设为首页收藏本站language 语言切换
查看: 860|回复: 0
收起左侧

求助:ASA9.1

[复制链接]
发表于 2016-4-1 22:31:11 | 显示全部楼层 |阅读模式
“http_mail”组里的用户可以访问“HTTP_POP”端口组里的端口,现在除了"FIN""IT"策略能上网以外,其他策略的允许访问端口都打不开(如WWW,pop3等)。老ASAVersion 8.2(1)就没问题
access-list inside_access_in extended permit tcp object-group http_mail any object-group HTTP_POP
access-list inside_access_in extended permit tcp object-group rs_mail any object-group POP_SMTP
access-list inside_access_in extended permit tcp object-group r_mail any object-group POP
access-list inside_access_in extended permit ip object-group weifei object-group out_weifei
access-list inside_access_in extended permit object-group HR object-group hr object-group out_hr
access-list inside_access_in extended permit tcp object-group gps object-group out_gps object-group GPS
access-list inside_access_in extended permit ip object-group fin any
access-list inside_access_in extended permit ip object-group it any
access-list inside_access_in extended permit udp object-group dns_http_server any eq domain
access-list inside_access_in extended permit tcp object-group dns_http_server any object-group DNS_HTTP
access-list out extended permit icmp any any
pager lines 24
logging enable
logging asdm informational
mtu management 1500
mtu outside 1500
mtu inside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-713.bin
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
!            
object network inside-network
nat (inside,outside) dynamic interface
access-group out in interface outside
access-group inside_access_in in interface inside
route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.1 1

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-5-15 04:48 , Processed in 0.116918 second(s), 23 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表