ASA防火墙实验手册含大量案例
一、Firewall Overview .......................................................................................................................... 3
二
、防火墙对流量的控制...................................................................................................................... 3
三
、Basic Initialization .......................................................................................................................... 4
3.1
防火墙功能和许可证..................................................................................................................... 4
3.2
初始设置(Initial Setup) ............................................................................................................. 5
3.3
配置接口参数............................................................................................................................... 5
四
、IP Routing..................................................................................................................................... 7
4.1
静态和缺省路由............................................................................................................................ 7
4.2
路由图——routemap...................................................................................................................
8
4.3
动态路由协议——RIP 和OSPF.................................................................................................... 8
4.4
实验练习...................................................................................................................................... 9
五
、 ACL .......................................................................................................................................... 12
5.1
配置ACL ................................................................................................................................. 12
5.2
Object Group............................................................................................................................. 12
5.2
实验练习.................................................................................................................................... 14
六
、NAT ............................................................................................................................................ 14
6.1
OVERVIEW............................................................................................................................... 14
6.2
NATControl....................................................................................................................
........... 16
6.3
NAT Bypass ............................................................................................................................... 16
6.4
策略NAT ................................................................................................................................. 16
6.5
DNS 和NAT ............................................................................................................................... 18
6.5
动态NAT 和PAT ........................................................................................................................ 19
6.6
实验练习.................................................................................................................................... 21
七
、AAA ............................................................................................................................................ 29
7.1
AAA OVERVIEW....................................................................................................................... 29
7.2
RADIUS .................................................................................................................................... 29
7.3
TACACS+.................................................................................................................................. 30
7.4
ASA 上AAA 的实现.................................................................................................................... 31
7.5
配置AAA................................................................................................................................... 31
7.6
配置可下载ACL ......................................................................................................................... 35
7.7
使用MAC 地址免除流量的认证和授权........................................................................................ 38
7.8
实验练习.................................................................................................................................... 39
**** Hidden Message *****
http://bbs.hh010.com/xwb/images/bgimg/icon_logo.png 该贴已经同步到 小乔的微博 {:6_291:}3Q {:6_269:}{:6_269:}{:6_269:}{:6_269:} {:6_291:} 有pix就好了 好好学习 定{:6_263:}{:6_291:} 感谢分享!!!! 哦哦 啥时候论坛改版了 谢谢分享 好好好好好 weeryd 看目录是很好的教材,下来看看 1321346546
来学习一下,刚好工作上有需要,可真谢了。