pix>enable pix#conf t pix(config)enable password cisco encry pix(config)#interface eth0 auto pix(config)#interface eth1 auto pix(config)#interface eth2 auto pix(config)#nameif e2 DMZ securit y50 pix(config)#ip add inside 10.110.245.1 255.255.255.0 pix(config)#ip add outside 211.137.252.192 255.255.255.240 pix(config)#ip add dmz 10.11.0.245 255.255.255.0 pix(config)#static (dmz,outside) tcp 211.137.252.195 80 192.168.0.29 80 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.195 443 192.168.0.29 443 netmask 255.255.255.255 0 0 conduit permit tcp host 211.137.252.195 eq 80 any conduit permit tcp host 211.137.252.195 eq 443 any |
;web服務器的靜態映射
pix(config)#static (dmz,outside) tcp 211.137.252.196 80 192.168.0.34 80 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.196 443 192.168.0.34 443 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.196 25 192.168.0.34 25 netmask 255.255.255.255 0 0 conduit permit tcp host 211.137.252.196 eq 80 any conduit permit tcp host 211.137.252.196 eq 443 any conduit permit tcp host 211.137.252.196 eq 25 any
|
;郵件服務器的靜態映射
pix(config)#static (dmz,outside) tcp 211.137.252.197 80 192.168.0.20 80 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.197 554 192.168.0.20 554 netmask 255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.197 1755 192.168.0.20 1755 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) udp 211.137.252.197 1755 192.168.0.20 1755 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) udp 211.167.252.197 5005 192.168.0.20 5005 netmask 255.255.255.255 0 0 conduit permit tcp host 211.137.252.197 eq 80 any conduit permit tcp host 211.137.252.197 eq 554 any conduit permit tcp host 211.137.252.197 eq 1755 any conduit permit udp host 211.137.252.197 eq 1755 any conduit permit udp host 211.137.252.197 eq 5005 any
|
;配置vod1服務器的靜態映射
pix(config)#static (dmz,outside) tcp 211.137.252.198 80 192.168.0.21 80 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.198 554 192.168.0.21 554 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) tcp 211.137.252.198 1755 192.168.0.21 1755 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) udp 211.137.252.198 1755 192.168.0.21 1755 netmask 255.255.255.255 0 0 pix(config)#static (dmz,outside) udp 211.137.252.198 5005 192.168.0.21 5005 netmask 255.255.255.255 0 0 conduit permit tcp host 211.137.252.198 eq 80 any conduit permit tcp host 211.137.252.198 eq 554 any conduit permit tcp host 211.137.252.198 eq 1755 any conduit permit udp host 211.137.252.198 eq 1755 any conduit permit udp host 211.137.252.198 eq 5005 any
|
;配置vod2服務器的靜態映射
pix(config)#ip access-list extended mz pix(config)#permit tcp 192.168.0.20 0.0.0.3 8001 10.110.245.41 0.0.0.3 8001 pix(config)#permit tcp 192.168.0.20 0.0.0.3 8002 10.110.245.41 0.0.0.3 8002
|
;對DMZ區中的兩臺流媒體服務器開放對這3臺服務器在8001、8002端口上(皆為TCP端口)的入站請求
pix(config)#permit tcp 192.168.0.25 0.0.0.7 53 10.110.245.10 0.0.0.3 53 pix(config)#permit tcp 192.168.0.25 0.0.0.7 88 10.110.245.10 0.0.0.3 88 pix(config)#permit tcp 192.168.0.25 0.0.0.7 135 10.110.245.10 0.0.0.3 135 pix(config)#permit tcp 192.168.0.25 0.0.0.7 137 10.110.245.10 0.0.0.3 137 pix(config)#permit tcp 192.168.0.25 0.0.0.7 139 10.110.245.10 0.0.0.3 139 pix(config)#permit tcp 192.168.0.25 0.0.0.7 389 10.110.245.10 0.0.0.3 389 pix(config)#permit tcp 192.168.0.25 0.0.0.7 445 10.110.245.10 0.0.0.3 445 pix(config)#permit tcp 192.168.0.25 0.0.0.7 636 10.110.245.10 0.0.0.3 636 pix(config)#permit tcp 192.168.0.25 0.0.0.7 3268 10.110.245.10 0.0.0.3 3268 pix(config)#permit tcp 192.168.0.25 0.0.0.7 4000 10.110.245.10 0.0.0.3 4000 pix(config)#permit udp 192.168.0.25 0.0.0.7 53 10.110.245.10 0.0.0.3 53 pix(config)#permit udp 192.168.0.25 0.0.0.7 88 10.110.245.10 0.0.0.3 88 pix(config)#permit udp 192.168.0.25 0.0.0.7 135 10.110.245.10 0.0.0.3 135 pix(config)#permit udp 192.168.0.25 0.0.0.7 137 10.110.245.10 0.0.0.3 137 pix(config)#permit udp 192.168.0.25 0.0.0.7 138 10.110.245.10 0.0.0.3 138 pix(config)#permit udp 192.168.0.25 0.0.0.7 389 10.110.245.10 0.0.0.3 389
|
;對DMZ區中的兩臺Web服務器和兩臺Exchange服務器開放對這兩臺AD服務器在以下端口上的入站請求
pix(config)#permit tcp 192.168.0.25 0.0.0.3 1433 10.110.245.35 0.0.0.3 1433
|
;對DMZ區中的兩臺Web服務器開放對此集群在1433(TCP)端口上的入站請求
pix(config)#access-group mz out interface inside pix(config)#route outside 0.0.0.0 0.0.0.0 211.137.252.191 pix(config)#global (outside) 1 211.137.252.192-211.137.252.194 netmask 255.255.255.240 pix(config)nat (inside) 1 192.168.0.0 255.255.255.0 pix(config)nat (inside) 1 10.11.0.0 255.255.255.0 pix(config)w r |