• ASA基本配置


    拓扑如下:

    ASA5520# show running-config
    : Saved
    :
    ASA Version 8.0(2)
    !
    hostname ASA5520
    enable password 2KFQnbNIdI.2KYOU encrypted
    names
    !
    interface Ethernet0/0
     nameif outside
     security-level 0
     ip address dhcp
    !
    interface Ethernet0/1
     nameif inside
     security-level 100
     ip address 192.168.1.254 255.255.255.0
    !
    interface Ethernet0/2
     no nameif
     no security-level
     no ip address
    !
    interface Ethernet0/3
     shutdown
     no nameif    
     no security-level
     no ip address
    !             
    interface Ethernet0/4
     shutdown     
     no nameif    
     no security-level
     no ip address
    !             
    interface Ethernet0/5
     shutdown     
     no nameif    
     no security-level
     no ip address
    !             
    passwd 2KFQnbNIdI.2KYOU encrypted
    no ftp mode passive
    dns domain-lookup outside
    dns server-group DefaultDNS
     name-server 10.0.0.1
    access-list out-to-in extended permit icmp any any echo
    access-list out-to-in extended permit icmp any any echo-reply
    access-list out-to-in extended permit tcp any interface outside eq www
    access-list out-to-in extended permit tcp any interface outside eq 3389
    access-list out-to-in extended permit tcp any interface outside eq telnet
    access-list out-to-in extended permit tcp any interface outside eq ftp
    access-list out-to-in extended permit tcp any interface outside eq 3306
    access-list out-to-in extended permit tcp any interface outside eq 2121
    access-list out-to-in extended permit tcp any interface outside eq 3128
    pager lines 24
    mtu outside 1500
    mtu inside 1500
    no failover   
    icmp unreachable rate-limit 1 burst-size 1
    no asdm history enable
    arp timeout 14400
    global (outside) 1 interface
    nat (inside) 1 192.168.1.0 255.255.255.0
    static (inside,outside) tcp interface www 192.168.1.2 www netmask 255.255.255.255
    static (inside,outside) tcp interface 3389 192.168.1.1 3389 netmask 255.255.255.255
    static (inside,outside) tcp interface telnet 192.168.1.1 telnet netmask 255.255.255.255
    static (inside,outside) tcp interface ftp 192.168.1.1 ftp netmask 255.255.255.255
    static (inside,outside) tcp interface 3306 192.168.1.2 3306 netmask 255.255.255.255
    static (inside,outside) tcp interface 2121 192.168.1.2 ftp netmask 255.255.255.255
    static (inside,outside) tcp interface 3128 192.168.1.2 3128 netmask 255.255.255.255
    access-group out-to-in in interface outside
    route outside 0.0.0.0 0.0.0.0 10.0.0.1 1
    timeout xlate 3:00:00
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
    timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
    timeout uauth 0:05:00 absolute
    dynamic-access-policy-record DfltAccessPolicy
    aaa authentication ssh console LOCAL
    no snmp-server location
    no snmp-server contact
    snmp-server enable traps snmp authentication linkup linkdown coldstart
    no crypto isakmp nat-traversal
    telnet timeout 5
    ssh 0.0.0.0 0.0.0.0 outside
    ssh timeout 10
    ssh version 2
    console timeout 0
    threat-detection basic-threat
    threat-detection statistics access-list
    !             
    class-map inspection_default
     match default-inspection-traffic
    !             
    !             
    policy-map type inspect dns preset_dns_map
     parameters   
      message-length maximum 512
    policy-map global_policy
     class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect netbios
      inspect rsh
      inspect rtsp
      inspect skinny  
      inspect esmtp
      inspect sqlnet
      inspect sunrpc
      inspect tftp
      inspect sip  
      inspect xdmcp
    !             
    service-policy global_policy global
    username cisco password 3USUcOPFUiMCO4Jk encrypted
    prompt hostname context
    Cryptochecksum:d41d8cd98f00b204e9800998ecf8427e
    : end

  • 相关阅读:
    ADO.NET Entity Framework(5)esql (二)。
    google首页动态图片代码
    ms sql 聚合事例
    GridView 一些操作
    《狼与狗的故事》
    Asp.net日期字符串格式化显示方法
    解决网爬工具爬取页面信息出现乱码的问题
    esql的查询结果集 ObjectQuery
    去空空格 null sql
    不安装 oracle的客户,就可以使用pl/sql访问远程oracle 数据库的方法
  • 原文地址:https://www.cnblogs.com/networking/p/4450804.html
Copyright © 2020-2023  润新知