Cisco PIX 525 Spécifications Page 158

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 157
4-6
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 4 Using PIX Firewall in SOHO Networks
Using PIX Firewall as an Easy VPN Remote Device
RELATED CONFIGURATION
sysopt connection permit-ipsec
global (outside) 10 interface
global (outside) 65001 90.0.0.10
nat (inside) 10 60.0.0.0 255.255.255.0 0 0
access-list _vpnc_pat_acl permit ip any 10.0.0.0 255.255.255.0
access-list _vpnc_pat_acl permit ip any 110.0.0.0 255.255.255.0
access-list _vpnc_acl permit ip host 90.0.0.10 10.0.0.0 255.255.255.0
access-list _vpnc_acl permit ip host 90.0.0.10 110.0.0.0 255.255.255.0
access-list _vpnc_acl permit ip host 80.0.0.2 10.0.0.0 255.255.255.0
access-list _vpnc_acl permit ip host 80.0.0.2 host 10.0.0.3
access-list _vpnc_iua_acl permit ip any 10.0.0.0 255.255.255.0
access-list _vpnc_iua_acl permit ip any 110.0.0.0 255.255.255.0
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
Controlling Remote Administration
PIX Firewall Version 6.3 introduces a feature that improves administrative security by letting you
identify the networks from which your PIX
Firewall can be remotely managed or by preventing remote
management altogether.
If you do not enable this feature, any host that has access to the outside interface of your PIX Firewall
through a VPN tunnel can manage it remotely.
To enable this feature, enter the following command:
vpnclient management tunnel ip_addr_1 ip_mask_1 [[ip_addr_2 ip_mask_2] ... ]]
Replace ip_addr_1 and ip_mask1_1 with the IP address and subnet mask of the remote host you would
like to allow to remotely manage your PIX
Firewall. Use additional IP addresses and subnet masks to
enable remote management from more than one host.
To completely prevent remote management using the outside interface of your PIX Firewall, enter the
following command:
vpnclient management clear
After entering this command, no remote management connection is allowed over a VPN tunnel to the
outside interface of the PIX
Firewall. By default, the PIX Firewall can only be remotely managed by
connecting to its outside interface over a secure VPN tunnel. To enable a remote management connection
to the inside interface of your PIX
Firewall, refer to the “Connecting to PIX Firewall Over a VPN
Tunnel” section on page 9-1 in Chapter 9, “Accessing and Monitoring PIX Firewall.
Using Secure Unit Authentication
This section describes how Secure Unit Authentication (SUA) affects the behavior of a PIX Firewall
used as an Easy VPN Remote device, and how you can manage this behavior. It includes the following
topics:
Overview, page 4-7
Establishing a Connection with SUA Enabled, page 4-8
Managing Connection Behavior with SUA, page 4-8
Vue de la page 157
1 2 ... 153 154 155 156 157 158 159 160 161 162 163 ... 465 466

Commentaires sur ces manuels

Pas de commentaire