CISCO防火墙常见功能实现.pptVIP

  • 4
  • 0
  • 约8.07千字
  • 约 37页
  • 2017-01-26 发布于北京
  • 举报
CISCO防火墙常见功能实现

Inspur group * * Inspur group CISCO防火墙常见功能实现 Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. Inspur group 主要内容 ASA/PIX基本配置 访问控制 VPN配置 双机配置 特殊情况使用 防火墙板卡 Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. Inspur group ASA/PIX基本配置 1、设备名称 asa(config) hostname asa 2、接口 信息配置 interface fastehernet 0/1 ip add 10.1.1.1 25.255.255.0 nameif outside security-level 0 6.0及以前版本使用如下命令: nameif fastethernet0/1 outside security-level 0 ip address outside 10.1.1.1 255.255.255.0 3、路由配置 route outside 0.0.0.0 0.0.0.0 10.1.1.2 Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. Inspur group ASA/PIX基本配置 Nameif:为每个端口确定名字 security-level :安全级别,你可以给每个端口分配1-99的任何一个安全级别,数值越大,安全级别越高。默认inside 100、 manage 100、outside0 Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. * Inspur group 访问控制 当你从一个高安全级别的端口访问低安全级别的端口时,使用NAT (inside→outside、inside →dmz、dmz →outside) 当你从一个低安全级别的端口访问高安全级别的端口时,使用STATIC + ACL (outside→inside、outside→dmz、dmz→inside) Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. Inspur group 访问控制-NAT 动态NAT 静态NAT BYPASS NAT Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. Inspur group 访问控制-NAT 动态NAT 将内网的多个私有地址转换成外网地址 Global (outside) 1 202.102.111.1 Nat (inside) 1 192.168.0.0 255.255.255.0 上述命令表示内部192.168.0.0/24网段访问外网的时将转换成 202.102.111.1的地址访问internet,若以外网端口地址转换则称为PAT Global (outside) 1 interface Nat (inside) 1 192.168.0.0 255.255.255.0 Evaluation only. Created with Aspose.Slides for .NET 3.5 Client Profile 5.2.0.0. Copyright 2004-2011 Aspose Pty Ltd. Inspur group 访问控制-NAT 动态NAT global ???? 指定公网地址范围:定义地址池。 ???? Global命令的配置语法: ???? global (if_name) nat_id ip

文档评论(0)

1亿VIP精品文档

相关文档