天天看點

尋求幫助

公司給他們配置的硬體防火牆是透明配置,隻開啟3389和9999端口。别的不需要配置。還有一點就是,他們分給我們一條可上網的網線,這條網線要連接配接到我們的防火牆上,要保證我們伺服器可以上網,其中一條連接配接到他們華為24口不可配置的交換機上,保證其他辦公室可以上網。問題是:在他們下班後做完配置,測試全部通過,但是一到早晨他們上班,網絡就癱瘓了,我們不能上網,其他辦公室也不能上網。

: Saved

:

ASA Version 7.2(4)

!

hostname ciscoasa

enable password 8Ry2YjIyt7RRXU24 encrypted

passwd 2KFQnbNIdI.2KYOU encrypted

names

interface Vlan1

 no nameif

 security-level 100

 ip address 192.168.1.1 255.255.255.0

interface Vlan2

 nameif outside

 security-level 0

 ip address 220.189.212.26 255.255.255.252

interface Vlan3

 nameif inside

 ip address 192.168.1.254 255.255.255.0

interface Ethernet0/0

 switchport access vlan 2

interface Ethernet0/1

 switchport access vlan 3

interface Ethernet0/2

switchport access vlan 3

interface Ethernet0/3

interface Ethernet0/4

interface Ethernet0/5

interface Ethernet0/6

interface Ethernet0/7

ftp mode passive

access-list 101 extended permit icmp any any

access-list 101 extended permit ip any any

access-list 101 extended permit tcp any interface outside eq 9999

access-list 101 extended permit tcp any interface outside eq 3389

pager lines 24

logging asdm informational

mtu outside 1500

mtu inside 1500

icmp unreachable rate-limit 1 burst-size 1

no asdm history enable

arp timeout 14400

global (outside) 1 interface

nat (inside) 1 0.0.0.0 0.0.0.0

static (inside,outside) tcp interface 9999 192.168.1.30 9999 netmask 255.255.255

.255

static (inside,outside) tcp interface 3389 192.168.1.30 3389 netmask 255.255.255

access-group 101 in interface outside

route outside 0.0.0.0 0.0.0.0 220.189.212.25 1

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00

timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00

timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

http server enable

no snmp-server location

no snmp-server contact

snmp-server enable traps snmp authentication linkup linkdown coldstart

telnet 0.0.0.0 0.0.0.0 inside

telnet timeout 5

ssh timeout 5

console timeout 0

dhcpd auto_config outside

class-map inspection_default

 match default-inspection-traffic

policy-map type inspect dns preset_dns_map

 parameters

  message-length maximum 512

policy-map global_policy

 class inspection_default

  inspect dns preset_dns_map

  inspect ftp

  inspect h323 h225

  inspect h323 ras

  inspect rsh

  inspect rtsp

  inspect esmtp

  inspect sqlnet

  inspect skinny

  inspect sunrpc

  inspect xdmcp

  inspect sip

  inspect netbios

  inspect tftp

service-policy global_policy global

prompt hostname context

Cryptochecksum:2da04c19477a80b3e148d183d01533ea

: end

"中國制造",講述中國60年往事

繼續閱讀