Cisco PIX 两界面多服务配置

发布者:上海IT外包来源:http://www.lanmon.net点击数:3775

结构图如下:

pix.jpg (29119 bytes)

PIX 520

Two Interface Multiple Server Configuration

nameif ethernet0 outside security0

nameif ethernet0 inside security100

interface ethernet0 auto

interface ethernet1 auto

ip address inside 10.1.1.1 255.0.0.0

ip address outside 204.31.17.10 255.255.255.0

logging on

logging host 10.1.1.11

logging trap 7

logging facility 20

no logging console

arp timeout 600

nat (inside) 1 10.0.0.0 255.0.0.0

nat (inside) 2 192.168.3.0 255.255.255.0

global (outside) 1 204.31.1.25-204.31.17.27

global (outside) 1 204.31.1.24

global (outside) 2 192.159.1.1-192.159.1.254

conduit permit icmp any any

outbound 10 deny 192.168.3.3 255.255.255.255 1720

outbound 10 deny 0 0 80

outbound 10 permit 192.168.3.3 255.255.255.255 80

outbound 10 deny 192.168.3.3 255.255.255.255 java

outbound 10 permit 10.1.1.11 255.255.255.255 80

apply (inside) 10 outgoing_src

no rip outside passive

no rip outside default

rip inside passive

rip inside default

route outside 0 0 204.31.17.1.1

tacacs-server host 10.1.1.12 lq2w3e

aaa authentication any inside 192.168.3.0 255.255.255.0 0 0 tacacs+

aaa authentication any inside 192.168.3.0 255.255.255.0 0 0

static (inside,outside) 204.31.19.0 192.168.3.0 netmask 255.255.255.0

conduit permit tcp 204.31.19.0 255.255.255.0 eg h323 any

static (inside,outside) 204.31.17.29 10.1.1.11

conduit permit tcp host 204.31.17.29 eq 80 any

conduit permit udp host 204.31.17.29 eq rpc host 204.31.17.17

conduit permit udp host 204.31.17.29 eq 2049 host 204.31.17.17

static (inside.outside) 204.31.1.30 10.1.1.3 netmask 255.255.255.255 10 10

conduit permit tcp host 204.31.1.30 eq smtp any

conduit permit tcp host 204.31.1.30 eq 113 any

snmp-server host 192.168.3.2

snmp-server location building 42

snmp-server contact polly hedra

snmp-server community ohwhatakeyisthee

telnet 10.1.1.11 255.255.255.255

telnet 192.168.3.0 255.255.255.0

说明:
以上典型配置有很多已经是厂商停产产品,但是,不少设备往往还有运行,关于该设备的配置或者方案优化,你可以联系蓝盟,我们的资深工程师会给你意外的惊喜!上海蓝盟网络技术有限公司于2002年成立,业务涵盖IT外包、电脑维护、网络维护、网管外包、驻场服务、人员派驻、应急支持、系统集成、网络搬迁、网络升级、数据备份、综合布线、电脑维修、计算机维护、计算机维修,网络改造、网络整理、网络调试、局域网组建、 应急上门、数据恢复、网络咨询、服务管理、运维咨询、ITIL培训、ITSS咨询等,拥有近200名工程师,正在为近500家客户提供“一站式” 的IT外包服务。网址:www.lanmon.com www.lanmon.net 官方微博:http://weibo.com/lanmon2012 咨询电话:4008200159 蓝色学苑:www.bluestudy.net
IT外包
>
400-635-8089
立即
咨询
电话咨询
服务热线
400-635-8089
微信咨询
微信咨询
微信咨询
公众号
公众号
公众号
返回顶部