跳转到主内容
websoft网络软件专家 - 深耕网络技术,打造实用软件!

CISCO-PIX506E详细配置以及命令注释(六)

五、案例分析 ( 1 ) pix pppoe 拨号的 配置 pixfirewall# sh run : Saved PIX Version 6.2(2) nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password 2KFQnbNIdI.2KYOU encrypted passwd 2KFQnbNIdI.2KYOU encrypted h

五、案例分析

(1)pix pppoe拨号的配置pixfirewall# sh run: Saved PIX Version 6.2(2) nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password 2KFQnbNIdI.2KYOU encrypted passwd 2KFQnbNIdI.2KYOU encrypted hostname pixfirewall fixup protocol ftp 21 fixup protocol http 80 fixup protocol h323 h225 1720 fixup protocol h323 ras 1718-1719 fixup protocol ils 389 fixup protocol rsh 514 fixup protocol rtsp 554 fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol sip 5060 no fixup protocol skinny 2000 names pager lines 24 interface ethernet0 auto interface ethernet1 auto mtu outside 1500 mtu inside 1500 ip address outside pppoe setroute ip address inside 10.80.1.254 255.255.255.0 ip audit info action alarm ip audit attack action alarm pdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 1 10.80.0.0 255.255.0.0 0 0 conduit permit icmp any any timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute aaa-server TACACS+ protocol tacacs+aaa-server RADIUS protocol radius aaa-server LOCAL protocol local no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps floodguard enable no sysopt route dnat telnet 10.80.1.0 255.255.255.0 inside telnet timeout 5 ssh timeout 5 vpdn group pppoex request dialout pppoe vpdn group pppoex localname xxxxxx vpdn group pppoex ppp authentication pap vpdn username xxxxxx password *********terminal width 80 Cryptochecksum:b68ce36b87522b2c412c29c6291ce5cc: end(2)外网192.168.1.X--(192.168.1.2)PIX 506E(192.168.10.2)--192.168.10.X内网PIX Version 6.3(5)interface ethernet0 autointerface ethernet1 autonameif ethernet0 outside security0nameif ethernet1 inside security100enable password 8Ry2YjIyt7RRXU24 encryptedpasswd 2KFQnbNIdI.2KYOU encryptedhostname MCPIXdomain-name MCPIXfixup protocol dns maximum-length 512fixup protocol ftp 21fixup protocol h323 h225 1720fixup protocol h323 ras 1718-1719fixup protocol http 80fixup protocol rsh 514fixup protocol rtsp 554fixup protocol sip 5060fixup protocol sip udp 5060fixup protocol skinny 2000fixup protocol smtp 25fixup protocol sqlnet 1521fixup protocol tftp 69namesaccess-list 100 permit icmp any anyaccess-list 100 permit tcp any any eq wwwaccess-list no-nat permit ip 192.168.10.0 255.255.255.0 192.168.10.0 255.255.255.0access-list no-nat permit ip 192.168.1.0 255.255.255.0 192.168.10.0 255.255.255.0access-list no-nat permit ip any anyaccess-list no-nat permit icmp any any access-list 100 permit ip 192.168.10.0 255.255.255.0 192.168.10.0 255.255.255.0pager lines 24mtu outside 1500mtu inside 1500ip address outside 192.168.1.220 255.255.255.0ip address inside 192.168.10.2 255.255.255.0ip audit info action alarmip audit attack action alarmip local pool dialer 192.168.10.150-192.168.10.200pdm history enablearp timeout 14400global (outside) 1 interfacenat (inside) 0 access-list no-natnat (inside) 10.0.0.0 0.0.0.0 0 0static (inside,outside) tcp 192.168.1.220 www 192.168.10.24 www netmask 255.255.255.255 0 0access-group100 ininterface outsideroute outside 0.0.0.0 0.0.0.0 192.168.1.1 1timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00timeout sip-disconnect 0:02:00 sip-invite 0:03:00timeout uauth 0:05:00 absoluteaaa-server TACACS+ protocol tacacs+aaa-server TACACS+ max-failed-attempts 3aaa-server TACACS+ deadtime 10aaa-server RADIUS protocol radiusaaa-server RADIUS max-failed-attempts 3aaa-server RADIUS deadtime 10aaa-server LOCAL protocol localhttp server enablehttp 192.168.1.0 255.255.255.0 outsidehttp 192.168.10.0 255.255.255.0 insideno snmp-server locationno snmp-server contactsnmp-server community publicno snmp-server enable trapsfloodguard enablesysopt connection permit-ipseccrypto ipsec transform-set aaades esp-des esp-md5-hmaccrypto dynamic-map dynomap 10 set transform-set aaadescrypto map vpnpeer 20 ipsec-isakmp dynamic dynomapcrypto map vpnpeer client configuration address initiatecrypto map vpnpeer client configuration address respondcrypto map vpnpeer client authentication LOCALcrypto map vpnpeer interface outsideisakmp enable outsideisakmp key ******** address 0.0.0.0 netmask 0.0.0.0isakmp client configuration address-pool local dialer outsideisakmp policy 10 authentication pre-shareisakmp policy 10 encryption desisakmp policy 10 hash md5isakmp policy 10 group 2isakmp policy 10 lifetime 86400vpngroup student0 address-pool dialervpngroup student0 idle-time 1800vpngroup student0 password ********telnet 192.168.10.0 255.255.255.0 insidetelnet timeout 5ssh 0.0.0.0 0.0.0.0 outsidessh timeout 5console timeout 0username cisco password 3USUcOPFUiMCO4Jk encrypted privilege 2terminal width 80Cryptochecksum:e9f237a2bab164d66cca0398c122b0dc: end两年砍柴

相关文章