1.网络拓扑如下图9 [7 W% t# A# f
screen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/001.jpg')}}" />3 h6 M! x! _% \7 o& i$ I" v8 x
2.CISCO pix515e使用PDM3.0配置如下
8 L- A& [0 K. ^8 Fscreen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/002.jpg')}}" /> `. d( y( C( H: m/ F
screen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/003.jpg')}}" />
, S' q2 z( F; Wscreen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/004.jpg')}}" />+ Z9 t$ _; T& g+ r2 q
screen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/005.jpg')}}" />
8 a2 x- F! T1 P* ~6 C# Zscreen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/006.jpg')}}" />
: r. `# N$ d- {7 a* j* Y( S; `screen.width*0.6) {this.width=screen.width*0.6;this.alt='';this.onmouseover=this.style.cursor='pointer';this.onclick=function(){window.open('http://www.eask.tk/nat/007.jpg')}}" /># S7 c& A" {$ s
% a' ^* Y; p7 c8 g2 p9 h
3.拟实现的网络功能:公网计算机通过光纤、ADSL、WIFI、mobile等方式接入因特网,再通过windows自带的虚拟专用网拨号连接或者CISCO的VPN cilent拨入PIX515e内部的VpnServer,以实现接入VpnServer所在的局域网,共享局域网内的资源,VPN Server在内网测试通过。: p0 f' H4 r# e2 O
# `" f$ ~) o- H: _6 R
4.遇到的问题:公网计算机无法通过pix515e的公网地址向内穿越NAT拨入VPNserver。能否在pix515e上建立一条Vpn Tunnel以实现第3条的网络功能,该如何建立。
8 v# f! w9 F5 p/ e! _. I9 D9 `# j1 a I- i# b1 k$ h
5.已失败的方法' b/ ?1 Z( b# Q9 e \ U6 a9 j
. N3 C% H' Y, C w$ CA:端口映射,该思科设备通过NAT功能将内网IP转换为公网IP,不是路由器,无法做端口映射。
, e7 x. O5 X4 ?- \3 g. T4 l3 |" g: Q% \2 P
B:在PDM3.0上尝试对PIX515e进行VPN的设置,未能凑效。
3 K/ t/ c# e0 l% S
$ F" C3 T% J" p0 m$ E2 sC:逆向NAT失败,PDM3.0不允许。! C# ?; e7 x2 }2 @0 o
0 p$ c9 z6 ]% x1 P, [& W- n& o; m设备目前的配置列表, K0 h4 K& T7 H2 f7 V8 O8 ~
' z- t# p5 G# Z% s3 G
Building configuration...6 u; O% h- b# s; q( A
: Saved
/ u% L7 b6 C! R( i! \( y:4 i* s- d# L B* @
PIX Version 6.3(3)
- ?% y, O+ M$ V! U( L! A6 linterface ethernet0 auto# @- v* E5 n" P! }) C c
interface ethernet1 auto& v! z+ L' m7 p3 a8 F+ C9 Y" M
nameif ethernet0 outside security0* x$ p9 b- S B
nameif ethernet1 inside security100
9 p6 J/ c. v/ w4 w4 [enable password /NNcO2U/e4a3IAX3 encrypted* w/ f* H0 C3 I2 s& E
passwd 2KFQnbNIdI.2KYOU encrypted9 `, q4 Y: B2 T' j
hostname huawei- o) W* O1 Y v% e: t
domain-name huawei.com
2 M* G3 t4 m# ^0 P, A5 xfixup protocol dns maximum-length 512
" o- b+ q$ V5 }" }- |, gfixup protocol ftp 212 ], y- v8 O7 h
fixup protocol h323 h225 1720
2 ~& |. J* g6 l; j4 mfixup protocol h323 ras 1718-1719
( ^. Y z' |& ifixup protocol http 80! y T' i7 H+ Z. O6 ~% w
fixup protocol rsh 514' I( s; K$ k- L
fixup protocol rtsp 554
3 N3 \3 n9 l9 Y; H5 afixup protocol sip 50601 w# D5 p% H# \" G P1 F1 y: k
fixup protocol sip udp 5060
6 n1 b/ h. e! w6 u- u* ufixup protocol skinny 2000
. i" l4 [' E( efixup protocol smtp 25
: [: \) N1 Y, k( h1 }; O; x' C1 F$ Pfixup protocol sqlnet 1521
8 Y0 g- x9 R' {' W; L/ x4 p+ Ofixup protocol tftp 69, h* p/ C: n" g, _, L* P2 [2 z
names: K ^' p1 t3 ^8 n" i3 Z; _
access-list outside_inbound_nat0_acl permit ip interface outside 192.168.0.0 255.255.255.0 ) ?+ S0 v5 C% i5 B& w ] P
pager lines 24
1 g- k- y! W4 D; z0 a( omtu outside 1500# A( m$ N3 s$ k
mtu inside 1500
4 R2 t( \( H0 o) T- Q% o4 D! Fip address outside 221.XXX.138.250 255.255.255.252
% \8 p5 a/ ~- U# `3 U8 qip address inside 192.168.0.254 255.255.255.0( D+ g8 \" G* b1 ?
ip audit info action alarm o S$ L- ^$ K8 N" Y/ t/ ]: I* u
ip audit attack action alarm7 V; S5 S; r' X$ T. h0 ?% |0 A
pdm location 192.168.0.3 255.255.255.255 inside
* T( r# [1 V5 s7 P+ Npdm location 192.168.0.24 255.255.255.255 inside, x7 e6 @4 A. I+ q
pdm location 192.168.0.1 255.255.255.255 inside8 P( I) z3 N/ O; A2 R# ~
pdm location 192.168.0.2 255.255.255.255 inside$ H& {( d% Y. C1 }) r- R
pdm location 192.168.0.12 255.255.255.255 inside
3 A1 g1 p$ S+ ?/ t8 Q& ?0 Spdm location 192.168.0.10 255.255.255.255 inside7 Q9 G- v! u- j3 [! N; j, A# ~
pdm location 192.168.0.16 255.255.255.255 inside2 f# b; d. L% q, [) p& N" F( C
pdm location 192.168.0.19 255.255.255.255 inside
" Q) c/ H- N3 B, u- U) r& p: zpdm location 192.168.0.20 255.255.255.255 inside. \$ r- E* z0 x
pdm location 192.168.0.22 255.255.255.255 inside
) T6 L# g; |8 m8 ~pdm location 192.168.0.23 255.255.255.255 inside2 \% o( |$ n) B- z+ K
pdm location 192.168.0.34 255.255.255.255 inside
3 n7 ^6 u' |9 ?$ e7 H4 L( d7 updm location 192.168.0.38 255.255.255.255 inside3 j' T& Z0 `3 @8 R
pdm location 192.168.0.40 255.255.255.255 inside
* U% E$ A& S6 \1 mpdm location 192.168.0.58 255.255.255.255 inside
# v1 Z8 [, g$ H3 ~4 lpdm location 192.168.0.17 255.255.255.255 inside
! e1 s6 u5 S$ Wpdm location 192.168.0.39 255.255.255.255 inside
( s# J& a! k, N1 B9 v; H1 H& ~pdm location 192.168.0.41 255.255.255.255 inside
. {6 ^/ z# U( G0 Bpdm location 192.168.0.13 255.255.255.255 inside' V0 w; j+ W+ J
pdm location 192.168.0.42 255.255.255.255 inside
1 e3 n& B6 |; w( Updm location 192.168.0.45 255.255.255.255 inside0 `, s3 ~6 f, W- r* E2 B
pdm location 192.168.0.46 255.255.255.255 inside
; q- |! ~! x- R* dpdm location 192.168.0.47 255.255.255.255 inside0 P! C+ N' |# n4 y e1 u0 L3 T
pdm location 192.168.0.50 255.255.255.255 inside
( m! h. {- j6 `) [) [4 Kpdm location 192.168.0.25 255.255.255.255 inside7 ? T! q, T; J
pdm location 192.168.0.4 255.255.255.255 inside
9 h8 H9 {- b! U% S4 ]: ^& b* U: epdm location 192.168.0.6 255.255.255.255 inside! U R: ^8 l0 Y2 d
pdm location 192.168.0.35 255.255.255.255 inside
4 [, P+ [. N, t! V; a+ gpdm location 192.168.0.21 255.255.255.255 inside
* q2 e+ i: v$ ^% Q. E. }* _+ y- S7 Apdm location 192.168.0.200 255.255.255.255 inside0 U- V% y# S9 q9 y6 @
pdm location 192.168.0.48 255.255.255.255 inside
) ^/ ^8 t; o o/ b7 } [pdm location 192.168.0.60 255.255.255.255 inside7 h, ]: O5 A. q" v) |
pdm location 192.168.0.51 255.255.255.255 inside
/ z+ p' O* M) V: A8 m0 bpdm location 192.168.0.32 255.255.255.255 inside3 l2 ]2 b( n8 v% c2 T3 z9 Z
pdm location 192.168.0.18 255.255.255.255 inside9 ]$ V" U0 W6 N, ]5 s( M$ i! Y
pdm location 192.168.0.7 255.255.255.255 inside8 u# d A: e* r
pdm location 192.168.0.201 255.255.255.255 inside
1 S3 ]4 }) q5 T& ?pdm location 192.168.0.36 255.255.255.255 inside, k9 l! L+ z" h
pdm location 192.168.0.100 255.255.255.255 inside6 H7 d9 p7 B9 z) O
pdm location 192.168.0.5 255.255.255.255 inside
4 g8 K0 R% W/ s3 l) x! \, c+ Updm location 192.168.0.202 255.255.255.255 inside
" G: F( @8 [+ I+ U/ Ipdm location 192.168.0.26 255.255.255.255 inside
; O* x/ Y q2 W! h" D/ ]$ npdm location 192.168.0.203 255.255.255.255 inside/ h5 t) G. M3 [: }
pdm location 192.168.0.14 255.255.255.255 inside
2 G' c+ ~1 E( @/ J/ @# m- q; P8 cpdm location 192.168.0.204 255.255.255.255 inside
. r5 J/ w! c2 f/ n$ _9 d' c$ E3 Bpdm location 192.168.0.251 255.255.255.255 inside' l% A$ O0 m( c: }) A+ d: z
pdm location 192.168.0.205 255.255.255.255 inside
1 l# n" g) t: {6 a! Epdm location 192.168.0.206 255.255.255.255 inside4 [3 `- r# C1 S/ u: D
pdm location 192.168.0.207 255.255.255.255 inside7 x( ^2 F0 t/ C$ j9 J' `
pdm location 192.168.0.208 255.255.255.255 inside# m8 P+ ]! p. D& f# {1 G
pdm location 192.168.0.209 255.255.255.255 inside
! G6 I! K6 c4 t( lpdm location 192.168.0.108 255.255.255.255 inside
8 X. `# k) d0 _5 ^- n+ fpdm location 192.168.0.31 255.255.255.255 inside4 {8 B Y9 S7 H! L& v8 P
pdm location 192.168.0.30 255.255.255.255 inside
: y9 H9 J2 T( m# y7 _& J: Cpdm location 192.168.0.210 255.255.255.255 inside- w/ b6 o2 h l& I
pdm location 192.168.0.8 255.255.255.255 inside
9 t& K( m- o, R; Ppdm location 192.168.0.11 255.255.255.255 inside
; Z. j3 s$ s" K! v2 kpdm location 192.168.0.29 255.255.255.255 inside; _" P# m& O+ E% N
pdm location 192.168.0.109 255.255.255.255 inside" D, `3 [4 f, Q! [( J5 z' |
pdm location 192.168.0.111 255.255.255.255 inside4 c( v) ]( K/ U; d- f% h
pdm location 192.168.0.116 255.255.255.255 inside M* y% u9 @9 x2 |" C3 `! V, p
pdm location 192.168.0.113 255.255.255.255 inside* B( x, r& r& { M: g' Q
pdm location 192.168.0.107 255.255.255.255 inside
. Q) }: {- c: ypdm location 192.168.0.240 255.255.255.255 inside
, u; Z: n3 Y/ a B4 zpdm location 192.168.0.241 255.255.255.255 inside
& q2 g2 \ i9 a" wpdm location 192.168.0.233 255.255.255.255 inside4 }! _; Q; p2 L2 Y9 p; Q$ t
pdm location 192.168.0.250 255.255.255.255 inside' a5 ~& I5 g7 g
pdm location 192.168.0.252 255.255.255.255 inside2 s5 k, q7 m, J0 g0 Z
pdm location 192.168.0.253 255.255.255.255 inside/ e0 _. M. T% @ ?$ t ]) ^
pdm location 192.168.0.44 255.255.255.255 inside
t$ D w6 [3 F9 U8 e! bpdm location 192.168.0.242 255.255.255.255 inside
' e: R5 Z% t, e" O0 O* t7 [pdm location 192.168.0.239 255.255.255.255 inside
7 ~6 b+ J# q9 i8 q4 cpdm location 192.168.0.27 255.255.255.255 inside
/ @# C0 a; G! vpdm location 192.168.0.249 255.255.255.255 inside
' e: e& e S; h+ T3 I* ~5 u# l5 H/ npdm location 192.168.0.61 255.255.255.255 inside
5 a4 e- l. u6 bpdm location 192.168.0.62 255.255.255.255 inside$ ^5 m8 k$ z; z) ?4 f
pdm location 192.168.0.63 255.255.255.255 inside4 y8 y6 o6 g. P( [: m
pdm location 192.168.0.64 255.255.255.255 inside
- I. _, h' ^) D6 ]3 L; ?pdm location 192.168.0.68 255.255.255.255 inside
; R* x( a$ R$ r6 Spdm location 192.168.0.211 255.255.255.255 inside
6 \ L4 O( C* w" Wpdm location 192.168.0.70 255.255.255.255 inside% `, s% b2 K; H
pdm location 192.168.0.65 255.255.255.255 inside8 D* n% E" l. n( y$ }
pdm location 192.168.0.121 255.255.255.255 inside4 A% D; u; u/ A( P6 }( q( J; l
pdm location 192.168.0.247 255.255.255.255 inside
6 K0 _5 ~; w7 D) f4 N; {pdm location 192.168.0.37 255.255.255.255 inside" a8 w* d& m2 g, ^$ n8 f4 Z
pdm location 192.168.0.73 255.255.255.255 inside
* i* R8 i' Z) B- @pdm location 192.168.0.112 255.255.255.255 inside9 s; z- n4 J& O8 U9 K7 h9 |. m
pdm location 192.168.0.57 255.255.255.255 inside. P* E: h2 C7 z2 J) A: y
pdm location 192.168.0.99 255.255.255.255 inside R7 o- p5 k( c- d) z6 s+ {
pdm location 192.168.0.124 255.255.255.255 inside
8 G# ?9 m5 S8 Z7 a" g, Hpdm location 192.168.0.52 255.255.255.255 inside) T6 |6 K, Z0 d1 m" n8 i
pdm location 192.168.0.118 255.255.255.255 inside& ?( i m+ O& g( d. S( v' \! [
pdm location 192.168.0.122 255.255.255.255 inside; W+ [* {1 ]1 _0 ?: O- z+ q; Z* ]
pdm location 192.168.0.49 255.255.255.255 inside
. \8 q' }! k, C( r( u* b# Y/ Bpdm location 192.168.0.55 255.255.255.255 inside
4 ^! ^' Y0 o+ v+ Bpdm location 192.168.0.43 255.255.255.255 inside
2 y8 p/ R( o/ V/ v# Wpdm location 192.168.0.103 255.255.255.255 inside8 w+ g7 V" M1 O7 B5 \* ^$ `. z& t/ C+ E- e
pdm location 192.168.0.54 255.255.255.255 inside3 n9 Q4 o* h0 v7 ]- h; N9 D
pdm location 192.168.0.243 255.255.255.255 inside
% d- h1 W9 h K3 s9 ?+ o+ ?2 @pdm location 192.168.0.244 255.255.255.255 inside
% V2 u o! f7 Y, I! `3 Q# Opdm location 192.168.0.230 255.255.255.255 inside
' h1 _3 Q; c6 X& Q; zpdm location 192.168.0.135 255.255.255.255 inside' g: p6 R5 p; d! ?
pdm location 192.168.0.115 255.255.255.255 inside. H9 S. E4 M9 W; ]0 W
pdm location 192.168.0.245 255.255.255.255 inside
7 x# K$ m: n% o2 G$ Tpdm location 192.168.0.238 255.255.255.255 inside2 @7 p8 K9 |$ O* w: x/ G* y
pdm location 192.168.0.237 255.255.255.255 inside+ b! P* O4 ^, I9 i
pdm location 192.168.0.231 255.255.255.255 inside
7 `- w5 P" O5 u6 |+ @% _pdm location 192.168.0.235 255.255.255.255 inside
' O) G5 ]5 F4 |+ i/ bpdm location 192.168.0.236 255.255.255.255 inside" ?; s5 X& I) C2 r7 g
pdm location 192.168.0.190 255.255.255.255 inside) g) m. `7 G, Y- @
pdm location 192.168.0.181 255.255.255.255 inside( d7 b! [$ v5 f9 C, M" j' K) b
pdm location 192.168.0.9 255.255.255.255 inside
5 N$ R2 \, F" u" [2 opdm location 192.168.0.246 255.255.255.255 inside7 u8 e3 [8 x5 Y, m( w/ ^' R: ?
pdm location 192.168.0.59 255.255.255.255 inside
8 Y& s4 A8 K0 q( `* Gpdm location 192.168.0.191 255.255.255.255 inside, J" M7 \) n3 p; x9 N0 A
pdm location 192.168.0.117 255.255.255.255 inside1 c- Q; N" Q0 v$ j
pdm location 192.168.0.171 255.255.255.255 inside
) k3 q( a! ~' r- W qpdm location 192.168.0.53 255.255.255.255 inside, @% N8 Y& O% b$ e
pdm location 192.168.0.130 255.255.255.255 inside! [5 ^" s4 Q% _- [( c1 R
pdm location 192.168.0.91 255.255.255.255 inside( b/ O% M3 r& o0 {! n+ x
pdm location 192.168.0.140 255.255.255.255 inside2 b7 k) P7 Q1 R+ O, s. @+ c
pdm location 192.168.0.220 255.255.255.255 inside+ f; j/ H5 N3 o- c
pdm location 192.168.0.119 255.255.255.255 inside; ]9 {3 D* s) G; P
pdm location 192.168.0.223 255.255.255.255 inside' G0 P: o2 M& X: f
pdm location 192.168.0.106 255.255.255.255 inside
, T/ p% K2 v, `1 q7 b8 ipdm location 192.168.0.123 255.255.255.255 inside
) q. O+ F( v- d* f$ ~0 }9 R: Ppdm location 192.168.0.67 255.255.255.255 inside; m1 \; ^& _* t# K8 v
pdm location 192.168.0.219 255.255.255.255 inside
/ ?% L I: U- u. x: ^7 ~8 W4 c: i; ^pdm location 192.168.0.56 255.255.255.255 inside: t! f0 X5 Q1 ?/ S+ O& a: b! Z
pdm location 192.168.0.66 255.255.255.255 inside
, N6 _0 B' d7 cpdm location 192.168.0.76 255.255.255.255 inside3 d3 e" [4 ~. Q9 i6 U6 ]" w# m
pdm location 192.168.0.102 255.255.255.255 inside
6 h) l. z: J9 l. apdm location 192.168.0.170 255.255.255.255 inside4 E) w3 ~1 R5 M: I+ K
pdm location 192.168.0.172 255.255.255.255 inside, e; v* z- V) c
pdm location 192.168.0.173 255.255.255.255 inside
0 N$ e. W" z& y2 _pdm location 192.168.0.174 255.255.255.255 inside
' ?: E! B! t) I! X8 y$ j- B. K. Ypdm location 192.168.0.175 255.255.255.255 inside
0 G S4 u7 D/ M9 z7 W0 u8 Jpdm location 192.168.0.160 255.255.255.255 inside6 A$ r$ L1 E( E& b8 e
pdm location 192.168.0.138 255.255.255.255 inside* o# [1 j- Q+ d5 d
pdm location 192.168.0.78 255.255.255.255 inside* t( j: G0 G& a) F) S! H2 l5 B
pdm location 192.168.0.69 255.255.255.255 inside) C/ l+ o# O# t7 G/ K! d. E5 ^
pdm location 192.168.0.221 255.255.255.255 inside
; ?: M! Q- y- A6 X' A9 Y" [' Dpdm location 192.168.0.110 255.255.255.255 inside) _' d4 M4 U: }( o* u$ [
pdm location 192.168.0.232 255.255.255.255 inside; p+ E$ C1 F: z# O9 N) q B' U
pdm location 192.168.0.80 255.255.255.255 inside; p2 K0 N" r8 ]1 f
pdm location 192.168.0.81 255.255.255.255 inside6 q: i; _- b4 p" A% w0 d/ [
pdm location 192.168.0.82 255.255.255.255 inside
( M+ T7 N- @2 v. h; wpdm location 192.168.0.83 255.255.255.255 inside
$ K" I4 W( p) z! @$ F/ W6 J8 m hpdm location 192.168.0.84 255.255.255.255 inside
0 P5 q5 q# b, H0 fpdm location 192.168.0.85 255.255.255.255 inside/ [3 N& f/ B1 ?' z) W) i
pdm location 192.168.0.86 255.255.255.255 inside. i& T. V) b" J( w2 C/ }. _
pdm location 192.168.0.87 255.255.255.255 inside. P8 c% h6 C8 _9 N7 b
pdm location 192.168.0.88 255.255.255.255 inside0 a9 w+ d( k& y
pdm location 192.168.0.89 255.255.255.255 inside
: Q2 B; H5 C. ]2 ]0 R* @! w: [7 Rpdm location 192.168.0.90 255.255.255.255 inside
- r; \$ ^; P1 ?5 k* H `. s: hpdm location 192.168.0.28 255.255.255.255 inside
" O1 O& K0 ?# S1 H: `6 Ypdm location 192.168.0.234 255.255.255.255 inside: \ W1 u, ^! u8 a1 d
pdm location 192.168.0.222 255.255.255.255 inside
5 t- H2 Q* ? o6 c' W2 R1 Fpdm location 192.168.0.150 255.255.255.255 inside2 X& v& \1 N, r: M/ i( @
pdm location 192.168.0.151 255.255.255.255 inside/ X' Y# N, m2 F' j/ M8 }
pdm location 192.168.0.152 255.255.255.255 inside
# j7 v( B2 `# e& A$ \pdm location 192.168.0.77 255.255.255.255 inside) ]' g8 v' N. q& O8 v2 T
pdm location 192.168.0.72 255.255.255.255 inside
$ M6 q8 a4 l6 i2 npdm location 192.168.0.225 255.255.255.255 inside, J* M( i& ^8 {
pdm location 192.168.0.161 255.255.255.255 inside
# w3 ^/ p# t9 d8 J+ H+ R q1 S3 K7 N. Npdm location 192.168.0.92 255.255.255.255 inside
7 z( y2 l } E Gpdm location 192.168.0.192 255.255.255.255 inside
. f' o/ @" P T5 _/ Apdm location 192.168.0.193 255.255.255.255 inside
2 ] n: w( @; t. @; D2 Kpdm location 192.168.0.15 255.255.255.255 inside" b4 G' ^, W6 E6 Z
pdm location 192.168.0.33 255.255.255.255 inside
5 z6 w. \5 I4 R$ W& d3 Q, ipdm location 192.168.0.79 255.255.255.255 inside6 {( k" M! Q# r. \+ }3 a* _
pdm location 192.168.0.93 255.255.255.255 inside, `4 t3 \# Z% T, w4 K$ k
pdm location 192.168.0.94 255.255.255.255 inside
2 \( J4 Y0 p: w: opdm location 192.168.0.95 255.255.255.255 inside* Y1 u6 O7 I& K% r8 R/ r6 M
pdm location 192.168.0.96 255.255.255.255 inside
, L+ Z: g# Q) }( Gpdm location 192.168.0.97 255.255.255.255 inside
# [( F9 u8 J$ T) u1 v3 }% E/ X( A0 w) ]pdm location 192.168.0.98 255.255.255.255 inside+ v! v/ L5 f |" Q- Y) w
pdm location 192.168.0.101 255.255.255.255 inside
) u' I$ D \) ~" dpdm location 192.168.0.104 255.255.255.255 inside
) ^ v/ s4 r' U: A( |pdm location 221.XXX.138.250 255.255.255.255 inside9 y- s% W! ]' ~8 K7 S
pdm location 192.168.0.71 255.255.255.255 inside! h) _% h) ]9 z# r# K3 V$ t
pdm location 192.168.0.185 255.255.255.255 inside' B! j* s: M2 @
pdm location 192.168.0.75 255.255.255.255 inside9 _- F& V$ r# ?% [1 N8 j* M
pdm location 192.168.0.120 255.255.255.255 inside
5 U0 e. f' n, \( R {pdm location 192.168.0.212 255.255.255.255 inside- Z9 e e; C' @, Z
pdm location 192.168.0.213 255.255.255.255 inside
/ w1 ]9 m) \5 ^% I2 H4 j( l' }pdm location 192.168.0.214 255.255.255.255 inside$ j% _2 y! Y$ S+ K( [( c
pdm location 192.168.0.215 255.255.255.255 inside6 d, x9 O" k8 M# f3 I) h- J, t
pdm location 192.168.0.128 255.255.255.192 outside7 G0 ?* b% k* R# `+ i; T
pdm history enable: n" K' G/ I( `( A
arp timeout 14400
5 b' a5 W; R. U. `global (outside) 10 interface$ ?8 t8 [% h4 I$ u, O
nat (outside) 0 access-list outside_inbound_nat0_acl outside2 f6 I; j5 Q" X7 D4 K
nat (inside) 10 192.168.0.1 255.255.255.255 0 0, Z$ v( Y' W# N
nat (inside) 10 192.168.0.3 255.255.255.255 0 0
7 P. x" J. v' Pnat (inside) 10 192.168.0.4 255.255.255.255 0 07 g+ r' l8 |/ U% ^: M
nat (inside) 10 192.168.0.5 255.255.255.255 0 01 \$ X3 N+ g- `2 Z3 c
nat (inside) 10 192.168.0.10 255.255.255.255 0 0. m4 P8 z" ~: W% n* h; E' P1 ]% t, x7 a
nat (inside) 10 192.168.0.11 255.255.255.255 0 00 q, g' E4 H/ g% K
nat (inside) 10 192.168.0.12 255.255.255.255 0 0
3 [' e7 X4 N2 F, _4 B+ G, Bnat (inside) 10 192.168.0.13 255.255.255.255 0 09 b) g$ F" e8 n
nat (inside) 10 192.168.0.14 255.255.255.255 0 0
. K' k6 @4 `6 a% y( s/ Jnat (inside) 10 192.168.0.15 255.255.255.255 0 0
0 T" w( F9 [2 Rnat (inside) 10 192.168.0.16 255.255.255.255 0 09 Y, C2 W! h2 ?0 V% L) ?4 q6 A
nat (inside) 10 192.168.0.17 255.255.255.255 0 0( e2 w& J! ^1 O
nat (inside) 10 192.168.0.21 255.255.255.255 0 0" V. a( D' X0 G
nat (inside) 10 192.168.0.22 255.255.255.255 0 0* K# {4 K4 D8 C' y/ X) t
nat (inside) 10 192.168.0.23 255.255.255.255 0 0
$ S8 D' n. L/ Tnat (inside) 10 192.168.0.24 255.255.255.255 0 00 l6 @$ Y$ f+ |1 V
nat (inside) 10 192.168.0.25 255.255.255.255 0 0
+ G, G5 x9 L+ X% R$ bnat (inside) 10 192.168.0.26 255.255.255.255 0 0
8 H( }: I% D2 z1 A. n& dnat (inside) 10 192.168.0.27 255.255.255.255 0 0
) `; O2 f* |' j7 c% i( Knat (inside) 10 192.168.0.29 255.255.255.255 0 0, f9 Y4 G& S8 ?% c3 y1 u
nat (inside) 10 192.168.0.31 255.255.255.255 0 0
$ M8 X% U9 p$ I5 _nat (inside) 10 192.168.0.32 255.255.255.255 0 0- K7 b' Z, Q, F* K
nat (inside) 10 192.168.0.33 255.255.255.255 0 0
* _0 E5 {9 F8 P* E* xnat (inside) 10 192.168.0.34 255.255.255.255 0 01 s& n2 G4 u6 a- [$ c) Y" _# ]
nat (inside) 10 192.168.0.37 255.255.255.255 0 03 I+ r/ B$ W' Q: O0 ^
nat (inside) 10 192.168.0.39 255.255.255.255 0 0
8 N) ?7 G# s" Z* R; V! k4 o& s) o p3 hnat (inside) 10 192.168.0.40 255.255.255.255 0 0
. J' Q* A: Z# c0 P* v; A& xnat (inside) 10 192.168.0.44 255.255.255.255 0 0
; N) ]& L2 w+ g9 u3 l3 ^, M$ knat (inside) 10 192.168.0.45 255.255.255.255 0 0
2 X$ u! e. t" m0 X- m1 y$ }: i" x' [nat (inside) 10 192.168.0.47 255.255.255.255 0 0+ i6 o9 T% E9 u0 ?
nat (inside) 10 192.168.0.48 255.255.255.255 0 0
3 [3 a7 V6 G" H ]3 Dnat (inside) 10 192.168.0.49 255.255.255.255 0 0: Q! k: _8 Z/ b3 x1 @2 a3 E
nat (inside) 10 192.168.0.50 255.255.255.255 0 0
5 Z6 J0 ^% U1 \: onat (inside) 10 192.168.0.51 255.255.255.255 0 0
8 Y1 a$ y5 X& R: M( j* [nat (inside) 10 192.168.0.52 255.255.255.255 0 0
P6 T1 U! s9 O: o: }8 Nnat (inside) 10 192.168.0.53 255.255.255.255 0 0
9 L) K4 u& r/ I, f$ I! b- Xnat (inside) 10 192.168.0.54 255.255.255.255 0 06 t3 L9 w! r4 ]" I' }, ^
nat (inside) 10 192.168.0.55 255.255.255.255 0 0
, V& t+ B8 H4 |8 l. E8 x3 S5 xnat (inside) 10 192.168.0.56 255.255.255.255 0 0 l8 ^) |" k, s
nat (inside) 10 192.168.0.57 255.255.255.255 0 0
; c% K- {. U2 C6 a4 A, T4 \nat (inside) 10 192.168.0.58 255.255.255.255 0 0
/ Q# ?3 D; S( z! Knat (inside) 10 192.168.0.59 255.255.255.255 0 0
2 y9 V; z0 n% O9 cnat (inside) 10 192.168.0.62 255.255.255.255 0 0
) `. Q+ u! Q4 d$ lnat (inside) 10 192.168.0.63 255.255.255.255 0 0
: n: N [ i4 h7 K' G! D5 w% |# tnat (inside) 10 192.168.0.64 255.255.255.255 0 0
) d& j, _8 Y0 F5 \8 Mnat (inside) 10 192.168.0.65 255.255.255.255 0 0
- L; B4 m3 D0 x; M) b5 pnat (inside) 10 192.168.0.66 255.255.255.255 0 0% g# R0 v+ N3 X* {: o2 f
nat (inside) 10 192.168.0.67 255.255.255.255 0 00 Q( `# z: t$ v7 g$ j q8 j9 ?1 [
nat (inside) 10 192.168.0.68 255.255.255.255 0 0; A5 r7 @- K7 A; P8 a+ Y& H7 l- C
nat (inside) 10 192.168.0.69 255.255.255.255 0 0! F; m2 ~4 f5 z. {, k6 u3 p
nat (inside) 10 192.168.0.71 255.255.255.255 0 0
7 r5 D: i( h4 o) X% s% z1 mnat (inside) 10 192.168.0.73 255.255.255.255 0 0
0 L! e& \/ \; E5 Nnat (inside) 10 192.168.0.76 255.255.255.255 0 0
# y5 P, h2 a) Y( Cnat (inside) 10 192.168.0.79 255.255.255.255 0 0
- J: e8 _# Q3 d# B) z4 X: hnat (inside) 10 192.168.0.80 255.255.255.255 0 0( y3 U# x5 ^8 N8 N, n
nat (inside) 10 192.168.0.81 255.255.255.255 0 0
- m( X8 `' }7 H' Z' ]+ `nat (inside) 10 192.168.0.82 255.255.255.255 0 08 |! Y1 Q7 e) R
nat (inside) 10 192.168.0.83 255.255.255.255 0 0
) K5 L; o% b; R% p2 t$ I" Xnat (inside) 10 192.168.0.85 255.255.255.255 0 0- x& V, `4 H/ G7 \. C4 P# }8 b
nat (inside) 10 192.168.0.86 255.255.255.255 0 0# l3 w: z2 @1 d& n
nat (inside) 10 192.168.0.87 255.255.255.255 0 03 Z9 I0 k6 x6 S+ y, y. y
nat (inside) 10 192.168.0.89 255.255.255.255 0 0 A& }' F; Z$ {9 C) P2 M
nat (inside) 10 192.168.0.90 255.255.255.255 0 0, O4 D, P, u p
nat (inside) 10 192.168.0.92 255.255.255.255 0 0
1 F! r+ d6 ]% h5 Nnat (inside) 10 192.168.0.93 255.255.255.255 0 0
) _ B: K# D( p. L, hnat (inside) 10 192.168.0.94 255.255.255.255 0 0- s' a! d1 W9 l
nat (inside) 10 192.168.0.95 255.255.255.255 0 0
- w9 }8 E% k. X2 A' Onat (inside) 10 192.168.0.96 255.255.255.255 0 0
9 o' J) b# S5 |) Bnat (inside) 10 192.168.0.97 255.255.255.255 0 0. U: O) B6 u" C% ?5 o7 I' }
nat (inside) 10 192.168.0.99 255.255.255.255 0 0: j' w& [( s2 m( X9 x
nat (inside) 10 192.168.0.101 255.255.255.255 0 0
8 I; x& F" Z- }/ t, dnat (inside) 10 192.168.0.102 255.255.255.255 0 0& Y4 F+ Q. Z; L/ T. w* m
nat (inside) 10 192.168.0.103 255.255.255.255 0 0
I0 X$ q! y. x& rnat (inside) 10 192.168.0.104 255.255.255.255 0 0
. R, q5 b Y- D8 ]nat (inside) 10 192.168.0.106 255.255.255.255 0 0
1 R, h/ [; q7 ^8 _/ b7 Mnat (inside) 10 192.168.0.107 255.255.255.255 0 0
( P+ V/ C# Z2 n4 a, Knat (inside) 10 192.168.0.108 255.255.255.255 0 0
3 i: ]+ X" K" o$ w9 fnat (inside) 10 192.168.0.118 255.255.255.255 0 0
5 g8 a* m& P9 z: g5 \nat (inside) 10 192.168.0.119 255.255.255.255 0 0
8 J- Q, _# P& z# K4 p# ]7 [nat (inside) 10 192.168.0.120 255.255.255.255 0 0
6 D \9 W& j. z ~" ]" _# |nat (inside) 10 192.168.0.121 255.255.255.255 0 0
1 Z% B H5 X; ~nat (inside) 10 192.168.0.200 255.255.255.255 0 0
+ h2 N* A4 ?% P" ]nat (inside) 10 192.168.0.201 255.255.255.255 0 0$ g+ M! S' c3 z4 U' Q$ r8 q
nat (inside) 10 192.168.0.202 255.255.255.255 0 0
& z( O7 f/ X3 dnat (inside) 10 192.168.0.203 255.255.255.255 0 0
" y# L* I5 k+ L: _, S) \$ {$ V$ p3 ]" wnat (inside) 10 192.168.0.204 255.255.255.255 0 0
* d, o7 k A' b) f1 e) L: c( tnat (inside) 10 192.168.0.205 255.255.255.255 0 0
! _2 c( _% h3 ?) U; c) [" F, cnat (inside) 10 192.168.0.206 255.255.255.255 0 0
. i1 r+ ~% d* Tnat (inside) 10 192.168.0.207 255.255.255.255 0 0% t6 M6 {- N8 y' v8 O! ?! N* v
nat (inside) 10 192.168.0.208 255.255.255.255 0 07 N& C5 g K; z1 W5 `: [* U
nat (inside) 10 192.168.0.209 255.255.255.255 0 0! |# [- { X; x
nat (inside) 10 192.168.0.210 255.255.255.255 0 0
8 E; c2 `1 E# M& A' Jnat (inside) 10 192.168.0.211 255.255.255.255 0 02 L X9 N2 I; O& g: x$ G3 P7 r- Z
nat (inside) 10 192.168.0.212 255.255.255.255 0 0# d- W$ i' p8 C. d. \3 T3 r1 q1 @6 Y! }
nat (inside) 10 192.168.0.213 255.255.255.255 0 0! `, Z( x6 {& e3 {! ^
nat (inside) 10 192.168.0.214 255.255.255.255 0 0
( f4 P4 ]+ `3 W2 Ynat (inside) 10 192.168.0.215 255.255.255.255 0 0
3 R: E* t! y- H0 \$ a/ E% fnat (inside) 0 192.168.0.0 255.255.255.0 0 0% D# ?. W) i) A" F# d
nat (inside) 10 0.0.0.0 0.0.0.0 0 0
9 D, k! j& C4 |* Uroute outside 0.0.0.0 0.0.0.0 221.XXX.138.249 1 @- J/ T0 \) }5 A8 |
timeout xlate 3:00:009 J; d, v( U% r8 [0 S* R A
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00& A) [$ {, l, s9 C, J
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
, _7 O5 o% r5 \0 ftimeout uauth 0:05:00 absolute/ q0 }4 t4 ~( v; C! g) ^' |" x/ c n+ i
aaa-server TACACS+ protocol tacacs+ + q& e3 J+ b7 d: m
aaa-server RADIUS protocol radius : x) v/ y/ s$ f+ k6 X5 J# Q
aaa-server LOCAL protocol local 9 Q" X$ B6 Z2 d3 c4 W0 u% V
http server enable) o$ r% p; L$ F4 N7 ~" m2 I3 I) d
http 192.168.0.0 255.255.255.0 inside
3 N" \, M) g3 I4 k8 Jno snmp-server location
- _1 q5 w: l3 ]1 ?1 x6 A. }6 bno snmp-server contact' t) q: ^7 k/ c1 B/ P
snmp-server community public! M2 j7 ^8 ^8 v5 P8 v& A$ ?
no snmp-server enable traps: w* R$ e) D9 A! T5 o
floodguard enable
7 K. X! C# E0 Y% nsysopt connection permit-ipsec
) Q+ m7 C2 ] gsysopt connection permit-l2tp8 I9 Y0 a4 n* g3 O8 P. V
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac 4 ^! B$ e. `: C' a
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
# |5 c$ x9 X9 Hisakmp enable outside' c9 n+ j( z0 p
isakmp enable inside7 X' h* e$ t( t. v8 y! U$ f
telnet timeout 5, ]- |) b5 `/ K' |( M/ v$ u
ssh 0.0.0.0 0.0.0.0 outside
" h8 g% r& A; y3 j1 bssh 0.0.0.0 0.0.0.0 inside, Y1 c- B% w" `0 Y7 X/ y
ssh timeout 5
* j0 [4 u9 b% j* jconsole timeout 08 r" j1 P: a, O3 B1 P' R/ j
vpdn username wanhine password ********* 4 Z% D# G$ M# k& b' D. q- _
vpdn enable outside
6 j- V8 ~) O5 U3 a( [vpdn enable inside N, K; h. V F; [- \/ P2 v
dhcpd address 192.168.0.20-192.168.0.200 inside' J, b0 M+ [# {' }+ N
dhcpd dns 202.103.24.68 202.103.0.117
& @2 L! c$ h/ O7 a8 P3 d+ G* b8 Adhcpd lease 36003 x' s& T/ H2 h& T
dhcpd ping_timeout 750
4 g* G0 f6 E$ w" R9 pterminal width 80
% g. Z1 ], G3 ^2 `$ `7 v; l9 dCryptochecksum:f40dc8963b7f456d60eac467e8c0ea87& u$ k n' M9 [% E, u/ @
: end
4 X- A0 Y) P* Y- f* a8 D+ O[OK]6 l5 E2 A. y- x5 @
; M: H, D- V9 H4 [7 p' z9 z
0 y! [8 j2 O2 x4 l0 X
5 \$ Z) W# ~. m5 S: ]
请高人指点.& }0 d! N( O* _1 |5 l% |- e- ]6 C
如果PDM无法实现,请发下完整的配置表谢谢,万分感谢! |