ÅäÖþ²Ì¬IPµØÖ··Ò루static£©£º
Èç¹û´ÓÍâÍø·¢ÆðÒ»¸ö»á»°£¬»á»°µÄÄ¿µÄµØÖ·ÊÇÒ»¸öÄÚÍøµÄipµØÖ·£¬static¾Í°ÑÄÚ²¿µØÖ··Òë³ÉÒ»¸öÖ¸¶¨µÄÈ«¾ÖµØÖ·£¬ÔÊÐíÕâ¸ö»á»°½¨Á¢¡£
staticÃüÁîÅäÖÃÓï·¨£ºstatic (internal_if_name£¬external_if_name) outside_ip_address inside_ ip_address£¬ÆäÖÐinternal_if_name±íʾÄÚ²¿ÍøÂç½Ó¿Ú£¬°²È«¼¶±ð½Ï¸ß¡£Èçinside.¡£external_if_nameΪÍâ²¿ÍøÂç½Ó¿Ú£¬°²È«¼¶±ð½ÏµÍ£¬ÈçoutsideµÈ¡£
outside_ip_addressΪÕýÔÚ·ÃÎʵĽϵͰ²È«¼¶±ðµÄ½Ó¿ÚÉϵÄipµØÖ·¡£inside_ ip_addressΪÄÚ²¿ÍøÂçµÄ±¾µØipµØÖ·¡£ ʾÀýÓï¾äÈçÏ£º
Pix525(config)#static (inside, outside) 61.144.51.62 192.168.0.8
ipµØÖ·Îª192.168.0.8µÄÖ÷»ú£¬¶ÔÓÚͨ¹ýpix·À»ðǽ½¨Á¢µÄÿ¸ö»á»°£¬¶¼±»·Òë³É61.144.51.62Õâ¸öÈ«¾ÖµØÖ·£¬Ò²¿ÉÒÔÀí½â³ÉstaticÃüÁî´´½¨ÁËÄÚ²¿ipµØÖ·192.168.0.8ºÍÍⲿipµØÖ·61.144.51.62Ö®¼äµÄ¾²Ì¬Ó³Éä¡£PIX½«°Ñ192.168.0.8Ó³ÉäΪ61.144.51.62ÒÔ±ãNAT¸üºÃµÄ¹¤×÷¡£
СÌáʾ£º
ʹÓÃstaticÃüÁî¿ÉÒÔÈÃÎÒÃÇΪһ¸öÌØ¶¨µÄÄÚ²¿ipµØÖ·ÉèÖÃÒ»¸öÓÀ¾ÃµÄÈ«¾ÖipµØÖ·¡£ÕâÑù¾ÍÄܹ»Îª¾ßÓнϵͰ²È«¼¶±ðµÄÖ¸¶¨½Ó¿Ú´´½¨Ò»¸öÈë¿Ú£¬Ê¹ËüÃÇ¿ÉÒÔ½øÈëµ½¾ßÓнϸ߰²È«¼¶±ðµÄÖ¸¶¨½Ó¿Ú¡£
¹ÜµÀÃüÁconduit£©£º
ʹÓÃstaticÃüÁî¿ÉÒÔÔÚÒ»¸ö±¾µØipµØÖ·ºÍÒ»¸öÈ«¾ÖipµØÖ·Ö®¼ä´´½¨ÁËÒ»¸ö¾²Ì¬Ó³É䣬µ«´ÓÍⲿµ½ÄÚ²¿½Ó¿ÚµÄÁ¬½ÓÈÔÈ»»á±»pix·À»ðǽµÄ×ÔÊÊÓ¦°²È«Ëã·¨(ASA)×èµ²£¬conduitÃüÁîÓÃÀ´ÔÊÐíÊý¾ÝÁ÷´Ó¾ßÓнϵͰ²È«¼¶±ðµÄ½Ó¿ÚÁ÷Ïò¾ßÓнϸ߰²È«¼¶±ðµÄ½Ó¿Ú£¬ÀýÈçÔÊÐí´ÓÍⲿµ½DMZ»òÄÚ²¿½Ó¿ÚµÄÈë·½ÏòµÄ»á»°¡£
¶ÔÓÚÏòÄÚ²¿½Ó¿ÚµÄÁ¬½Ó£¬staticºÍconduitÃüÁһÆðʹÓã¬À´Ö¸¶¨»á»°µÄ½¨Á¢¡£ËµµÃͨË×Ò»µã¹ÜµÀÃüÁconduit£©¾ÍÏ൱ÓÚÒÔÍùCISCOÉ豸µÄ·ÃÎÊ¿ØÖÆÁÐ±í£¨ACL£©¡£
conduitÃüÁîÅäÖÃÓï·¨£º
conduit permit|deny global_ip port[-port] protocol foreign_ip [netmask]£¬ÆäÖÐpermit|denyΪÔÊÐí|¾Ü¾ø·ÃÎÊ£¬global_ipÖ¸µÄÊÇÏÈǰÓÉglobal»òstaticÃüÁÒåµÄÈ«¾ÖipµØÖ·£¬Èç¹ûglobal_ipΪ0£¬¾ÍÓÃany´úÌæ0£»Èç¹ûglobal_ipÊÇһ̨Ö÷»ú£¬¾ÍÓÃhostÃüÁî²ÎÊý¡£
portÖ¸µÄÊÇ·þÎñËù×÷ÓõĶ˿ڣ¬ÀýÈçwwwʹÓÃ80£¬smtpʹÓÃ25µÈµÈ£¬ÎÒÃÇ¿ÉÒÔͨ¹ý·þÎñÃû³Æ»ò¶Ë¿ÚÊý×ÖÀ´Ö¸¶¨¶Ë¿Ú¡£protocolÖ¸µÄÊÇÁ¬½ÓÐÒ飬±ÈÈ磺TCP¡¢UDP¡¢ICMPµÈ¡£foreign_ip±íʾ¿É·ÃÎÊglobal_ipµÄÍⲿip¡£¶ÔÓÚÈÎÒâÖ÷»ú¿ÉÒÔÓÃany±íʾ¡£Èç¹ûforeign_ipÊÇһ̨Ö÷»ú£¬¾ÍÓÃhostÃüÁî²ÎÊý¡£Ê¾ÀýÓï¾äÈçÏ£º
Pix525(config)#conduit permit tcp host 192.168.0.8 eq www any
±íʾÔÊÐíÈκÎÍⲿÖ÷»ú¶ÔÈ«¾ÖµØÖ·192.168.0.8µÄÕą̂Ö÷»ú½øÐÐhttp·ÃÎÊ¡£ÆäÖÐʹÓÃeqºÍÒ»¸ö¶Ë¿ÚÀ´ÔÊÐí»ò¾Ü¾ø¶ÔÕâ¸ö¶Ë¿ÚµÄ·ÃÎÊ¡£Eq ftp¾ÍÊÇÖ¸ÔÊÐí»ò¾Ü¾øÖ»¶ÔftpµÄ·ÃÎÊ¡£
Pix525(config)#conduit deny tcp any eq ftp host 61.144.51.89
ÉèÖò»ÔÊÐíÍⲿÖ÷»ú61.144.51.89¶ÔÈκÎÈ«¾ÖµØÖ·½øÐÐftp·ÃÎÊ¡£
Pix525(config)#conduit permit icmp any any
ÉèÖÃÔÊÐíicmpÏûÏ¢ÏòÄÚ²¿ºÍÍⲿͨ¹ý¡£
Pix525(config)#static (inside, outside) 61.144.51.62 192.168.0.3 Pix525(config)#conduit permit tcp host 61.144.51.62 eq www any
ÕâÁ½¾äÊǽ«staticºÍconduitÓï¾ä½áºÏ¶øÉúЧµÄ£¬192.168.0.3ÔÚÄÚÍøÊÇһ̨web·þÎñÆ÷£¬ÏÖÔÚÏ£ÍûÍâÍøµÄÓû§Äܹ»Í¨¹ýpix·À»ðǽµÃµ½web·þÎñ¡£ËùÒÔÏÈ×östatic¾²Ì¬Ó³Éä°ÑÄÚ²¿IP192.168.0.3ת»»ÎªÈ«¾ÖIP61.144.51.62£¬È»ºóÀûÓÃconduitÃüÁîÔÊÐíÈκÎÍⲿÖ÷»ú¶ÔÈ«¾ÖµØÖ·61.144.51.62½øÐÐhttp·ÃÎÊ¡£
СÌáʾ£º
¶ÔÓÚÉÏÃæµÄÇé¿ö²»Ê¹ÓÃconduitÓï¾äÉèÖÃÈÝÐí·ÃÎʹæÔòÊDz»¿ÉÒԵģ¬ÒòΪĬÈÏÇé¿öÏÂPIX²»ÈÝÐíÊý¾Ý°üÖ÷¶¯´ÓµÍ°²È«¼¶±ðµÄ¶Ë¿ÚÁ÷Ïò¸ß°²È«¼¶±ðµÄ¶Ë¿Ú¡£
ÅäÖÃfixupÐÒ飺
fixupÃüÁî×÷ÓÃÊÇÆôÓ㬽ûÖ¹£¬¸Ä±äÒ»¸ö·þÎñ»òÐÒéͨ¹ýpix·À»ðǽ£¬ÓÉfixupÃüÁîÖ¸¶¨µÄ¶Ë¿ÚÊÇpix·À»ðǽҪÕìÌýµÄ·þÎñ¡£Ê¾ÀýÀý×ÓÈçÏ£º
Pix525(config)#fixup protocol ftp 21
ÆôÓÃftpÐÒ飬²¢Ö¸¶¨ftpµÄ¶Ë¿ÚºÅΪ21
Pix525(config)#fixup protocol http 80
Pix525(config)#fixup protocol http 1080
ΪhttpÐÒéÖ¸¶¨80ºÍ1080Á½¸ö¶Ë¿Ú¡£
Pix525(config)#no fixup protocol smtp 80
½ûÓÃsmtpÐÒé¡£
ÉèÖÃtelnet£º
ÔÚpix5.0֮ǰֻÄÜ´ÓÄÚ²¿ÍøÂçÉϵÄÖ÷»úͨ¹ýtelnet·ÃÎÊpix¡£ÔÚpix 5.0¼°ºóÐø°æ±¾ÖУ¬¿ÉÒÔÔÚËùÓеĽӿÚÉÏÆôÓÃtelnetµ½pixµÄ·ÃÎÊ¡£µ±´ÓÍⲿ½Ó¿ÚÒªtelnetµ½pix·À»ðǽʱ£¬telnetÊý¾ÝÁ÷ÐèÒªÓÃipsecÌṩ±£»¤£¬Ò²¾ÍÊÇ˵Óû§±ØÐëÅäÖÃpixÀ´½¨Á¢Ò»Ìõµ½ÁíÍâһ̨pix£¬Â·ÓÉÆ÷»òvpn¿Í»§¶ËµÄipsecËíµÀ¡£ÁíÍâ¾ÍÊÇÔÚPIXÉÏÅäÖÃSSH£¬È»ºóÓÃSSH client´ÓÍⲿtelnetµ½PIX·À»ðǽ¡£
ÎÒÃÇ¿ÉÒÔʹÓÃtelnetÓï¾ä¹ÜÀíµÇ¼PIXµÄȨÏÞ£¬telnetÅäÖÃÓï·¨£ºtelnet local_ip [netmask] local_ip ±íʾ±»ÊÚȨͨ¹ýtelnet·ÃÎʵ½pixµÄipµØÖ·¡£Èç¹û²»Éè´ËÏpixµÄÅäÖ÷½Ê½Ö»ÄÜÓÉconsole½øÐС£Ò²¾ÍÊÇ˵ĬÈÏÇé¿öÏÂÖ»ÓÐͨ¹ýconsole¿Ú²ÅÄÜÅäÖÃPIX·À»ðǽ¡£
СÌáʾ£º
ÓÉÓÚ¹ÜÀíPIX¾ßÓÐÒ»¶¨µÄΣÏÕÐÔ£¬ÐèÒªµÄ°²È«¼¶±ð·Ç³£¸ß£¬ËùÒÔ²»½¨Òé´ó¼Ò¿ª·ÅÌṩÍâÍøIPµÄtelnet¹ÜÀíPIXµÄ¹¦ÄÜ¡£Èç¹ûʵ¼ÊÇé¿öÒ»¶¨ÒªÍ¨¹ýÍâÍøIP¹ÜÀíPIXÔòʹÓÃSSH¼ÓÃÜÊÖ¶ÎÀ´Íê³É¡£
×ܽ᣺
ͨ¹ýÁù¸ö»ù±¾ÃüÁîºÍËĸö¸ß¼¶ÃüÁîÎÒÃǾͿÉÒÔºÏÀíÅäÖÃPIXÉ豸£¬¶ÔÓÚÆäËû¹«Ë¾µÄPIXÅäÖÃÃüÁîÎÒÃÇÒ²¿ÉÒÔÒ»¾ä¾äµÄ¿´¶®ÁË¡£ÏÂһƪÎÒÃǾÍΪ´ó¼Ò³ÊÏÖÒ»Ì×PIXµÄÅäÖÃʵÀý£¬¶ÔÓڹؼüµØ·½½«Îª´ó¼Ò¼ÓÉÏ×¢ÊÍ¡£Ï£Íû¸÷λ¶ÁÕßÕæÕýÕÆÎÕÿÌõÓï¾ä¡£
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |