ASAPIX的双出口问题解决方案_第1页
ASAPIX的双出口问题解决方案_第2页
ASAPIX的双出口问题解决方案_第3页
ASAPIX的双出口问题解决方案_第4页
ASAPIX的双出口问题解决方案_第5页
已阅读5页,还剩3页未读, 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、ASA+PIX的双出口问题解决方案Asa/PIX的Static Route Tracking命令可以有效解决双ISP出口的问题存在问题: 静态路由没有固定的机制来决定是否可用,即使下一跳不可达,静态路由还是会存在路由表里,是有当ASA自己的和这条路由相关接口down了,才会从路由表里删除解决办法: Static Route Tracking这个feature提供一种方法来追踪静态路由,当主路由失效时可以安装备份路由进路由表,例如:2条缺省指向不同ISP,当主的ISP断了,可以立即启用备用ISP链路,它是使用ICMP来进行追踪的,如果在一定holdtime没有收到reply的话就认为这条链路do

2、wn了,就会立即删除该静态路由,预先设置的备份路由就会进入路由表。注意:配置时要在outside口上放开icmp reply(如果打开了icmp限制)pixFirewall(config)#sla monitor sla_id 指定检测的slaIDPixfirewall(config-sla-monitor)# type echo protocol ipIcmpEcho target_ip interfaceif_name 指定检测的协议类型为ICMP协议,并指定检测目的地址和接口这个必须是个可以ping通的地址,当这个地址不可用时,track跟踪的路由就会被删除,备份路由进路由表pixFir

3、ewall(config)#sla monitor schedule sla_id life forever | seconds start-time hh:mm:ss month day | day month | pending | now | after hh:mm:ss ageout seconds recurring 指定一个Schedule,一般会是start now必须要写时间表,不然track的路由进不了路由表pixFirewall(config)# track track_idrtr sla_idreachability指定一个TrackID,并要求追踪SlaID的可达性pi

4、xFirewall(config)# route if_name dest_ip mask gateway_ip admin_distance track track_i 设定默认路由,并绑定一个TrackID配置实例:sla monitor 1type echo protocol ipIcmpEcho interface dxsla monitor schedule 1 start-time now(必须配置,不然track的路由进不了路由表)track 2 rtr 1 reachabilityroute dx 1 tr

5、ack 2 (电信默认网关,会追踪地址的可达性)route wt 2 (网通默认网关)当配置的 ping不通(ICMP协议不能Reachability)的时候,route dx 1就会在路由表里删除,并由第二条默认路由即route wt 2取代,当恢复后,又会重新变为dx 1这个feature我想大家在很多项目里都会遇到,ASA可以有效解决!这与我们用路

6、由器实现双出口备份是一样的,通过配置SAA,检查其连通性。并跟踪这结果。来对路由进行选择,实现思路非常精巧!-附:PIX双出口ISP配置实例网络拓扑图:配置文件:Pixfirewall# show running-config: Saved:PIX Version 7.2(1)!hostname pixdomain-name default.domain.invalidenable password 9jNfZuG3TC5tCVH0 encryptednames!interface Ethernet0nameif outsidesecurity-level 0ip address 10.200

7、.159.2 48!interface Ethernet1nameif backup!- 命名链接备份ISP接口的接口名字,随便起名字的security-level 0ip address 48!interface Ethernet2nameif insidesecurity-level 100ip address 63 !interface Ethernet3shutdownno nameifno security-levelno ip address!interfac

8、e Ethernet4shutdownno nameifno security-levelno ip address!interface Ethernet5shutdownno nameifno security-levelno ip address!passwd 2KFQnbNIdI.2KYOU encryptedftp mode passivedns server-group DefaultDNSdomain-name default.domain.invalidpager lines 24logging enablelogging buffered debuggingmtu outsid

9、e 1500mtu backup 1500mtu inside 1500no failoverasdm image flash:/asdm521.binno asdm history enablearp timeout 14400global (outside) 1 interfaceglobal (backup) 1 interfacenat (inside) 1 !- 配置双ISP接口的NAT,都直接指定接口而不是IP地址route outside 1 track 1!- 配置被追踪的

10、默认静态路由,并指定管理距离为1.!- 被追踪的静态路由如果追踪成功则在路由表中,否则从路由表中清除 route backup 254!- 配置备份的默认静态路由,一定要指定的管理距离大于被追踪的静态默认路由 !- 当被追踪默认静态路由追踪成功时,则选用被追踪路由,因为其管理距离小 !- 当被追踪的默认静态路由追踪不成功时,则选用本条路由,因为被追踪的默认路由已从路由表中清除.timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:

11、00:02timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00timeout uauth 0:05:00 absoluteusername cisco password ffIRPGpDSOJh9YLq encryptedhttp server enablehttp insideno s

12、nmp-server locationno snmp-server contactsnmp-server enable traps snmp authentication linkup linkdown coldstartsla monitor 123type echo protocol ipIcmpEcho interface outsidenum-packets 3frequency 10sla monitor schedule 123 life forever start-time now!- 配置SLA Monitor,设定ID为123;指定协议和监测目的IP地址及接

13、口!- 并且设置了包的个数和频率为10秒!- 配置了SLA Monitor ID为123的生命期和开始的时间!track 1 rtr 123 reachability!- 配置Track ID为1的RTR,要求判断标准为可达性.!- 与前面的命令route outside 1 track 1 相对应telnet timeout 5ssh timeout 5console timeout 0!class-map inspection_defaultmatch default-inspection-traffic!policy-map type inspect dns preset_dns_mapparametersmessage-length maximum 512policy-map global_policyclass inspection_defaultinspect dns preset_dns_mapinspect ftpinspect h323 h225inspect h323 rasinspect netbiosinspect rshinspect rtspinspect skinnyinspect esmtp

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论