欢迎来到天天文库
浏览记录
ID:10022332
大小:470.50 KB
页数:14页
时间:2018-05-21
《asa防火墙配置要点》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、ASA防火墙技术要点二〇〇六年九月二十七日1.基本配置12.常用技巧23.故障倒换24.配置telnet、ssh及http管理35.vpn常用管理命令46.配置访问权限47.配置端口NAT(PAT)48.NAT一般规则59.DMZ区访问内网服务器510.配置sitetosite之VPN511.webvpn配置(sslvpn)612.远程拨入VPN913.日志服务器配置1114.Snmp网管配置1115.ACS配置1116.AAA配置1217.升级IOS1318.疑难杂症131.基本配置配置名称hostnamemelcohkasadomain-namecosmel.com配置
2、用户及密码:usernameahsupasswordWtIBQAqhMu/Lx5iyencryptedprivilege15aaaauthenticationhttpconsoleLOCALaaaauthenticationsshconsoleLOCALaaaauthenticationtelnetconsoleLOCALaaaauthenticationenableconsoleLOCALenablepasswordiraxXocttscgektgencrypted配置时区:clocktimezoneHKST8第14页共14页ntpserver192.168.2.16so
3、urceinsideprefer或ntpserverstdtime.gov.hksourceoutsideprefershclock显示时间信息配置http和telnet管理:management-accessinsidehttp192.168.0.0255.255.0.0insidetelnet192.168.0.0255.255.0.0inside1.常用技巧Shruntp查看与ntp有关的Shrucrypto查看与vpn有关的Shru
4、inccrypto只是关健字过滤而已copyrunning-configflash:/20070305.cfg把某一天的配置保存一下2
5、.故障倒换failoverfailoverlanunitprimaryfailoverlaninterfacetestintEthernet0/3failoverlinktestintEthernet0/3failovermacaddressEthernet0/10018.1900.50000018.1900.5001failovermacaddressEthernet0/00018.1900.40000018.1900.4001failovermacaddressEthernet0/20018.1900.60000018.1900.6001failovermacaddre
6、ssManagement0/00018.1900.70000018.1900.7001failoverinterfaceiptestint10.3.3.1255.255.255.0standby10.3.3.2注:最好配置虚拟MAC地址shfailover显示配置信息writestandby写入到备用的防火墙中第14页共14页failover命令集如下:configuremodecommands/options:interfaceConfiguretheIPaddressandmasktobeusedforfailoverand/orstatefulupdateinform
7、ationinterface-policySetthepolicyforfailoverduetointerfacefailureskeyConfigurethefailoversharedsecretorkeylanSpecifytheunitasprimaryorsecondaryorconfiguretheinterfaceandvlantobeusedforfailovercommunicationlinkConfiguretheinterfaceandvlantobeusedasalinkforstatefulupdateinformationmacSpecify
8、thevirtualmacaddressforaphysicalinterfacepolltimeConfigurefailoverpollintervalreplicationEnableHTTP(port80)connectionreplicationtimeoutSpecifythefailoverreconnecttimeoutvalueforasymmetricallyroutedsessionsshfailover命令集如下:historyShowfailoverswitchinghistoryinte
此文档下载收益归作者所有