pix535實際配置

來源:互聯網
上載者:User

  實際使用pix兩個連接埠。

  最終目的是:不使用nat讓內部網路的地址直接出去,pix內外均為cernet地址。

  配置1中不使用NAT的,內部節點不能通過pix出去

  配置2中使用NAT的,內部節點可以通過pix出去

  兩個配置除了NAT以外,都一樣。

  請大家協助檢查一下,看看不做nat時,怎樣才能做通。謝謝!

  配置1: 沒有使用NAT,內部節點不能通過pix出去

  : Saved

  PIX Version 6.1(2)

  nameif gb-ethernet0 outside security0

  nameif gb-ethernet1 inside security100

  nameif ethernet0 intf2 security10

  nameif ethernet1 intf3 security15

  enable password 8Ry2YjIyt7RRXU24 encrypted

  passwd 2KFQnbNIdI.2KYOU encrypted

  hostname pixfirewall

  fixup protocol ftp 21

  fixup protocol http 80

  fixup protocol h323 1720

  fixup protocol rsh 514

  fixup protocol rtsp 554

  fixup protocol smtp 25

  fixup protocol sqlnet 1521

  fixup protocol sip 5060

  fixup protocol skinny 2000

  names

  pager lines 24

  interface gb-ethernet0 1000auto

  interface gb-ethernet1 1000auto

  interface ethernet0 auto shutdown

  interface ethernet1 auto shutdown

  mtu outside 1500

  mtu inside 1500

  mtu intf2 1500

  mtu intf3 1500

  ip address outside 202.*.212.2 255.255.255.0

  ip address inside 202.*.8.2 255.255.255.0

  ip address intf2 127.0.0.1 255.255.255.255

  ip address intf3 127.0.0.1 255.255.255.255

  ip audit info action alarm

  ip audit attack action alarm

  no failover

  failover timeout 0:00:00

  failover poll 15

  failover ip address outside 0.0.0.0

  failover ip address inside 0.0.0.0

  failover ip address intf2 0.0.0.0

  failover ip address intf3 0.0.0.0

  pdm history enable

  arp timeout 14400

  nat (inside) 0 202.*.8.0 255.255.255.0 0 0

  conduit permit icmp any any

  route outside 0.0.0.0 0.0.0.0 202.*.212.1 1

  timeout xlate 3:00:00

  timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si



相關文章

Beyond APAC's No.1 Cloud

19.6% IaaS Market Share in Asia Pacific - Gartner IT Service report, 2018

Learn more >

Apsara Conference 2019

The Rise of Data Intelligence, September 25th - 27th, Hangzhou, China

Learn more >

Alibaba Cloud Free Trial

Learn and experience the power of Alibaba Cloud with a free trial worth $300-1200 USD

Learn more >

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。