设为首页 收藏本站
查看: 729|回复: 0

[经验分享] Cisco ASA 8.4 NAT&***总结

[复制链接]
发表于 2018-7-10 11:11:47 | 显示全部楼层 |阅读模式
  Dynamic NAT
  object network my-range-obj
  range 10.2.2.1 10.2.2.10
  object network my-inside-net
  subnet 192.168.2.0 255.255.255.0
  nat (inside,outside) dynamic my-range-obj
  -------------------------------------------------------------
  Dynamic NAT with dynamic PAT backup!!
  object network nat-range1
  range 10.10.10.10 10.10.10.20
  object network pat-ip1
  host 10.10.10.21
  object-group network nat-pat-grp
  network-object object nat-range1
  network-object object pat-ip1
  object network my_net_obj5
  subnet 10.76.11.0 255.255.255.0
  nat (inside,outside) dynamic nat-pat-grp interface
  --------------------------------------------------------------
  Dynamic PAT!!
  object network my-inside-net
  subnet 192.168.2.0 255.255.255.0
  nat (inside,outside) dynamic 10.2.2.2
  Dynamic PAT,Interface!!
  object network my-inside-net
  subnet 192.168.2.0 255.255.255.0
  nat (inside,outside) dynamic interface
  --------------------------------------------------------------
  The following example configures static NAT for the real host 10.1.1.1 on the inside to 10.2.2.2 on the
  outside with DNS rewrite enabled.
  object network my-host-obj1
  host 10.1.1.1
  nat (inside,outside) static 10.2.2.2 dns
  --------------------------------------------------------------
  The following example configures static NAT for the real host 10.1.1.1 on the inside to 2.2.2.2 on the
  outside using a mapped object.
  object network my-mapped-obj
  host 10.2.2.2
  object network my-host-obj1
  host 10.1.1.1
  nat (inside,outside) static my-mapped-obj
  ---------------------------------------------------------------
  The following example configures static NAT-with-port-translation for 10.1.1.1 at TCP port 21 to the
  outside interface at port 2121.
  object network my-ftp-server
  host 10.1.1.1
  nat (inside,outside) static interface service tcp 21 2121
  ---------------------------------------------------------------
  Identity NAT:
  object network my-host-obj1
  host 10.1.1.1
  nat (inside,outside) static 10.1.1.1
  object network my-host-obj1-identity
  host 10.1.1.1
  object network my-host-obj1
  host 10.1.1.1
  nat (inside,outside) static my-host-obj1-identity
  ---------------------------------------------------------------
  L2TP Over IPSec:
  crypto ikev1 enable outside
  crypto ikev1 policy 10
  authentication pre-share
  encryption 3des
  hash sha
  group 2
  lifetime 86400
  crypto ipsec ikev1 transform-set my-transform-set-ikev1 esp-des esp-sha-hmac
  crypto ipsec ikev1 transform-set my-transform-set-ikev1 mode transport
  ip local pool sales_addresses 209.165.202.129-209.165.202.158
  tunnel-group DefaultRAGroup general-attributes
  default-group-policy sales_policy
  address-pool sales_addresses
  tunnel-group DefaultRAGroup ipsec-attributes
  pre-shared-key *
  tunnel-group DefaultRAGroup ppp-attributes
  no authentication pap
  authentication chap
  authentication ms-chap-v1
  authentication ms-chap-v2
  group-policy sales_policy internal
  group-policy sales_policy attributes
  wins-server value 209.165.201.3 209.165.201.4
  dns-server value 209.165.201.1 209.165.201.2
  ***-tunnel-protocol l2tp-ipsec
  crypto dynamic-map dyno 10 set ikev1 transform-set trans
  crypto map *** 20 ipsec-isakmp dynamic dyno
  crypto map *** interface outside
  ---------------------------------------------------------------
  Romote ***:
  interface ethernet0
  ip address 10.10.4.200 255.255.0.0
  nameif outside
  no shutdown
  crypto ikev1 policy 1
  authentication pre-share
  encryption 3des
  hash sha
  group 2
  lifetime 43200
  crypto ikev1 outside
  ip local pool testpool 192.168.0.10-192.168.0.15
  username testuser password 12345678
  crypto ipsec ikev1 transform set FirstSet esp-3des esp-md5-hmac
  tunnel-group testgroup type remote-access
  tunnel-group testgroup general-attributes
  address-pool testpool
  tunnel-group testgroup ipsec-attributes
  ikev1 pre-shared-key 44kkaol59636jnfx
  crypto dynamic-map dyn1 1 set ikev1 transform-set FirstSet
  crypto dynamic-map dyn1 1 set reverse-route
  crypto map mymap 1 ipsec-isakmp dynamic dyn1
  crypto map mymap interface outside
  write memory

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-535821-1-1.html 上篇帖子: cisco NAT配置示例 下篇帖子: Cisco技术ASA配置failover实例
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表