ASA Version 9.6(1)
!
hostname FW1
names
!
interface GigabitEthernet1/1
 nameif outside
 security-level 0
 ip address 172.11.33.2 255.255.255.252
!
interface GigabitEthernet1/2
 nameif inside
 security-level 100
 ip address 172.11.33.9 255.255.255.248
!
interface GigabitEthernet1/3
 no nameif
 no security-level
 no ip address
 shutdown
!
interface GigabitEthernet1/4
 no nameif
 no security-level
 no ip address
 shutdown
!
interface GigabitEthernet1/5
 no nameif
 no security-level
 no ip address
 shutdown
!
interface GigabitEthernet1/6
 no nameif
 no security-level
 no ip address
 shutdown
!
interface GigabitEthernet1/7
 no nameif
 no security-level
 no ip address
 shutdown
!
interface GigabitEthernet1/8
 no nameif
 no security-level
 no ip address
 shutdown
!
interface Management1/1
 management-only
 no nameif
 no security-level
 no ip address
 shutdown
!
!
route outside 0.0.0.0 0.0.0.0 172.11.33.1 1
!
access-list INSIDE-OUT extended permit ip any any
access-list OUTSIDE-RETURN extended permit icmp host 8.8.8.8 192.11.0.0 255.255.0.0 echo-reply
access-list OUTSIDE-RETURN extended permit udp host 8.8.8.8 eq domain 192.11.0.0 255.255.0.0
access-list OUTSIDE-RETURN extended permit tcp host 8.8.8.8 eq www 192.11.0.0 255.255.0.0
!
!
access-group INSIDE-OUT in interface inside
access-group OUTSIDE-RETURN in interface outside
!
!
class-map inspection_default
 match default-inspection-traffic
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp 
  inspect icmp 
  inspect tftp 
!
service-policy global_policy global
!
telnet timeout 5
ssh timeout 5
!
!
!
!
router ospf 1
 router-id 172.11.99.3
 log-adjacency-changes
 network 172.11.33.0 255.255.255.252 area 0
 network 172.11.33.8 255.255.255.248 area 0
