pix version 6.3(3)
interface ethernet1 100full 【程序编程相关:巩固有私有VLAN和VLAN访问控制列表】\\配置接口名称,安全级别,主机名,使用的域名 interface ethernet0 100full 【推荐阅读:配置示例:Catalyst 2900XL】interface gb-ethernet1 1000auto 【扩展信息:Catalyst 6000上的QoS策略】interface gb-ethernet0 1000autonameif ethernet0 cimo security10nameif ethernet1 intf3 security15nameif gb-ethernet0 outside security0nameif gb-ethernet1 inside security100enable password 52network encryptedpasswd 52network encryptedhostname pix-adomain-name 52network.com\\ 配置pix允许的协议类型,要加密保护的数据流量 fixup protocol dns maximum-length 512fixup protocol ftp 21fixup protocol h323 h225 1720fixup protocol h323 ras 1718-1719fixup protocol http 80fixup protocol ils 389fixup protocol rsh 514fixup protocol rtsp 554fixup protocol sip 5060fixup protocol skinny 2000fixup protocol smtp 25fixup protocol splnet 1521fixup protocoltftp 69namesaccess-list inside_outbound_nat0_acl permit ip 202.102.54.0 255.255.255.0 10.0.1.0 255.255.255.0access-list outside_cryptomap_20 permit ip 202.102.54.0 255.255.255.0 10.0.1.0 255.255.255.0\\设置日志服务器,pix各接口的ip地址,pix设备的故障切换功能 pager lines 24logging timestamplogging standbylogging trap informationallogging facility 22logging host inside 202.102.54.5mtu cimo 1500mtu intf3 1500mtu outside 1500mtu inside 1500ip address cimo 192.168.0.1 255.255.255.252ip address intf3 127.0.0.1 255.255.255.255ip address outside 202.102... 下一页