设为首页收藏本站language 语言切换
查看: 2014|回复: 3
收起左侧

思科ASA防火墙映射问题求助~~

[复制链接]
发表于 2013-8-19 16:01:35 | 显示全部楼层 |阅读模式
ciscoasa# show run
: Saved
:
ASA Version 8.0(4)
!
hostname ciscoasa
enable password 2KFQnbNIdI.2KYOU encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Ethernet0/0
nameif outside
security-level 10
ip address 111.75.211.215 255.255.255.128
!
interface Ethernet0/1
nameif inside
security-level 100
ip address 192.168.100.1 255.255.255.0
!
interface Ethernet0/2
shutdown
no nameif
no security-level
no ip address
!
interface Ethernet0/3
shutdown
no nameif
no security-level
no ip address                         822613
!
interface Management0/0
shutdown
no nameif
no security-level
no ip address
!
ftp mode passive
access-list inside_access_in extended permit icmp any any
access-list inside_access_in extended permit ip any any
access-list inside_access_in extended permit tcp any any
access-list inside_access_in extended permit udp any any
access-list inside_nat_outbound extended permit ip 192.168.100.0 255.255.255.0 any
access-list inside_nat_outbound extended permit ip 192.168.16.0 255.255.255.0 any
access-list inside_nat_outbound extended permit ip 192.168.1.0 255.255.255.0 any
access-list outside_access_in extended permit ip any any
access-list outside_access_in extended permit ip any host 111.75.211.216
access-list outside_access_in extended permit ip any host 111.75.211.217
access-list outside_access_in extended permit tcp any host 111.75.211.215 eq www
access-list outside_access_in extended permit tcp any host 111.75.211.215 eq 808
pager lines 24
mtu outside 1500
mtu inside 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 access-list inside_nat_outbound
static (inside,outside) tcp interface www 192.168.16.210 www netmask 255.255.255.255
static (inside,outside) tcp interface 808 192.168.16.210 808 netmask 255.255.255.255
static (inside,outside) 111.75.211.216 192.168.16.250 netmask 255.255.255.255
static (inside,outside) 111.75.211.217 192.168.100.2 netmask 255.255.255.255
access-group outside_access_in in interface outside
access-group inside_access_in in interface inside
route outside 0.0.0.0 0.0.0.0 111.75.211.129 1
route inside 192.168.1.0 255.255.255.0 192.168.100.2 1
route inside 192.168.16.0 255.255.255.0 192.168.100.2 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
dynamic-access-policy-record DfltAccessPolicy
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet 0.0.0.0 0.0.0.0 inside
telnet timeout 5
ssh 0.0.0.0 0.0.0.0 outside
ssh 0.0.0.0 0.0.0.0 inside
ssh timeout 30
ssh version 1
console timeout 0

有一台防火墙ASA 5510 配置如上所示,防火墙是外网出口,下连一台交换机,交换机是三层和防火墙互联,内网用户都是192.168.16.0/24网段的,目前有一台服务器 192.168.16.193 做了映射8080 端口到外网 的808端口,外网可以正常访问内部的应用,但是如果我 在想内网输入 外网IP+端口号 确打不开,但是 内网可以,求教 还需要加什么命令吗,!!!!我记得H3C 的设备只需在内网接口下做映射就好了!!!!!!!!
 成长值: 57235
发表于 2013-8-29 18:01:58 | 显示全部楼层
如果是内网的DNS服务器就好办,你肯定用的是公网的DNS吧!
沙发 2013-8-29 18:01:58 回复 收起回复
回复 支持 反对

使用道具 举报

 楼主| 发表于 2013-9-22 09:45:14 | 显示全部楼层
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-1-31 13:50 , Processed in 0.054855 second(s), 11 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表