
公网ip是112.64.141.122,网关是112.64.141.121,内网ip是192.168.2.0网段,PIX我设置ip是192.168.2.3配置如下:
; U" g" I. a& N- Y# D9 APIX Version 6.3(3)# Z' g5 ^. a6 Q
interface ethernet0 auto+ G6 k+ V/ c, A' {9 l, `
interface ethernet1 auto
& z: C, H. ?! B! T; D# S. Wnameif ethernet0 outside security0
) ?" O$ F% M# G. O: j8 d- Ynameif ethernet1 inside security100
/ m* U& m" w/ V: A* penable password 8Ry2YjIyt7RRXU24 encrypted7 p5 x, }( A: a- n" A {5 m x
passwd 2KFQnbNIdI.2KYOU encrypted
- J @' r6 |, o3 ahostname pixfirewall
* s8 q7 l' a8 U( P D4 Pfixup protocol dns maximum-length 512
+ H& Y6 Z& b( \ Afixup protocol ftp 215 J/ ~0 m* D1 ~" W) S+ Z2 v
fixup protocol h323 h225 1720- u! r9 F7 M8 ~+ W6 E+ A& P' c
fixup protocol h323 ras 1718-17197 s9 x! q8 I; h) S2 E6 ~4 o/ u& ]1 E
fixup protocol http 80" ]2 U9 t. X2 j0 E, E
fixup protocol rsh 514
4 I# Y7 Z% c1 |9 R$ ifixup protocol rtsp 554
) n c! V% m3 Q4 Ifixup protocol sip 5060
# P0 k1 k5 y4 U' ?- D! {+ ]5 ufixup protocol sip udp 5060, B# C' n* h7 @! G' v$ `) B
fixup protocol skinny 2000
! ?4 q. R' H2 V, a, Kfixup protocol smtp 252 g7 M$ q2 G1 C! B9 H
fixup protocol sqlnet 1521
" w' u) a5 m3 T( N; o0 Afixup protocol tftp 69
- H4 A. [+ w5 B; unames
6 J8 D! @: U7 g4 E# E5 |( daccess-list 80 permit ip 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0
* f2 T. ~5 @, p& R5 Gaccess-list 101 permit ip 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0 z d/ {1 ^$ B& X
access-list 101 permit icmp 192.168.2.0 255.255.255.0 192.168.3.0 255.255.255.0
% A" z: k' I$ b) J* ^/ Kaccess-list 102 permit icmp any any
+ X8 c+ D/ X5 I/ }1 Taccess-list 103 permit ip any 112.64.141.0 255.255.255.0 . w# d: j* t' I/ ]% L, g
pager lines 24
" v# B B2 R9 G0 t# @& o0 d% {mtu outside 1500
8 D; a- V. S; Z4 P# ~/ |- dmtu inside 15005 n+ C |9 E# \6 r" C1 g
ip address outside 112.64.141.122 255.255.255.0: G1 g1 E; ?/ M. t0 j
ip address inside 192.168.2.3 255.255.255.08 A1 _1 {" F/ ^6 W
ip audit info action alarm
# D% w* {. e% t+ I8 dip audit attack action alarm% Z7 v, Q- Y( H; h$ I
pdm history enable3 ]$ x/ X! p; x' k; A) ]
arp timeout 14400; ?5 B/ X# V( G6 f/ P
global (outside) 1 interface" d X' D# U" K. y1 g
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
3 {" @8 q3 z4 l o. ~6 ^, |access-group 80 in interface outside+ s5 [3 P9 @1 t4 _: L' C# c
conduit permit tcp host 192.168.2.6 eq www any 9 {9 u" {3 }8 T& l
conduit permit udp host 192.168.2.6 eq domain any ; X! v* v$ j4 k' m4 `
route outside 0.0.0.0 0.0.0.0 112.64.141.121 1
0 W3 M0 w" O/ z- ]: U; f$ }1 Jtimeout xlate 3:00:005 Y0 T- R) I9 O& n! G
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00& m9 S- a6 C: H8 s! n$ _, y
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
. R: z4 N9 j# n4 K/ Z( qtimeout uauth 0:05:00 absolute
8 N# a& W7 E! [2 C0 A$ U" M4 C' eaaa-server TACACS+ protocol tacacs+ : k7 T: h4 i& c |6 k% Q2 i! K. i
aaa-server RADIUS protocol radius
1 V2 C8 a4 U6 Naaa-server LOCAL protocol local " l1 G* p( L3 @
no snmp-server location
. ]3 T9 J8 e& t8 H% y: \9 u8 Sno snmp-server contact2 [7 E4 E9 }9 X$ G
snmp-server community public
1 S3 O0 E8 }) y6 I& V6 gno snmp-server enable traps: Q1 z' U0 W1 S) C9 k" p) h
floodguard enable* }2 ~) Z0 A- i0 o7 U4 m/ G8 L4 A
telnet timeout 5
. S1 u! ], f" T Q7 \, M7 tssh timeout 5
% m% ^% _, B( ]& x9 g# G, econsole timeout 0
; M% b; V4 c) A" z, l: fterminal width 80 T% a# [! T* n. C! ^8 {! S
Cryptochecksum:ee1c51874b492520381d3ff1d5185008
6 q/ h9 E! S2 r, l: end |
|