欢迎来到天天文库
浏览记录
ID:47104397
大小:15.47 KB
页数:4页
时间:2019-08-03
《ASA的sslwebvpn》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、代码:ASA(config)#showstartup-config :Saved:Writtenbyenable_15at00:14:28.859UTCThuDec21999!ASAVersion8.0(2)!hostnameASAenablepassword8Ry2YjIyt7RRXU24encryptednames!interfaceEthernet0/0nameifoutsidesecurity-level0ipaddress10.67.6.251255.255.255.0!interfaceEthernet0/1nameifinsidesecurity-level100i
2、paddress192.168.1.254255.255.255.0!interfaceEthernet0/2shutdownnonameifnosecurity-levelnoipaddress!interfaceEthernet0/3shutdownnonameifnosecurity-levelnoipaddress!interfaceEthernet0/4shutdownnonameifnosecurity-levelnoipaddress!interfaceEthernet0/5shutdownnonameifnosecurity-levelnoipaddress!pas
3、swd2KFQnbNIdI.2KYOUencryptedbootconfigdisk0:/.private/startup-configftpmodepassiveaccess-list10standardpermitanyaccess-listsplitstandardpermit192.168.1.0255.255.255.0 ;定义需要分离的数据流access-listipsecextendedpermitip192.168.1.0255.255.255.0anypagerlines24mtuoutside1500mtuinside1500iplocalpoolvpn_po
4、ol172.16.0.1-172.16.0.254mask255.255.255.0 ;定义vpn的地址池nofailovericmpunreachablerate-limit1burst-size1asdmimagedisk0:/asdm-603.binnoasdmhistoryenablearptimeout14400routeoutside0.0.0.00.0.0.010.67.6.2541timeoutxlate3:00:00timeoutconn1:00:00half-closed0:10:00udp0:02:00icmp0:00:02timeoutsunrpc0:
5、10:00h3230:05:00h2251:00:00mgcp0:05:00mgcp-pat0:05:00timeoutsip0:30:00sip_media0:02:00sip-invite0:03:00sip-disconnect0:02:00timeoutuauth0:05:00absolutedynamic-access-policy-recordDfltAccessPolicy aaa-serverradiusgpprotocolradius ;定义认证协议为radiusaaa-serverradiusgp(outside)host10.67.10.4 ;定义rad
6、ius服务器地址keywww.sierraatlantic.com ;定义radius服务器的keyhttpserverenablehttp0.0.0.00.0.0.0outsidenosnmp-serverlocationnosnmp-servercontactsnmp-serverenabletrapssnmpauthenticationlinkuplinkdowncoldstartcryptoipsectransform-setESP-3DES-MD5esp-3desesp-md5-hmac ;定义加密认证等参数cryptodynamic-mapdynmap1settra
7、nsform-setESP-3DES-MD5 cryptomapvpnmap10ipsec-isakmpdynamicdynmapcryptomapvpnmapinterfaceoutside ;将加密图应用到外部接口cryptoisakmpenableoutsidecryptoisakmppolicy10 ;IKE策略authenticationpre-shareencryption3deshashmd5group2lifetime86400nocrypt
此文档下载收益归作者所有