permit udp host xxx.xxx.xxx.145 xxx.xxx.xxx.0 255.255.255.0
access-list acl_outside permit icmp xxx.xxx.xxx.0 255.255.255.0 host xxx.xxx.xxx.145
access-list acl_outside permit icmp host xxx.xxx.xxx.145 xxx.xxx.xxx.0 255.255.255.0
access-list acl_outside permit tcp any host xxx.xxx.xxx.159 eq 2100
access-list acl_outside permit icmp any host xxx.xxx.xxx.159
access-list acl_outside permit icmp host xxx.xxx.xxx.159 any
access-list acl_outside permit ah host xxx.xxx.xxx.138 any
access-list acl_outside permit esp host xxx.xxx.xxx.138 any
access-list acl_outside permit tcp host xxx.xxx.xxx.192 any eq www
access-list acl_outside permit tcp host xxx.xxx.xxx.192 any eq ftp
access-list acl_outside permit tcp host xxx.xxx.xxx.192 any eq https
access-list acl_outside permit tcp host xxx.xxx.xxx.192 any eq citrix-ica
access-list acl_outside permit tcp any host xxx.xxx.xxx.142 eq www
access-list acl_outside permit tcp any host xxx.xxx.xxx.142 eq https
access-list acl_outside permit tcp any host xxx.xxx.xxx.146 eq www
access-list acl_outside permit tcp any host xxx.xxx.xxx.146 eq https
access-list acl_outside permit tcp any host xxx.xxx.xxx.147 eq www
access-list acl_outside permit tcp any host xxx.xxx.xxx.147 eq https
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq 10000
access-list acl_outside permit tcp host xxx.xxx.xxx.192 any eq 10000
access-list acl_outside permit esp host xxx.xxx.xxx.191 any
access-list acl_outside permit tcp any host xxx.xxx.xxx.141 eq 995
access-list acl_outside permit udp any host xxx.xxx.xxx.141 eq 995
access-list acl_outside permit tcp any host xxx.xxx.xxx.140 eq smtp
access-list acl_outside permit tcp any host xxx.xxx.xxx.141 eq https
access-list acl_outside permit udp host xxx.xxx.xxx.191 any eq dnsix
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq domain
access-list acl_outside permit gre host xxx.xxx.xxx.138 any
access-list acl_outside permit gre any host xxx.xxx.xxx.138
access-list acl_outside permit icmp any host xxx.xxx.xxx.138
access-list acl_outside permit tcp host xxx.xxx.xxx.191 any eq pop3
access-list acl_outside permit tcp any host xxx.xxx.xxx.137 eq ssh
access-list acl_outside permit tcp any host xxx.xxx.xxx.148 eq www
access-list acl_outside permit tcp any host xxx.xxx.xxx.148 eq https
access-list acl_outside permit esp any host xxx.xxx.xxx.130
access-list acl_outside permit ah any host xxx.xxx.xxx.130
access-list acl_outside permit udp any host xxx.xxx.xxx.130 eq isakmp
access-list acl_outside permit tcp any host xxx.xxx.xxx.130 eq 500
access-list acl_outside permit tcp any host xxx.xxx.xxx.130 eq ssh
access-list acl_outside permit icmp host xxx.xxx.xxx.136 any
access-list acl_outside permit icmp any host xxx.xxx.xxx.136
access-list acl_outside permit ip host xxx.xxx.xxx.136 any
access-list acl_outside permit tcp any host xxx.xxx.xxx.136 eq pptp
access-list acl_outside permit ah host xxx.xxx.xxx.136 any
access-list acl_outside permit ah any host xxx.xxx.xxx.136
access-list acl_outside permit esp host xxx.xxx.xxx.136 any
access-list acl_outside permit esp any host xxx.xxx.xxx.136
access-list acl_outside permit gre host xxx.xxx.xxx.136 any
access-list acl_outside permit gre any host xxx.xxx.xxx.136
access-list acl_outside permit tcp host xxx.xxx.xxx.136 any eq pptp
access-list acl_inside permit icmp 10.1.0.0 255.255.0.0 10.0.0.0 255.0.0.0
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 host xxx.xxx.xxx.61 eq 10000
access-list acl_inside permit tcp 10.1.0.0 255.255.0.0 10.0.0.0 255.0.0.0
access-list acl_inside permit udp 10.1.0.0 255.255.0.0 10.0.0.0 255.0.0.0
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 host xxx.xxx.xxx.212 eq www
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 host xxx.xxx.xxx.212 eq citrix-ica
access-list acl_inside permit tcp 10.1.2.0 255.255.255.0 host xxx.xxx.xxx.212 eq www
access-list acl_inside permit tcp 10.1.2.0 255.255.255.0 host xxx.xxx.xxx.212 eq citrix-ica
access-list acl_inside permit tcp 10.1.5.0 255.255.255.0 host xxx.xxx.xxx.212 eq citrix-ica
access-list acl_inside permit tcp 10.1.5.0 255.255.255.0 host xxx.xxx.xxx.212 eq www
access-list acl_inside permit tcp 10.1.90.0 255.255.255.0 host xxx.xxx.xxx.212 eq www
access-list acl_inside permit tcp 10.1.90.0 255.255.255.0 host xxx.xxx.xxx.212 eq citrix-ica
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq ftp
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq 5050
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq https
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq ssh
access-list acl_inside permit udp 10.1.1.0 255.255.255.0 any eq ntp
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq 123
access-list acl_inside permit tcp 10.7.34.0 255.255.255.0 10.0.0.0 255.0.0.0
access-list acl_inside permit udp 10.7.34.0 255.255.255.0 10.0.0.0 255.0.0.0
access-list acl_inside permit icmp 10.7.34.0 255.255.255.0 10.0.0.0 255.0.0.0
access-list acl_inside permit icmp host 10.1.1.25 any
access-list acl_inside permit icmp any host 10.1.1.25
access-list acl_inside permit esp xxx.xxx.xxx.0 255.255.255.0 host 10.1.1.25
access-list acl_inside permit ah xxx.xxx.xxx.0 255.255.255.0 host 10.1.1.25
access-list acl_inside permit ip xxx.xxx.xxx.0 255.255.255.0 host 10.1.1.25
access-list acl_inside permit tcp xxx.xxx.xxx.0 255.255.255.0 host 10.1.1.25
access-list acl_inside permit udp xxx.xxx.xxx.0 255.255.255.0 host 10.1.1.25
access-list acl_inside permit udp host 10.1.1.25 xxx.xxx.xxx.0 255.255.255.0
access-list acl_inside permit tcp host 10.1.1.25 xxx.xxx.xxx.0 255.255.255.0
access-list acl_inside permit ip host 10.1.1.25 xxx.xxx.xxx.0 255.255.255.0
access-list acl_inside permit esp host 10.1.1.25 xxx.xxx.xxx.0 255.255.255.0
access-list acl_inside permit ah host 10.1.1.25 xxx.xxx.xxx.0 255.255.255.0
access-list acl_inside permit icmp host 10.1.1.25 xxx.xxx.xxx.0 255.255.255.0
access-list acl_inside permit tcp 10.1.2.0 255.255.255.0 any eq www
access-list acl_inside permit tcp 10.1.2.0 255.255.255.0 any eq https
access-list acl_inside permit tcp 10.1.2.0 255.255.255.0 any eq ftp
access-list acl_inside permit tcp 10.1.2.0 255.255.255.0 any eq ftp-data
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq ftp-data
access-list acl_inside permit tcp 10.1.6.0 255.255.255.0 xxx.xxx.xxx.0 255.255.255.0 eq 10000
access-list acl_inside permit tcp 10.1.6.0 255.255.255.0 xxx.xxx.xxx.0 255.255.255.0 eq citrix-ica
access-list acl_inside permit icmp host 10.1.36.59 any
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq 1863
access-list acl_inside permit tcp host 10.1.36.59 any eq 2100
access-list acl_inside permit tcp host 10.1.6.151 any eq ftp
access-list acl_inside permit tcp host 10.1.6.151 any eq ftp-data
access-list acl_inside permit tcp host 10.1.6.151 any eq https
access-list acl_inside permit tcp host 10.1.6.62 any eq 10000
access-list acl_inside permit tcp host 10.1.6.122 host 12.96.247.99 eq 10000
access-list acl_inside permit icmp host 10.1.1.30 any
access-list acl_inside permit ip host 10.1.1.30 any
access-list acl_inside permit gre host 10.1.1.30 any
access-list acl_inside permit esp host 10.1.1.30 any
access-list acl_inside permit ah host 10.1.1.30 any
access-list acl_inside permit tcp host 10.1.1.2 any eq domain
access-list acl_inside permit udp host 10.1.1.2 any eq domain
access-list acl_inside permit tcp host 10.1.2.3 any eq domain
access-list acl_inside permit udp host 10.1.2.3 any eq domain
access-list acl_inside permit tcp host 10.1.6.1 any eq domain
access-list acl_inside permit udp host 10.1.6.1 any eq domain
access-list acl_inside permit tcp host 10.1.36.2 any eq domain
access-list acl_inside permit udp host 10.1.36.2 any eq domain
access-list acl_inside permit udp host 10.1.41.2 any eq domain
access-list acl_inside permit tcp host 10.1.41.2 any eq domain
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq ftp
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq 5050
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq https
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq ssh
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq 1863
access-list acl_inside permit udp 10.1.80.0 255.255.255.0 any eq 1863
access-list acl_inside permit udp 10.1.80.0 255.255.255.0 any eq ntp
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq 123
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq www
access-list acl_inside permit tcp 10.1.80.0 255.255.255.0 any eq citrix-ica
access-list acl_inside permit tcp 10.1.1.0 255.255.255.0 any eq pop3
access-list acl_inside permit tcp any host 10.1.1.14 eq ssh
access-list acl_inside permit tcp host 10.1.6.53 any eq ftp
access-list acl_inside permit tcp host 10.1.6.53 any eq ftp-data
access-list acl_inside permit tcp host 10.1.6.53 any eq https
access-list acl_inside permit icmp host 10.1.1.20 any
access-list acl_inside permit icmp any host 10.1.1.20
access-list acl_inside permit gre host 10.1.1.20 any
access-list acl_inside permit gre any host 10.1.1.20
access-list acl_inside permit ah host 10.1.1.20 any
access-list acl_inside permit ah any host 10.1.1.20
access-list acl_inside permit esp host 10.1.1.20 any
access-list acl_inside permit esp any host 10.1.1.20
access-list acl_inside permit ip host 10.1.1.20 any
access-list acl_inside permit ip any host 10.1.1.20
access-list acl_dmz1 permit icmp any any
access-list acl_dmz1 permit tcp any any
access-list acl_dmz1 permit udp any any
access-list acl_dmz1 permit ah any any
access-list acl_dmz1 permit esp any any
access-list acl_dmz1 permit icmp 10.4.1.0 255.255.255.0 any
access-list acl_dmz1 permit icmp any 10.4.1.0 255.255.255.0
access-list acl_dmz1 permit ip any 10.4.1.0 255.255.255.0
access-list acl_dmz1 permit ip 10.4.1.0 255.255.255.0 any
access-list pixtosw permit ip 10.1.0.0 255.255.0.0 10.3.1.0 255.255.255.0
access-list pixtosw permit icmp 10.1.0.0 255.255.0.0 10.3.1.0 255.255.255.0
access-list pixtosw permit ip 10.3.1.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list pixtosw permit icmp 10.3.1.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list 101 permit ip 10.1.0.0 255.255.0.0 10.4.1.0 255.255.255.0
access-list 101 permit icmp 10.1.0.0 255.255.0.0 10.4.1.0 255.255.255.0
access-list 101 permit icmp 10.4.1.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list 101 permit ip 10.4.1.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list 101 permit icmp 10.0.2.0 255.255.255.0 10.4.1.0 255.255.255.0
access-list 101 permit icmp 10.4.1.0 255.255.255.0 10.0.2.0 255.255.255.0
access-list 101 permit ip 10.0.2.0 255.255.255.0 10.4.1.0 255.255.255.0
access-list 101 permit ip 10.4.1.0 255.255.255.0 10.0.2.0 255.255.255.0
pager lines 23
logging on
logging timestamp
logging monitor notifications
logging trap notifications
logging facility 22
logging queue 0
logging host inside 10.1.1.20
mtu outside 1500
mtu inside 1500
mtu unused1 1500
mtu dmz1 1500
mtu unused3 1500
mtu VPN 1500
ip address outside xxx.xxx.xxx.130 255.255.255.128
ip address inside 10.1.0.129 255.255.0.0
ip address unused1 127.0.0.1 255.255.255.255
ip address dmz1 10.0.2.129 255.255.255.0
ip address unused3 127.0.0.1 255.255.255.0
no ip address VPN
ip verify reverse-path interface outside
ip audit info action alarm
ip audit attack action alarm
ip local pool ippool 10.4.1.10-10.4.1.20
no failover
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
no failover ip address unused1
no failover ip address dmz1
no failover ip address unused3
no failover ip address VPN
no pdm history enable
arp timeout 60
global (outside) 5 xxx.xxx.xxx.191
global (outside) 6 xxx.xxx.xxx.192
global (outside) 7 xxx.xxx.xxx.193
global (dmz1) 1 interface
nat (inside) 0 access-list 101
nat (inside) 5 10.1.2.2 255.255.255.255 0 0
nat (inside) 5 10.1.2.3 255.255.255.255 0 0
nat (inside) 5 10.1.2.4 255.255.255.255 0 0
nat (inside) 5 10.1.2.5 255.255.255.255 0 0
nat (inside) 5 10.1.2.6 255.255.255.255 0 0
nat (inside) 5 10.1.2.7 255.255.255.255 0 0
nat (inside) 5 10.1.2.8 255.255.255.255 0 0
nat (inside) 5 10.1.2.9 255.255.255.255 0 0
nat (inside) 5 10.1.2.10 255.255.255.255 0 0
nat (inside) 5 10.1.2.11 255.255.255.255 0 0
nat (inside) 5 10.1.2.12 255.255.255.255 0 0
nat (inside) 5 10.1.2.13 255.255.255.255 0 0
nat (inside) 5 10.1.2.14 255.255.255.255 0 0
nat (inside) 5 10.1.2.15 255.255.255.255 0 0
nat (inside) 5 10.1.2.16 255.255.255.255 0 0
nat (inside) 5 10.1.2.17 255.255.255.255 0 0
nat (inside) 5 10.1.2.18 255.255.255.255 0 0
nat (inside) 5 10.1.2.19 255.255.255.255 0 0
nat (inside) 5 10.1.2.20 255.255.255.255 0 0
nat (inside) 5 10.1.2.21 255.255.255.255 0 0
nat (inside) 5 10.1.2.22 255.255.255.255 0 0
nat (inside) 5 10.1.2.23 255.255.255.255 0 0
nat (inside) 5 10.1.2.24 255.255.255.255 0 0
nat (inside) 5 10.1.2.40 255.255.255.255 0 0
nat (inside) 5 10.1.2.41 255.255.255.255 0 0
nat (inside) 5 10.1.2.42 255.255.255.255 0 0
nat (inside) 5 10.1.2.43 255.255.255.255 0 0
nat (inside) 5 10.1.2.44 255.255.255.255 0 0
nat (inside) 6 10.1.6.53 255.255.255.255 0 0
nat (inside) 6 10.1.6.62 255.255.255.255 0 0
nat (inside) 6 10.1.6.122 255.255.255.255 0 0
nat (inside) 6 10.1.6.151 255.255.255.255 0 0
nat (inside) 5 10.1.1.0 255.255.255.0 0 0
nat (inside) 7 10.1.21.0 255.255.255.0 0 0
static (dmz1,outside) xxx.xxx.xxx.143 10.0.2.143 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.140 10.0.2.140 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.144 10.0.2.144 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.141 10.0.2.141 netmask 255.255.255.255 0 0
static (inside,dmz1) 10.0.0.0 10.0.0.0 netmask 255.0.0.0 0 0
static (inside,outside) xxx.xxx.xxx.154 10.1.6.154 netmask 255.255.255.255 0 0
static (inside,outside) xxx.xxx.xxx.145 10.1.1.25 netmask 255.255.255.255 0 0
static (inside,outside) xxx.xxx.xxx.159 10.1.36.59 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.142 10.0.2.142 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.146 10.0.2.146 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.147 10.0.2.147 netmask 255.255.255.255 0 0
static (inside,outside) xxx.xxx.xxx.137 10.1.1.14 netmask 255.255.255.255 0 0
static (dmz1,outside) xxx.xxx.xxx.148 10.0.2.148 netmask 255.255.255.255 0 0
static (inside,outside) xxx.xxx.xxx.138 10.1.1.30 netmask 255.255.255.255 0 0
static (inside,outside) xxx.xxx.xxx.136 10.1.1.20 netmask 255.255.255.255 0 0
access-group acl_outside in interface outside
access-group acl_inside in interface inside
access-group acl_dmz1 in interface dmz1
route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.129 1
route outside 10.3.1.0 255.255.255.0 xxx.xxx.xxx.130 1
route inside 10.7.32.0 255.255.255.0 10.1.2.128 1
route inside 10.7.33.0 255.255.255.0 10.1.2.128 1
route inside 10.7.34.0 255.255.255.0 10.1.2.128 1
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
aaa-server AuthInbound protocol radius
aaa-server AuthInbound (inside) host 10.1.90.2 ************** timeout 10
ntp server 203.21.37.18 source outside
no snmp-server location
no snmp-server contact
snmp-server community ess
no snmp-server enable traps
floodguard enable
sysopt connection permit-ipsec
sysopt noproxyarp inside
sysopt noproxyarp dmz1
crypto ipsec transform-set strongsha esp-3des esp-sha-hmac
crypto ipsec transform-set myset esp-3des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set myset
crypto map tosonicwall 20 ipsec-isakmp
crypto map tosonicwall 20 match address pixtosw
crypto map tosonicwall 20 set peer xxx.xxx.xxx.xxx
crypto map tosonicwall 20 set transform-set strongsha
crypto map mymap 10 ipsec-isakmp dynamic dynmap
crypto map mymap client configuration address initiate
crypto map mymap client authentication AuthInbound
crypto map mymap interface outside
isakmp enable outside
isakmp key ******** address xxx.xxx.xxx.xxx netmask 255.255.255.255
isakmp identity address
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash sha
isakmp policy 20 group 2
isakmp policy 20 lifetime 28800
vpngroup vpn3000 address-pool ippool
vpngroup vpn3000 dns-server 10.1.1.2 10.1.2.3
vpngroup vpn3000 wins-server 10.1.1.2 10.1.2.3
vpngroup vpn3000 default-domain essvote.com
vpngroup vpn3000 split-tunnel 101
vpngroup vpn3000 idle-time 1800
vpngroup vpn3000 max-time 86400
vpngroup vpn3000 password ********
telnet timeout 15
ssh 10.1.1.0 255.255.255.0 inside
ssh 10.1.2.0 255.255.255.0 inside
ssh 10.1.90.0 255.255.255.0 inside
ssh 10.1.5.0 255.255.255.0 inside
ssh 10.1.0.0 255.255.255.0 inside
ssh timeout 15
console timeout 0
terminal width 80