Ò»¡¢»ù±¾ÅäÖÃ
#hostname name //Ãû×ÖµÄÉèÖà #interface gigabitethernet0/0 //½øÈë½Ó¿Ú0/0 #nameif outside //ÅäÖýӿÚÃûΪoutside #security-level 0 //ÉèÖð²È«¼¶±ð¡£ ¼¶±ð´Ó0--100£¬¼¶±ðÔ½¸ß°²È«¼¶±ðÔ½¸ß #ip address 218.xxx.xxx.xxx 255.255.255.248 //ÉèÖÃÍⲿipµØÖ· #no shutdown #interface ethernet0/1 //½øÈë½Ó¿Ú0/1 #nameif inside //ÅäÖýӿÚÃûΪinside #security-level 100 //ÉèÖð²È«¼¶±ð¡£ ¼¶±ð´Ó0--100£¬¼¶±ðÔ½¸ß°²È«¼¶±ðÔ½¸ß #ip address 192.168.10.1 255.255.255.0 //ÉèÖÃipµØÖ· #duplex full //ȫ˫¹¤ #speed 100 //ËÙÂÊ #no shutdown #interface ethernet0/2 //½øÈë½Ó¿Ú0/2 #nameif dmz //ÅäÖýӿÚÃûΪdmz #security-level 50 //ÉèÖð²È«¼¶±ð¡£ ¼¶±ð´Ó0--100£¬¼¶±ðÔ½¸ß°²È«¼¶±ðÔ½¸ß #ip address 192.168.9.1 255.255.255.0 //ÉèÖÃdmz½Ó¿ÚipµØÖ· #no shutdown #interface Management0/0 //½øÈë¹ÜÀí½Ó¿Ú # nameif guanli //½Ó¿ÚÃû # security-level 100 //°²È«¼¶±ð #ip address 192.168.1.1 255.255.255.0 //IPµØÖ· |
×¢Ò⣺security-level ÅäÖð²È«¼¶±ð¡£Ä¬ÈÏÍâÍø½Ó¿ÚΪ 0/0
°²È«¼¶±ðĬÈÏΪ 0
ÄÚÍø½Ó¿ÚΪ 0/1 °²È«¼¶±ðĬÈÏΪ 100
dmz ½Ó¿ÚΪ 0/2 °²È«¼¶±ðĬÈÏΪ 50
ĬÈÏÇé¿öÏ£¬Ïàͬ°²È«¼¶±ð½Ó¿ÚÖ®¼ä²»ÔÊÐíͨÐÅ£¬¿ÉÒÔʹÓÃÒÔÏÂÃüÁ
#same-security-traffic permit interface
//ÔÊÐíÏàͬ°²È«¼¶±ð½Ó¿ÚÖ®¼ä»¥ÏàͨÐÅ¡£
½Ï¸ß°²È«½Ó¿Ú·ÃÎʽϵͰ²È«½Ó¿Ú£ºÔÊÐíËùÓлùÓÚIPµÄÊý¾ÝÁ÷ͨ¹ý£¬³ý·ÇÓÐACL·ÃÎÊ¿ØÖÆÁÐ±í£¬ÈÏÖ¤»òÊÚȨµÄÏÞÖÆ¡£
½ÏµÍ°²È«½Ó¿Ú·ÃÎʽϸ߰²È«½Ó¿Ú£º³ý·ÇÓÐconduit»òacl½øÐÐÃ÷È·µÄÐí¿É£¬·ñÔò¶ªÆúËùÓеÄÊý¾Ý°ü¡£
¶þ¡¢global¡¢nat¡¢static¡¢routeÃüÁî
1¡¢globalÃüÁî
global (if_name) nat_id ipaddress--ipaddress [netmask mask] ¡¡¡¡if_name:Ö¸µÄÊÇ½Ó¿Ú ¡¡¡¡nat_id:ΪµØÖ·³ØµÄID±êʶºÅ ¡¡¡¡ipaddress--ipaddress [netmask mask]£ºÖ¸¶¨µÄIPµØÖ·³Ø·¶Î§£¬Ò²¿ÉÒÔÊÇÒ»¸öµØÖ· |
Àý£º
global(outside) 1 218.106.236.247-218.106.236.249 //ÅäÖÃÒ»¸öµØÖ·³Ø ¡¡¡¡global(outside) 1 interface //ÅäÖõ¥¸öµØÖ·Îªoutside½Ó¿ÚµÄµØÖ· ¡¡¡¡global(outside) 1 218.106.236.237 netmask 255.255.255.248
//ÅäÖÃÒ»¸öµØÖ·³Ø£¬Îª255.255.255.248ËùÓÐ×ÓÍø·¶Î§ÄڵĵØÖ· |
2¡¢natÃüÁî
£¨1£©»ù±¾Ó÷¨
nat (if_name) nat_id local_ip [netmask] ¡¡¡¡if_name:Ö¸µÄÊÇ½Ó¿Ú ¡¡¡¡nat_id:ΪµØÖ·³ØµÄID±êʶºÅ£¬¼´globalÖж¨ÒåµÄnat_id ¡¡¡¡local_ip [netmask] :ÄÄЩµØÖ·×ª»»µ½nat_idÕâ¸öµØÖ·³ØÉÏ¡£ |
(2)¶¯Ì¬ÄÚ²¿natת»»£¨¶à¶Ô¶à£©
Àý£º
global(outside) 1 218.106.236.247-218.106.236.249 //ÅäÖÃÒ»¸öµØÖ·³Ø ¡¡¡¡nat (inside) 1 192.168.9.0 255.255.255.0
//ºÍÉÏÃæµÄglobalÅäÖÃÒ»ÆðʹÓ㬼´°Ñ192.168.9.0 Õâ¸öÍø¶ÎµÄµØÖ·×ª»»Îª218.106.236.247-218.106.236.249Õâ¸öÍø¶Î |
(3) pat (¶à¶ÔÒ»nat)
µ±¶à¸öipµØÖ·×ª»»ÎªÒ»¸öipµØÖ·Ê±£¬¾Í×Ô¶¯ÔÚÍⲿIPµØÖ·µÄºóÃæ¼ÓÉÏ´óÓÚ1024µÄ¶Ë¿ÚºÅ£¬ÒÔÇø±ð²»Í¬µÄת»»·ÃÎÊ¡£
global(outside) 1 218.106.236.247 //ÅäÖÃÒ»¸öÍⲿµØÖ· ¡¡¡¡nat (inside) 1 192.168.9.0 255.255.255.0
//ºÍÉÏÃæµÄglobalÅäÖÃÒ»ÆðʹÓ㬼´°Ñ192.168.9.0 Õâ¸öÍø¶ÎµÄµØÖ·×ª»»Îª218.106.236.247Õâ¸öÍⲿIPµØÖ·¡£
ÍⲿÈË¿´µ½µÄÊÇ×Ô¶¯¼ÓÁ˶˿ںŵĵØÖ·¡£ |
(4)²ßÂÔnat
access-list extended net1 permit ip 192.168.9.0 255.255.255.0 host 209.165.200.1 //¶¨ÒåÒ»¸ö²ßÂÔ ¡¡¡¡global(outside) 1 209.165.200.100 //¶¨ÒåÒ»¸öµØÖ· ¡¡¡¡nat (inside) 1 access-list net1
//µ±192.168.9.0 Íø¶ÎµÄµØÖ··ÃÎÊ 209.165.200.1Õą̂µçÄÔʱ£¬×ª»»Îª209.165.200.100Õâ¸öipµØÖ·¡£ |
(5)¶¯Ì¬Íⲿnatת»»
µ±µÍ¼¶±ðµÄÏëÍù¸ß¼¶±ðµÄת»»Ê±£¬ÔÚºóÃæ¼Óoutside¹Ø¼ü×Ö¼´¿É¡£
nat (dmz) 1 192.168.7.0 255.255.255.0 outside //°Ñdmz½Ó¿ÚϵĵØÖ·nat µ½inside½Ó¿ÚÖÐ ¡¡¡¡global(inside) 1 192.168.9.10-192.168.9.20
//¼´dmz½Ó¿ÚÖеÄ192.168.7.0 Íø¶ÎµÄµØÖ··ÃÎÊÄÚÍøÊ±£¬½«×ª»»ÎªÄÚÍøµØÖ·Îª192.168.9.10-192.168.9.20 |
(6)nat 0 ¼´nat Ãâ³ý
nat 0 ±íʾ´©¹ý·À»ðǽ¶ø²»½øÐÐnatת»»¡£¼´±íʾµØÖ·²»¾¹ýת»»Ö±½Ó×÷ΪԴµØÖ··¢ËÍ´©¹ý·À»ðǽ´ïµ½µÍ¼¶±ð°²È«½Ó¿Ú¡£
nat (dmz) 0 192.168.0.9 255.255.255.255 |
×¢Ò⣺ִÐÐnatµÄ˳Ðò£º
nat 0 (natÃâ³ý£©
¾²Ì¬natºÍ¾²Ì¬pat (¼´staticÃüÁ
²ßÂÔ¶¯Ì¬ nat (nat access-list)
Õý³£µÄ¶¯Ì¬natºÍpat (nat)
3¡¢staticÓ³ÉäÃüÁî
³äÐíÒ»¸öλÓڵͰ²È«¼¶±ð½Ó¿ÚµÄÁ÷Á¿£¬´©¹ý·À»ðǽ´ïµ½Ò»¸ö½Ï¸ß¼¶±ðµÄ½Ó¿Ú¡£¼´Êý¾ÝÁ÷´Ó½ÏµÍ°²È«¼¶±ð½Ó¿Úµ½½Ï¸ß°²È«¼¶±ð¡£
(1)³£Ó÷½·¨£º
static (real_ifname mapped_ifname) {mapped_ip|interface} real_ip [netmask mask] |
real_ifname :½Ï¸ß¼¶±ð½Ó¿ÚÃû mapped_ifname:½ÏµÍ¼¶±ð½Ó¿ÚÃû
mapped_ip:½ÏµÍ¼¶±ð½Ó¿ÚipµØÖ· interface:½ÏµÍ¼¶±ð½Ó¿Ú real_ip£º½Ï¸ß¼¶±ðipµØÖ·
À©ºÅÄÚµÄ˳ÐòÊÇ£ºÏȸ߼¶±ðºóµÍ¼¶±ð£¬À©ºÅÍâµÄ˳ÐòÊÇÏȵͼ¶±ðºó¸ß¼¶±ð£¬ÕýºÃÏà·´¡£
Àý£º static (inside outside) 218.107.233.234 192.167.9.1
//¼´°Ñ218.107.233.234Õâ¸öÍⲿµØÖ·Ó³Éäµ½ÄÚ²¿µØÖ·192.168.9.1ÉÏ¡£
(2)¾²Ì¬¶Ë¿ÚÓ³Éä
static (real_ifname mapped_ifname) {tcp | udp} {mapped_ip|interface} mapped_port real_ip real_port [netmask mask] |
real_ifname :½Ï¸ß¼¶±ð½Ó¿ÚÃû mapped_ifname:½ÏµÍ¼¶±ð½Ó¿ÚÃû
tcp|udp :ÒªÓ³ÉäµÄ¶Ë¿ÚÐÒéÃû
mapped_ip:½ÏµÍ¼¶±ð½Ó¿ÚipµØÖ· interface:½ÏµÍ¼¶±ð½Ó¿Ú mapped_port:¶Ë¿ÚÃû»ò¶Ë¿ÚºÅ
real_ip£º½Ï¸ß¼¶±ðipµØÖ· real_port:¶Ë¿ÚÃû»ò¶Ë¿ÚºÅ
×¢ÒâÒ»µãºÜÖØÒª£º²¢²»ÊÇÅäÖÃÁËstatic¾Í¿ÉÒÔ´ÓÍⲿ·ÃÎÊÄÚ²¿ÁË£¬±ØÐëÒª¶¨ÒåÒ»¸ö·ÃÎÊ¿ØÖÆÁбíÀ´ÊµÏÖÒ»¸öͨµÀ£¬ÔÊÐíÄÄЩ·þÎñ»ò¶Ë¿Ú£¬»òÄÄЩµØÖ·¿ÉÒÔ·ÃÎÊ¡£
Àý£º
static (inside,outside) tcp interface ftp 192.168.10.4 ftp netmask 255.255.255.255
//°Ñoutside½Ó¿ÚipµØÖ·µÄftp¶Ë¿ÚÓ³Éäµ½192.168.10.4 ÄÚ²¿IPµÄFTP¶Ë¿Ú¡£ ¡¡¡¡access-list ftp extended permit tcp any interface outside eq ftp
//¶¨ÒéÒ»¸ö·ÃÎÊ¿ØÖÆÁÐ±í£¬ÒÔÔÊÐíftpÊý¾ÝÁ÷ͨ¹ý¡£ ¡¡¡¡access-group ftp in interface outside //°Ñ·ÃÎÊ¿ØÖÆÁбíÓ¦ÓÃÓÚ½Ó¿Ú |
4¡¢route ÃüÁî
route if_name destination_ip gateway [metric] ¡¡¡¡if_name: ½Ó¿ÚÃû ¡¡¡¡destination_ip: Ä¿µÄµØ ¡¡¡¡gateway: Íø¹Ø ¡¡¡¡metric: ÌøÊý ¡¡¡¡Àý£ºroute outside 0 0 218.102.33.247 1 //¼´Ä¬ÈÏÍø¹ØÎª 218.102.33.247 £¬Ö»ÓÐÒ»Ìø ¡¡¡¡route inside 192.168.9.0 255.255.255.0 192.168.10.1 //ÉèÖõ½Ä¿±ê192.168.9.0Íø¶ÎµÄÍø¹ØÎª192.168.10.1 |
Èý¡¢·ÃÎÊ¿ØÖÆ
·ÃÎÊ¿ØÖƵķ½·¨Óë·ÓÉÆ÷µÄûÓÐÇø±ð¡£»ù±¾²½ÖèÊÇÏȶ¨Òå·ÃÎÊ¿ØÖÆÁÐ±í£¬È»ºóÔÙÓ¦Óõ½½Ó¿Ú¼´¿É¡£Ôڴ˲»¶à×÷½âÊÍ£¬ÔÚ·ÓÉÆ÷Ä£¿éÀ»áµ¥¶À°Ñ·ÃÎÊÁбí×÷½âÊÍ¡£
ËÄ¡¢·À»ðǽ»ù±¾¹ÜÀí
1¡¢telnet ÅäÖÃ
#usename name password password //ÉèÖõÇÈëµÄÕʺźÍÃÜÂë ¡¡¡¡#aaa authentication telnet console LOCAL
//ÉèÖÃAAAÑéÖ¤·½Ê½¡£ ´Ë´¦ÎªLOCAL±¾µØ¡£Ò²¿ÉÒÔÓÃAAA·þÎñÆ÷½øÈëÑéÖ¤¡£ ¡¡¡¡#telnet 0.0.0.0 0.0.0.0 inside //ÄÄЩµØÖ·¿Ételnet½ø´Ë½Ó¿Ú ¡¡¡¡#telnet timeout 10 //³¬Ê±Ê±³¤£¬ÒÔ·ÖÖÓΪµ¥Î» ¡¡¡¡2¡¢sshµÇ¼ÅäÖà ¡¡¡¡#usename name password password //ÉèÖõÇÈëµÄÕʺźÍÃÜÂë ¡¡¡¡#aaa authentication ssh console LOCAL
//ÉèÖÃAAAÑéÖ¤·½Ê½¡£ ´Ë´¦ÎªLOCAL±¾µØ¡£Ò²¿ÉÒÔÓÃÆäËû·þÎñÆ÷½øÈëÑéÖ¤¡£ ¡¡¡¡#ssh timeout 10 ¡¡¡¡#crypto key generate rsa modulus 1024
//Ö¸¶¨rsaÃÜÔ¿µÄ´óС,Õâ¸öÖµÔ½´ó,²úÉúrsaµÄʱ¼äÔ½³¤,ciscoÍÆ¼öʹÓÃ1024. ¡¡¡¡# write mem //±£´æ¸Õ²Å²úÉúµÄÃÜÔ¿ ¡¡¡¡#ciscoasa(config)#ssh 0.0.0.0 0.0.0.0 {inside|outside}
//ÔÊÐíÄÄЩIP¿ÉÒÔͨ¹ýSSHµÇ¼´Ë·À»ðǽ¡£ insideΪÄÚÍø½Ó¿Ú£¬outsideΪÍâÍø½Ó¿Ú¡£
0.0.0.0 0.0.0.0 ±íʾËùÓÐIP£¬¿ÉÅäÖõ¥¸öIP£¬Ò²¿ÉÒÔÅäÖÃij¶ÎIP¡£ ¡¡¡¡#ssh timeout 30 //ÉèÖó¬Ê±Ê±¼ä,µ¥Î»Îª·ÖÖÓ ¡¡¡¡#ssh version 1 //Ö¸¶¨SSH°æ±¾,¿ÉÒÔÑ¡Ôñ°æ±¾2 ¡¡¡¡#passwd ÃÜÂë //passwdÃüÁîËùÖ¸¶¨µÄÃÜÂëΪԶ³Ì·ÃÎÊÃÜÂë ¡¡¡¡show ssh //²é¿´SSHÅäÖÃÐÅÏ¢ ¡¡¡¡crypto key zeroize //Çå¿ÕÃÜÔ¿ ¡¡¡¡show crypto key mypubkersa //²é¿´²úÉúµÄrsaÃÜÔ¿Öµ |
2¡¢asdmÅäÖÃ
ÏÈÉÏ´«ÏàÓ¦asdm°æ±¾µ½·À»ðǽÖС£
# webvpn // ½øÈëWEBVPNģʽ ¡¡¡¡# username cisco password cisco // н¨Ò»¸öÓû§ºÍÃÜÂë ¡¡¡¡# http server enable //¿ªÆôHTTP·þÎñ ¡¡¡¡# http 192.168.9.10 255.255.255.0 inside
//ÔÊÐíÄÄЩip ͨ¹ýÄĸö½Ó¿Ú¿ÉÒÔͨ¹ýhttpÁ¬ÉÏÀ´¡£
´Ë´¦µÄÒâ˼Ϊ£ºÔÊÐí192.168.9.10 Õâ¸öIPÓÃhttpͨ¹ýinsideÁ¬ÉÏ·À»ðǽ. ¡¡¡¡# http 192.168.1.0 255.255.255.0 guanli
//ÔÊÐí192.168.1.0Íø¶Î¾¹ý¹ÜÀí½Ó¿ÚÁ¬ÉÏ·À»ðǽ¡£
×¢ÒâÒªÓý»²æÏߺ͹ÜÀí½Ó¿ÚÁ¬½Ó£¬½øÐÐÅäÖᣵ±È»ÊÂÏÈÒªÉèÖùÜÀí½Ó¿ÚµÄIP£¬ºÍÃû³Æ¡£ |
¾¹ýÒÔÉÏÅäÖþͿÉÒÔÓÃASDMÅäÖ÷À»ðǽÁË¡£
Èç¹ûÅäÖÃÁËinside½Ó¿Ú·ÃÎÊ£¬¿ÉÖ±½ÓÊäÈë·À»ðǽinsideµÄipµØÖ·¡£ https://192.168.9.1
Èç¹ûÅäÖÃÁ˹ÜÀí½Ó¿Ú·ÃÎÊ£¬Ê×ÏÈÓý»²æÏ߰ѵçÄԺͷÀ»ðǽµÄ¹ÜÀí¿ÚÏàÁ¬£¬°ÑµçÄÔÉè³ÉºÍ¹ÜÀí¿Ú¶ÎµÄIPµØÖ·,±¾ÀýÖÐÉèΪ192.168.1.0
¶ÎµÄIP´ò¿ªä¯ÀÀÆ÷ÔÚµØÖ·À¸ÖÐÊäÈë¹ÜÀí¿ÚµÄIPµØÖ·: https://192.168.1.1
µ¯³öһϰ²È«Ö¤Êé¶Ô»°¿ò£¬µ¥»÷ ¡°ÊÇ¡±
ÊäÈëÓû§ÃûºÍÃÜÂ루¾ÍÊÇÔÚ´®¿ÚµÄWEBVPNģʽÏÂн¨µÄÓû§ºÍÃÜÂ룩£¬È»ºóµã»÷¡°È·¶¨¡±¡£
³öÏÖҲ϶Ի°¿ò£¬µã»÷¡°Download ASDM Launcher and Start ASDM¡±¿ªÊ¼°²×°ASDM¹ÜÀíÆ÷£¬°²×°ÍêÒÔºó´ÓÍøÉÏÏÂÔØÒ»¸öJAVAÐéÄâ»úÈí¼þ(ʹÓÃ1.4ÒÔÉÏ
Java °æ±¾)£¬½øÈëWWW.JAVA.COMÏÂÔØ°²×°£¬°²×°Íêºóµã»÷ÏÂÃæµÄ¡°Run ASDM as a
Java Applet ¡±¡£
³öÏÖÒÔ϶Ի°¿ò£¬ µã»÷¡°ÊÇ¡±¡£
³öÏÖÒÔ϶Ի°¿ò£¬ÊäÈëÓû§ÃûºÍÃÜÂ루¾ÍÊÇÔÚ´®¿ÚµÄWEBVPNģʽÏÂн¨µÄÓû§ºÍÃÜÂ룩£¬È»ºóµã»÷¡°ÊÇ¡±¡£
³öÏÖÒÔ϶Ի°¿ò£¬µã»÷¡°ÊÇ¡±¡£
½øÈëASDM¹ÜÀíÆ÷¡£
ÕâÑù¾Í¿ÉÒÔͨ¹ýASDMÀ´ÅäÖ÷À»ðǽÁË¡£
ÒÔºó¾Í¿ÉÒÔÖ±½ÓʹÓÃASDMÀ´¹ÜÀí·À»ðǽÁË¡£
Ò»¶¨Òª×¢ÒâÒ»µã£ºÓÐʱºòjavaµÄ°æ±¾¹ý¸ß1.6°æÒÔÉÏ£¬»á´ò²»¿ª£¬¾ÍÊÔÓõͰ汾µÄ(1.4)ÊÔһϡ£
3¡¢ÆäËû¹ÜÀíÃüÁî
#write memory //°ÑÅäÖñ£´æ ¡¡¡¡#clear configure all //°Ñrun-configÖеÄÄÚÈÝÇå¿Õ ¡¡¡¡#write erase //¿ÉÇå³ýflashÉÁ´æÖеÄÅäÖà ¡¡¡¡#dir //ÏÔʾflashÖеÄÎļþ ¡¡¡¡#boot [system|config] <usr>: |
Àý£º #boot system flash:/pix-701.bin //¼´´ÓÄĸöϵͳ¾µÏñÖÐÆô¶¯
flashÖпÉÒÔ´æ¶à¸öϵͳ¾µÏñºÍÅäÖÃÎļþ¡£boot¿ÉÒÔÑ¡Ôñ´ÓÄĸöϵͳ¾µÏñÖÐÆô¶¯¡£
#clock set 21:00 apr 1 2002 //ÉèÖÃʱ¼ä ¡¡¡¡#show memery ¡¡¡¡#show version ¡¡¡¡#show cpu usage |
Áù¡¢ÐéÄâ·À»ðǽ
£¨Ò»£©ÐéÄâ·À»ðǽµÄÌØÐÔ£º
1¡¢ÎÒÃÇ¿ÉÒÔ½«Ò»¸öµ¥Ò»µÄÎïÀí·À»ðǽÂß¼ÉÏ·ÖΪ¶à¸öÐéÄâ·À»ðǽ£¬Ã¿¸öÐéÄâ·À»ðǽ¶¼ÊǶÀÁ¢µÄÉ豸¡£
2¡¢ËüÃÇÓÐ×ÔÒѶÀÁ¢µÄ°²È«²ßÂÔ£¬½Ó¿ÚºÍ¹ÜÀí½Ó¿Ú
3¡¢Ã¿¸öÐéÄâ·À»ðǽ±£´æÒ»¸öÅäÖÃÎļþ£¬ÒÔ±£´æÃ¿¸öÐéÄâ·À»ðǽµÄ²ßÂÔºÍÅäÖá£
4¡¢ÐéÄâ·À»ðǽ²»Ö§³Övpn,×é²¥ºÍ¶¯Ì¬Â·ÓÉÐÒé
(¶þ)ÐéÄâ·À»ðǽµÄÖÖÀà
ÐéÄâ·À»ðǽ·ÖΪ:admin contextºÍÆÕͨÐéÄâ·À»ðǽ¡£
admin context·À»ðÇ½ÌØÐÔ£º
admin context±ØÐëÏÈÓÚÆäËûµÄÐéÄâ·À»ðǽ½øÐд´½¨ºÍÅäÖá£
Óû§µÇ¼µ½admin contextÐéÄâ·À»ðǽ¾ÍÓµÓÐÁËϵͳ¹ÜÀíÔ±µÄȨÏÞ£¬¿ÉÒÔ·ÃÎÊϵͳÒÔ¼°ÆäËûÐéÄâ·À»ðǽ¡£
£¨Èý£©Á÷Á¿·ÖÀà
ÒòÒ»¸öÎïÀí·À»ðǽ·ÖΪ¶à¸öÐéÄâ·À»ðǽ£¬Äǵ½µ×ÄÄЩÊý¾ÝÁ÷Á¿ÊôÓÚÄĸöÐéÄâ·À»ðǽµÄÄØ£¿¼´ÈçºÎ°ÑÊý¾ÝÁ÷Á¿·ÖÅ䏸ÐéÄâ·À»ðǽ¡£
1¡¢°´½Ó¿Ú»®·Ö£º¼´½«Ò»¸ö½Ó¿ÚΨһµÄ»®·Öµ½Ò»¸öÐéÄâ·À»ðǽÖУ¬ÄÇôͨ¹ýÕâ¸ö½Ó¿ÚµÄÁ÷Á¿¾Í¶¼ÊôÓÚÕâ¸öÐéÄâ·À»ðǽµÄ¡£
2¡¢»ùÓÚMACµØÖ·»®·Ö:Ò»¸ö½Ó¿ÚÊôÓÚ¶à¸öÐéÄâ·À»ðǽ¹²ÓС£ÐèҪΪÕâ¸ö¹²Ïí½Ó¿ÚÖ¸¶¨¶à¸öMACµØÖ·£¬¼´Ã¿¸öÐéÄâ·À»ðǽָ¶¨Ò»¸ömacµØÖ·¡£¿ÉÊÖ¹¤Ö¸¶¨£¬Ò²¿É×Ô¶¯²úÉú¡£
ÓÉÓÚASAµÄ½Ó¿ÚÓÐÏÞ£¬ËùÒÔÔÚ¶àÐéÄâ·À»ðǽµÄģʽÏ£¬ÎÒÃǻᾳ£Óöµ½Ò»¸ö½Ó¿Úͬʱ·ÖÅ䏸¶à¸öÐéÄâ·À»ðǽ¡£Õâ¸öʱºòʹÓÃÎïÀí½Ó¿ÚÀ´¶ÔÁ÷Á¿½øÐзÖÀàµÄ°ì·¨½«ÔÚÕâÖÖÇé¿öϲ»ÔÙÊÊÓã¬ÒòΪ·À»ðǽÎÞ·¨È·¶¨Á÷Á¿¾¿¾¹Ó¦¸Ãת·¢µ½ÄĸöÐéÄâ·À»ðǽ¡£ÎÒÃÇÐèҪʹÓÃÆäËûµÄ·½·¨À´¶ÔÁ÷Á¿µÄ×ßÏò½øÐÐÇø·Ö£¬Í¨³£ÎÒÃÇ»áʹÓÃ×Ô¶¯»òÕßÊÖ¶¯ÎªÕâ¸ö·ÖÅ䏸¶à¸öÐéÄâ·À»ðǽµÄ¹²Ïí½Ó¿ÚÖ¸¶¨²»Í¬µÄMACµØÖ·£¬·À»ðǽ½«Ê¹ÓÃMACµØÖ·À´Çø·ÖÁ÷Á¿µÄ×ßÏò¡£
ÊÖ¶¯Ö¸¶¨MACµØÖ·£º
ÔÚÿ¸öÐéÄâ·À»ðǽµÄ¸Ã¹²Ïí½Ó¿ÚÏÂÅäÖãºmac-address HHH.HHH.HH
ÀýÈ磺
¡¡hostname(config)#Interface F0/0 ¡¡¡¡hostname(config-if)# mac-address 0001.0001.0001 |
×Ô¶¯Ö¸¶¨MACµØÖ·£º
ÔÚ·À»ðǽµÄSYSTEMƽ̨µÄÈ«¾ÖÅäÖÃģʽÏÂÅäÖãºmac-address auto
ÀýÈ磺
hostname(config)# mac-address auto |
3¡¢»ùÓÚNAT»®·Ö£ºÈç¹ûûÓÐΪ½Ó¿ÚÖ¸¶¨Î¨Ò»µÄMACµØÖ·£¬·À»ðǽµ±ÊÕµ½Ò»¸öͨ¹ý¹²Ïí½Ó¿ÚµÄÁ÷Á¿Ê±£¬·À»ðǽֻ»á¼ì²éÄ¿µÄIPµØÖ·¡£Í¨¹ýҪʹÓÃÄ¿µÄIPµØÖ·À´¾ö¶¨Êý¾Ý°üµÄ×ßÏò£¬ÄÇô·À»ðǽ±ØÐëÖªµÀÄ¿µÄµØÖ·ÊDZ»¶¨Î»ÔÚÄĸöÐéÄâ·À»ðǽÉÏ¡£NAT¼¼Êõ¿ÉÒÔÌṩÕâÑùµÄ¹¦ÄÜ¡£NATµÄת»»ÌõÄ¿¿ÉÒÔʹ·À»ðǽ½«Êý¾Ý°üת·¢µ½ÕýÈ·µÄÐéÄâ·À»ðǽÉÏ¡£
ÅäÖþ²Ì¬NATת»»£º
? Context A: ¡¡¡¡static (inside,shared) 10.10.10.0 10.10.10.0 netmask 255.255.255.0 ¡¡¡¡? Context B: ¡¡¡¡static (inside,shared) 10.20.10.0 10.20.10.0 netmask 255.255.255.0 ¡¡¡¡? Context C: ¡¡¡¡static (inside,shared) 10.30.10.0 10.30.10.0 netmask 255.255.255.0 |
µ±ÎÒÃÇʹÓöà·À»ðǽģʽ£¬²¢ÇÒ¹²ÏíÁ˽ӿڵ½¶à¸öÐéÄâ·À»ðǽµÄʱºò£¬ÎÒÃÇÐèҪעÒ⽫Á÷Á¿×ª·¢µ½ÕýÈ·µÄÐéÄâ·À»ðǽÉÏÈ¥£¬Èç¹ûûÓÐÖ¸¶¨MACµØÖ·£¨²»¹ÜÊÇÊÖ¶¯»¹ÊÇ×Ô¶¯£©²¢ÇÒҲûÓÐÅäÖÃNATµÄ»°£¬·À»ðǽ½«²»ÄÜÕÒµ½ÕýÈ·µÄÄ¿µÄµØÖ·¶ø½«Êý¾Ý°ü¶ªÆú¡£
(ËÄ)ÅäÖÃÐéÄâ·ÓÉÆ÷
1¡¢»ù±¾ÅäÖÃ
#show mode //ÏÔʾµ±Ç°Â·ÓÉÆ÷ÔËÐеÄģʽ ¡¡¡¡#mode mltiple //ÆôÓöàÐéÄâ·À»ðǽ ¡¡¡¡#admin-context name //Ê×ÏÈ´´½¨Ò»¸öadmin-contextÐéÄâ·À»ðǽ ¡¡¡¡#context name //´´½¨ÆäËûÐéÄâ·À»ðǽ£¬×¢ÒâÐéÄâ·À»ðǽÃûÇø·Ö´óСд |
2¡¢ÎªÐéÄâ·À»ðǽ·ÖÅä½Ó¿Ú
ÏÈÉèÖúÃÐéÄâ·À»ðǽÃû£¬È»ºóÔÚÐéÄâ·À»ðǽÅäÖÃģʽÏÂÅäÖãº
#allocate-interface ÎïÀí½Ó¿ÚÃû [±ðÃû] [visible | invisible] //Ϊ½Ó¿Ú¹ØÁªÒ»¸ö±ðÃû¡£Ò²¿ÉÒÔ²»¹ØÁª¡£ ¡¡¡¡#allocate-interface eth0 int0 visible
//°Ñeth0»®·Ö¸øÒ»¸öÐéÄâ·À»ðǽ£¬²¢ÇÒ¹ØÁªÒ»¸ö±ðÃû½Ðint0£¬²¢ÇÒÈÃÎïÀí½Ó¿ÚIDÊǿɼûµÄ¡£invisibleÊDz»¿É¼û¡£ ¡¡¡¡#config-url url //ÿ¸öÐéÄâ·À»ðǽÓжÀÁ¢µÄÅäÖá£ÎªÐéÄâ·À»ðǽָ¶¨ÏÂÔØÅäÖõĵصãºÍÃû³Æ¡£ ¡¡¡¡#config-url c1.cfg //Ö¸¶¨ÅäÖÃΪc1.cfg |
Æß¡¢·À»ðǽģʽ
·À»ðǽÓÐÁ½ÖÖģʽ£ºÂ·ÓÉÆ÷ģʽºÍ͸Ã÷ģʽ¡£Â·ÓÉÆ÷ģʽÊdz£ÓõÄģʽ£¬ÅäÖ÷½·¨Èç³£¹æ·½·¨£¬ÕâÀïÖ÷Òª½âÊÍ͸Ã÷ģʽ¡£
(Ò») ·À»ðǽµÄ͸Ã÷ģʽµÄÌØÐÔ£º
£¨1£©¹¤×÷ÔÚ¶þ²ã£¬½Ó¿Ú²»ÐèÒªÅäÖÃIPµØÖ·£»
£¨2£©Ö»Ö§³ÖÁ½¸ö½Ó¿Ú£¬insideºÍoutside½Ó¿Ú£¬ÕâÁ½¸ö½Ó¿Ú¶¼½ÓÄÚÍøµØÖ·£¬Ïñ½»»»»úµÄÒ»¸ö¶Ë¿ÚÒ»Ñù£¬Ã»ÓÐÇø±ð¡£
£¨3£©²»Ö§³Önat,QOS,¶à²¥£¬VPN£¬¶¯Ì¬Â·ÓÉÐÒé,ipv6,dhcpÖм̣¨¿É×÷DHCP·þÎñÆ÷£¬µ«²»ÄÜ×öDHCPÖм̣©
£¨4£©Ö§³Ö¶àÐéÄâ·À»ðǽ¡£ÔÚ¶àÐéÄâ·À»ðǽÏ£¬Ã¿¸öÐéÄâ·À»ðǽ¶¼ÐèÅäÒ»¸ö¹ÜÀíIPµØÖ·£¬µ«²»ÄܰѹÜÀíIP×÷ÎªÍø¹Ø¡£
£¨5£©¹¤×÷ÔÚ¶þ²ã£¬µ«IPµÈÈý²ãÁ÷Á¿ÒªÍ¨¹ý·À»ðǽ£¬ÈÔÐèÒªACL·ÃÎÊ¿ØÖÆÃ÷È·ÔÊÐí
£¨6£©arpÁ÷Á¿²»ÐèÒªACL¿ØÖƾͿÉÒÔͨ¹ý·À»ðǽ¡£µ«¿ÉÒÔÓÃARPÉó²éÀ´¿ØÖÆÁ÷Á¿¡£
(¶þ) ͸Ã÷·À»ðǽµÄ»ù±¾ÅäÖÃ
#show firesall //ÏÔʾµ±Ç°·À»ðǽµÄÔËÐÐģʽ ¡¡¡¡#firewall transparent //ÆôÓÃ͸Ã÷·À»ðǽģʽ ¡¡¡¡#no firewall transparent //·µ»ØROUTEģʽ ¡¡¡¡#ip address 192.168.9.1 255.255.255.0 //ÅäÖùÜÀíIPµØÖ·¡£×¢Ò⣬ֻÊǹÜÀíIPµØÖ·¡£ |
×¢Ò⣺ÔÚÅäÖÃ͸Ã÷·À»ðǽµÄ½Ó¿Úʱ£¬ÆäËûºÍ·ÓÉÆ÷ģʽ¶¼Ò»Ñù£¬µ«²»ÄÜÅäÖÃIPµØÖ·¡£
(Èý£©¶¨ÖÆmac±í
͸Ã÷ģʽµÄ·À»ðǽת·¢°ü¾ÍÊÇÒÀ¾ÝMACµØÖ·½øÐÐת·¢£¬Ñ§Ï°MACµØÖ·µÄ·½·¨ºÍ½»»»»úÒ»Ñù¡£Ä¬ÈÏÇé¿öÏ£¬Ã¿¸ö½Ó¿Ú×Ô¶¯Ñ§Ï°Í¨¹ýËüµÄÁ÷Á¿µÄMACµØÖ·¡£È»ºó½«ÏìÓ¦µÄMACµØÖ·¼ÓÈëMACµØÖ·±íÖС£¿ÉÒԹصôÕâ¸ö¹¦ÄÜ£¬µ«±ØÐëÊÖ¹¤¼ÓÈ뾲̬MACµØÖ·ÌõÄ¿µ½MACµØÖ·±íÖУ¬·ñÔòASA·À»ðǽ½«²»ÄÜת·¢ÈκÎÁ÷Á¿¡£
#mac-learn int_name disable //int_nameÊǽӿÚÃû£¬¼´¹ØµôÄĸö½Ó¿ÚµÄMAC×Ô¶¯Ñ§Ï°¡£ ¡¡¡¡#mac-address-table aging-time static int_name mac_address
//int_name Ö¸µÄÊǽӿÚÃû£¬ mac_addressÖ¸µÄÊǼÓÈëµÄ¾²Ì¬macµØÖ·¡£ ¡¡¡¡#mac-address-table aging-time timeout_value //macµØÖ·µÄ³¬Ê±Ê±¼ä¡£ |
£¨ËÄ£© arpÉó²é
arpÉó²é¿ÉÒÔ·ÀÖ¹arpÆÛƹ¥»÷£¬µ±ÆôÓÃÁËARPÉó²é£¬ASA·À»ðǽ»á½«½ÓÊÕµ½µÄARP°üÖеÄmacµØÖ·¡¢IPµØÖ·ºÍ¶Ë¿ÚºÅÓ뾲̬arp±í¶Ô±È¡£
Èç¹ûmacµØÖ·¡¢IPµØÖ·ºÍ¶Ë¿ÚºÅÓ뾲̬arp±íÕâÈýÏîÍêÈ«ÏàÆ¥Å䣬Ôòת·¢°ü
Èç¹ûmacµØÖ·¡¢IPµØÖ·ºÍ¶Ë¿ÚºÅÓ뾲̬arp±í(ÕâÈýÏîÖÐ)ÓÐÈκÎÒ»Ìõ²»Æ¥Å䣬Ôò¶ªÆú°ü
Èç¹ûÓ뾲̬arp±íÖÐÈκÎÌõĿûÓÐÈÎºÎÆ¥Å䣬Ôò¿ÉÉèÖý«°ü¶ªÆú»¹Êǽ«°üflood(ºé·º³öÈ¥£©
×¢Ò⣺ֻÓ뾲̬ARPÏà±È½Ï£¬Èç¹û²»¶¨Ò徲̬ARP±í£¬ÄÇôARPÉó²é¾ÍûÓÐÈκÎÒâÒåÁË¡£
|