Professional Documents
Culture Documents
ASA Objetos
ASA Objetos
ASA
Profesor
El Router
Configuracin bsica del ASA 1) Interfaces:
3) NAT dinmico bsico: Object network RED-INTERNA nat (INSIDE, OUTSIDE) dynamic interface Object network RED-DMZ nat (DMZ, OUTSIDE) dynamic interface 4) NAT esttico bsico: Object network SRV1 nat (DMZ, OUTSIDE) static 150.1.1.4
El Router
5) Crear objetos de servicios: Object-group service TCP_WEB tcp port-object eq 80 port-object eq 443
6) Crear una ACL para permitir trfico desde el OUTSIDE: access-list OUTSIDE_access_in extended permit tcp any object SRV1 object-group TCP_WEB
El Router
8) Port Forwarding: object network INSIDE_HOST host 192.168.1.5 nat (INSIDE,OUTSIDE) static interface service 26883 26883
El Router
El Router
hostname(config)# service object HTTPS hostname(config-service-object)# service tcp source range 0 1024 destination eq https
hostname(config)# object-group service Group1 hostname(config-service-object-group)# service-object object SSH hostname(config-service-object-group)# service-object object EIGRP hostname(config-service-object-group)# service-object object HTTPS
hostname (config)# object-group service services2 udp hostname (config-service)# description RADIUS Group hostname (config-service)# port-object eq radius hostname (config-service)# port-object eq radius-acct
hostname (config)# object-group service services3 tcp hostname (config-service)# description LDAP Group hostname (config-service)# port-object eq ldap
hostname (config)# object-group icmp-type ping hostname (config-service)# description Ping Group hostname (config-service)# icmp-object echo hostname (config-service)# icmp-object echo-reply
El Router
hostname (config)# object-group protocol tcp_udp_icmp hostname (config-protocol)# protocol-object tcp hostname (config-protocol)# protocol-object udp hostname (config-protocol)# protocol-object icmp