预览加载中,请您耐心等待几秒...
1/10
2/10
3/10
4/10
5/10
6/10
7/10
8/10
9/10
10/10

亲,该文档总共28页,到这已经超出免费预览范围,如果喜欢就直接下载吧~

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

PIX/ASA:PortRedirection(Forwarding)withnat, global,staticandaccess−listCommands DocumentID:63872 Introduction Prerequisites Requirements ComponentsUsed RelatedProducts Conventions NetworkDiagram InitialConfiguration AllowOutboundAccess AllowInsideHostsAccesstoOutsideNetworkswithNAT AllowInsideHostsAccesstoOutsideNetworkswiththeuseofPAT RestrictInsideHostsAccesstoOutsideNetworks AllowUntrustedHostsAccesstoHostsonYourTrustedNetwork UseACLsonPIXVersions7.0andLater DisableNATforSpecificHosts/Networks PortRedirection(Forwarding)withStatics NetworkDiagram−PortRedirection(Forwarding) PartialPIXConfiguration−PortRedirection LimitTCP/UDPSessionusingStatic TimeBasedAccessList InformationtoCollectifYouOpenaTechnicalSupportCase NetProDiscussionForums−FeaturedConversations RelatedInformation Introduction InordertomaximizesecuritywhenyouimplementCiscoPIXSecurityApplianceversion7.0,itisimportant tounderstandhowpacketspassbetweenhighersecurityinterfacesandlowersecurityinterfaceswhenyouuse thenat−control,nat,global,static,access−listandaccess−groupcommands.Thisdocumentexplainsthe differencesbetweenthesecommandsandhowtoconfigurePortRedirection(Forwarding)andtheoutside NetworkAddressTranslation(NAT)featuresinPIXsoftwareversion7.x,withtheuseofthecommandline interfaceortheAdaptiveSecurityDeviceManager(ASDM). Note:SomeoptionsinASDM5.2andlatercanappeardifferentthantheoptionsinASDM5.1.Refertothe ASDMdocumentationformoreinformation. Prerequisites Requirements RefertoAllowingHTTPSAccessforASDMinordertoallowthedevicetobeconfiguredbytheASDM. ComponentsUsed Theinformationinthisdocumentisbasedonthesesoftwareandhardwareversions: •CiscoPIX500SeriesSecurityApplianceSoftwareversion7.0andlater •ASDMversion5.xandlater Theinformationinthisdocumentwascreatedfromthedevicesinaspecificlabenvironment.Allofthe devicesusedinthisdocumentstartedwithacleared(default)configuration.Ifyournetworkislive,makesure thatyouunderstandthepotentialimpactofanycommand. RelatedProducts Youcanalsousethisconfigurat