如题所述
é²ç«å¢æ¥å£å¯ä»¥åé
ç¸åçå®å
¨çº§å«ï¼å
许æ¥å£é´çæµéäºéã
建ç«è¿æ¥
1ãé ç½®æ¥å£åä½
ï¼1ï¼æ¡ä»¶ï¼æ¥å£å¿ é¡»è¿è¡ç¸åçåè½ï¼insideæoutsideï¼
è¿æ¥å°åä¸ä¸ªç½ç»
å ¶ä¸ä» æä¸ä¸ªæ¥å£å¤äºactiveç¶æï¼å¦å¤ä¸ä¸ªæ¥å£å¤äºstandbyç¶æï¼ä¸ä½activeæ¥å£ä¸§å¤±é¾è·¯ç¶æ并
åæ¢å·¥ä½ï¼standbyæ¥å£ç«å³æ¿æ´»å¹¶æ¥ç®¡ä¼ è¾æ°æ®çå·¥ä½
两个æ¥å£å¿ 须为åä¸ç±»åï¼10ã100ã1000以太ç½æ¥å£ï¼
ï¼2ï¼é ç½®é»è¾åä½æ¥å£
interface redundant 1 é ç½®ä¸ä¸ªredundantèææ¥å£
member-interface ethernet0/1 å å ¥æ¥å£æå
member-interface ethernet0/2 å å ¥æ¥å£æå
no shutdown å¼å¯ç«¯å£
show interface redundant 1 æ¥çredundantæ¥å£ç¶æ
注ï¼é ç½®æ¥å£ç顺åºé常éè¦ï¼ç¬¬ä¸ä¸ªæ·»å å°é»è¾åä½æ¥å£çç©çæ¥å£ä½ä¸ºactiveï¼æ¥å£è¿éç¨ç¬¬ä¸ä¸ªå å ¥
æ¥å£çMACå°åï¼ä¸ç®¡åªä¸ªç©çæ¥å£å¤äºactiveç¶æï¼é½æ¯ç¨åæ ·çMACå°å
æ¥å£åæ¢æ¶æ¶é´å¾çï¼åªæç³»ç»æ¥å¿éå¯ä»¥æ¥è¯¢ debug redundant å½ä»¤æ¥çæ§åæ¢è¿ç¨
ï¼3ï¼é»è®¤æ åµä¸æ¥å£ä¸ºadministrator down
ï¼4ï¼å®ä¹ä¸ä¸ªé»è¾VLANæ¥å£
interface vlan 1 å®ä¹é»è¾VLAN
interface e0/1 vlan 1 logical é ç½®e0/1为é»è¾æ¥å£
interface e0/1.1 å®ä¹åæ¥å£
vlan 1 é ç½®æ¥å£å°VLAN1
(5)ç©çæ¥å£é ç½®
nameif outside å®ä¹æ¥å£ä¸ºoutbound
security-level 30 å®ä¹æ¥å£å®å ¨çº§å«ä¸º30
ip address é ç½®IPå°å
ip address outside dhcp [setroute] [retry]é ç½®æ¥å£éè¿DHCPè·å¾å°åï¼
setroute å¨dhcpåºçè¿åçé»è®¤ç½å ³åæ°ä¸è®¾ç½®é²ç«å¢çé»è®¤è·¯ç±
retry é ç½®éè¯è¯·æ±ç次æ°ã
(6)å¦ä½ä½¿æ¥å£å¯ä»¥æ¥æç¸åçå®å ¨çº§å«
same-security-traffic permit inter-interface
é ç½® arpé«éç¼å
1ãå®ä¹éæARP表项
arp outside 1.1.1.1 0000.1111.1111.1111 alias outside表æå¨outsideæ¥å£ä¸
å¯ä»¥æ¾å°ä¸»æº
2ã设置ARPæç»å®æ¶å¨ï¼é»è®¤æ åµä¸ä¿ææ¶é´4å°æ¶ï¼
arp timeout seconds 60
show arp statistics æ¾ç¤ºarp计æ¶å¨
精确å¶å®å ¥ç«ACL
æä½³åæ³å»ºè®®ä»»ä½å ¥ç«è®¿é®å¿ é¡»æ¢äºä¸ç«åºï¼DMZï¼é²ç«å¢æ¥å£ä¸ç主æºï¼èä¸æ¯å ç½ç½ç»ä¸ç主æº
åºç«æµéï¼å é¨ç¨æ·é常æ¯å·²ç¥çåä¿¡ä»»çï¼å¯ä»¥å¼æ¾åºç«è®¿é®ï¼ä½æä½³åæ³å»ºè®®é ç½®åºç«è®¿é®å表ï¼
以é²æ¢å é¨ç½ç»ç主æºåä¸é对DMZæå¤é¨ç½ç»çè è«ææ»å»
é²ç«å¢æµéçæµæµç¨
æ°æ®å --åå§æ ¡éª--Xlateæ£æ¥--è¿æ¥æ¥æ¾--ACLæ¥æ¾--Xlateæ¥æ¾--ç¨æ·éªè¯æ¥æ¾--æ£æµå¼æ--æ°æ®å
æ¥å£X ä» ä¸ºåºç« ä» ä¸ºå ¥ç« æ¥å£Y
é²ç«å¢ç¹æ§å许å¯è¯
å½é²ç«å¢è¿è¡ä¸ä¸ªæä½ç³»ç»çéåæ¶ï¼å¿ é¡»æåéç许å¯è¯æ¿æ´»å¯é¥æ¥è§£éæéè¦çç¹æ§ã
show version æ¥çé²ç«å¢ç¹æ§
asa5510åasa5505ä¸æ¯æfailoverï¼å¯ä»¥éè¿è®¸å¯è¯æ¥æ¿æ´»ï¼
建ç«è¿æ¥
1ãé ç½®æ¥å£åä½
ï¼1ï¼æ¡ä»¶ï¼æ¥å£å¿ é¡»è¿è¡ç¸åçåè½ï¼insideæoutsideï¼
è¿æ¥å°åä¸ä¸ªç½ç»
å ¶ä¸ä» æä¸ä¸ªæ¥å£å¤äºactiveç¶æï¼å¦å¤ä¸ä¸ªæ¥å£å¤äºstandbyç¶æï¼ä¸ä½activeæ¥å£ä¸§å¤±é¾è·¯ç¶æ并
åæ¢å·¥ä½ï¼standbyæ¥å£ç«å³æ¿æ´»å¹¶æ¥ç®¡ä¼ è¾æ°æ®çå·¥ä½
两个æ¥å£å¿ 须为åä¸ç±»åï¼10ã100ã1000以太ç½æ¥å£ï¼
ï¼2ï¼é ç½®é»è¾åä½æ¥å£
interface redundant 1 é ç½®ä¸ä¸ªredundantèææ¥å£
member-interface ethernet0/1 å å ¥æ¥å£æå
member-interface ethernet0/2 å å ¥æ¥å£æå
no shutdown å¼å¯ç«¯å£
show interface redundant 1 æ¥çredundantæ¥å£ç¶æ
注ï¼é ç½®æ¥å£ç顺åºé常éè¦ï¼ç¬¬ä¸ä¸ªæ·»å å°é»è¾åä½æ¥å£çç©çæ¥å£ä½ä¸ºactiveï¼æ¥å£è¿éç¨ç¬¬ä¸ä¸ªå å ¥
æ¥å£çMACå°åï¼ä¸ç®¡åªä¸ªç©çæ¥å£å¤äºactiveç¶æï¼é½æ¯ç¨åæ ·çMACå°å
æ¥å£åæ¢æ¶æ¶é´å¾çï¼åªæç³»ç»æ¥å¿éå¯ä»¥æ¥è¯¢ debug redundant å½ä»¤æ¥çæ§åæ¢è¿ç¨
ï¼3ï¼é»è®¤æ åµä¸æ¥å£ä¸ºadministrator down
ï¼4ï¼å®ä¹ä¸ä¸ªé»è¾VLANæ¥å£
interface vlan 1 å®ä¹é»è¾VLAN
interface e0/1 vlan 1 logical é ç½®e0/1为é»è¾æ¥å£
interface e0/1.1 å®ä¹åæ¥å£
vlan 1 é ç½®æ¥å£å°VLAN1
(5)ç©çæ¥å£é ç½®
nameif outside å®ä¹æ¥å£ä¸ºoutbound
security-level 30 å®ä¹æ¥å£å®å ¨çº§å«ä¸º30
ip address é ç½®IPå°å
ip address outside dhcp [setroute] [retry]é ç½®æ¥å£éè¿DHCPè·å¾å°åï¼
setroute å¨dhcpåºçè¿åçé»è®¤ç½å ³åæ°ä¸è®¾ç½®é²ç«å¢çé»è®¤è·¯ç±
retry é ç½®éè¯è¯·æ±ç次æ°ã
(6)å¦ä½ä½¿æ¥å£å¯ä»¥æ¥æç¸åçå®å ¨çº§å«
same-security-traffic permit inter-interface
é ç½® arpé«éç¼å
1ãå®ä¹éæARP表项
arp outside 1.1.1.1 0000.1111.1111.1111 alias outside表æå¨outsideæ¥å£ä¸
å¯ä»¥æ¾å°ä¸»æº
2ã设置ARPæç»å®æ¶å¨ï¼é»è®¤æ åµä¸ä¿ææ¶é´4å°æ¶ï¼
arp timeout seconds 60
show arp statistics æ¾ç¤ºarp计æ¶å¨
精确å¶å®å ¥ç«ACL
æä½³åæ³å»ºè®®ä»»ä½å ¥ç«è®¿é®å¿ é¡»æ¢äºä¸ç«åºï¼DMZï¼é²ç«å¢æ¥å£ä¸ç主æºï¼èä¸æ¯å ç½ç½ç»ä¸ç主æº
åºç«æµéï¼å é¨ç¨æ·é常æ¯å·²ç¥çåä¿¡ä»»çï¼å¯ä»¥å¼æ¾åºç«è®¿é®ï¼ä½æä½³åæ³å»ºè®®é ç½®åºç«è®¿é®å表ï¼
以é²æ¢å é¨ç½ç»ç主æºåä¸é对DMZæå¤é¨ç½ç»çè è«ææ»å»
é²ç«å¢æµéçæµæµç¨
æ°æ®å --åå§æ ¡éª--Xlateæ£æ¥--è¿æ¥æ¥æ¾--ACLæ¥æ¾--Xlateæ¥æ¾--ç¨æ·éªè¯æ¥æ¾--æ£æµå¼æ--æ°æ®å
æ¥å£X ä» ä¸ºåºç« ä» ä¸ºå ¥ç« æ¥å£Y
é²ç«å¢ç¹æ§å许å¯è¯
å½é²ç«å¢è¿è¡ä¸ä¸ªæä½ç³»ç»çéåæ¶ï¼å¿ é¡»æåéç许å¯è¯æ¿æ´»å¯é¥æ¥è§£éæéè¦çç¹æ§ã
show version æ¥çé²ç«å¢ç¹æ§
asa5510åasa5505ä¸æ¯æfailoverï¼å¯ä»¥éè¿è®¸å¯è¯æ¥æ¿æ´»ï¼
温馨提示:答案为网友推荐,仅供参考