- 论坛徽章:
- 0
|
PIX Version 7.0(6)
配置如下:
interface Ethernet0
description outside
nameif ethernet0
security-level 0
ip address 10.201.65.166 255.255.255.252
!
interface Ethernet1
description inside
nameif security100
security-level 0
ip address 10.201.92.140 255.255.255.224
!
passwd S4lRmsvyCcXs9BmU encrypted
ftp mode passive
access-list outside extended permit icmp 10.201.92.128 255.255.255.224 any
<--- More --->
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq 2640
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq 123
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq 4100
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq 6504
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq 6505
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq ftp
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq telnet
access-list outside extended permit tcp any 10.201.92.0 255.255.255.0 eq 3389
access-list outside extended permit tcp any 192.168.55.0 255.255.255.0 eq www
pager lines 24
mtu security100 1500
mtu ethernet0 1500
no asdm history enable
arp timeout 14400
route ethernet0 0.0.0.0 0.0.0.0 10.201.65.1651
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh timeout 5
console timeout 0
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map global_policy
class inspection_default
inspect dns maximum-length 512
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
!
<--- More --->
service-policy global_policy global
Cryptochecksum:1ee4793f8570384237d2c5c6fc7b9b22
我现在在防火墙上可PING出去,也可PING通局域网,但是在局域网10.201.92.128/30这个网段的机器都不能PING出去,只能PING到防火墙内口,到不了外口;inside IP地址为我机器网关;
不知哪位朋友知否,谢谢了!!!! |
|