·¢²¼Ê±¼ä : ÐÇÆÚÈý ÎÄÕÂGNS3Ä£ÄâASA·À»ðǽ¸üÐÂÍê±Ï¿ªÊ¼ÔĶÁ
ÈçÔÊÐíÍâÍøÍø¶ÎΪ172.16.16.0/24·ÃÎÊÄÚÍøÖ÷»ú10.1.1.1
2> ÔÊÐí³öÕ¾Á¬½ÓµÄÁ÷Á¿
Èç½ûÖ¹ÄÚÍø10.1.1.0/24·ÃÎÊÍâÍø
5¡¢ ÅäÖþ²Ì¬Â·ÓÉ
Óï·¨¸ñʽ£º
(config)#route ½Ó¿ÚÃû network mask next-hop-address
ÈçÔÚASAÍø¹ØÉ豸ÉÏÅäÖÃÒ»ÌõĬÈÏ·ÓÉ£¬Á¬½ÓÍâÍø£¨ISPµÄIPΪ10.0.0.1/24£©
²é¿´Â·ÓÉ±í£º #show route
6¡¢ ÆäËûÅäÖÃ
1> ICMPÐÒé
ĬÈÏÇé¿öÏ£¬ASA·À»ðǽ½ûÖ¹ICMP±¨ÎÄͨ¹ý£¬Èç¹ûÏëÒªÄÜͨ¹ý£¬¿ÉÒÔͨ¹ý½¨Á¢ACLÀ´¿ØÖÆ
2> ÆäËûÅäÖÃÃüÁî
£¨1£© ±£´ærunning configurationµ½startup configuration #write memory »òÕß
#copy running-config startup-config
ÓÉÓÚGNS3Ä£ÄâÆ÷Ä£ÄâASA·À»ðǽʱFlash¿Õ¼äÖ»ÓÐ256KB£¬ËùÒÔÕâÌõÃüÁîÅäÖÃʱ»á±¨´í¡£µ±È»ÄãÒ²¿ÉÒÔ»»µôFlash£¬¶øʹÃüÁî²»»á±¨´í¡£ £¨2£© Çå³ýrunning configurationµÄËùÓÐÅäÖà (config)#clear configure all
£¨3£© Çå³ýrunning configurationÖÐÖ¸¶¨ÃüÁîµÄÅäÖà (config)#clear configure ÃüÁî ÀýÈçÇå³ýËùÓÐaccess-list
£¨4£© ɾ³ýstartup-configÅäÖÃÎļþ #write erase
ËÄ¡¢¶à°²È«ÇøÓò
1¡¢ DMZÇøÓò¸ÅÊö
1> DMZµÄ¸ÅÄîºÍ×÷ÓÃ
DMZ³ÉΪ¸ôÀëÇø£¬Ò²³ÉΪ·Ç¾üÊ»¯Çø£¬Î»ÓÚÆóÒµÄÚ²¿ÍøÂçºÍÍⲿÍøÂçÖ®¼äµÄÒ»¸öÍøÂçÇøÓò¡£ÔÚÕâ¸öÇøÓòÄÚ¿ÉÒÔ·ÅÖÃһЩ±ØÐ빫¿ªµÄ·þÎñÆ÷¡£ ËùÒÔDMZÇøÓòÒ»°ãÊÇÖ¸·þÎñÆ÷ËùÔÚµÄÇøÓò 2> ĬÈϵķÃÎʹæÔò
ĬÈϵķÃÎʹæÔò¼´Îª°²È«¼¶±ð¸ßµÄ¿ÉÒÔ·ÃÎÊ°²È«¼¶±ðµÍµÄ£¬¶øͬÖÖ°²È«¼¶±ð½ûÖ¹·ÃÎÊ¡£DMZ´¦ÓÚinsideºÍoutsideÖ®¼äµÄ°²È«¼¶±ð£¬ËùÒÔ¾ßÌå˼·ÐèÒª×Ô¼ºÀí½â¡£
ÔÚÅäÖõÄʱºò£¬¿ÉÒÔ½«½Ó¿ÚÃû×Ö¸ÄΪdmz£¨ÆäËûÒ²¿É£¬¾ÍÊǸö±ê¼Ç£©£¬°²È«¼¶±ðÔÚinsideºÍoutsideÖ®¼ä¼´¿É
Îå¡¢ÅäÖÃʵÀý
Èçͼ£º
¡úÎÒËùÓеÄÉ豸¶¼ÊÇÓ÷ÓÉÆ÷Ä£Ä⣨³ýASA·À»ðǽ£© ¡úIPµØÖ·¼°ÆäËûÈçͼËùʾ
¡úÅäÖÃinsideÇøÓò¿ÉÒÔpingͨÍâÍø
¡úÅäÖÃĬÈÏ·Óɺ;²Ì¬Â·ÓÉ£¬Ê¹È«Íø»¥Í¨ £¨1£© ÔÚDevelopÉÏÅäÖà ¡úÅäÖÃIPµØÖ·ºÍĬÈÏ·ÓÉ
¡ú¿ªÆôtelnetÔ¶³ÌµÇ¼£¬ÒÔ±ãÉÔºó²âÊÔ
£¨2£© ÔÚOtherÉÏÅäÖÃ
¡úÓëDevelopÅäÖÃÀàËÆ£¬ÅäÖÃIPºÍ·ÓÉ£¬Í¬Ê±¿ªÆôÔ¶³ÌµÇ¼
£¨3£© ÔÚServerÉÏÅäÖà ¡úÓëÉÏÊöÀàËÆ
£¨4£© ÔÚISPÉÏÅäÖÃ
¡úÅäÖÃIPµØÖ·ºÍ·Óɼ´¿É
£¨5£© ÔÚInternetÉÏÅäÖÃ
¡úÅäÖÃIPµØÖ·ºÍÍø¹Ø£¬Í¬Ê±ÅäÖÃtelnetÔ¶³ÌµÇ¼
£¨6£© ÔÚASA1ÉÏÅäÖÃ
¡ú»®·Ö¸÷¸öÇøÓòºÍÅäÖÃIPµØÖ·
¡úÅäÖÃÏòÍâµÄĬÈÏ·ÓɺÍÏòÄڵľ²Ì¬Â·ÓÉ
¡úÅäÖÃACL£¬ÔÊÐíÄÚÍøpingͨÍâÍø
¡úÅäÖÃÍâÍø¿ÉÒÔ·ÃÎÊÄÚ²¿·þÎñÆ÷£¨Ä£ÄâÍâÍø¿ÉÒÔtelnetµ½·þÎñÆ÷£©
£¨7£© ÑéÖ¤
¡úÄÚÍø£¨Develop£©¿ÉÒÔpingͨÍâÍø£¨Internet£©
¡úinsideÇøÓò¿ÉÒÔ·ÃÎÊDMZÇøÓò
¡úÍâÍø£¨Internet£©¿ÉÒÔ·ÃÎÊ·þÎñÆ÷£¨Server£©£¬Ê¹ÓÃtelnetÄ£Äâ