天下网吧 >> 网吧方案 >> 方案分析 >> 正文

在pix或asa如何防止内网用户乱改ip配置案例

rp inside chengxiaojie 0016.3564.8a6b

arp inside xingzhonghe 00e0.4c60.a8da

arp inside dhcp 0014.5e2b.77b5

arp inside zhangyi 0013.7222.4819

arp inside lixuesong-dell 0018.8ba2.d1c5

arp inside machi 000a.e6b5.0600

arp inside 10.64.64.18 0015.c510.12d4

****************************************************

上一页  [1] [2] [3] [4] 下一页

arp timeout 14400

global (outside) 1 interface

nat (inside) 0 access-list inside_nat0_outbound

nat (inside) 1 10.64.64.0 255.255.240.0

nat (dmz) 0 access-list dmz_nat0_outbound

static (inside,outside) tcp interface 1503 chufw 1503 netmask 255.255.255.255

static (inside,outside) tcp interface h323 chufw h323 netmask 255.255.255.255

access-group outside_access_in in interface outside

应用acl到inside端口

****************************************************

access-group inside_access_in in interface inside

****************************************************

route outside 0.0.0.0 0.0.0.0 X.X.76.25 1

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00

timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00

timeout uauth 0:05:00 absolute

group-policy caiwu internal

group-policy caiwu attributes

 dns-server value 219.150.32.132

 vpn-tunnel-protocol IPSec

 split-tunnel-policy tunnelspecified

 split-tunnel-network-list value caiwu_splitTunnelAcl

group-policy remote internal

group-policy remote attributes

 dns-server value 219.150.32.132

 vpn-tunnel-protocol IPSec

 split-tunnel-policy tunnelspecified

 split-tunnel-network-list value remote_splitTunnelAcl

username chufw password hs6C0g7Y0Zza/dVN encrypted privilege 15

username chufw attributes

 vpn-group-policy remote

 vpn-framed-ip-address 1.1.1.111 255.255.255.0

http server enable

http chufw 255.255.255.255 inside

http 219.148.242.228 255.255.255.255 outside

http 219.148.242.227 255.255.255.255 outside

http 1.1.1.111 255.255.255.255 outside

no snmp-server location

no snmp-server contact

snmp-server enable traps snmp authentication linkup linkdow

本文来源:天下网吧 作者:网吧方案

相关文章
没有相关文章
声明
声明:本站所发表的文章、评论及图片仅代表作者本人观点,与本站立场无关。若文章侵犯了您的相关权益,请及时与我们联系,我们会及时处理,感谢您对本站的支持!联系Email:support@txwb.com,系统开号,技术支持,服务联系QQ:1175525021本站所有有注明来源为天下网吧或天下网吧论坛的原创作品,各位转载时请注明来源链接!
天下网吧·网吧天下