PIX515E-R防火牆安裝ACS3.0做使用者身分識別驗證

來源:互聯網
上載者:User

  我把下午做實驗的PIX配置貼出來:

  PIX Version 6.3(1) // os 我用的 6.3 版本的,這個版本支援 IPSec VPN with NAT

  interface ethernet0 auto

  interface ethernet1 auto

  nameif ethernet0 outside security0

  nameif ethernet1 inside security100

  enable password 8Ry2YjIyt7RRXU24 encrypted

  passwd 2KFQnbNIdI.2KYOU encrypted

  hostname ISSC-PIX515E-R

  fixup protocol ftp 21

  fixup protocol h323 h225 1720

  fixup protocol h323 ras 1718-1719

  fixup protocol http 80

  fixup protocol ils 389

  fixup protocol rsh 514

  fixup protocol rtsp 554

  fixup protocol sip 5060

  fixup protocol sip udp 5060

  fixup protocol skinny 2000

  fixup protocol smtp 25

  fixup protocol sqlnet 1521

  names

  access-list 101 permit ip 192.168.10.0 255.255.255.0 192.168.32.0 255.255.255.0

  access-list 102 permit ip 192.168.10.0 255.255.255.0 192.168.32.0 255.255.255.0

  access-list 104 permit icmp any any

  pager lines 24

  mtu outside 1500

  mtu inside 1500

  ip address outside 10.0.0.1 255.255.255.0

  ip address inside 192.168.10.252 255.255.255.0

  ip audit info action alarm

  ip audit attack action alarm

  ip local pool pccw 192.168.32.1-192.168.32.10

  ip local pool pccw02 192.168.32.50

  pdm history enable

  arp timeout 14400

  global (outside) 1 interface

  nat (inside) 0 access-list 102 //對VPN串連的使用者不經過NAT,這裡的102對應上面的access-list 102

  nat (inside) 1 192.168.10.0 255.255.255.0 0 0

  access-group 104 in interface outside

  route outside 0.0.0.0 0.0.0.0 202.108.48.181 1

  timeout xlate 3:00:00

  timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00

  timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00

  timeout uauth 0:05:00 absolute

  aaa-server TACACS+ protocol tacacs+

  aaa-server RADIUS protocol radius

  aaa-server LOCAL protocol local

  aaa-server partnerauth protocol radius



相關文章

Beyond APAC's No.1 Cloud

19.6% IaaS Market Share in Asia Pacific - Gartner IT Service report, 2018

Learn more >

Apsara Conference 2019

The Rise of Data Intelligence, September 25th - 27th, Hangzhou, China

Learn more >

Alibaba Cloud Free Trial

Learn and experience the power of Alibaba Cloud with a free trial worth $300-1200 USD

Learn more >

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。