欢迎来到天天文库
浏览记录
ID:46864182
大小:107.50 KB
页数:15页
时间:2019-11-28
《204实验指导(ASA基本配置)》由会员上传分享,免费在线阅读,更多相关内容在工程资料-天天文库。
1、实验指导(防火墙基本配置)一、实验任务Outside1Inside▼申跆也佔•佰⑸2410.4•伯/生―e0/0刖0弋LoOg10.15.15.1/24DMZ区;■10.35.35:3/^4e0/0・310.25.25.2/2VLAN3印/0LoO:10.3.3.3/24•任务:1.从内网能主动访问DMZ区、外网,反之不然2.DMZ区能主动访问外网,反之不然实验步骤1.预配:R1:hostnameR1interfacee0/0noshutdownduplexfullipaddress10.15.15.1255.255.255.0interfacelooOipaddre
2、ss10.1.1.1255.255.255.0iproute10.0.0.0255.0.0.010.15.15.5linevtv04passwordciscologinR2:hostnameR2interfacee0/0noshutdownduplexful1LoO:10.2.2.2/24ipaddress10.25.25.2255.255.255.0interfacelooOipaddress10.2.2.2255.255.255.0routerripnetwork10.0.0.01inevty04passwordciscologinR3:hostnameR3int
3、erfacee0/0noshutdownduplexfullipaddress10.35.35.3255.255.255.0interfacelooOipaddress10.3.3.3255.255.255.0routerripnetwork10.0.0.0linevty04passwordciscologinSI:(在下执行以下命令)vlandatabasevlan2vlan3exitconfthostnameSwitchinterfaccFastEthorncl0/0shutdowninterfaceFastEthernetO/5noshutdownswitchp
4、orttrunknativevlan1000switchporttrunkendotswitchportmodetrunkduplexful1speed10interfaceFastEthernetO/2switchportmodeaccessswitchportaccessvlan2interfaceFastEthernet0/3switchportmodeaccessswitchportaccessvlan32.基本配置(PIX±):hostnamePIX1interfaceEthernetOnoshutdowni•interfaceEthernetO.1vlan
5、1nameifOutsideipaddress10.15.15.5255.255.255.0I•interfaceEthernetO.2vlan2nameifInsideipaddress10.25.25.5255.255.255.0I•interfaceEthernetO.3vlan3nameifDMZipaddress10.35.35.5255.255.255.0Irouteoutside0010.15.15.1测试:从PIXping各个路由器,检测网络的连通性3.配置路由协议(PIX):routerripnetwork10.0.0.0redistributest
6、atic在PIX±showroute检测路由表,在其他路由器上也检测路由表4.配置安全等级(PIX):interfaceEthernetO.1security-level0interfaceEthernetO・2security-level100interfaceEthernetO.3security-level505.测试:三个路由之间互相telnet,查看是否只有从高安全等级到底安全等级才能telnet成功?三、完整配置R1version12.4servicetimestampsdebugdatetimemsecservicetimestampslogdateti
7、memsecnoservicepassword-encryptioni■hostnameR1i•boot-start-markerboot^end-markeri■I•noaaanew-modelmemory-sizeiomem5iiipcefinterfaccLoopbackOipaddress10.1.1.1255.255.255.0IinterfaceEthernet0/0ipaddress10.15.15.1255.255.255.0full-duplexi■interfaceEthernetO/1noipaddressshutdownhal
此文档下载收益归作者所有