配置如下
ASA Version 8.2(5)
!
interface GigabitEthernet0/0
nameif outside
security-level 0
ip address 123.123.123.123 255.255.255.240
!
interface GigabitEthernet0/1
nameif ENI
security-level 0
ip address 10.6.184.11 255.255.255.248
!
interface GigabitEthernet0/2
nameif inside
security-level 100
ip address 192.168.7.254 255.255.255.0
!
interface GigabitEthernet0/3
nameif wuxian
security-level 100
ip address 192.168.8.254 255.255.255.0
!
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list ENI_access_in extended permit ip any any
access-list 7to8 extended permit icmp 192.168.7.0 255.255.255.0 192.168.8.0 255.255.255.0
access-list 7to8 extended permit ip 192.168.7.0 255.255.255.0 192.168.8.0 255.255.255.0
access-list 7to8 extended permit ip any any
access-list 8to7 extended permit icmp 192.168.8.0 255.255.255.0 192.168.7.0 255.255.255.0
access-list 8to7 extended permit ip 192.168.8.0 255.255.255.0 192.168.7.0 255.255.255.0
access-list 8to7 extended permit ip any any
access-list outside_access_in extended permit ip any any
access-list outside_access_in extended permit tcp any any
access-list ENI_nat0_outbound extended permit ip any 192.168.7.192 255.255.255.192
access-list ENI_nat0_outbound extended permit ip host neiwang 192.168.7.192 255.255.255.192
access-list ENI_nat0_outbound extended permit ip host 192.168.7.0 192.168.7.192255.255.255.192
access-list ENI_nat0_outbound extended permit ip host 192.168.8.0 192.168.7.192 255.255.255.192
access-list testvpn_splitTunnelAcl standard permit 192.168.7.0 255.255.255.0
access-list testvpn_splitTunnelAcl standard permit neiwang 255.0.0.0
access-list inside_nat0_outbound extended permit ip 192.168.7.0 255.255.255.0 192.168.3.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip neiwang 255.0.0.0 192.168.3.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip any 192.168.3.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip 192.168.7.0 255.255.255.0 192.168.7.0 255.255.255.0
access-list youxiang extended permit tcp any any eq pop3
access-list youxiang extended permit tcp any any eq smtp
access-list huochezhanvpn_splitTunnelAcl standard permit 192.168.7.0 255.255.255.0
access-list outside_nat0_outbound extended permit ip 192.168.7.0 255.255.255.0 192.168.7.0 255.255.255.0
access-list huochezhanvpn_splitTunnelAcl_1 standard permit 192.168.7.0 255.255.255.0
access-list huochezhanvpn_splitTunnelAcl_1 standard permit 192.168.8.0 255.255.255.0
access-list wuxian_nat0_outbound extended permit ip 192.168.7.0 255.255.255.0 192.168.7.128 255.255.255.128
access-list wuxian_nat0_outbound extended permit ip 192.168.8.0 255.255.255.0 192.168.7.128 255.255.255.128
pager lines 24
logging enable
logging asdm informational
mtu outside 1500
mtu ENI 1500
mtu inside 1500
mtu wuxian 1500
ip local pool vpnpool 192.168.7.150-192.168.7.200 mask 255.255.255.0
no failover
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-625-53.bin
no asdm history enable
arp inside 192.168.7.23 0016.36ce.5b54
arp timeout 14400
global (outside) 1 interface
global (ENI) 1 interface
nat (outside) 0 access-list outside_nat0_outbound
nat (ENI) 0 access-list ENI_nat0_outbound
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 192.168.7.0 255.255.255.0
nat (wuxian) 0 access-list wuxian_nat0_outbound
nat (wuxian) 1 192.168.8.0 255.255.255.0
static (inside,outside) tcp interface 3314 192.168.7.14 3389 netmask 255.255.255.255