
PIX Version 6.3(3)
) K) q3 p4 N ~# Binterface ethernet0 auto 2 {2 Y& M b, N
interface ethernet1 100full ! [& }* K3 u( O' V1 ]9 s8 b! e
interface ethernet2 auto shutdown
/ v1 J2 Q: |# ?1 |+ S! snameif ethernet0 outside security0 4 }4 i/ g* X) f% B
nameif ethernet1 inside security100 & ~+ E- ?/ d4 H6 O" L# D) \
nameif ethernet2 intf2 security4
6 Y6 X4 b6 R) K) denable password g1vsSglS6RRKRfvz encrypted 6 X( j; B, n! f& j* I+ a4 _
passwd 2KFQnbNIdI.2KYOU encrypted
0 `( e! V% y7 ^2 c# A/ h2 J1 Z) q$ qhostname pix515e
" E X% V& S/ S' G6 v% ? Pdomain-name www.hymaco.com
8 r& F5 U$ I6 N% {fixup protocol dns maximum-length , n0 i! n; C% _) s: t; @! r3 W: I
fixup protocol ftp 21 ; o6 r, P9 i. R; v7 {
fixup protocol h323 h225 1720
2 A1 h- i; ]- r7 P3 a/ m4 Lfixup protocol h323 ras 1718-1719
% w* Y$ e3 \/ R) j' b+ J+ k$ @fixup protocol http 80 ! w- q& P6 D# X0 z+ a
fixup protocol rsh 514 ! r' o9 j) t& j* H% g# w
fixup protocol rtsp 554
" k7 a- ^7 J# E$ K+ m2 P% ?* Xfixup protocol sip 5060
8 t5 ?# m% r" c- ]+ Ufixup protocol sip udp 5060 6 O* d* d* B5 H3 j" Z. [
no fixup protocol skinny 2000
/ l! F" X& Y0 i; F! @" lfixup protocol smtp 25
) _) q9 j8 u) f! {% d1 a/ ~fixup protocol sqlnet 1521
3 H6 a. q% f5 F0 Sfixup protocol tftp 69
# F3 G) G& _1 L# r* f( J5 cnames 4 I% ]( M6 q/ c7 f8 [- t! b. ?; m1 s) u
access-list 100 permit ip any any
9 G8 I+ ?: w. a" X' S4 h% C1 {; c: Npager lines 24
2 s% w4 M0 s9 m# M8 u; I) Jmtu outside 1500
& A7 P! h6 v& d- C2 cmtu inside 1500 + D' D$ P% z6 \7 O0 K9 N9 T
mtu intf2 1500 1 q( A; G2 K7 Q
ip address outside 61.187.182.70 255.255.255.192
* [, N1 Y7 J4 }6 d; C* B# w Sip address inside 192.168.48.3 255.255.255.248 3 U1 J/ \8 w! P% x
no ip addres
! R; S# S8 x/ S) t* e$ u5 s3 `/ oip audit info action alarm / H( }8 J8 H+ t7 I7 Q7 S0 U* Z
ip audit attack action alarm $ U( l/ u" o3 W- i
pdm history enable
8 l( t8 B! n# }arp timeout 14400
/ S. U7 G9 l5 C. }global (outside) 1 61.187.182.71 * V- S1 H+ g: H6 o! z: A7 c) }1 A
nat (inside) 1 192.168.5.58 255.255.255.255 0 0
+ N- a3 M+ j* _. a5 g o" f6 `/ Pnat (inside) 1 192.168.8.6 255.255.255.255 0 0
. c; A3 E9 L s; Z& p7 M$ pnat (inside) 1 192.168.8.10 255.255.255.255 0 0
( i$ Y3 I [1 }6 Tnat (inside) 1 192.168.48.0 255.255.255.248 0 0
4 @/ @) G, r# Z) Xnat (inside) 1 192.168.1.0 255.255.255.0 0 0
4 V% V5 W" Z+ o$ e$ x7 P k) o0 d0 Jnat (inside) 1 192.168.2.0 255.255.255.0 0 0
3 k' S) i9 G& J3 N& Hnat (inside) 1 192.168.3.0 255.255.255.0 0 0 ( {' _2 b: V& |) d
nat (inside) 1 192.168.4.0 255.255.255.0 0 0 % T* e; }( _6 R+ j% w
nat (inside) 1 192.168.27.0 255.255.255.0 0 0
- ?0 L. U2 y( p9 N/ N4 bnat (inside) 1 192.168.70.0 255.255.254.0 0 0 8 r& D$ H& l8 ?4 m8 ^
nat (inside) 1 192.168.72.0 255.255.254.0 0 0 & U( D8 {; P$ \- F: N. a
nat (inside) 1 192.168.74.0 255.255.254.0 0 0 ; T1 e0 M! Y+ z
nat (inside) 1 192.168.76.0 255.255.254.0 0 0
' _4 X3 }3 u8 F0 Mstatic (inside,outside) tcp 61.187.182.68 smtp 192.168.1.3 smtp netmask 255.255.
4 k5 V8 d$ W# t0 a2 \8 H255.255 0 0 0 e( v& w) I- Z0 V) ^
static (inside,outside) tcp 61.187.182.68 pop3 192.168.1.3 pop3 netmask 255.255.
! ~% Q4 K! o4 g6 f2 u255.255 0 0 6 N) V$ ~ w2 C( ~7 c, A
static (inside,outside) tcp 61.187.182.68 8080 192.168.1 9 O1 J0 A" @7 d& ^6 u: a b$ K% {
255.255 0 0
& a9 a$ z* Q2 q0 N: ^/ D' }% y# C3 P( fstatic (inside,outside) tcp 61.187.182.68 www 192.168.1.2 www netmask 255.255.25 * K% H7 t$ f0 q: z" _
5.255 0 0 1 v* G; k6 g! G' W) I2 ~% k _; l
static (inside,outside) tcp 61.187.182.68 ftp 192.168.1.3 ftp netmask 255.255.25
3 v' [ v7 J. f# K5.255 0 0
/ e5 u; m9 o( \+ r7 s* I; H2 R5 Estatic (inside,outside) tcp 61.187.182.68 2080 192.168.1.3 2080 netmask 255.255.
5 r" Q1 |$ i" l0 H$ F255.255 0 0
% k4 {+ k1 i) ~9 Y T/ paccess-group 100 in interface outside
5 Q+ B7 j8 ?6 X, @+ waccess-group 100 in interface inside
" ~7 D/ e) t4 w1 ^- Y# H. Q- Lconduit permit icmp any any
* K& S% G: t5 m, L7 V5 wrouter ospf 1 & ~' {" i5 h$ F8 i
network 192.168.48.0 255.255.255.248 area 0 4 ^% b0 W, r# `- T, a: P
router-id 1.1.1.1
( ]& D% R" x5 X# ?6 Y log-adj-changes
6 X! z8 A1 T- p) v1 E3 d redistribute connected
6 ~1 x$ L9 l" T; m. j( D. }) groute outside 0.0.0.0 0.0.0.0 61.187.182.65 1# q9 C2 i% G( T- C0 a0 ]
timeout xlate 3:00:004 t- j, z' [! H3 s3 m' `, {
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
, S8 r0 \' T) ?2 t7 L8 Q) H% w& gtimeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
. j! v. D! h- U2 ]timeout uauth 0:05:00 absolute' q3 J& [* l' J6 i/ q. s+ ^
aaa-server TACACS+ protocol tacacs+
8 X& H- Z/ B/ p+ w* P# E1 k! q- xaaa-server RADIUS protocol radius
+ A9 r( z7 \$ g: c- w9 ~8 ^2 Paaa-server LOCAL protocol local
5 }# P' X. ~4 g; b& {1 V/ |! J# Wno snmp-server location$ Q, A& a2 {# F! g- z; e. Y( F
no snmp-server contact
" k* y* f$ w9 o3 \7 d% Tsnmp-server community public
+ |) O/ ^: H8 x' _2 q8 g+ ?no snmp-server enable traps9 I& D8 ]( T, J3 T
floodguard enable
8 J, Z: C( z5 F4 J0 i9 j1 wtelnet 192.168.76.0 255.255.254.0 inside
& l9 r+ }$ B8 X- B' n( O. htelnet 192.168.48.0 255.255.255.248 inside
& P0 N. V2 \+ Itelnet 192.168.3.0 255.255.255.0 inside- l+ C$ i; b- m y4 |. x1 ^$ L
telnet timeout 5
, y+ |9 H5 C& o+ z# W& A+ ~ l2 Lssh timeout 5
) R2 i' b* n8 s {; y" Y6 [- Aconsole timeout 0( I# I% T4 S0 P" I% L
terminal width 80, X& y6 b2 a6 R$ H2 A5 w, ?9 I8 k2 a
Cryptochecksum:36160959adc028535def9db74bbde3ef
1 t2 H& M+ U% N6 [: end0 P* o6 }5 J* v, }) K
& s; X/ B) H" ~+ |$ B
这个是我现在的配置,我在做想做MAC地址绑定给指定的客户机上网。因为用# d7 b- O2 L F* G" u( W7 l
nat (inside) 1 192.168.1.18 255.255.255.255
# q: U. U m8 Z5 e当这台机子不上网的时候,他可以改成其他的IP地址,让别的机子改成他的IP地址上网,所以我想用ARP绑定MAC+IP地址。
v% ~) h& K; M3 t- J我用
6 z( t1 E7 U) O" Jarp inside 192.168.17.18 00e0.4c7b.0685 alias0 r0 r$ |" _, \2 R; n1 I* v) L7 y% A/ V
提示:Network IP address is not allowed
. R& w9 o- @4 E4 ]; g允许的IP地址,请大虾指点啊。。。急!~!!!! |
|