- 积分
- 700
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 40
- 听众
- 收听
中级工程师
   
|
ciscoasa# show run
: Saved
:
ASA Version 8.2(5)
!
hostname ciscoasa
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Vlan1
nameif inside
security-level 100
ip address 10.65.108.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address 58.247.76.XXX 255.255.255.252
!
ftp mode passive
access-list vpn extended permit ip 10.65.108.0 255.255.255.0 10.65.106.0 255.255.255.0
access-list nonat extended permit ip 10.65.108.0 255.255.255.0 10.65.106.0 255.255.255.0
access-list 100 extended permit icmp any any
access-list 100 extended permit ip any any
pager lines 24
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
icmp permit any inside
icmp permit any outside
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list nonat
nat (inside) 1 0.0.0.0 0.0.0.0
access-group 100 in interface outside
route outside 0.0.0.0 0.0.0.0 58.247.76.XXX 1
http server enable
http 0.0.0.0 0.0.0.0 inside
http 10.65.108.0 255.255.255.0 inside
telnet 0.0.0.0 0.0.0.0 inside
telnet timeout 5
ssh 0.0.0.0 0.0.0.0 inside
ssh 0.0.0.0 0.0.0.0 outside
ssh timeout 20
ssh version 2
console timeout 0
dhcpd dns 208.67.222.222 8.8.8.8
dhcpd auto_config outside
!
dhcpd address 10.65.108.90-10.65.108.180 inside
dhcpd lease 7200 interface inside
dhcpd enable inside
!
webvpn
enable outside
username sslvpn password bzN3HgmMqoLp3Liy encrypted
tunnel-group 116.236.238.XXX type ipsec-l2l
tunnel-group 116.236.238.XXX ipsec-attributes
pre-shared-key *****
配置大概如上,为什么我在外网SSH连不上设备,但telnet 它的22端口是通的。设备是ASA 5505 IOS 8.2.
请问哪里有不对的地方吗?
|
|