标题: [防火墙与蜜罐] PIX防火墙配置问题 在线等 (查看:239 回复:3)
派翠西亚
学徒网管




UID 772731
精华 0
积分 5
帖子 13
MST币 11 点    
BST币 5 点    赚取
阅读权限 60
注册 2008-7-29
状态 离线
 
[ 使用道具 ]  
发表于 2008-9-24 13:54  [ 资料 ]  [ 博客 ]  [ 短消息 ]  [ 加为好友
PIX防火墙配置问题 在线等
本帖发表在我是网管论坛,帖子地址:http://bbs.54master.com/273208,1,1
外网无法访问192.168.100.5和192.168.100.6的服务,小弟初次接触PIX,请大侠们帮帮忙啊!!小弟先谢谢拉!

PIX Version 6.3(5)
interface ethernet0 auto
interface ethernet1 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password kq8VjfQOgHWNjFvy encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname pix535
domain-name www.cisco.com
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names         
access-list 101 permit icmp any any
access-list 101 permit tcp any host 202.106.89.172 eq www
access-list 101 permit tcp any host 202.106.89.172 eq smtp
access-list 101 permit tcp any host 202.106.89.172 eq pop3
access-list 101 permit tcp any host 202.106.89.172 eq ftp
access-list 101 permit tcp any host 202.106.89.172 eq telnet
access-list 101 permit tcp any host 202.106.89.172 eq 24
access-list 101 permit tcp any host 202.106.89.172 eq ssh
access-list 101 permit tcp any host 202.106.89.172 eq 8080
access-list 101 permit tcp any host 202.106.89.172 eq 1433
access-list 101 permit tcp any host 202.106.89.172 eq 9002
access-list 101 permit tcp any host 202.106.89.172 eq 8017
access-list 101 permit tcp any host 202.106.89.172 eq 8014
access-list 101 permit tcp any host 202.106.89.172 eq 2332
access-list 101 permit tcp any host 202.106.89.172 eq 8800
access-list 101 permit tcp any host 202.106.89.172 eq 4899
access-list 101 permit tcp any host 202.106.89.172 eq 9988
access-list 101 permit tcp any host 202.106.89.172 eq 8088
access-list 101 permit tcp any host 202.106.89.171 eq 7879
pager lines 24
mtu outside 1500
mtu inside 1500
ip address outside 202.106.89.172 255.255.255.248
ip address inside 192.168.100.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
no failover
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) tcp interface www 192.168.100.5 www netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 1433 192.168.100.5 1433 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 9002 192.168.100.5 9002 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 8017 192.168.100.5 8017 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 8014 192.168.100.5 8014 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 2332 192.168.100.5 2332 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 4899 192.168.100.5 4899 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 8800 192.168.100.5 8800 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 8088 192.168.100.6 8088 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 9988 192.168.100.6 9988 netmask 255.255.255.255 0 0
static (inside,outside) tcp interface 8080 192.168.100.6 8080 netmask 255.255.255.255 0 0
static (inside,outside) 202.106.89.171 192.168.100.7 netmask 255.255.255.255 0 0
access-group 101 in interface outside
route outside 0.0.0.0 0.0.0.0 202.106.89.174 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
terminal width 80
Cryptochecksum:e8545ace997b34879ff1631c95f20518
: end

[ 点这里复制网址,推荐给你QQ/MSN上的好友们! ]
本站声明:以上内容由网友 派翠西亚 提供,与54master立场无关!
[ 顶部 ]
域名、虚拟主机、服务器租用/托管一站式IT服务 V5.0
牵狼逛街的羊
学徒网管



UID 796540
精华 0
积分 5
帖子 53
MST币 129 点    
BST币 5 点    赚取
阅读权限 60
注册 2008-9-3
状态 离线
 
[ 使用道具 ]  
发表于 2008-9-24 18:57  [ 资料 ]  [ 博客 ]  [ 短消息 ]  [ 加为好友
这是什么防火墙啊,我用的是其他的,但是原理也不懂,所以帮不了你了,实在不行就换了吧。

[ 本帖最后由 blazewind 于 2008-9-25 08:06 编辑 ]

本站声明:以上内容由网友 牵狼逛街的羊 提供,与54master立场无关!
《我是网管》论坛
ヽoo沒有激烈的親吻゛╰哪來的床仩的翻滾╰ァ。
[ 顶部 ]
域名、虚拟主机、服务器租用/托管一站式IT服务 V5.0
忧郁米兰
学徒网管




UID 725077
精华 0
积分 5
帖子 42
MST币 0 点    
BST币 5 点    赚取
阅读权限 60
注册 2008-5-11
状态 离线
 
[ 使用道具 ]  
发表于 2008-9-25 16:01  [ 资料 ]  [ 博客 ]  [ 短消息 ]  [ 加为好友
谢谢

谢谢分享,楼主很厚道

本站声明:以上内容由网友 忧郁米兰 提供,与54master立场无关!
[ 顶部 ]
域名、虚拟主机、服务器租用/托管一站式IT服务 V5.0
忧郁米兰
学徒网管




UID 725077
精华 0
积分 5
帖子 42
MST币 0 点    
BST币 5 点    赚取
阅读权限 60
注册 2008-5-11
状态 离线
 
[ 使用道具 ]  
发表于 2008-9-25 16:11  [ 资料 ]  [ 博客 ]  [ 短消息 ]  [ 加为好友
好东西 顶顶顶 顶顶顶 顶顶顶 顶顶顶 顶顶顶 顶顶顶好东西 顶顶顶 顶顶顶 顶顶顶 顶顶顶 顶顶顶 顶顶顶好东西 顶顶顶 顶顶顶 顶顶顶 顶顶顶 顶顶顶 顶顶顶

本站声明:以上内容由网友 忧郁米兰 提供,与54master立场无关!
[ 顶部 ]
域名、虚拟主机、服务器租用/托管一站式IT服务 V5.0
  
 



当前时区 GMT+8, 现在时间是 2008-12-2 09:20

Powered by Discuz! 5.5.0  © 2001-2007 Comsenz Inc.
Processed in 0.966695 second(s), 12 queries , Gzip enabled

清除 Cookies - 关于我是网管 - 联系我是网管 - 广告服务 - 诚聘版主 - 无图版 - WAP -