Thanks, Here goes...
Current configuration : 2853 bytes
!
version 12.2
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname Router
!
enable secret xxxxx...
enable password xxxxx...
!
ip subnet-zero
ip name-server xxxx.x.x
ip name-server xx.xx.x.x
!
ip inspect max-incomplete high 1100
ip inspect one-minute high 1100
ip inspect name Serial_Out tcp
ip inspect name Serial_Out udp
ip inspect name Serial_Out cuseeme
ip inspect name Serial_Out ftp
ip inspect name Serial_Out h323
ip inspect name Serial_Out rcmd
ip inspect name Serial_Out realaudio
ip inspect name Serial_Out smtp
ip inspect name Serial_Out streamworks
ip inspect name Serial_Out vdolive
ip inspect name Serial_Out sqlnet
ip inspect name Serial_Out tftp
ip inspect name Serial_Out http java-list 50
ip inspect name Serial_In tcp
ip inspect name Serial_In udp
ip inspect name Serial_In smtp
ip inspect name Serial_In http java-list 50
!
!
!
interface Loopback0
no ip address
!
interface Ethernet0
ip address dhcp
ip access-group 100 in
no ip redirects
ip nat outside
ip inspect Serial_In in
ip inspect Serial_Out out
traffic-shape rate 3450000 34500 34500 64
no cdp enable
!
interface Ethernet1
ip address 10.0.0.1 255.0.0.0
ip nat inside
!
ip nat pool fwall xx.xx.xxx.xxx xx.xx.xxx.xxx prefix-length 25
ip nat inside source list 9 pool fwall overload
ip classless
ip route 0.0.0.0 0.0.0.0 Ethernet0
ip http server
!
access-list 9 permit 10.0.0.0 0.0.0.255
access-list 50 permit any
access-list 75 permit 10.0.0.0 0.255.255.255
access-list 100 permit gre host xxx.xxx.xxx.xx any
access-list 100 permit tcp host xxx.xxx.xxx.xx any range 135 139
access-list 100 permit udp host xxx.xxx.xxx.xx any range 135 netbios-ss
access-list 100 permit tcp host xxx.xxx.xxx.xx any eq 445
access-list 100 permit udp host xxx.xxx.xxx.xx any eq 445
access-list 100 permit udp host xx.xx.x.x eq domain any
access-list 100 permit udp host xx.xx.x.x eq domain any
access-list 100 deny tcp any any range 135 139
access-list 100 deny udp any any range 135 netbios-ss
access-list 100 deny tcp any any eq 445
access-list 100 deny udp any any eq 445
access-list 100 deny ip 0.0.0.0 0.255.255.255 any
access-list 100 deny ip 10.0.0.0 0.255.255.255 any
access-list 100 deny ip 127.0.0.0 0.255.255.255 any
access-list 100 deny ip 169.254.0.0 0.0.255.255 any
access-list 100 deny ip 172.16.0.0 0.15.255.255 any
access-list 100 deny ip 192.0.2.0 0.0.0.255 any
access-list 100 deny ip 192.168.0.0 0.0.255.255 any
access-list 100 deny ip 224.0.0.0 15.255.255.255 any
access-list 100 deny ip 240.0.0.0 7.255.255.255 any
access-list 100 deny ip 248.0.0.0 7.255.255.255 any
access-list 100 deny ip host 255.255.255.255 any
access-list 100 deny icmp any any
!
line con 0
access-class 75 in
line vty 0 4
access-class 75 in
password xxxx
login
!
end
There it is. I've masked the IPs for obvious reasons. Thanks for taking the time to check it out. Go easy on me, I'm still learning Cisco IOS. 😱