您的位置:程序门 -> 硬件使用 -> 网络设计与维护



急急急!! 思科防火墙-pix-506e配置总是不成功,请高手指点


[收藏此页] [打印本页]选择字色:背景色:字体:[][][]


急急急!! 思科防火墙-pix-506e配置总是不成功,请高手指点
发表于:2007-04-12 22:33:16 楼主
由交换机分配了一个外网地址:
172.150.64.2
现在需要   192.168.1.*网段的机器都能访问internet

我直接把地址172.150.64.2设置到pc是可以上网的  

我的配置参数如下:

pix   version   6.3(5)
interface   ethernet0   auto
interface   ethernet1   auto
nameif   ethernet0   outside   security0
nameif   ethernet1   inside   security100
enable   password   8ry2yjiyt7rrxu24   encrypted
passwd   2kfqnbnidi.2kyou   encrypted
hostname   pixfirewall
domain-name   ciscopix.com
fixup   protocol   dns   maximum-length   512
fixup   protocol   ftp   21
fixup   protocol   h323   h225   1720
fixup   protocol   h323   ras   1718-1719
fixup   protocol   http   80
fixup   protocol   rsh   514
fixup   protocol   rtsp   554
fixup   protocol   sip   5060
fixup   protocol   sip   udp   5060
fixup   protocol   skinny   2000
fixup   protocol   smtp   25
fixup   protocol   sqlnet   1521
fixup   protocol   tftp   69
names
pager   lines   24
mtu   outside   1500
mtu   inside   1500
ip   address   outside   172.150.64.3   255.255.255.0
ip   address   inside   192.168.1.1   255.255.255.0
ip   audit   info   action   alarm
ip   audit   attack   action   alarm
pdm   logging   informational   100
pdm   history   enable
arp   timeout   14400
global   (outside)   1   172.150.64.2
nat   (inside)   1   0.0.0.0   0.0.0.0   0   0
route   outside   0.0.0.0   0.0.0.0   172.150.64.2   1
timeout   xlate   0:05:00
timeout   conn   1:00:00   half-closed   0:10:00   udp   0:02:00   rpc   0:10:00   h225   1:00:00
timeout   h323   0:05:00   mgcp   0:05:00   sip   0:30:00   sip_media   0:02:00
timeout   sip-disconnect   0:02:00   sip-invite   0:03:00
timeout   uauth   0:05:00   absolute
aaa-server   tacacs+   protocol   tacacs+
aaa-server   tacacs+   max-failed-attempts   3
aaa-server   tacacs+   deadtime   10
aaa-server   radius   protocol   radius
aaa-server   radius   max-failed-attempts   3
aaa-server   radius   deadtime   10
aaa-server   local   protocol   local
http   server   enable
http   192.168.1.0   255.255.255.0   inside
no   snmp-server   location
no   snmp-server   contact
snmp-server   community   public
no   snmp-server   enable   traps
floodguard   enable
telnet   192.168.1.0   255.255.255.0   inside
telnet   timeout   5
ssh   timeout   5
console   timeout   0
dhcpd   lease   3600
dhcpd   ping_timeout   750
terminal   width   80
cryptochecksum:275cded34a2d78b3698b5aefbf0a404d
:   end
发表于:2007-12-28 17:56:091楼 得分:0
怎么不见你激活啊,no   sh
发表于:2007-12-28 17:57:122楼 得分:0
不要忘记配置好后要激活,要不然所有的配置是米用的
发表于:2007-12-30 14:14:563楼 得分:0
inside和outside都设啦auto,内部口是默认激活的,但是外部口要手动激活的


快速检索

最新资讯
热门点击