您好,登錄后才能下訂單哦!
ASA防火墻上配置IPSEC ×××和SSL ×××
一:實驗拓撲:
二:實驗要求:
1:PC1屬于上海分公司內網主機,PC2屬于總公司主機.要求上海分公司的用戶直接可以喝總公司的PC2通信.(Site-to-Site IPSEC ×××實現)
2:公網上用戶可以訪問總公司的OA服務器PC2.(SSL ×××實現)
三:配置過程:
1:基本配置:
ASA1(config)#int e0/1
ASA1(config-if)#nameif inside
INFO: Securitylevel for "inside" set to 100 by default.
ASA1(config-if)#ip add 172.16.1.254 255.255.255.0
ASA1(config-if)#no sh
ASA1(config-if)#int e0/0
ASA1(config-if)#nameif outside
INFO: Securitylevel for "outside" set to 0 by default.
ASA1(config-if)#ip add 12.0.0.1 255.255.255.0
ASA1(config-if)#no sh
ASA1(config-if)#
ASA1# ping172.16.1.1
Type escapesequence to abort.
Sending 5,100-byte ICMP Echos to 172.16.1.1, timeout is 2 seconds:
!!!!!
Success rateis 100 percent (5/5), round-trip min/avg/max = 10/344/1670 ms
R1(config)#intf0/0
R1(config-if)#ipadd 12.0.0.2 255.255.255.0
R1(config-if)#nosh
R1(config-if)#intf1/0
R1(config-if)#ipadd 23.0.0.2 255.255.255.0
R1(config-if)#nosh
R1(config-if)#intf2/0
R1(config-if)#ipadd 1.1.1.254 255.255.255.0
R1(config-if)#nosh
ASA2(config)#int e0/0
ASA2(config-if)#nameif outside
INFO: Securitylevel for "outside" set to 0 by default.
ASA2(config-if)#ip add 23.0.0.3 255.255.255.0
ASA2(config-if)#no sh
ASA2(config-if)#int e0/1
ASA2(config-if)#nameif inside
INFO: Securitylevel for "inside" set to 100 by default.
ASA2(config-if)#ip add 192.168.1.254 255.255.255.0
ASA2(config-if)#no sh
配置路由,NAT,ACL
ASA1(config)#route outside 0 0 12.0.0.2
ASA1(config)#nat-control
ASA1(config)#nat (inside) 1 0 0
ASA1(config)#global (outside) 1 interface
INFO: outsideinterface address added to PAT pool
ASA1(config)#access-list haha permit icmp any any
ASA1(config)#access-group haha in interface outside
ASA2(config)#route outside 0 0 23.0.0.2
ASA2(config)#nat-con
ASA2(config)#nat-control
ASA2(config)#nat (inside) 1 0 0
ASA2(config)#global (outside) 1 interface
INFO: outsideinterface address added to PAT pool
ASA2(config)#access-list haha permit icmp any any
ASA2(config)#access-group haha in interface outside
私網上公網沒問題,但兩個私網無法互通
2:配置Site-to-Site ×××
ASA1(config)#access-list no-nat permit ip 172.16.1.0 255.255.255.0 192.168.1.0 255.255.255.0
ASA1(config)#nat (inside) 0 access-list no-nat
ASA2(config)#access-list no-nat permit ip 192.168.1.0 255.255.255.0 172.16.1.0 255.255.255.0
ASA2(config)#nat (inside) 1 access-list no-nat
ASA1(config)#crypto isakmp enable outside
ASA1(config-isakmp-policy)#authentication pre-share
ASA1(config-isakmp-policy)#encryption des
ASA1(config-isakmp-policy)#hash md5
ASA1(config-isakmp-policy)#group 2
ASA1(config-isakmp-policy)#exit
ASA1(config)#isakmp key cisco address 23.0.0.3
ASA1(config)#crypto ipsec transform-set mytrans esp-des esp-md
ASA1(config)#crypto ipsec transform-set mytrans esp-des esp-md5-hmac
ASA1(config)#crypto map mymap 10 set peer 23.0.0.3
ASA1(config)#crypto map mymap 10 set transform-set mytrans
ASA1(config)#crypto map mymap 10 match address no-nat
ASA1(config)#crypto map mymap interface outside
ASA2(config)#crypto isakmp enable outside
ASA2(config-isakmp-policy)#authentication pre-share
ASA2(config-isakmp-policy)#encryption des
ASA2(config-isakmp-policy)#hash md5
ASA2(config-isakmp-policy)#group 2
ASA2(config-isakmp-policy)#exit
ASA2(config)#isakmp key cisco address 12.0.0.1
ASA2(config)#crypto ipsec transform-set mytrans esp-des esp-md
ASA2(config)#crypto ipsec transform-set mytrans esp-des esp-md5-hmac
ASA2(config)#crypto map mymap 10 set peer 12.0.0.1
ASA2(config)#crypto map mymap 10 set transform-set mytrans
ASA2(config)#crypto map mymap 10 match address no-nat
ASA2(config)#crypto map mymap interface outside
Site-to-SiteIPSEC 配置完成.
ASA2(config)#web***
ASA2(config-web***)#enable outside
INFO: Web×××and DTLS are enabled on 'outside'.
ASA2(config-web***)#svc p_w_picpath disk0:/sslclient-win-1.1.3.173.pkg
ASA2(config-web***)#svc enable
ASA2(config-web***)#exit
ASA2(config)#username cisco password cisco
ASA2(config)#ip local pool *** 192.168.100.1-192.168.100.200
ASA2(config)#access-list 100 permit ip 192.168.1.0 255.255.255.0 any
ASA2(config)#group-policy my10 internal
ASA2(config)#group-policy my10 attributes
ASA2(config-group-policy)#***-tunnel-protocol web*** svc
ASA2(config-group-policy)#split-tunnel-policy tunnelspecified
ASA2(config-group-policy)#split-tunnel-network-list value 100
ASA2(config-group-policy)#web***
ASA2(config-group-web***)#svc ask enable
ASA2(config-group-web***)#exit
ASA2(config-group-policy)#exit
ASA2(config)#tunnel-group jishu type web***
ASA2(config)#tunnel-group jishu general-attributes
ASA2(config-tunnel-general)#address-pool ***
ASA2(config-tunnel-general)#default-group-policy my10
ASA2(config-tunnel-general)#web***
ASA2(config-web***)#tunnel-group-list enable
ASA2(config-web***)#tunnel-group jishu web***-attributes
ASA2(config-tunnel-web***)#group-alias 2t39
SSL ×××配置完畢.
access-listssl*** extended permit ip 192.168.1.0 255.255.255.0 192.168.100.0 255.255.255.0
nat (inside) 0access-list ssl***
免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。