欢迎来到天天文库
浏览记录
ID:13933188
大小:470.50 KB
页数:14页
时间:2018-07-25
《asa防火墙配置要点》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、ASA防火墙技术要点二〇〇六年九月二十七日1.基本配置12.常用技巧23.故障倒换24.配置telnet、ssh及http管理35.vpn常用管理命令46.配置访问权限47.配置端口NAT(PAT)48.NAT一般规则59.DMZ区访问内网服务器510.配置sitetosite之VPN511.webvpn配置(sslvpn)612.远程拨入VPN913.日志服务器配置1114.Snmp网管配置1115.ACS配置1116.AAA配置1217.升级IOS1318.疑难杂症131.基本配置配置名称hostn
2、amemelcohkasadomain-namecosmel.com配置用户及密码:usernameahsupasswordWtIBQAqhMu/Lx5iyencryptedprivilege15aaaauthenticationhttpconsoleLOCALaaaauthenticationsshconsoleLOCALaaaauthenticationtelnetconsoleLOCALaaaauthenticationenableconsoleLOCALenablepasswordiraxXoc
3、ttscgektgencrypted配置时区:clocktimezoneHKST8第14页共14页ntpserver192.168.2.16sourceinsideprefer或ntpserverstdtime.gov.hksourceoutsideprefershclock显示时间信息配置http和telnet管理:management-accessinsidehttp192.168.0.0255.255.0.0insidetelnet192.168.0.0255.255.0.0inside1.常用技
4、巧Shruntp查看与ntp有关的Shrucrypto查看与vpn有关的Shru
5、inccrypto只是关健字过滤而已copyrunning-configflash:/20070305.cfg把某一天的配置保存一下2.故障倒换failoverfailoverlanunitprimaryfailoverlaninterfacetestintEthernet0/3failoverlinktestintEthernet0/3failovermacaddressEthernet0/10018.1900.5000
6、0018.1900.5001failovermacaddressEthernet0/00018.1900.40000018.1900.4001failovermacaddressEthernet0/20018.1900.60000018.1900.6001failovermacaddressManagement0/00018.1900.70000018.1900.7001failoverinterfaceiptestint10.3.3.1255.255.255.0standby10.3.3.2注:最好配
7、置虚拟MAC地址shfailover显示配置信息writestandby写入到备用的防火墙中第14页共14页failover命令集如下:configuremodecommands/options:interfaceConfiguretheIPaddressandmasktobeusedforfailoverand/orstatefulupdateinformationinterface-policySetthepolicyforfailoverduetointerfacefailureskeyConfi
8、gurethefailoversharedsecretorkeylanSpecifytheunitasprimaryorsecondaryorconfiguretheinterfaceandvlantobeusedforfailovercommunicationlinkConfiguretheinterfaceandvlantobeusedasalinkforstatefulupdateinformationmacSpecifythevirtualmacaddressforaphysicalinterf
9、acepolltimeConfigurefailoverpollintervalreplicationEnableHTTP(port80)connectionreplicationtimeoutSpecifythefailoverreconnecttimeoutvalueforasymmetricallyroutedsessionsshfailover命令集如下:historyShowfailoverswitchinghistoryinte
此文档下载收益归作者所有