一个PIX506E的配置实例

最近出于考试的原因,不得不研究这个技术玩意,初弄起来其实是比较难的啊,找师兄要了点技术文章确实很有借鉴意义,下面是师兄的配置实例,学习后着实看懂了些东西,真可谓受益匪浅啊 ~~`~~(适用与用PIX又只有一个外网IP且想做static的)
interface ethernet0 auto
interface ethernet1 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password 5Pi.ymYwLiU8volV encrypted
passwd Ta.5POa/MPM0/qsu encrypted
hostname XXXXXXXX
domain-name XXXXXXXXXXX
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names
pager lines 24
mtu outside 1500
mtu inside 1500
ip address outside 222.22.222.22 255.255.255.0
ip address inside 192.168.100.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
pdm location 192.168.100.2 255.255.255.255 inside
pdm logging informational 100
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) tcp interface www 192.168.100.2 www netmask 255.255.255.255 0 0
static (inside,outside) tcp interface ftp 192.168.100.2 ftp netmask 255.255.255.255 0 0
conduit permit tcp host 222.22.222.22 eq www any
conduit permit tcp host 222.22.222.22 eq ftp any
conduit permit icmp any any
conduit deny ip any any
route outside 0.0.0.0 0.0.0.0 222.22.222.1 1
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
http server enable
http 192.168.100.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
terminal width 80这里的防火墙外网IP为222.22.222.22,网关为222.22.222.1,内网IP为192.168.100.1。
另外还把防火墙的80和21端口映射到了192.168.100.2这个内网的机器上。
注意路由和static的配置方法就好了。我的防火墙型号为PIX506E。

你可能感兴趣的:(配置,职场,实例,休闲)