思科PIX防火墙VPN的配置实例

豆豆网   技术应用频道   2006年07月04日  【字号: 收藏本文

本文详细介绍思科PIX防火墙VPN的配置实例

  mtu inside 1500

  ip address outside 172.18.124.153 255.255.255.0

  ip address inside 10.1.1.1 255.255.255.0

  ip audit info action alarm

  ip audit attack action alarm

  pdm history enable

  arp timeout 14400

  !--- Do not do NAT on traffic to other PIXes.

  nat (inside) 0 access-list 100

  route outside 0.0.0.0 0.0.0.0 172.18.124.1 1

  timeout xlate 3:00:00

  timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00

  timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00

  timeout uauth 0:05:00 absolute

  aaa-server TACACS+ protocol tacacs+

  aaa-server RADIUS protocol radius

  aaa-server LOCAL protocol local

  no snmp-server location

  no snmp-server contact

  snmp-server community public

  snmp-server enable traps

  floodguard enable

  sysopt connection permit-ipsec

  crypto ipsec transform-set myset esp-des esp-md5-hmac

  !--- This is traffic to PIX 2.

  crypto map newmap 20 ipsec-isakmp

  crypto map newmap 20 match address 120

  crypto map newmap 20 set peer 172.18.124.154

  crypto map newmap 20 set transform-set myset

  !--- This is traffic to PIX 3.

  crypto map newmap 30 ipsec-isakmp

  crypto map newmap 30 match address 130

  crypto map newmap 30 set peer 172.18.124.157

  crypto map newmap 30 set transform-set myset

责编:豆豆技术应用

正在加载评论...