PIX515E-R防火墙安装ACS3.0做用户身份验证(1)
我把下午做试验的PIX配置贴出来:
PIX Version 6.3(1) // os 我用的 6.3 版本的,这个版本支持 IPSec VPN with NATinterface ethernet0 autointerface ethernet1 autonameif ethernet0 outside security0nameif ethernet1 inside security100enable passWord 8Ry2YjIyt7RRXU24 encryptedpasswd 2KFQnbNIdI.2KYOU encryptedhostname ISSC-PIX515E-Rfixup protocol ftp 21fixup protocol h323 h225 1720fixup protocol h323 ras 1718-1719fixup protocol http 80fixup protocol ils 389fixup protocol rsh 514fixup protocol rtsp 554fixup protocol sip 5060fixup protocol sip udp 5060fixup protocol skinny 2000fixup protocol smtp 25fixup protocol sqlnet 1521namesAccess-list 101 permit ip 192.168.10.0 255.255.255.0 192.168.32.0 255.255.255.0 access-list 102 permit ip 192.168.10.0 255.255.255.0 192.168.32.0 255.255.255.0 access-list 104 permit icmp any any pager lines 24mtu outside 1500mtu inside 1500ip address outside 10.0.0.1 255.255.255.0ip address inside 192.168.10.252 255.255.255.0ip audit info action alarmip audit attack action alarmip local pool pccw 192.168.32.1-192.168.32.10ip local pool pccw02 192.168.32.50pdm history enablearp timeout 14400global (outside) 1 interfacenat (inside) 0 access-list 102 //对VPN连接的用户不经过NAT,这里的102对应上面的access-list 102nat (inside) 1 192.168.10.0 255.255.255.0 0 0access-group 104 in interface outsideroute outside 0.0.0.0 0.0.0.0 202.108.48.181 1timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00timeout uauth 0:05:00 absolute