




全文预览已结束
下载本文档
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
基本上网+端口映射+SSHsh run: Saved:ASA Version 8.4(4)1 !hostname ciscoasaenable password 2KFQnbNIdI.2KYOU encrypted 正常加密配置!enable密码passwd 2KFQnbNIdI.2KYOU encryptednames!interface Ethernet0/0 正常配置! nameif outside security-level 0 ip address X.X.X.X !interface Ethernet0/1 正常配置! nameif inside security-level 100 ip address !interface Ethernet0/2 shutdown no nameif no security-level no ip address! interface Ethernet0/3 shutdown no nameif no security-level no ip address!interface Management0/0 shutdown no nameif no security-level no ip address management-only!ftp mode passiveobject network inside-outside 引入object,上网的地址段 subnet 上网子网,可以写 object network server 端口映射的服务器地址 host 54 不写掩码object network server-outside 外网ip,多个公网ip一对一映射用 host X.X.X.Xobject network pc host object network server63888 服务器4个端口映射 host 54object network server5900 host 54object network server5901 host 54object network server11034 host 54access-list 110 extended permit ip any any 正常配置!access-list 110 extended permit icmp any any pager lines 24mtu outside 1500mtu inside 1500icmp unreachable rate-limit 1 burst-size 1no asdm history enablearp timeout 14400!object network inside-outside NAT配置 nat (inside,outside) dynamic interface 只有一个公网ip配置, nat (inside,outside) dynamic X.X.X.X 写特定公网ip,多个公网ip配置方法1多个公网ip配置方法2举例:对于有大量公网地址用户,常应用在运营商或者公司内网Object network outside Range 0Object network inside Subnet Nat (inside,outside) static outsideobject network server 端口映射!4个端口 nat (inside,outside) static interface service tcp 5903 5903 object network server5900 nat (inside,outside) static interface service tcp 5900 5900 object network server5901 nat (inside,outside) static interface service tcp 5901 5901 object network server11034 nat (inside,outside) static interface service tcp 11034 11034 access-group 110 in interface outside 正常配置!access-group 110 in interface insideroute outside Y.Y.Y.Y 1默认路由正常配置!timeout xlate 3:00:00 timeout pat-xlate 0:00:30timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolutetimeout tcp-proxy-reassembly 0:01:00timeout floating-conn 0:00:00dynamic-access-policy-record DfltAccessPolicyuser-identity default-domain LOCAL SSH配置先配置此命令,其它正常配置!aaa authentication ssh console LOCAL. SSH本地验证,aaa authentication telnet console LOCAL telnet 验证no snmp-server locationno snmp-server contactsnmp-server enable traps snmp authentication linkup linkdown coldstart warmstartcrypto ca trustpoint _SmartCallHome_ServerCA crl configure crypto ca certificate chain _SmartCallHome_ServerCA certificate ca 6ecc7aa5a7032009b8cebcf4e952d491telnet insidetelnet timeout 5ssh outside SSHssh insidessh timeout 60ssh version 1ssh key-exchange group dh-group1-sha1console timeout 0dhcpd dns N.N.N.N dhcp配置!dhcpd address -00 insidedhcpd enable inside!threat-detection basic-threatthreat-detection statistics access-listno threat-detection statistics tcp-interceptusername admin password eY/fQXw7Ure8Qrz7 encrypted SSH调用用户名和密码username cisco password 3USUcOPFUiMCO4Jk encrypted SSH调用用户名和密码!class-map inspection_default match default-inspection-traffic !policy-map type inspect dns preset_dns_map parameters message-length maximum client auto message-length maximum 512policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect s
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 【正版授权】 ISO/IEC 19086-2:2018/AMD2:2025 EN Cloud computing - Service level agreement (SLA) framework - Part 2: Metric model - Amendment 2
- 【正版授权】 ISO 7689:2025 EN Aerospace series - Bolts,with MJ threads,made of alloy steel,strength class 1 100 MPa - Procurement specification
- 【正版授权】 ISO 16468:2025 EN Investment castings (steel,nickel alloys and cobalt alloys) - General technical requirements
- 【正版授权】 IEC 60335-2-15:2002+AMD1:2005 CSV FR-D Household and similar electrical appliances - Safety - Part 2-15: Particular requirements for appliances for heating liquids
- 【正版授权】 IEC 61326-2-6:2025 EN-FR Electrical equipment for measurement,control and laboratory use - EMC requirements - Part 2-6: Particular requirements - In vitro diagnostic (IVD)
- 【正版授权】 IEC 60079-18:2025 EN-FR Explosive atmospheres - Part 18: Equipment protection by encapsulation “m”
- GB/T 45955-2025气象仪器设备性能测试方法温度
- 校车人员安全知识培训课件
- 校安头条安全知识培训课件
- 北戴河区法律知识培训课件
- DB51-T 3251-2025 煤矿井下应急广播系统使用管理规范
- 静压植桩机钢管桩施工技术
- 高值耗材点评制度
- 防台防汛培训课件教学
- 2024年施工员题库含完整答案(必刷)
- 道路施工流程讲解
- 有限合伙企业合伙协议
- 保险资管合规风险管理-深度研究
- 2022教师民族团结培训
- 《慢阻肺健康大课堂》课件
- 2024人教版英语七年级下册《Unit 3 Keep Fit How do we keep fit》大单元整体教学设计2022课标
评论
0/150
提交评论