
由于asa5510默认的ssl vpn只有两个许可;所以在调试的时候许可不够用;
" X0 X) g. K' L- F) }6 K0 [在防火墙上ciscoasa(config)# show vpn-sessiondb webvpn( S" h& m' V5 q9 Z
& V! M0 s! W8 a! [7 k2 d# YSession Type: WebVPN5 s) L. n: W1 f2 L8 s9 i
4 ^ ]4 Z& `6 X7 D# `Username : ***** Index : 6* s8 A5 v M I
Public IP : 117.85.161.80: a, c2 k& z1 Q* V6 a
Protocol : Clientless0 I9 i9 A7 B# ~% {
Encryption : RC4 Hashing : SHA1/ V) |" x/ D7 B0 j
Bytes Tx : 0 Bytes Rx : 0
! f( d& ^( N- k; f. kGroup Policy : group_policy_ssl Tunnel Group : vpnclient_ssl
" [4 [& L0 o0 @' y: L: e' yLogin Time : 19:54:49 CST Wed Apr 13 2011* h' }% R6 w' `6 x
Duration : 0h:31m:14s$ F& \" k5 V h: O, `
NAC Result : Unknown
9 b# ~$ Q8 C1 O0 S, {VLAN Mapping : N/A VLAN : none! c, K; x# [; a) e9 { p
; y* R9 k% u# O
Username : ***** Index : 78 i! L9 o% m8 K8 j
Public IP : 117.85.161.800 ~- J4 p! K( C \$ g- E
Protocol : Clientless
. C( L/ {8 X9 _0 D* h4 ]: j: @Encryption : RC4 Hashing : SHA1
2 t. {% K% U- ~Bytes Tx : 0 Bytes Rx : 00 y( i. U$ ~ s
Group Policy : group_policy_ssl Tunnel Group : vpnclient_ssl
% M2 Y" u, s9 a3 K$ \8 VLogin Time : 19:55:22 CST Wed Apr 13 20113 |' Z1 t3 k& z6 I
Duration : 0h:30m:41s' C" N) a% F* K y
NAC Result : Unknown, A( Y. y; g W& Q
VLAN Mapping : N/A VLAN : none
1 Z2 Z4 W X% p+ A
. X% V% o1 }& k! t1 [- Z% s9 Wciscoasa(config)#) j& E O- @& p9 \, O0 s$ C A" i
能看到相应的两个会话;9 k. ?7 _' c% d- x
但是使用命令清除不掉:0 m6 K: K: r! K% R
ciscoasa(config)# clear vpn-sessiondb statistics webvpn4 f1 _( t7 ~# y* I \+ t7 o
INFO: Number of sessions of type "webvpn" cleared : 2
/ q+ L. v1 y6 l8 g4 F提示已经清除2个会话了;2 i% K" I& j& V( o' w2 ?: Q4 N
但是再次查询还是有这两个会话在;, t2 c5 x D+ M: L9 ^% j* D7 j
- a0 R" `- w! h$ g% F: W
怎么回事?
$ g! b. c( A% c" I# @: P1 n+ v2 ]谢谢! |
|