防火墙控制对象组

  • 1.扩展访问控制列表:
    • ciscoasa(config)# access-list 100 permit  icmp any any
    • ciscoasa(config)# access-group 100 in interface outside
  • 2.object group对象组
    • 1.对象组:
      • icmp-type:指定PING包的类型 echo echo-relay等
      • network:指定host、subnet或网络地址
      • protocol:指定IP协议(协议类型1-254),或名称标识(TCP UDP ICMP GRE IGMP);如果想包含所有的IP协议,可以使用关键字IP
      • service:指定TCP UDP端口和特定的服务。
    • 2.protocol对象组
      • ciscoasa(config)# object-group protocol daiv-protocol
      • ciscoasa(config-protocol-object-group)# protocol-object tcp
      • ciscoasa(config-protocol-object-group)# protocol-object udp
      • ciscoasa(config-protocol-object-group)# protocol-object icmp
    • 3.Network对象组
      • ciscoasa(config)# object-group network daiv-network
      • ciscoasa(config-network-object-group)# network-object host 3.3.3.3
      • ciscoasa(config-network-object-group)# network-object 3.3.3.0255.255.255.0
    • 4.service对象组
      • ciscoasa(config)# object-group service daiv-service
      • ciscoasa(config-service-object-group)# service-object tcp
      • ciscoasa(config-service-object-group)# service-object udp
      • ciscoasa(config-service-object-group)# service-object icmp
    • 5.icmp-type对象组
      • ciscoasa(config)# object-group icmp-type daiv-icmp
      • ciscoasa(config-icmp-object-group)# icmp-object echo
      • ciscoasa(config-icmp-object-group)# icmp-object echo-reply
  • 3.对象组的调用方法:
    • 1:写访问控制列表去调用对象
      • ciscoasa(config)# object-group network daiv-network 创建网络组对象
      • ciscoasa(config-network-object-group)# network-object 3.3.3.0 255.255.255.0
      • ciscoasa(config-network-object-group)# exit
      • ciscoasa(config)# object-group network daiv1-network
      • ciscoasa(config-network-object-group)# network-object 1.1.1.0 255.255.255.0
      • access-list 110 extended permit icmp object-group daiv-network (源地址) object-group daiv1-network(目的地址)
      • access-list 100 extended permit tcp object-group daiv-network (源地址) 3.3.3.0 255.255.255.0 (目的地址)
    • 2.应用访问控制列表:
      • ciscoasa(config)# access-group 100 in interface outside
    • 3.查看及清除匹配的次数
      • ciscoasa# clear access-list 100 counters
      • ciscoasa# show access-list 100
      • access-list 100; 1 elements; name hash: 0xc6c44b7c
      • access-list 100 line 1 extended permit ip any any (hitcnt=0) 0xa2f91e1d
  • 4.基于时间的访问控制列表:
    • time-range worker
    • absolute start 15:27 05September 2017 end 15:27 05 September 2018
    • periodic weekdays 9:00 to 17:00
    • access-list 111 extended permit ip any host 192.168.1.1 time-rangeworker
    • access-group 111 in interface outside
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值