【正文】
ide//對(duì)內(nèi)啟用ASDM連接accesslist acl_out extended permit tcp any any eq //允許tcp協(xié)議80端口入站accesslist acl_out extended permit tcp any any eq //允許tcp協(xié)議443端口入站accesslist acl_out extended permit tcp any host eq ftp//accesslist acl_out extended permit tcp any host eq 3389//accesslist acl_out extended permit tcp any host eq 1433//accesslist acl_out extended permit tcp any host eq 8080//asa5505(config)show accesslist//驗(yàn)證配置asa5505(config)route dmz 1//asa5505(config)route outside 1//asa5505 show route//顯示路由信息asa5505(config) static (inside,outside) netmask //asa5505(config)accesslist acl_out extended permit icmp any any//控制列表名acl_out允許ICMP協(xié)議asa5505(config)accessgroup acl_out in interface outside//控制列表acl_out應(yīng)用到outside接口asa5505(config)static (inside,dmz) netmask //asa5505(config)accesslist acl_dmz extended permit icmp any any//控制列表名acl_dmz允許ICMP協(xié)議asa5505(config)accessgroup acl_dmz in interface dmz//控制列表acl_out應(yīng)用到dmz接口asa5505(config)Show nat//驗(yàn)證配置asa5505(config)global(outside) 1 //定義全局地址池asa5505(config)nat(inside) 1 //內(nèi)部轉(zhuǎn)換地址池asa5505(config) show xlate//驗(yàn)證配置(PAT)asa5505(config)global (outside) 2 interface//定義全局地址即outside地址:asa5505(config)nat (inside) 2 //內(nèi)部轉(zhuǎn)換地址池asa5505(config) show xlate//驗(yàn)證配置(failover)1).主防火墻配置asa5505(config)failover mac addr outside //故障倒換虛擬MAC地址asa5505(config)failover mac addr inside //故障倒換虛擬MAC地址asa5505(config)failover mac addr inside //故障倒換虛擬MAC地址asa5505(config)failover//啟動(dòng)故障倒換asa5505(config)failover lan unit primary//設(shè)置主要防火墻asa5505(config)failover lan interface standby Vlan4//故障倒換接口名standbyasa5505(config)failover interface ip standby standby //配置主防火墻IP:,備用防火墻IP:asa5505 show failover//驗(yàn)證配置2).備防火墻配置asa5505(config)failover mac addr outside //故障倒換虛擬MAC地址asa5505(config)failover mac addr inside //故障倒換虛擬MAC地址asa5505(config)failover mac addr inside //故障倒換虛擬MAC地址asa5505(config)failover//啟動(dòng)故障倒換asa5505(config)failover lan unit secondary//設(shè)置備用防火墻asa5505(config)failover lan interface standby Vlan4//故障倒換接口名standbyasa5505(config)failover interface ip standby standby //配置主防火墻IP:,備用防火墻IP:asa5505 show failover//驗(yàn)證配置asa5505 show switch macaddresstableasa5505 write memory