| Sendt: 14-Juli-2010 kl. 13:14 | IP-adresse registreret
|
|
|
Så fik jeg klaret routeren :) og jeg har hul ud til internettet gennem firewallen. Men jeg brug for lidt NAT hjælp. Jeg vil gerne have flere webservere igennem og andet internt snask.. Men jeg syntes ikke den vil tillade det jeg ønsker :(
Her er min running config (er ikke komplet endnu)
hostname F1 domain-name no.domain enable password XXXXXXXXXXXXX encrypted names name 192.168.210.20 DMZ20-WWW
dns-guard ! interface Ethernet0/0 description TDC Fiber nameif outside security-level 0 ip address xx.xx.xx.134 255.255.255.248 ! interface Ethernet0/1 nameif inside security-level 100 ip address 192.168.210.1 255.255.255.0 ! interface Ethernet0/2 shutdown no nameif no security-level no ip address ! interface Management0/0 shutdown nameif management security-level 100 no ip address management-only ! passwd XXXXXXXXXXXXX encrypted banner motd "Unauthorized access prohibited" ftp mode passive access-list outside_access_in extended permit tcp any any eq www 192.168.210.0 255.255.255.0 pager lines 24 mtu outside 1500 mtu inside 1500 mtu management 1500 asdm image disk0:/asdm506.bin no asdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 0 access-list inside_nat0_outbound nat (inside) 1 192.168.210.0 255.255.255.0 static (inside,outside) tcp interface www DMZ20-WWW www netmask 255.255.255.255 access-group outside_access_in in interface outside route outside 0.0.0.0 0.0.0.0 xx.xx.xx.133 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute
http server enable http 192.168.210.0 255.255.255.0 inside http 192.168.210.0 255.255.255.0 management no snmp-server location no snmp-server contact ! class-map inspection_default match default-inspection-traffic ! ! policy-map global_policy class inspection_default inspect dns maximum-length 512 inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp
|