欢迎来到天天文库
浏览记录
ID:8931447
大小:255.00 KB
页数:12页
时间:2018-04-12
《asa防火墙配置命令-王军》由会员上传分享,免费在线阅读,更多相关内容在应用文档-天天文库。
1、ASA防火墙配置命令(v1.0)作者王军审核分类网络子类防火墙时间2021年6月20日版本说明版本日期内容编写人V1.02010-3-14创建文档王军服务交付中心(西区)第12页共12页目录1.常用技巧32.故障倒换33.配置telnet、ssh及http管理54.vpn常用管理命令55.配置访问权限66.配置sitetosite之VPN67.webvpn配置(sslvpn)78.远程拨入VPN89.日志服务器配置1010.Snmp网管配置1111.ACS配置1112.AAA配置1113.升级IOS1214.疑难杂症12服务交付中心(西区)第12页共12页1.常用技
2、巧Shruntp查看与ntp有关的Shrucrypto查看与vpn有关的Shru
3、inccrypto只是关健字过滤而已2.故障倒换failoverfailoverlanunitprimaryfailoverlaninterfacetestintEthernet0/3failoverlinktestintEthernet0/3failovermacaddressEthernet0/10018.1900.50000018.1900.5001failovermacaddressEthernet0/00018.1900.40000018.1900.4001failoverm
4、acaddressEthernet0/20018.1900.60000018.1900.6001failovermacaddressManagement0/00018.1900.70000018.1900.7001failoverinterfaceiptestint10.3.3.1255.255.255.0standby10.3.3.2注:最好配置虚拟MAC地址shfailover显示配置信息writestandby写入到备用的防火墙中服务交付中心(西区)第12页共12页failover命令集如下:configuremodecommands/options:inte
5、rfaceConfiguretheIPaddressandmasktobeusedforfailoverand/orstatefulupdateinformationinterface-policySetthepolicyforfailoverduetointerfacefailureskeyConfigurethefailoversharedsecretorkeylanSpecifytheunitasprimaryorsecondaryorconfiguretheinterfaceandvlantobeusedforfailovercommunicationlin
6、kConfiguretheinterfaceandvlantobeusedasalinkforstatefulupdateinformationmacSpecifythevirtualmacaddressforaphysicalinterfacepolltimeConfigurefailoverpollintervalreplicationEnableHTTP(port80)connectionreplicationtimeoutSpecifythefailoverreconnecttimeoutvalueforasymmetricallyroutedsession
7、sshfailover命令集如下:historyShowfailoverswitchinghistoryinterfaceShowfailovercommandinterfaceinformationstateShowfailoverinternalstateinformationstatisticsShowfailovercommandinterfacestatisticsinformation服务交付中心(西区)第12页共12页
8、Outputmodifiers3.配置telnet、ssh及http管理usernamejiangpasswordCsmep3
9、VzvPQPCbkxencryptedprivilege15aaaauthenticationenableconsoleLOCALaaaauthenticationtelnetconsoleLOCALaaaauthenticationsshconsoleLOCALaaaauthorizationcommandLOCALhttp192.168.40.0255.255.255.0managementssh192.168.40.0255.255.255.0inside4.vpn常用管理命令shvpn-sessiondbfulll2l显示sitetosite之vpn通道
此文档下载收益归作者所有