
PIX配置好后连接交换机,再用了台PC连接交换机,PC和PIX再一个网段,但是ping的通联通给的地址,ping不通外网的网关,更别提网站了。配置如下
$ n; S0 d! m1 P# a9 T& L# RPIX Version 6.3(3)
8 O( w$ K, x$ x3 a6 Y" {interface ethernet0 auto+ E h; l; C' E5 w
interface ethernet1 auto
6 `* V$ r& _: t' F# A- wnameif ethernet0 outside security0, ^3 A* C+ g9 a, g, X- L( Q7 W
nameif ethernet1 inside security100- n+ e+ o, P$ w0 E6 c- G
enable password 8Ry2YjIyt7RRXU24 encrypted
* f8 H/ {3 M1 `8 N! Cpasswd 2KFQnbNIdI.2KYOU encrypted% a$ T' ]7 q7 J; L4 L/ i
hostname pix515e9 g( j9 v) ]$ x
domain-name aubridgegroup.com
2 o+ Y- R X* i" X" u# } ufixup protocol dns maximum-length 512
6 a. g7 s# I; K0 s# h+ bfixup protocol ftp 21
1 D, F' V+ B! D- s, Q" @9 `fixup protocol h323 h225 1720
# w) a* Z( d% x' Zfixup protocol h323 ras 1718-17194 i/ I# g% ?3 o6 i
fixup protocol http 806 u, U" p9 z0 S4 A! q" a2 _
fixup protocol rsh 5147 E; u0 z$ n" _- z
fixup protocol rtsp 554
t' E# }% B3 Y8 Yfixup protocol sip 5060
0 t& C' ` }# q0 z; E! q2 q$ Z8 _fixup protocol sip udp 5060' K3 l0 K0 o& k7 g5 O# u
fixup protocol skinny 2000
/ S& z, n" U0 l5 i. e# A' lfixup protocol smtp 25
$ T0 h, z+ {: e6 tfixup protocol sqlnet 1521
$ [( D* b; x rfixup protocol tftp 69
# g* I/ a' i7 K. P, v% @' W! a, knames , i0 s5 \% W3 e) l
access-list 80 permit ip 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0
2 x% W# J4 e: _4 d" R' xaccess-list 101 permit ip 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0
) G1 P6 p+ W/ w6 N7 b1 G4 @8 W, eaccess-list 101 permit icmp 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0 6 E* N6 F, _2 ^/ }; _
access-list 102 permit icmp any any
! z5 x) O: s1 M& T# v7 U3 q5 @access-list 103 permit ip any 112.64.141.0 255.255.255.0 % b5 h$ Y- N& N7 P9 g: w7 |$ D" O
pager lines 24; H/ h- X! {& I: s2 v9 Y. ?
mtu outside 1500
5 m5 {- P$ x: d+ n" kmtu inside 1500. v; ?0 Y* O! | m
ip address outside 112.64.141.122 255.255.255.0 ~& I( V$ T& E
ip address inside 192.168.2.15 255.255.255.0
_7 v9 [: _' J i- Bip audit info action alarm
2 W2 f3 _" G! [! k9 j1 dip audit attack action alarm* E* Z, Z7 K. n- p
ip local pool dialerl 192.168.2.241-192.168.2.249 s* f0 ~0 z* ~3 O1 U* s0 Y% N
pdm history enable+ e. x/ d; `! }1 N& e9 U3 A
arp timeout 14400
+ q' w' ?, z7 g) J" Jglobal (outside) 1 interface
% K: j' b! v+ ]$ [* }" knat (inside) 1 0.0.0.0 0.0.0.0 0 0
W* `" H1 n0 o2 k& u! T( maccess-group 80 in interface outside
+ g$ k" i; _* s" utimeout xlate 3:00:00
4 e: `* J' `* Q/ |timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
. {2 a4 i' p+ C2 Ptimeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00, \/ k, u0 a4 a# a2 W& N
timeout uauth 0:05:00 absolute0 K: O# D F# ?
aaa-server TACACS+ protocol tacacs+ ) K- o# I: T/ Q: I- R% H
aaa-server RADIUS protocol radius
; n# p, @; I0 Baaa-server LOCAL protocol local
: ?$ e6 m6 z4 {( jno snmp-server location
6 }) A! Q$ K. Kno snmp-server contact& E9 w% ]% m1 F0 }
snmp-server community public- x5 Q: A$ E% F: U3 C
no snmp-server enable traps
* ?: T$ d0 K; k- {! A: i& l1 U1 s! g2 pfloodguard enable2 k9 ], Z5 R+ R/ g) u$ \& o
telnet timeout 5
0 f/ U! F/ e* R9 Fssh timeout 57 C5 ]% T- S! b; G# H( d5 [6 ]
console timeout 0
) _2 W6 g2 L; P3 R3 U" W1 ~ Lterminal width 80
' U3 L3 w0 o8 t. c! w6 x7 kCryptochecksum:3ce5c7f1d4ffa817ec7e6890d7b5b299
! u1 P+ G# [1 x0 z( Q. I2 X: end |
|