永发信息网

packetTracer6.2 ,ASA配置,外网电脑无法访问dmz中的服务器,贴配置,请高手帮帮我吧

答案:1  悬赏:80  手机版
解决时间 2021-01-29 23:21
  • 提问者网友:记得曾经
  • 2021-01-29 10:01
ASA Version 8.4(2)
!
hostname ciscoasa
names
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
switchport access vlan 3
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address 209.165.200.226 255.255.255.248
!
interface Vlan3
no forward interface Vlan1
nameif dmz
security-level 50
ip address 192.168.2.1 255.255.255.0
!
object-group service DM_INLINE_SERVICE_1
service-object tcp destination eq 80
service-object tcp destination eq 23
service-object icmp
object network Webserver
host 192.168.2.100
object network Webserver-Ext
host 209.165.200.230
object network dmz-subnet
subnet 192.168.2.0 255.255.255.0
object network inside-subnet
subnet 192.156.1.0 255.255.255.0
object-group service myService
!
route outside 0.0.0.0 0.0.0.0 209.165.200.225 1
!
access-list Outside_access_in extended permit object-group DM_INLINE_SERVICE_1 any object Webserver
access-list Outside_access_in extended permit icmp any any
access-list dmz-acl extended permit tcp any any
access-list dmz-acl extended permit icmp any any
access-list dmz-acl extended permit udp any any
!
!
access-group Outside_access_in in interface outside
access-group dmz-acl in interface dmz
object network Webserver
nat (dmz,outside) static 209.165.200.230
object network dmz-subnet
nat (dmz,outside) dynamic interface
object network inside-subnet
nat (inside,outside) dynamic interface
!
!
!
!
class-map global-class
match default-inspection-traffic
!
policy-map global-policy
class global-class
inspect dns
inspect ftp
inspect h323
inspect http
inspect icmp
inspect tftp
!
service-policy global-policy global
!
telnet timeout 5
ssh timeout 5
!
dhcpd address 192.168.1.5-192.168.1.35 inside
dhcpd enable inside
!
dhcpd auto_config outside

解决了:

access-list Outside_access_in extended permit object-group DM_INLINE_SERVICE_1 any object Webserver这条改成
access-list Outside_access_in extended permit tcp any any
然后外网的PC就可以访问dmz的服务器了。

我也不知道为什么这么改就可以了,只是觉得思科ASA越搞越神经,版本这么多,配置命令变化那么大,packetTracer上的参考配置实例如此之少。对于想用PT学习安全配置的新手来说,真的很痛苦。
最佳答案
  • 五星知识达人网友:蓝房子
  • 2021-01-29 11:05
你确定你的语句没敲错?
我要举报
如以上回答内容为低俗、色情、不良、暴力、侵权、涉及违法等信息,可以点下面链接进行举报!
点此我要举报以上问答信息
大家都在看
推荐资讯