pixfirewall(config)# sh run
PIX Version 7.2(1)
!
interface Ethernet0
nameif inside
security-level 100
ip address 172.16.1.1 255.255.255.0
!
interface Ethernet1
nameif outside
security-level 0
ip address 192.168.1.1 255.255.255.0
!
interface Ethernet2
nameif dmz
security-level 50 ----定义dmz区域安全级别为50
ip address 10.10.1.1 255.255.255.0
!
access-list 1 extended permit ip any any
access-list 2 extended permit ip any any
static (inside,outside) 192.168.1.100 172.16.1.2 netmask 255.255.255.255 ----inside ip地址172.16.1.2静态转换为outside ip地址192.168.1.100,实现内网访问外网
static (dmz,outside) 192.168.1.200 10.10.1.2 netmask 255.255.255.255 ----dmz ip地址10.10.1.2静态转换为outside ip地址192.168.1.200,实现dmz访问外网
static (dmz,inside) 172.16.1.200 10.10.1.2 netmask 255.255.255.255 ----dmz ip地址10.10.1.2静态转换为inside ip地址172.16.1.200,实现dmz访问内网
access-group 1 in interface outside ----内网访问外网时,返回数据包被允许进入
access-group 2 in interface dmz ----dmz访问内网时,返回数据包被允许进入
route inside 1.1.1.0 255.255.255.0 172.16.1.2 1
route outside 2.2.2.0 255.255.255.0 192.168.1.2 1
route dmz 3.3.3.0 255.255.255.0 10.10.1.2 1
R1#sh run
interface Loopback0
ip address 1.1.1.1 255.255.255.0
!
interface FastEthernet0/0
ip address 172.16.1.2 255.255.255.0
duplex auto
speed auto
ip route 0.0.0.0 0.0.0.0 172.16.1.1
R2#sh run
interface Loopback0
ip address 2.2.2.2 255.255.255.0
!
interface FastEthernet0/0
ip address 192.168.1.2 255.255.255.0
duplex auto
speed auto
ip route 0.0.0.0 0.0.0.0 192.168.1.1
R3#sh run
interface Loopback0
ip address 3.3.3.3 255.255.255.0
!
interface FastEthernet0/0
ip address 10.10.1.2 255.255.255.0
duplex auto
speed auto
ip route 0.0.0.0 0.0.0.0 10.10.1.1
show:
pixfirewall(config)# show xlate ----查看转换槽
3 in use, 5 most used
Global 192.168.1.100 Local 172.16.1.2
Global 192.168.1.200 Local 10.10.1.2
Global 172.16.1.200 Local 10.10.1.2
pixfirewall(config)# clear xlate ----清空转换槽
阅读(484) | 评论(0) | 转发(0) |