Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

ÓʼþÍøÂ簲ȫ

ϵͳ°²È« | ÓʼþÈí¼þ©¶´ | °²È«»ù´¡ | Êý×ÖÇ©Ãû | ¹¥·À¼¼Êõ | ²¡¶¾¹«¸æ | ²¡¶¾²éɱ | ISA Server | ·À»ðǽ |
Ê×Ò³ > ÓʼþÍøÂ簲ȫ > ÈíÓ²¼þ·À»ðǽ > Cisco PIX·À»ðǽµÄ°²×°Á÷³Ì > ÕýÎÄ

Cisco PIX·À»ðǽµÄ°²×°Á÷³Ì

³ö´¦£ºÊÕ¼¯ÕûÀí ×÷ÕߣºÊÕ¼¯ÕûÀí ʱ¼ä£º2006-5-22 10:10:00
 1. ½«PIX°²·ÅÖÁ»ú¼Ü£¬¾­¼ì²âµçԴϵͳºó½ÓÉϵçÔ´£¬²¢¼ÓµçÖ÷»ú¡£

    2. ½«CONSOLE¿ÚÁ¬½Óµ½PCµÄ´®¿ÚÉÏ£¬ÔËÐÐHyperTerminal³ÌÐò´ÓCONSOLE¿Ú½øÈëPIXϵͳ£»´ËʱϵͳÌáʾpixfirewall>.

    3. ÊäÈëÃüÁenable£¬½øÈëÌØÈ¨Ä£Ê½£¬´ËʱϵͳÌáʾΪpixfirewall#.

    4. ÊäÈëÃüÁ configure terminal£¬¶Ôϵͳ½øÐгõʼ»¯ÉèÖá£

    5. ÅäÖÃÒÔÌ«¿Ú²ÎÊý£º
    interface ethernet0 auto¡¡ £¨autoÑ¡Ïî±íÃ÷ϵͳ×ÔÊÊÓ¦Íø¿¨ÀàÐÍ £©
    interface ethernet1 auto

    6. ÅäÖÃÄÚÍâÍø¿¨µÄIPµØÖ·£º
    ip address inside ip_address netmask
    ip address outside ip_address netmask

    7. Ö¸¶¨ÍⲿµØÖ··¶Î§£º
    global 1 ip_address-ip_address

    8. Ö¸¶¨Òª½øÐÐҪת»»µÄÄÚ²¿µØÖ·£º
    nat 1 ip_address netmask

    9. ÉèÖÃÖ¸ÏòÄÚ²¿ÍøºÍÍâ²¿ÍøµÄȱʡ·ÓÉ
    route inside 0 0 inside_default_router_ip_address
    route outside 0 0 outside_default_router_ip_address

   10. ÅäÖþ²Ì¬IPµØÖ·¶ÔÓ³£º
    static outside ip_address¡¡¡¡inside ip_address

   11. ÉèÖÃijЩ¿ØÖÆÑ¡Ï
    conduit global_ip port[-port] protocol foreign_ip [netmask]
    global_ip¡¡ Ö¸µÄÊÇÒª¿ØÖƵĵØÖ·
    port¡¡¡¡¡¡¡¡Ö¸µÄÊÇËù×÷ÓõĶ˿ڣ¬ÆäÖÐ0´ú±íËùÓж˿Ú
    protocol¡¡¡¡Ö¸µÄÊÇÁ¬½ÓЭÒ飬±ÈÈ磺TCP¡¢UDPµÈ
    foreign_ip¡¡±íʾ¿É·ÃÎÊglobal_ipµÄÍⲿip£¬ÆäÖбíʾËùÓеÄip.

   12. ÉèÖÃtelnetÑ¡Ï
    telnet local_ip [netmask] l
    ocal_ip¡¡¡¡±íʾ±»ÔÊÐíͨ¹ýtelnet·ÃÎʵ½pixµÄipµØÖ·£¨Èç¹û²»Éè´ËÏPIXµÄÅäÖÃÖ»ÄÜÓÉconsle·½Ê½½øÐУ©¡£

    13. ½«ÅäÖñ£´æ£º
    wr mem

    14. ¼¸¸ö³£ÓõÄÍøÂç²âÊÔÃüÁ
    #ping
    #show interface¡¡¡¡¡¡²é¿´¶Ë¿Ú״̬
    #show static¡¡¡¡¡¡¡¡ ²é¿´¾²Ì¬µØÖ·Ó³Éä

    Cisco PIX 520 ÊÇÒ»¿îÐÔÄÜÁ¼ºÃµÄÍøÂ簲ȫ²úÆ·£¬Èç¹ûÔÙ¼ÓÉÏCheck Point µÄÈí¼þ·À»ðǽ×é³ÉÁ½µÀ·À»¤£¬¿ÉÒԵõ½¸ü¼ÓÍêÉÆµÄ°²È«·À·¶¡£

    Ö÷ÒªÓÃÓÚ¾ÖÓòÍøµÄÍâÁ¬É豸£¨Èç·ÓÉÆ÷¡¢²¦ºÅ·ÃÎÊ·þÎñÆ÷µÈ£©ÓëÄÚ²¿ÍøÂçÖ®¼ä£¬ÊµÏÖÄÚ²¿ÍøÂçµÄ°²È«·À·¶£¬±ÜÃâÀ´×ÔÍⲿµÄ¶ñÒâ¹¥»÷¡£

    Cisco PIX 520µÄĬÈÏÅäÖÃÔÊÐí´ÓÄÚµ½ÍâµÄËùÓÐÐÅÏ¢ÇëÇ󣬾ܾøÒ»ÇÐÍâÀ´µÄÖ÷¶¯·ÃÎÊ£¬Ö»ÔÊÐíÄÚ²¿ÐÅÏ¢µÄ·´À¡ÐÅÏ¢½øÈë¡£µ±È»Ò²¿ÉÒÔͨ¹ýijЩÉèÖã¬ÀýÈ磺·ÃÎʱíµÈ£¬ÔÊÐíÍⲿµÄ·ÃÎÊ¡£ÒòΪ£¬Ô¶³ÌÓû§µÄ·ÃÎÊÐèÒª´ÓÍâµ½ÄڵķÃÎÊ¡£ÁíÍ⣬¿ÉÒÔͨ¹ýNATµØÖ·×ª»»£¬ÊµÏÖ¹«ÓеØÖ·ºÍ˽ÓеØÖ·µÄת»»¡£

    ¼òµ¥µØ½²£¬PIX 520µÄÖ÷Òª¹¦ÄÜÓÐÁ½µã£º

    1.ʵÏÖÍøÂ簲ȫ

    2.ʵÏÖµØÖ·×ª»»

    ÏÂÃæ¼òµ¥ÁгöPIX 520 µÄ»ù±¾ÅäÖÃ

1.Configure without NAT

nameif ethernet0 outside security0

nameif ethernet1 inside security100

interface ethernet0 auto

interface ethernet1 auto

¡¡¡¡¡¡¡¡¡¡ip address outside 202.109.77.1 255.255.255.0 (¼ÙÉè¶ÔÍâ¶Ë¿ÚµØÖ·) ¡¡¡¡¡¡

¡¡¡¡¡¡¡¡¡¡ip address inside 10.1.0.9 255.255.255.0(¼ÙÉèÄÚ²¿ÍøÂçΪ:10.1.0.0)

¡¡¡¡¡¡¡¡¡¡hostname bluegarden

arp timeout 14400

no failover

names

pager lines 24

¡¡¡¡¡¡¡¡ logging buffered debugging

¡¡¡¡¡¡¡¡ nat (inside) 0 0 0

rip inside default no rip inside passive no rip outside default rip outside passive

route outside 0.0.0.0 0.0.0.0 202.109.77.2 1(ÍâÁ¬É豸µÄÄÚ²¿¶Ë¿ÚµØÖ·)

timeout xlate 3:00:00 conn 1:00:00 udp 0:02:00 timeout rpc 0:10:00 h323 0:05:00 timeout uauth 0:05:00 absolute

no snmp-server location no snmp-server contact snmp-server community public

mtu outside 1500 mtu inside 1500

2.Configure with NAT

nameif ethernet0 outside security0

nameif ethernet1 inside security100

interface ethernet0 auto

interface ethernet1 auto

¡¡¡¡¡¡¡¡ ip address outside 202.109.77.1 255.255.255.0 (¼ÙÉè¶ÔÍâ¶Ë¿ÚµØÖ·) ¡¡¡¡¡¡

¡¡¡¡¡¡¡¡ ip address inside 10.1.0.9 255.255.255.0(¼ÙÉèÄÚ²¿ÍøÂçΪ:10.1.0.0)

¡¡¡¡¡¡¡¡ hostname bluegarden

arp timeout 14400

no failover

names

pager lines 24

¡¡¡¡¡¡¡¡ logging buffered debugging

¡¡¡¡¡¡¡¡ nat (inside) 1 0 0

global (outside) 1 202.109.77.10-202.109.77.20 global (outside) 1 202.109.22.21

no rip inside default no rip inside passive no rip outside default no rip outside passive

conduit permit icmp any any

route outside 0.0.0.0 0.0.0.0 202.109.77.2 1(ÍâÁ¬É豸µÄÄÚ²¿¶Ë¿ÚµØÖ·)

timeout xlate 3:00:00 conn 1:00:00 udp 0:02:00 timeout rpc 0:10:00 h323 0:05:00 timeout uauth 0:05:00 absolute

no snmp-server location no snmp-server contact snmp-server community public

mtu outside 1500 mtu inside 1500

Cisco PIX µÄ¶àµã·þÎñÅäÖÃ

¡¡½á¹¹Í¼ÈçÏÂ:

¡¡PIX 520

¡¡Two Interface Multiple Server Configuration

¡¡nameif ethernet0 outside security0

¡¡nameif ethernet0 inside security100

¡¡interface ethernet0 auto

¡¡interface ethernet1 auto

¡¡ip address inside 10.1.1.1 255.0.0.0

¡¡ip address outside 204.31.17.10 255.255.255.0

¡¡logging on

¡¡logging host 10.1.1.11

¡¡logging trap 7

¡¡logging facility 20

¡¡no logging console

¡¡arp timeout 600

¡¡nat (inside) 1 10.0.0.0 255.0.0.0

¡¡nat (inside) 2 192.168.3.0 255.255.255.0

¡¡global (outside) 1 204.31.1.25-204.31.17.27

¡¡global (outside) 1 204.31.1.24

¡¡global (outside) 2 192.159.1.1-192.159.1.254

¡¡conduit permit icmp any any

¡¡outbound 10 deny 192.168.3.3 255.255.255.255 1720

¡¡outbound 10 deny 0 0 80

¡¡outbound 10 permit 192.168.3.3 255.255.255.255 80

¡¡outbound 10 deny 192.168.3.3 255.255.255.255 java

¡¡outbound 10 permit 10.1.1.11 255.255.255.255 80

¡¡apply (inside) 10 outgoing_src

¡¡no rip outside passive

¡¡no rip outside default

¡¡rip inside passive

¡¡rip inside default

¡¡route outside 0 0 204.31.17.1.1

¡¡tacacs-server host 10.1.1.12 lq2w3e

¡¡aaa authentication any inside 192.168.3.0 255.255.255.0 0 0 tacacs+

¡¡aaa authentication any inside 192.168.3.0 255.255.255.0 0 0

¡¡static (inside,outside) 204.31.19.0 192.168.3.0 netmask 255.255.255.0

¡¡conduit permit tcp 204.31.19.0 255.255.255.0 eg h323 any

¡¡static (inside,outside) 204.31.17.29 10.1.1.11

¡¡conduit permit tcp host 204.31.17.29 eq 80 any

¡¡conduit permit udp host 204.31.17.29 eq rpc host 204.31.17.17

¡¡conduit permit udp host 204.31.17.29 eq 2049 host 204.31.17.17

¡¡static (inside.outside) 204.31.1.30 10.1.1.3 netmask 255.255.255.255 10 10

¡¡conduit permit tcp host 204.31.1.30 eq smtp any

¡¡conduit permit tcp host 204.31.1.30 eq 113 any

¡¡snmp-server host 192.168.3.2

¡¡snmp-server location building 42

¡¡snmp-server contact polly hedra

¡¡snmp-server community ohwhatakeyisthee

¡¡telnet 10.1.1.11 255.255.255.255

¡¡telnet 192.168.3.0 255.255.255.0

    CISCO PIX ·À »ð ǽ Åä Öà ʵ ¼ù ¡ª¡ª ½é ÉÜ Ò» ¸öPIX ·À »ð ǽ ʵ ¼Ê Åä Öà °¸ Àý£¬ Òò Ϊ · ÓÉ Æ÷ µÄ ÅäÖÃÔÚ °² È« ÐÔ ·½ Ãæ ºÍPIX ·À »ð ǽ ÊÇ Ïà ¸¨ Ïà ³É µÄ£¬ Ëù ÒÔ Â· ÓÉÆ÷µÄ Åä Öà ʵ Àý Ò² Ò» ²¢ ÁÐ ³ö¡£

PIX ·À »ð ǽ

Éè ÖÃPIX ·À »ð ǽ µÄ Íâ ²¿µØÖ·£º

ip address outside 131.1.23.2

Éè ÖÃPIX ·À »ð ǽ µÄ ÄÚ ²¿µØÖ·£º

ip address inside 10.10.254.1

Éè Öà һ ¸ö ÄÚ ²¿ ¼Æ Ëã»úÓëInternet ÉÏ ¼Æ Ëã »ú ½ø ÐРͨ Њʱ Ëù Ðè µÄ È« ¾Ö µØ Ö·³Ø£º

global 1 131.1.23.10-131.1.23.254

ÔÊ Ðí Íø Âç µØ Ö· Ϊ10.0.0.0 µÄÍø¶Î µØ Ö· ±»PIX ·­ Òë ³É Íâ ²¿ µØ Ö·£º

nat 1 10.0.0.0

Íø ¹Ü ¹¤ ×÷ Õ¾ ¹Ì ¶¨ ʹ Óà µÄ ÍⲿµØ Ö· Ϊ131.1.23.11£º

static 131.1.23.11 10.14.8.50

ÔÊ Ðí ´ÓRTRA ·¢ ËÍ µ½ µ½ Íø ¹Ü ¹¤×÷Õ¾ µÄ ϵ ͳ ÈÕ Ö¾ °ü ͨ ¹ýPIX ·À »ð ǽ£º

conduit 131.1.23.11 514 udp 131.1.23.1 255.255.255.255

ÔÊ Ðí ´Ó Íâ ²¿ ·¢ Æð µÄ ¶Ô ÓÊ ¼þ·þÎñ Æ÷ µÄ Á¬ ½Ó£¨131.1.23.10£©£º

mailhost 131.1.23.10 10.10.254.3

ÔÊ Ðí Íø Âç ¹Ü Àí Ô± ͨ ¹ý Ô¶ ³ÌµÇ¼ ¹Ü ÀíIPX ·À »ð ǽ£º

telnet 10.14.8.50

ÔÚ Î» ÓÚ Íø ¹Ü ¹¤ ×÷ Õ¾ ÉÏ µÄ ÈÕÖ¾·þ Îñ Æ÷ ÉÏ ¼Ç ¼ Ëù ÓÐ Ê ¼þ ÈÕ Ö¾£º

syslog facility 20.7

syslog host 10.14.8.50

· ÓÉ Æ÷ RTRA

----RTRA ÊÇ Íâ ²¿ ·À »¤ · ÓÉÆ÷£¬Ëü ±Ø Ðë ±£ »¤PIX ·À »ð ǽ Ãâ ÊÜ Ö± ½Ó ¹¥ »÷£¬ ±£ »¤FTP/HTTP ·þÎñÆ÷£¬ ͬ ʱ ×÷ Ϊ Ò» ¸ö ¾¯ ±¨ ϵ ͳ£¬ Èç ¹û ÓÐ ÈË ¹¥ Èë ´Ë Â·ÓÉÆ÷£¬ ¹Ü Àí ¿É ÒÔ Á¢ ¼´ ±» ͨ Öª¡£


×è Ö¹ Ò» Щ ¶Ô · ÓÉ Æ÷ ±¾ Éí µÄ¹¥»÷£º

no service tcp small-servers

Ç¿ ÖÆ · ÓÉ Æ÷ Ïò ϵ ͳ ÈÕ Ö¾ ·þÎñÆ÷ ·¢ ËÍ ÔÚ ´Ë · ÓÉ Æ÷ ·¢ Éú µÄ ÿ Ò» ¸ö Ê ¼þ£¬ °ü À¨ ±» ´æ È¡ÁÐ±í ¾Ü ¾ø µÄ °ü ºÍ · ÓÉ Æ÷ Åä Öà µÄ ¸Ä ±ä£» Õâ ¸ö ¶¯ ×÷ ¿É ÒÔ ×÷Ϊ¶Ô ϵ ͳ ¹Ü Àí Ô± µÄ Ôç ÆÚ Ô¤ ¾¯£¬ Ô¤ ʾ ÓÐ ÈË ÔÚ ÊÔ Í¼ ¹¥ »÷ ·ÓÉÆ÷£¬ »ò Õß ÒÑ ¾­ ¹¥ Èë · ÓÉ Æ÷£¬ Õý ÔÚ ÊÔ Í¼ ¹¥ »÷ ·À »ðǽ£º

logging trap debugging

´Ë µØ Ö· ÊÇ Íø ¹Ü ¹¤ ×÷ Õ¾ µÄ ÍⲿµØ Ö·£¬ · ÓÉ Æ÷ ½« ¼Ç ¼ Ëù ÓÐ Ê ¼þ µ½ ´Ë Ö÷ »ú ÉÏ£º

logging 131.1.23.11

±£ »¤PIX ·À »ð ǽ ºÍHTTP/FTP ·þÎñÆ÷ ÒÔ ¼° ·À ÎÀ ÆÛ Æ­ ¹¥ »÷£¨ ¼û ´æ È¡ ÁÐ ±í£©£º

¡¡¡¡¡¡ enable secret xxxxxxxxxxx

¡¡¡¡¡¡ interface Ethernet 0

¡¡¡¡¡¡ ip address 131.1.23.1 255.255.255.0

¡¡¡¡¡¡ interface Serial 0

¡¡¡¡¡¡ ip unnumbered ethernet 0

¡¡¡¡¡¡ ip access-group 110 in

½û Ö¹ ÈÎ ºÎ ÏÔ Ê¾ Ϊ À´ Ô´ ÓÚ Â·ÓÉÆ÷RTRA ºÍPIX ·À »ð ǽ Ö® ¼ä µÄ ЊϢ °ü£¬ Õâ ¿É ÒÔ ·À Ö¹ ÆÛ Æ­¹¥»÷£º

access-list 110 deny ip 131.1.23.0 0.0.0.255 any log

·À Ö¹ ¶ÔPIX ·À »ð ǽ Íâ ²¿ ½Ó ¿ÚµÄÖ± ½Ó ¹¥ »÷ ²¢ ¼Ç ¼ µ½ ϵ ͳ ÈÕ Ö¾ ·þ Îñ Æ÷ ÈÎ ºÎ Æó ͼ Á¬ ½ÓPIX ·À »ð ǽ Íâ ²¿ ½Ó ¿Ú µÄ Ê ¼þ£º

access-list 110 deny ip any host 131.1.23.2 log

¡¡

ÔÊ Ðí ÒÑ ¾­ ½¨ Á¢ µÄTCP »á »° µÄÐÅÏ¢ °ü ͨ ¹ý£º

access-list 110 permit tcp any 131.1.23.0 0.0.0.255 established

ÔÊ Ðí ºÍFTP/HTTP ·þ Îñ Æ÷ µÄFTP Á¬½Ó£º

access-list 110 permit tcp any host 131.1.23.3 eq ftp

ÔÊ Ðí ºÍFTP/HTTP ·þ Îñ Æ÷ µÄFTP Êý¾Ý Á¬ ½Ó£º

access-list 110 permit tcp any host 131.1.23.2 eq ftp-data

ÔÊ Ðí ºÍFTP/HTTP ·þ Îñ Æ÷ µÄHTTP Á¬½Ó£º

access-list 110 permit tcp any host 131.1.23.2 eq www

½û Ö¹ ºÍFTP/HTTP ·þ Îñ Æ÷ µÄ ±ðµÄÁ¬ ½Ó ²¢ ¼Ç ¼ µ½ ϵ ͳ ÈÕ Ö¾ ·þ Îñ Æ÷ ÈÎ ºÎ Æó ͼ Á¬ ½ÓFTP/HTTP µÄÊ ¼þ£º

access-list 110 deny ip any host 131.1.23.2 log

ÔÊ Ðí Æä Ëû Ô¤ ¶¨ ÔÚPIX ·À »ð ǽºÍ· ÓÉ Æ÷RTRA Ö® ¼ä µÄ Á÷ Á¿£º

access-list 110 permit ip any 131.1.23.0 0.0.0.255

ÏÞ ÖÆ ¿É ÒÔ Ô¶ ³Ì µÇ ¼ µ½ ´Ë ·ÓÉÆ÷ µÄIP µØ Ö·£º

¡¡¡¡¡¡ line vty 0 4

¡¡¡¡¡¡ login

¡¡¡¡¡¡ password xxxxxxxxxx

¡¡¡¡¡¡ access-class 10 in

Ö» ÔÊ Ðí Íø ¹Ü ¹¤ ×÷ Õ¾ Ô¶ ³Ì µÇ¼µ½ ´Ë · ÓÉ Æ÷£¬ µ± Äã Ïë ´ÓInternet ¹Ü Àí ´Ë Â· ÓÉ Æ÷ ʱ£¬ Ó¦¶Ô´Ë ´æ È¡ ¿Ø ÖÆ ÁÐ ±í ½ø ÐÐ ÐÞ ¸Ä£º

access-list 10 permit ip 131.1.23.11

· ÓÉ Æ÷ RTRB

----RTRB ÊÇ ÄÚ ²¿ Íø ·À »¤ ·ÓÉÆ÷£¬ Ëü ÊÇ Äã µÄ ·À »ð ǽ µÄ ×î ºó Ò» µÀ ·À Ïߣ¬ ÊÇ ½ø Èë ÄÚ ²¿ÍøµÄ Èë ¿Ú¡£


¼Ç ¼ ´Ë · ÓÉ Æ÷ ÉÏ µÄ Ëù ÓÐ »î¶¯µ½ Íø ¹Ü ¹¤ ×÷ Õ¾ ÉÏ µÄ ÈÕ Ö¾ ·þ Îñ Æ÷£¬ °ü À¨ Åä Öà µÄ Ð޸ģº

logging trap debugging

logging 10.14.8.50

ÔÊ Ðí ͨ Ïò Íø ¹Ü ¹¤ ×÷ Õ¾ µÄ ϵͳÈÕ Ö¾ ЊϢ£º

¡¡¡¡¡¡ interface Ethernet 0

¡¡¡¡¡¡ ip address 10.10.254.2 255.255.255.0

¡¡¡¡¡¡ no ip proxy-arp

¡¡¡¡¡¡ ip access-group 110 in

¡¡¡¡¡¡ access-list 110 permit udp host 10.10.254.0 0.0.0.255

½û Ö¹ Ëù ÓÐ ±ð µÄ ´ÓPIX ·À »ð ǽ·¢À´ µÄ ЊϢ °ü£º

access-list 110 deny ip any host 10.10.254.2 log

ÔÊ Ðí ÓÊ ¼þ Ö÷ »ú ºÍ ÄÚ ²¿ ÓÊ ¼þ·þÎñ Æ÷ µÄSMTP ÓÊ ¼þ Á¬ ½Ó£º

access-list permit tcp host 10.10.254.3 10.0.0.0 0.255.255.255 eq smtp

½û Ö¹ ±ð µÄ À´ Ô´ Óë ÓÊ ¼þ ·þ ÎñÆ÷µÄ Á÷ Á¿£º

access-list deny ip host 10.10.254.3 10.0.0.0 0.255.255.255

·À Ö¹ ÄÚ ²¿ Íø Âç µÄ ÐÅ ÈÎ µØ Ö·ÆÛÆ­£º

access-list deny ip any 10.10.254.0 0.0.0.255

ÔÊ Ðí Ëù ÓÐ ±ð µÄ À´ Ô´ ÓÚPIX ·À»ðǽ ºÍ · ÓÉ Æ÷RTRB Ö® ¼ä µÄ Á÷ Á¿£º

access-list permit ip 10.10.254.0 0.0.0.255 10.0.0.0 0.255.255.255

ÏÞ ÖÆ ¿É ÒÔ Ô¶ ³Ì µÇ ¼ µ½ ´Ë ·ÓÉÆ÷ ÉÏ µÄIP µØ Ö·£º

¡¡¡¡¡¡      line vty 0 4

¡¡¡¡¡¡¡¡ login

¡¡¡¡¡¡¡¡ password xxxxxxxxxx

¡¡¡¡¡¡¡¡ access-class 10 in

Ö» ÔÊ Ðí Íø ¹Ü ¹¤ ×÷ Õ¾ Ô¶ ³Ì µÇ¼µ½ ´Ë · ÓÉ Æ÷£¬ µ± Äã Ïë ´ÓInternet ¹Ü Àí ´Ë Â· ÓÉ Æ÷ ʱ£¬ Ó¦¶Ô´Ë ´æ È¡ ¿Ø ÖÆ ÁÐ ±í ½ø ÐÐ ÐÞ ¸Ä£º

access-list 10 permit ip 10.14.8.50

----°´ ÒÔ ÉÏ Éè Öà Åä Öà ºÃPIX ·À»ðǽ ºÍ · ÓÉ Æ÷ ºó£¬PIX ·À »ð ǽ Íâ ²¿ µÄ ¹¥ »÷ Õß ½« ÎÞ ·¨ ÔÚ ÍⲿÁ¬ ½Ó ÉÏ ÕÒ µ½ ¿É ÒÔ Á¬ ½Ó µÄ ¿ª ·Å ¶Ë ¿Ú£¬ Ò² ²» ¿É ÄÜ ÅÐ ¶Ï ³öÄÚ²¿ ÈÎ ºÎ Ò» ̨ Ö÷ »ú µÄIP µØ Ö·£¬ ¼´ ʹ ¸æ Ëß ÁË ÄÚ ²¿ Ö÷ »úµÄIP µØÖ·£¬ Òª Ïë Ö± ½Ó ¶Ô Ëü ÃÇ ½ø ÐÐPing ºÍ Á¬ ½Ó Ò² ÊÇ ²» ¿É Äܵġ£ ÕâÑù ¾Í ¿É ÒÔ ¶Ô Õû ¸ö ÄÚ ²¿ Íø ½ø ÐÐ ÓРЧ µÄ ±£ »¤¡£


Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • Ò»¸ö˼¿ÆPIX·À»ðǽµÄʵ¼ÊÓ¦ÓÃÅäÖÃ
  • Cisco Secure PIX FirewallÉϵÄaliasÃüÁî
  • ÇÉÅäPIX˼¿Æ·À»ðǽ ¼Ó¹ÌÆóÒµÍøÂç
  • ˼¿ÆPIX·À»ðǽÃüÁ½âÊÍ˵Ã÷
  • ´òÔìÆóÒµ¼á¹ÌµÄ³Çǽ Cisco PIX·À»ðÇ½ÌØÊâÅäÖÃ
  • Cisco PIX·À»ðǽPPTP VPNÏà¹ØÅäÖÃ
  • ´òÔìÆóÒµ¼á¹ÌµÄ³Çǽ PIX·À»ðÇ½ÌØÊâÅäÖÃ
  • cisco pix·À»ðǽ½Ó¹ÜsmtpµÄÎÊÌâ
  • ÔÚPIX·À»ðǽÉÏʵÏÖVPNµÄÅäÖò½Öè
  • ˼¿ÆPIX·À»ðǽÉèÖÃÏê½â
  • ÁãÆðµãÅäÖÃPIX·À»ðǽ ¸ß¼¶ÅäÖÃ
  • PIX·À»ðÇ½Ð£Ô°ÍøÅäÖÃʵÀý
  • [ͼ½â]ÈçºÎÉèÖôúÀí·þÎñÆ÷£¿
  • Kerio Winroute Firewall 6.01 VPNʹÓÃÏê½â
  • Kerio WinRoute Firewall°²×°È«¹¥ÂÔ
  • Kerio Network MonitorÍêȫʹÓý̳Ì
  • CISCO PIX ·À»ðǽ¼°ÍøÂ簲ȫÅäÖÃ
  • ·ÓÉÆ÷µäÐÍ·À»ðǽÉèÖÃ
  • ¾ª±¬£¡ÌÚѶQQ2003¢óÕýʽ°æ°²È«³öÏÖ©¶´(ͼ)
  • PIX·À»ðǽϵͳ¹ÜÀí
  • Óʼþ·þÎñÆ÷Óë´úÀí·þÎñÆ÷Èí¼þÅäºÏ·½°¸
  • ÍêÕûµÄpix525ÅäÖÃ
  • ÓÃPIX¹¹ÖþͭǽÌú±Ú
  • CISCO PIX515E ·À»ðǽµÄÉèÖÃ
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ