您好,登录后才能下订单哦!
发一个cisco asa5505 nat上网的基本配置.
: Saved    
: 
ASA Version 7.2(2)         
! 
hostname ASA5505        
enable password STypWFenN9FPWnMW                
names   
! 
interface Vlan1  //默认vlan      
 no nameif     
 security-level 100          
 ip address 192.168.1.1 255.255.255.0                   
! 
interface Vlan2  //内网192.168.5.0/24      
 nameif inside       
 security-level 0         
 ip address 192.168.5.1 255.255.255.0                   
! 
interface Vlan3  //外网       
 nameif outside        
 security-level 0         
 ip address 10.156.20.132 255.255.255.240                     
! 
interface Ethernet0/0           
 switchport access vlan 2             
! 
interface Ethernet0/1           
 switchport access vlan 3             
! 
interface Ethernet0/2           
 switchport access vlan 2             
! 
interface Ethernet0/3           
! 
interface Ethernet0/4           
! 
interface Ethernet0/5           
! 
interface Ethernet0/6           
! 
interface Ethernet0/7           
! 
passwd Q0j7JX5x9Y4w16J6 encrypted                 
ftp mode passive        
same-security-traffic permit inter-interface                      
access-list 101 extended permit ip 192.168.5.0 0.0.0.255 any //匹配192.168.5.0/25这个网段到any                               
access-list 101 extended permit icmp any any //匹配icmp,any to any                          
pager lines 24       
logging enable       
logging asdm informational             
mtu inside 1500        
mtu outside 1500        
icmp unreachable rate-limit 1 burst-size 1                     
asdm p_w_picpath disk0:/asdm-522.bin               
no asdm history enable           
arp timeout 14400         
global (outside) 1 interface  //全局转换地址outside             
nat (inside) 1 0.0.0.0 0.0.0.0 //转换全部inside地址              
access-group 101 in interface inside //将ACL101应用到inside区域                 
route outside 0.0.0.0 0.0.0.0 10.156.20.129 1 //默认路由                       
timeout xlate 3:00:00           
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02                                 
timeout sunrpc 0:10:00 h423 0:05:00 h325 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00                                       
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00                                        
timeout uauth 0:05:00 absolute               
username admin-fir password 2RjJaGjOpINC.T4R encrypted privilege 15                                  
http server enable         
no snmp-server location            
no snmp-server       
snmp-server enable traps snmp authentication linkup linkdown coldstart                                   
no service password-recovery              
telnet 0.0.0.0 0.0.0.0 inside  //允许inside区域any telnet              
telnet timeout 60         
ssh 0.0.0.0 0.0.0.0 inside             
ssh timeout 5             
console timeout 0         
dhcpd auto_config outside             
! 
dhcpd address 192.168.5.10-192.168.5.100 inside //dhcp服务配置                       
dhcpd dns 202.96.209.5 210.22.70.3 interface inside                          
dhcpd enable inside          
! 
! 
class-map inspection_default              
 match default-inspection-traffic                 
! 
! 
policy-map type inspect dns preset_dns_map                     
 parameters      
 message-length maximum 51             
policy-map global_policy            
 class inspection_default             
 inspect dns preset_dns_map              
 inspect ftp       
 inspect h423 h325          
 inspect h423 ras         
 inspect rsh       
 inspect rtsp       
 inspect esmtp        
 inspect sqlnet        
 inspect skinny        
 inspect sunrpc        
 inspect xdmcp        
 inspect sip       
 inspect netbios         
 inspect tftp       
! 
service-policy global_policy global                  
prompt hostname context            
Cryptochecksum:a25cde3f4cffdd2c71caacbc20c80e79                        
: end   
免责声明:本站发布的内容(图片、视频和文字)以原创、转载和分享为主,文章观点不代表本网站立场,如果涉及侵权请联系站长邮箱:is@yisu.com进行举报,并提供相关证据,一经查实,将立刻删除涉嫌侵权内容。