全部博文(42)
分类: 网络与安全
2009-07-13 19:11:22
使用静态外部转换
不允许外部4.2主机访问内部网络,但可以访问DMZ
不允许外部2.2、3.2主机访问DMZ,但可以访问内部网路
PIX Version 7.2(1)
!
interface Ethernet0
nameif inside
security-level 100
ip address 172.16.1.1 255.255.255.0
!
interface Ethernet1
nameif outside
security-level 0
ip address 192.168.1.1 255.255.255.0
!
interface Ethernet2
nameif dmz
security-level 50
ip address 10.10.1.1 255.255.255.0
!
access-list 1 extended deny ip 2.2.4.0 255.255.255.0 172.16.1.0 255.255.255.0 ----拒绝4.0网段访问内网
access-list 1 extended deny ip 2.2.2.0 255.255.255.0 10.10.1.0 255.255.255.0 ----拒绝2.0网段访问DMZ
access-list 1 extended deny ip 2.2.3.0 255.255.255.0 10.10.1.0 255.255.255.0 ----拒绝3.0网段访问DMZ
access-list 1 extended permit ip 2.2.0.0 255.255.0.0 any ----允许2.2.0.0网段访问所有
static (inside,outside) 2.2.2.2 172.16.1.22 netmask 255.255.255.255 ----使外部主机2.2.2.2静态映射为内部IP地址172.16.1.22
static (inside,outside) 2.2.3.2 172.16.1.23 netmask 255.255.255.255 ----使外部主机2.2.3.2静态映射为内部IP地址172.16.1.23
static (dmz,outside) 2.2.4.2 10.10.1.22 netmask 255.255.255.255 ----使外部主机2.2.4.2静态映射为DMZ IP地址10.10.1.22
access-group 1 in interface outside
route inside 1.1.1.0 255.255.255.0 172.16.1.2 1
route outside 2.2.0.0 255.255.0.0 192.168.1.2 1
route dmz 3.3.3.0 255.255.255.0 10.10.1.2 1
pixfirewall(config)# sh xl
3 in use, 3 most used
Global 2.2.2.2 Local 172.16.1.22
Global 2.2.3.2 Local 172.16.1.23
Global 2.2.4.2 Local 10.10.1.22
pixfirewall(config)#
R1#sh run
interface Loopback0
ip address 1.1.1.1 255.255.255.0
!
interface FastEthernet0/0
ip address 172.16.1.2 255.255.255.0
duplex auto
speed auto
!
ip route 0.0.0.0 0.0.0.0 172.16.1.1
R2#sh run
interface Loopback0
ip address 2.2.2.2 255.255.255.0
!
interface Loopback1
ip address 2.2.3.2 255.255.255.0
!
interface Loopback2
ip address 2.2.4.2 255.255.255.0
!
interface FastEthernet0/0
ip address 192.168.1.2 255.255.255.0
duplex auto
speed auto
!
ip route 0.0.0.0 0.0.0.0 192.168.1.1
R3#sh run
interface Loopback0
ip address 3.3.3.3 255.255.255.0
!
interface FastEthernet0/0
ip address 10.10.1.2 255.255.255.0
duplex auto
speed auto
!
ip route 0.0.0.0 0.0.0.0 10.10.1.1