思科PIX防火墙VPN的配置实例

豆豆网   技术应用频道   2006年07月04日  【字号: 收藏本文

本文详细介绍思科PIX防火墙VPN的配置实例

  fixup protocol sip udp 5060

  fixup protocol skinny 2000

  fixup protocol smtp 25

  fixup protocol sqlnet 1521

  fixup protocol tftp 69

  names

  !--- This is traffic to PIX Central.

  access-list 110 permit ip 10.3.3.0 255.255.255.0 10.1.1.0 255.255.255.0

  !--- Do not do NAT on traffic to PIX Central.

  access-list 100 permit ip 10.3.3.0 255.255.255.0 10.1.1.0 255.255.255.0

  pager lines 24

  logging on

  mtu outside 1500

  mtu inside 1500

  ip address outside 172.18.124.157 255.255.255.0

  ip address inside 10.3.3.1 255.255.255.0

  ip audit info action alarm

  ip audit attack action alarm

  no failover

  failover timeout 0:00:00

  failover poll 15

  no failover ip address outside

  no failover ip address inside

  pdm history enable

  arp timeout 14400

  !--- Do not do NAT on traffic to PIX Central.

  nat (inside) 0 access-list 100

  route outside 0.0.0.0 0.0.0.0 172.18.124.1 1

  timeout xlate 3:00:00

  timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00

  timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00

  timeout uauth 0:05:00 absolute

  aaa-server TACACS+ protocol tacacs+

  aaa-server RADIUS protocol radius

  aaa-server LOCAL protocol local

  no snmp-server location

  no snmp-server contact

  snmp-server community public

  no snmp-server enable traps

  floodguard enable

  sysopt connection permit-ipsec

  crypto ipsec transform-set myset esp-des esp-md5-hmac

  !--- This is traffic to PIX Central.

  crypto map newmap 10 ipsec-isakmp

  crypto map newmap 10 match address 110

  crypto map newmap 10 set peer 172.18.124.153

  crypto map newmap 10 set transform-set myset

  crypto map newmap interface outside

  isakmp enable outside

  isakmp key ******** address 172.18.124.153 netmask 255.255.255.255

  no-xauth no-config-mode

  isakmp identity address

  isakmp policy 10 authentication pre-share

  isakmp policy 10 encryption des

  isakmp policy 10 hash md5

  isakmp policy 10 group 1

  isakmp policy 10 lifetime 1000

  telnet timeout 5

  ssh timeout 5

  console timeout 0

  terminal width 80

  Cryptochecksum:aa3bbd8c6275d214b153e1e0bc0173e4

  : end

责编:豆豆技术应用

正在加载评论...