天天看點

ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序

實驗目的:

驗證ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序。

拓撲:

ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序

一 8.3以前

ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序

配置:

access-list acl-outside extended permit tcp any host 202.1.1.10 eq telnet

access-list acl-outside extended permit icmp any any

nat-control

static (inside,outside) 202.1.1.10 192.168.1.1 netmask 255.255.255.255

access-group acl-outside in interface outside

使用的是轉化以後的IP(202.1.1.10)

驗證:

ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序
ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序

二 8.3以後

ASA8.3(包含8.3)以後和ASA8.3以前NAT和ACL執行順序

配置

access-list acl-outside extended permit tcp any host 192.168.1.1 eq telnet

object network Static-Outside-Address

host 202.1.1.10

object network Static-Inside-Address

host 192.168.1.1

nat (Inside,Outside) static Static-Outside-Address

驗證

ASA