- 1.扩展访问控制列表:
- ciscoasa(config)# access-list 100 permit icmp any any
- ciscoasa(config)# access-group 100 in interface outside
- 2.object group对象组
- 1.对象组:
- icmp-type:指定PING包的类型 echo echo-relay等
- network:指定host、subnet或网络地址
- protocol:指定IP协议(协议类型1-254),或名称标识(TCP UDP ICMP GRE IGMP);如果想包含所有的IP协议,可以使用关键字IP
- service:指定TCP UDP端口和特定的服务。
- 2.protocol对象组
- ciscoasa(config)# object-group protocol daiv-protocol
- ciscoasa(config-protocol-object-group)# protocol-object tcp
- ciscoasa(config-protocol-object-group)# protocol-object udp
- ciscoasa(config-protocol-object-group)# protocol-object icmp
- 3.Network对象组
- ciscoasa(config)# object-group network daiv-network
- ciscoasa(config-network-object-group)# network-object host 3.3.3.3
- ciscoasa(config-network-object-group)# network-object 3.3.3.0255.255.255.0
- 4.service对象组
- ciscoasa(config)# object-group service daiv-service
- ciscoasa(config-service-object-group)# service-object tcp
- ciscoasa(config-service-object-group)# service-object udp
- ciscoasa(config-service-object-group)# service-object icmp
- 5.icmp-type对象组
- ciscoasa(config)# object-group icmp-type daiv-icmp
- ciscoasa(config-icmp-object-group)# icmp-object echo
- ciscoasa(config-icmp-object-group)# icmp-object echo-reply
- 1.对象组:
- 3.对象组的调用方法:
- 1:写访问控制列表去调用对象
- ciscoasa(config)# object-group network daiv-network 创建网络组对象
- ciscoasa(config-network-object-group)# network-object 3.3.3.0 255.255.255.0
- ciscoasa(config-network-object-group)# exit
- ciscoasa(config)# object-group network daiv1-network
- ciscoasa(config-network-object-group)# network-object 1.1.1.0 255.255.255.0
- access-list 110 extended permit icmp object-group daiv-network (源地址) object-group daiv1-network(目的地址)
- access-list 100 extended permit tcp object-group daiv-network (源地址) 3.3.3.0 255.255.255.0 (目的地址)
- 2.应用访问控制列表:
- ciscoasa(config)# access-group 100 in interface outside
- 3.查看及清除匹配的次数
- ciscoasa# clear access-list 100 counters
- ciscoasa# show access-list 100
- access-list 100; 1 elements; name hash: 0xc6c44b7c
- access-list 100 line 1 extended permit ip any any (hitcnt=0) 0xa2f91e1d
- 1:写访问控制列表去调用对象
- 4.基于时间的访问控制列表:
- time-range worker
- absolute start 15:27 05September 2017 end 15:27 05 September 2018
- periodic weekdays 9:00 to 17:00
- access-list 111 extended permit ip any host 192.168.1.1 time-rangeworker
- access-group 111 in interface outside
防火墙控制对象组
最新推荐文章于 2024-07-11 02:37:30 发布