
这个防火墙的配置如下
2 f& b1 p7 J( O; `% F4 f" A基本没做什么,只是修改了一个2个ETH的IP; i- H- l7 }. V0 ~9 ]% I
可是在内网里ping不出去,而且VPN连接不到外面4 i& I2 K# J- K# b$ }0 H% o4 F
连接的时候总是在验证用户名和密码这卡住,等待一分钟后,719错误,对方服务器无应答.' G% `( D: z: Z! l7 x* E9 I
$ B' w+ U0 \6 D% D
: Saved
) M: [; z. z- {4 ], o5 A( x, n: Written by enable_15 at 01:42:54.855 UTC Tue Jul 4 2006' l9 e% k5 l; j* [7 \
PIX Version 6.3(1)
3 @( a4 R$ {; `+ \0 [! Yinterface ethernet0 auto2 P$ H) ]+ e: z
interface ethernet1 100full
# A# y& ^" T A9 l; lnameif ethernet0 outside security0) `3 n4 P7 ^2 S& F/ k9 |0 A, o
nameif ethernet1 inside security100) k! r! q7 ? Q$ E0 l1 U, f* f
enable password 8Ry2YjIyt7RRXU24 encrypted% \' Y0 d4 [5 `
passwd 2KFQnbNIdI.2KYOU encrypted
- C4 d2 _: D4 y7 _. S; n0 G, thostname zg
1 G9 H* g# P1 O; a& x# v$ Xfixup protocol ftp 212 x; f; |" z; j7 g5 ^0 [9 \
fixup protocol h323 h225 1720
& m1 S' o* E K7 P* e: @) sfixup protocol h323 ras 1718-1719& }2 V2 W4 _- z% U, w' I+ e1 h* l
fixup protocol http 80
+ V0 E! C5 h' W2 ?! E3 Cfixup protocol ils 3894 j1 H3 t3 C; y; j
fixup protocol rsh 514
& E; ^4 [9 z5 ?9 s) ]% Mfixup protocol rtsp 554+ a, @( b- Q# B' ^
fixup protocol sip 2000 |" U, h ~6 {2 ]
fixup protocol sip 5060/ a& X7 j8 Z( R) U; u
fixup protocol sip udp 5060
1 e$ S. H+ z! t/ s2 Cno fixup protocol skinny 2000
6 \( v( X8 ]4 Z9 B$ ^fixup protocol smtp 25
9 E8 u1 e( }. @ J: ?fixup protocol sqlnet 15214 c$ ^5 x0 @# N& o& U# @8 H2 u8 _
names! G! d& _; ?$ m9 j) C* x
pager lines 24. v, V3 Z% |! g. [; T6 V
mtu outside 1500
; R- W2 Y& p! }/ z" Rmtu inside 15006 ~% y: X; r4 d: k1 n0 e9 M$ A
ip address outside 222.223.71.88 255.255.255.0
|( y' b) U3 c- h5 ?$ A' ~9 @( Nip address inside 192.168.0.1 255.255.255.0# W0 K) M+ |1 v" O3 I4 g p
ip audit info action alarm) }' o- G5 T k& Q( U2 x1 L
ip audit attack action alarm. l3 b7 D/ B$ S/ H7 a( _
pdm logging informational 1003 d+ L- E! I! ^+ A( p5 }
pdm history enable
, Y: p& @' J9 d# k6 uarp timeout 14400
, L& Q8 g n# @2 W7 vglobal (outside) 1 interface
" y; h; s1 E! v4 Ynat (inside) 1 0.0.0.0 0.0.0.0 0 0/ L( l6 r7 I0 {- e
conduit permit udp any any
V. g. {1 j1 w: Z' X4 u" ]conduit deny udp any any, ^* J- ^3 m% t9 g9 I
route outside 0.0.0.0 0.0.0.0 222.223.71.1 1
3 @6 I. i8 m. ^. X% _; l) h: N7 Ntimeout xlate 0:05:00
d' K2 P; m- F* Z1 Ktimeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
, U0 D. p9 n! S2 w' _* W3 Gtimeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
% }$ J6 b( {$ y7 P; J; c5 d) Ltimeout uauth 0:05:00 absolute
$ b' ~9 w+ [4 Paaa-server TACACS+ protocol tacacs+
" e% {: L6 W _aaa-server RADIUS protocol radius8 \6 p4 X2 d. w# {3 A7 t7 e
aaa-server LOCAL protocol local' b! i. |& A- e; y- y4 c) `
http server enable9 S+ z8 ~* W4 r Z
http 192.168.1.0 255.255.255.0 inside6 _6 Q( u6 f# T; S Z
no snmp-server location' T+ t/ P, J. S2 r, R
no snmp-server contact4 z0 o& w$ J' |/ g6 U; Q( s* l" X
snmp-server community public) F( y( a# [) [# ?9 ~+ u
no snmp-server enable traps- Z5 E8 w V5 I0 I3 g& z
no floodguard enable3 g- u" a- ~0 D3 T
telnet 192.168.0.0 255.255.255.0 inside
# x6 F" A6 F0 J$ }telnet timeout 5: u. d% j. x: G$ r7 _5 Z) G
ssh timeout 5
& D+ R0 z2 H6 S; y0 Jconsole timeout 0
4 r. J( n' Y8 D/ J! p4 W+ _3 E- Ldhcpd lease 3600
@* z# z/ p4 G5 M9 idhcpd ping_timeout 7504 Q1 _9 j3 ~! g* Q/ U7 y; {
dhcpd auto_config outside' P+ h( S: K* Q9 m
terminal width 80) O2 t8 {7 _+ X- c
Cryptochecksum:c70fb7e1bb5fcebc4f2f4e3765ce7d45 |
|