PIX防火墙 配置:
(1)配置静态IP地址翻译命令
Pix525(config)#static(inside,outside) inside-ip-address out-ip-address
Pix525(config)#static(inside,outside) 61.144.51.62 192.168.3.1
192.168.3.1对全局地址61.144.51.62的映射
Pix525(config)#static(dmz,outside) dmz-ip-address outside-ip-address
(2) 管道命令-conduit
Pix525(config)#conduit permit|deny protocol global-ip port forgign-ip
Pix525(config)#conduit permit tcp any eq ftp host 61.133.55.109 允许外部主机61.133.55.109对任何全局地址进行ftp的访问
Pix525(config)#conduit permit tcp host 192.168.234.150 eq www any 允许任何外部主机对主机192.168.234.150进行http访问
路由器配置:
(1)Router-number-id(config-interface-id)>|# access-list permit|deny protocol global-ip-address port forgign-ip-address
R1(config-s0)>|# access-list 101 permit tcp any host 201.10.1.1 eq www 允许任何主机访问服务器进行http访问
例如:access-list 101permit tcp any host 201.10.1.1 eq telnet 允许任何主机访问服务器通过telnet进行http访问
(2)OSPF配置