class-map type inspect match-all SELF_OUT match protocol icmp class-map type inspect match-all DHCP match access-group name DHCP class-map type inspect match-any ZBF_ALLOW_ALL match protocol dns match protocol icmp match protocol ftp match protocol telnet match protocol ssh match protocol tcp match protocol udp class-map type inspect match-all SSH match protocol ssh match access-group name SSH class-map type inspect match-all IPSEC match access-group name IPSEC ! policy-map type inspect INSIDE-OUTSIDE class type inspect ZBF_ALLOW_ALL inspect class class-default pass policy-map type inspect SELF-OUTSIDE class type inspect SELF_OUT inspect class class-default pass policy-map type inspect OUTSIDE-SELF class type inspect IPSEC pass class type inspect DHCP pass class type inspect SSH pass class class-default drop ! zone security INSIDE zone security OUTSIDE zone-pair security OUTSIDE-SELF source OUTSIDE destination self service-policy type inspect OUTSIDE-SELF zone-pair security INSIDE-OUTSIDE source INSIDE destination OUTSIDE service-policy type inspect INSIDE-OUTSIDE zone-pair security SELF-OUTSIDE source self destination OUTSIDE service-policy type inspect SELF-OUTSIDE ! interface GigabitEthernet0/0 description INTERNET ip address dhcp ip nat outside ip virtual-reassembly in zone-member security OUTSIDE ! interface GigabitEthernet0/1 description LAN ip address 172.30.10.1 255.255.255.0 ip nat inside ip virtual-reassembly in zone-member security INSIDE ! ip nat inside source list NAT interface GigabitEthernet0/0 overload ! ip access-list extended DHCP permit udp any any eq bootpc ip access-list extended IPSEC permit esp any any permit udp any any eq isakmp permit udp any any eq non500-isakmp ip access-list extended NAT permit ip 172.30.10.0 0.0.0.255 any ip access-list extended SSH permit tcp host X.X.X.X any eq 22 !