免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1831 | 回复: 0

关于PIX506E的配置问题 [复制链接]

论坛徽章:
0
发表于 2007-04-16 16:57 |显示全部楼层
下面是我的防火墙的配置。

# show run
: Saved
:
PIX Version 6.3(5)
interface ethernet0 auto
interface ethernet1 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password rca9DMuOZtC0zY2B encrypted
passwd ga6y/OqUw0hT5TW4 encrypted
hostname GBTNFW01
clock timezone CST 8
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
no names      
access-list acl_in permit icmp any any
access-list acl_in permit tcp any any
access-list acl_in permit ip any any
access-list acl_in permit udp any any
access-list acl_out permit icmp any any
access-list acl_out permit ip any any
access-list acl_out permit tcp any any
access-list acl_out permit udp any any
pager lines 24
logging on   
logging buffered warnings
logging trap warnings
logging host inside 172.16.1.20
mtu outside 1500
mtu inside 1500
ip address outside 10.10.10.254 255.255.255.0
ip address inside 172.16.0.254 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
ip local pool tnpool 10.10.10.108
pdm logging informational 100
pdm history enable
arp timeout 14400
global (outside) 10 10.10.10.100-10.10.10.109
global (outside) 1 10.10.10.110-10.10.10.119
global (outside) 2 10.10.10.120-10.10.10.129
global (outside) 3 10.10.10.130-10.10.10.139
global (outside) 4 10.10.10.140-10.10.10.149
global (outside) 5 10.10.10.150-10.10.10.159
nat (inside) 10 172.16.0.0 255.255.255.0 0 0
nat (inside) 1 172.16.1.0 255.255.255.0 0 0
nat (inside) 2 172.16.2.0 255.255.255.0 0 0
nat (inside) 3 172.16.3.0 255.255.255.0 0 0
nat (inside) 4 172.16.4.0 255.255.255.0 0 0
nat (inside) 5 172.16.5.0 255.255.255.0 0 0
static (inside,outside) 10.10.10.50 172.16.5.10 netmask 255.255.255.255 0 0
static (inside,outside) 10.10.10.51 172.16.5.20 netmask 255.255.255.255 0 0
static (inside,outside) 10.10.10.30 172.16.3.60 netmask 255.255.255.255 0 0
static (inside,outside) 10.10.10.31 172.16.3.40 netmask 255.255.255.255 0 0
static (inside,outside) 10.10.10.32 172.16.3.50 netmask 255.255.255.255 0 0
static (inside,outside) 10.10.10.40 172.16.4.10 netmask 255.255.255.255 0 0
access-group acl_out in interface outside
access-group acl_in in interface inside
route outside 0.0.0.0 0.0.0.0 10.10.10.253 1
route inside 172.16.1.0 255.255.255.0 172.16.0.253 1
route inside 172.16.2.0 255.255.255.0 172.16.0.253 1
route inside 172.16.3.0 255.255.255.0 172.16.0.253 1
route inside 172.16.4.0 255.255.255.0 172.16.0.253 1
route inside 172.16.5.0 255.255.255.0 172.16.0.253 1
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
ntp server 172.16.1.20 source inside
snmp-server host inside 172.16.4.10 trap
no snmp-server location
no snmp-server contact
snmp-server community public
snmp-server enable traps
floodguard enable
telnet 10.10.10.108 255.255.255.255 outside
telnet 172.16.4.10 255.255.255.255 inside
telnet 172.16.1.10 255.255.255.255 inside
telnet 172.16.0.253 255.255.255.255 inside
telnet 172.16.1.20 255.255.255.255 inside
telnet 172.16.0.108 255.255.255.255 inside
telnet timeout 20
ssh timeout 5
console timeout 0
dhcpd lease 3600
dhcpd ping_timeout 750
terminal width 80
Cryptochecksum:fcf9f746935b885de78dad4e01c89a85
: end         


现在在外网的一台客户端10.10.10.208(与防火墙外网口接在同一switch中)用FTP协议向内外172.16.5.10 (10.10.10.51)上传数据,速度很慢(2k/s),但是在内网中上传很快(7M/s)

请问防火墙的配置有问题吗?
或者速度慢的原因是什么?
谢谢!
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP