Pix-Pix的配置(2) ip audit info action alarmip audit attack action alarmpdm history enablearp timeout 14400!--- Do not do NAT on traffic to other PIXes.nat (inside) 0 access-list 100route outside 0.0.0.0 0.0.0.0 172.18.124.1 1timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00timeout uauth 0:05:00 absoluteaaa-server TACACS+ protocol tacacs+ aaa-server RADIUS protocol radius aaa-server LOCAL protocol local no snmp-server locationno snmp-server contactsnmp-server community publicsnmp-server enable trapsfloodguard enablesysopt connection permit-ipseccrypto ipsec transform-set myset esp-des esp-md5-hmac !--- This is traffic to PIX 2.crypto map newmap 20 ipsec-isakmpcrypto map newmap 20 match address 120crypto map newmap 20 set peer 172.18.124.154crypto map newmap 20 set transform-set myset!--- This is traffic to PIX 3.crypto map newmap 30 ipsec-isakmpcrypto map newmap 30 match address 130crypto map newmap 30 set peer 172.18.124.157crypto map newmap 30 set transform-set mysetcrypto map newmap interface outsideisakmp enable outsideisakmp key ******** address 172.18.124.154 netmask 255.255.255.255 no-xauth no-config-mode isakmp key ******** address 172.18.124.157 netmask 255.255.255.255 no-xauth no-config-mode isakmp identity addressisakmp policy 10 authentication pre-shareisakmp policy 10 encryption desisakmp policy 10 hash md5isakmp policy 10 group 1isakmp policy 10 lifetime 1000telnet timeout 5ssh timeout 5console timeout 0terminal width 80Cryptochecksum:d41d8cd98f00b204e9800998ecf8427e: endPIX 2Building configuration...: Saved:PIX Version 6.3(3)interface ethernet0 auto