Minh ko the truy cap tu mang inside vao vung dmz bang cac giao thuc tcp: http, ftp. Nhung co the ping duoc.
Pix cua minh co 3 zone: 1 outside, 1 dmz, 1 inside. Cau hinh cua minh duoi day:
#--------------------------
interface Ethernet0
nameif outside
security-level 0
ip address 203.x.x.x 255.255.255.252
!
interface Ethernet1
nameif inside
security-level 100
ip address 10.1.1.1 255.255.255.0
!
interface Ethernet2
nameif dmz
security-level 50
ip address 192.1.1.1 255.255.255.248
!
#---------access-list
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list outside_access_in extended permit ip any any
access-list outside_access_in extended permit icmp any any
access-list inside_nat0_outbound extended permit ip any 192.1.1.0 255.255.2
55.248
access-list acl_dmz extended permit ip any any
access-list acl_dmz extended permit icmp any any
access-list acl_inside extended permit ip any any
access-list acl_inside extended permit icmp any any
mtu outside 1500
mtu inside 1500
mtu dmz 1500
icmp permit any outside
icmp permit any inside
icmp permit any dmz
#nat-------
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 10.0.0.0 255.0.0.0
access-group outside_access_in in interface outside
access-group acl_inside in interface inside
access-group acl_dmz in interface dmz
route outside 0.0.0.0 0.0.0.0 203.x.x.x 1
Pix cua minh co 3 zone: 1 outside, 1 dmz, 1 inside. Cau hinh cua minh duoi day:
#--------------------------
interface Ethernet0
nameif outside
security-level 0
ip address 203.x.x.x 255.255.255.252
!
interface Ethernet1
nameif inside
security-level 100
ip address 10.1.1.1 255.255.255.0
!
interface Ethernet2
nameif dmz
security-level 50
ip address 192.1.1.1 255.255.255.248
!
#---------access-list
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list outside_access_in extended permit ip any any
access-list outside_access_in extended permit icmp any any
access-list inside_nat0_outbound extended permit ip any 192.1.1.0 255.255.2
55.248
access-list acl_dmz extended permit ip any any
access-list acl_dmz extended permit icmp any any
access-list acl_inside extended permit ip any any
access-list acl_inside extended permit icmp any any
mtu outside 1500
mtu inside 1500
mtu dmz 1500
icmp permit any outside
icmp permit any inside
icmp permit any dmz
#nat-------
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 10.0.0.0 255.0.0.0
access-group outside_access_in in interface outside
access-group acl_inside in interface inside
access-group acl_dmz in interface dmz
route outside 0.0.0.0 0.0.0.0 203.x.x.x 1
Comment