早教吧 育儿知识 作业答案 考试题库 百科 知识分享

asa5510设置acl规则麻烦帮忙看一下人家的配置搞的我一点都不懂access-listcachedACLlogflows:total0,denied0(deny-flow-max4096)alert-interval300access-listindmz;1elementsaccess-listindmzline1extendedpermitip192

题目详情
asa5510设置acl规则 麻烦帮忙看一下人家的配置 搞的我一点都不懂
access-list cached ACL log flows:total 0,denied 0 (deny-flow-max 4096)
alert-interval 300
access-list in_dmz; 1 elements
access-list in_dmz line 1 extended permit ip 192.168.0.0 255.255.0.0 192.168.25.0 255.255.255.0 (hitcnt=0) 0x4a655920
access-list vpnnonat; 1 elements
access-list vpnnonat line 1 extended permit ip 192.168.20.0 255.255.255.0 10.1.1.0 255.255.255.0 (hitcnt=0) 0x13a2561a
access-list slipt; 2 elements
access-list slipt line 1 extended permit ip 192.168.20.0 255.255.255.0 10.1.1.0 255.255.255.0 (hitcnt=0) 0xfbdddc95
access-list slipt line 2 extended permit ip 192.168.25.0 255.255.255.0 10.1.1.0 255.255.255.0 (hitcnt=0) 0xc0cfe743
access-list out-acl; 2 elements
access-list out-acl line 1 extended permit icmp any any (hitcnt=17083) 0x242408d5
access-list out-acl line 2 extended permit ip any any (hitcnt=11638) 0x8dffb043
access-list dmz-acl; 1 elements
access-list dmz-acl line 1 extended permit icmp any any (hitcnt=0) 0x40af7c3b
access-list in-dmz; 1 elements
access-list in-dmz line 1 extended permit ip 192.168.20.0 255.255.255.0 192.168.25.0 255.255.255.0 (hitcnt=0) 0x1515257b
翻译一下这个配置、、、、、怎么在加一个acl命令禁止qq农场还有一些游戏:QQ游戏,联众 对战平台 删除一个acl怎么用命令
▼优质解答
答案和解析
access-list in_dmz line 1 extended permit ip 192.168.0.0 255.255.0.0 192.168.25.0 255.255.255.0
限制访问DMZ的流
access-list vpnnonat line 1 extended permit ip 192.168.20.0 255.255.255.0 10.1.1.0 255.255.255.0
VPN拨入不做NAT地址转换
access-list slipt line 1 extended permit ip 192.168.20.0 255.255.255.0 10.1.1.0 255.255.255.0 access-list slipt line 2 extended permit ip 192.168.25.0 255.255.255.0 10.1.1.0 255.255.255.0
对拨入VPN的加用隧道分离
access-list out-acl line 1 extended permit icmp any any
允许ICMP协议流入
access-list out-acl line 2 extended permit ip any any
允许所有IP协议流入
access-list dmz-acl line 1 extended permit icmp any any
允许ICMP协议流入DMZ区域
access-list in-dmz line 1 extended permit ip 192.168.20.0 255.255.255.0 192.168.25.0 255.255.255.0
允许192.168.20.0访问DMZ区域
怎么在加一个acl命令禁止qq农场还有一些游戏:QQ游戏,联众 对战平台
这些平台服务器都是都是很多IP地址和端口的,用ACL是封不住的
删除一个acl怎么用命令
在ACL的命令前加no
比如 no access-list out-acl line 2 extended permit ip any any
sh run 看命令