
ciscoasa# show run6 {6 w9 t3 ^* ~7 _; y5 D6 _% C
: Saved1 s: m" [- C1 Z3 X, U
: R* y! p& ]1 ]
ASA Version 7.0(8)" ]3 d9 h' v( {. H" s- U
!
& U) F C6 y/ t/ k( L xhostname ciscoasa J% `$ I3 ^' |1 r
enable password bvalPmsJo1vFkzZM encrypted5 |" Q2 }" Q! e9 t1 l3 S
passwd bvalPmsJo1vFkzZM encrypted
) }7 T/ ]9 r9 Enames! e/ q2 E# L6 k
dns-guard
* S( x- T1 o0 m9 y. ~' z!
8 `5 X* t* B: k( i+ a* W7 Linterface Ethernet0/00 I9 l9 |2 ^, k1 \5 w& q5 ^
nameif outside! W% C7 ~- i: U" X2 V3 q# q+ e
security-level 0, p' D; _0 ?& ` [* W1 J$ ~
ip address 10.2.14.2 255.255.255.0
. x. c' A' A' @, M' M( f3 N!
8 |! g3 D3 | qinterface Ethernet0/1
4 B. S8 n; l0 F! W6 J0 K' [5 o nameif inside. v! Q: T, }: t
security-level 100
5 B2 Z" L) W3 I8 R i2 t ip address 10.1.1.1 255.255.255.0
0 {# G% G p) A# M!1 W0 v% ~$ w( G4 h
interface Ethernet0/27 `8 q! G* ?9 a/ }
shutdown
H% W6 N/ |$ G' {0 c no nameif
* Y. Y I0 ~ W" i5 b; f. B9 T+ j no security-level
* _8 A' d& P- Q! I2 I9 y no ip address
% t6 u% n/ h+ ~( N% L6 n0 u!7 N, l1 x2 A5 Z' j3 t
interface Management0/0
% ~( M% B4 m7 g8 f nameif management
- x$ l4 O( s# b security-level 100
: {% w, i% a' |$ N' L7 G! \0 a ip address 192.168.1.1 255.255.255.0" H7 _. d# \# e; N
management-only2 `) E( @" z! |0 k& |
!
4 e3 _) S+ Z3 o5 Wftp mode passive) ^) z+ T$ i6 H9 J* I4 l9 f5 T% V
dns domain-lookup outside
" g$ Z% U i( t) P# {" `: T- U) O' Idns name-server 119.253.1.26: t3 Z8 O- v9 @0 J% a$ o) }
access-list list_name extended permit udp any any eq 5222
0 I& ] Z. {; B8 ^9 j2 Eaccess-list list_name extended permit udp any any eq 8100/ d9 l. K3 `. |
access-list list_name extended permit udp any any eq 8084/ a* |( ~7 s; Q! R8 y/ E
access-list list_name extended permit udp any any eq 8085
/ c& w4 d9 L* L" p# _access-list list_name extended permit udp any any eq 5525% T- H2 a: j7 H
access-list list_name extended permit udp any any eq 443, `' {. g |1 H! B9 U( X
access-list list_name extended permit udp any any eq 5526, F f$ }/ Y8 a4 Q1 l, q9 }
access-list list_name extended permit tcp any any eq 5222
4 _4 y/ G0 L6 O, x4 ?access-list list_name extended permit tcp any any eq 8100
+ n$ ]0 ?. n( E4 q4 u" B& @access-list list_name extended permit tcp any any eq 8084( E/ L* I5 m' d4 {) j
access-list list_name extended permit tcp any any eq 8085
( z6 }: k4 e3 Q1 gaccess-list list_name extended permit tcp any any eq 5525) X( C- k# O7 H3 g0 v8 ^
access-list list_name extended permit tcp any any eq https
- _' b' Z/ `8 `1 h G0 Oaccess-list list_name extended permit tcp any any eq 5526' h, W* _( l" r s/ u& u
access-list list_name extended permit tcp any any eq 11433- t* v5 h* Y' J2 u
pager lines 24
8 [7 s/ Q' p# G) D! u' F. F2 j) blogging asdm informational1 D4 e0 v+ g- W% t
mtu outside 1500
% e7 Z) K8 R* [0 w0 \0 mmtu inside 1500( a4 _, C4 [( l: z7 O2 H
mtu management 1500) p. G9 r4 @% H( X7 q p
asdm image disk0:/asdm-508.bin: c0 X' V. @( f
no asdm history enable
8 S2 d, {+ A b6 _+ ]/ s& B% |arp timeout 14400
^( p% j, f8 D% z0 A7 N$ |0 cglobal (outside) 1 119.255.37.97 netmask 255.255.255.240- f* A" F6 v* F, k! |1 T9 F
nat (inside) 1 10.1.10.0 255.255.255.01 [ l1 E5 U; e
nat (inside) 1 10.1.20.0 255.255.255.07 Y: y& G9 y9 C
nat (inside) 1 10.1.30.0 255.255.255.03 S/ H4 k5 M9 c: Z
nat (inside) 1 10.1.40.0 255.255.255.0% m% F8 G9 U" I) j# K( M4 _, ]
nat (inside) 1 10.1.50.0 255.255.255.0
& S7 t( v+ X2 v: _: |, M& ^' Wnat (inside) 1 10.1.60.0 255.255.255.0
5 \0 S: ?( k3 O) ?" |nat (inside) 1 10.1.70.0 255.255.255.0
% v( W; ^& Z. L$ U( J) A" T1 Znat (inside) 1 10.1.80.0 255.255.255.0# q6 H& V% [" r+ ?+ C' v
nat (inside) 1 10.1.100.0 255.255.255.0
9 W& q' H2 J; cnat (inside) 1 10.1.120.0 255.255.255.00 k+ y; R0 g% T) V6 p
access-group list_name in interface outside' M5 n7 Z9 c0 S( x7 g; R
route outside 0.0.0.0 0.0.0.0 10.2.14.1 1* v& y% q; t: Z/ M( f6 P/ e
route inside 10.1.0.0 255.255.0.0 10.1.1.2 1, y1 g. _6 W; A1 T9 x& D
timeout xlate 3:00:00
2 ]" V0 F# z% {. p4 A Utimeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02) x [7 B) G8 n8 k3 B: E6 C$ T
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
. X4 `% s1 R8 btimeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:009 z# H6 H0 h. P6 x) m
timeout uauth 0:05:00 absolute
- e9 o4 r7 m% ousername innobac.com password Osy2gHsVboIB7pqY encrypted0 B# H2 {6 I8 v G: L- u( t3 u
http server enable
# s' G( C4 D9 S9 m2 Z! [5 l0 thttp 192.168.1.0 255.255.255.0 management, ^3 p3 k% u8 u# N2 q' T5 Y* ^
no snmp-server location% v) v% h0 g1 b9 v
no snmp-server contact
: U6 I' d3 |$ \3 F# Q. B- Jsnmp-server enable traps snmp authentication linkup linkdown coldstart
8 G1 O( _6 |, J) ]1 @' z" J O+ d+ ecrypto ipsec security-association lifetime seconds 28800
0 @: m/ e# m6 d; h7 Acrypto ipsec security-association lifetime kilobytes 46080002 _- Q a# f7 ~9 P
telnet 0.0.0.0 0.0.0.0 inside
+ o+ _9 l1 v. X8 ]0 p" y# e0 {telnet timeout 52 ?4 V: ^) l0 G
ssh timeout 52 s# h1 _( |1 x' J) B8 ?5 N9 ]6 A9 n
console timeout 0
) J* B+ j- d* B& f! r& F, Bdhcpd address 192.168.1.2-192.168.1.254 management
0 `) T$ x/ n. ?4 t* Udhcpd lease 36001 C. X3 m" H& z
dhcpd ping_timeout 50
- T5 ~. e8 M$ J! {6 y* W& z, r+ Pdhcpd enable management) i9 t- ?6 g' V! N6 @& [" S
!
- }) |, \& C* j; m" A kclass-map inspection_default+ _4 p$ {! L4 [9 }" U+ ~4 g( y) o
match default-inspection-traffic
( I- _, l) C$ ^( W& P, A!1 u, {1 A5 P, Q
!
. W8 C* O' Z- _7 k( gpolicy-map global_policy
( Q+ R5 H6 w: |; ]% t; \" q class inspection_default
: q9 h3 e* H2 J( p3 u4 }: k inspect dns maximum-length 512
* J, \! M( V+ ^& y2 r inspect ftp" I. z1 N* o2 z. K+ n! C
inspect h323 h2259 w1 E7 W" G, l, q7 e
inspect h323 ras
1 h4 _( T, S) @# n5 y% i/ S0 \6 v8 { inspect rsh. \3 |( x% Q6 _6 C' j/ p5 M: ^
inspect rtsp
2 N( C- v$ m9 B! u( V& i% R inspect esmtp
3 S3 q* @: c _! Q. I inspect sqlnet
: v& `4 O/ M* A, r( d. ~ inspect skinny
# q' K4 _0 z$ ^0 E4 k5 d0 Y( I inspect sunrpc- T+ c' n4 [/ U# g" J* v4 F+ ~
inspect xdmcp
+ }" y' a$ R2 n6 P0 I0 o" Y5 }, L8 ^ inspect sip9 P* l- [( l h5 f5 K; Y% _
inspect netbios
3 J# R& w) t) d8 I6 ]7 W' `8 v2 ^ inspect tftp4 Q A8 {# ]" w8 h9 ^
!" W4 H4 W. k& z, \% S; {
service-policy global_policy global v$ T8 } X# Z8 ]. x2 m6 f& l+ m
Cryptochecksum:f2d8d2ac576052587c3b0e391d28d398
, ^% Z9 E; v. C- e: end
. b; e* }" ^% A6 [- H( `ciscoasa#* D9 r3 o; P# t) ~* C" q! s
---------------------------------------------------------------2 @" m6 u9 M) c) U5 |) F. j
近期我司更换外网(换了另一家的光纤),机房有思科防火墙当做路由器来用了,以上就是目前配置了。% t9 L( P- z- X' f3 @* N% i
! V! R6 v; H D( t- H0 T
以上配置是现有配置,如果要换外网ip的话具体该怎么做呢?请大侠们指点小弟,越详细越好,小弟是个大白菜,很白很白!再次雪地脱裤跪地了!救命啊~~~~ |
|