PIX 525 配置实例

发表于:2007-06-23来源:作者:点击数: 标签:
PIX Version 6.0(1) nameif ethernet0 outside security0 nameif ethernet1 inside security100 enable password yk/qh389FGH87k4fE encrypted passwd ju/qh3OPKB9lk6gT encrypted hostname pixfirewall domain-name xf.com fixup protocol ftp 21 fixup pro

   
  PIX Version 6.0(1)
  
  nameif ethernet0 outside security0
  
  nameif ethernet1 inside security100
  
  enable password yk/qh389FGH87k4fE encrypted
  
  passwd ju/qh3OPKB9lk6gT encrypted

  
  hostname pixfirewall
  
  domain-name xf.com
  
  fixup protocol ftp 21
  
  fixup protocol http 80
  
  fixup protocol h323 1720
  
  fixup protocol rsh 514
  
  fixup protocol smtp 25
  
  fixup protocol sqlnet 1521
  
  fixup protocol sip 5060
  
  fixup protocol skinny 2000
  
  names
  
  pager lines 24
  
  logging timestamp
  
  logging console debugging
  
  interface ethernet0 auto
  
  interface ethernet1 auto
  
  mtu outside 1500
  
  mtu inside 1500
  
  ip address outside 61.141.165.165 255.255.248.0
  
  ip address inside 192.168.166.1 255.255.255.0
  
  ip audit info action alarm
  
  ip audit attack action alarm
  
  pdm location 192.168.166.5 255.255.255.255 inside
  
  pdm history enable
  
  arp timeout 14400
  
  global (outside) 1 61.141.165.166
  
  nat (inside) 1 0.0.0.0 0.0.0.0 0 0
  
  static (inside,outside) 61.141.165.162 192.168.166.100 netmask 255.255.255.255 0 0
  
  static (inside,outside) 61.141.165.164 192.168.166.4 netmask 255.255.255.255 0 0
  
  conduit permit icmp any any
  
  conduit permit tcp host 61.141.165.162 eq www any
  
  conduit permit tcp host 61.141.165.162 eq domain any
  
  conduit permit udp host 61.141.165.162 eq domain any
  
  conduit permit tcp host 61.141.165.164 eq www any
  
  conduit permit tcp host 61.141.165.164 eq smtp any
  
  conduit permit tcp host 61.141.165.164 eq pop3 any
  
  route outside 0.0.0.0 0.0.0.0 61.141.165.161 1
  
  timeout xlate 3:00:00
  
  timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00
  
  timeout uauth 0:05:00 absolute
  
  aaa-server TACACS+ protocol tacacs+
  
  aaa-server RADIUS protocol radius
  
  http server enable
  
  http 192.168.166.5 255.255.255.255 inside
  
  no snmp-server location
  
  no snmp-server contact
  
  snmp-server community public
  
  no snmp-server enable traps
  
  floodguard enable
  
  no sysopt route dnat
  
  telnet 192.168.166.5 255.255.255.255 inside
  
  telnet timeout 35
  
  ssh timeout 5
  
  terminal width 80
  
  Cryptochecksum:f6887798da2928498fe24d39825444b9
  
  end

原文转自:http://www.ltesting.net