Choosetheinterfacetoterminate"> Choosetheinterfacetoterminate" />
欢迎来到天天文库
浏览记录
ID:39775365
大小:50.00 KB
页数:5页
时间:2019-07-11
《全系列VPN技术集锦第三卷第2章(SSL VPN)》由会员上传分享,免费在线阅读,更多相关内容在工程资料-天天文库。
1、全系列VPN技术集锦第三卷第2章(SSLVPN)作者:论坛整理zdnet网络安全CNETNews.com.cn2008-01-1913:29:21关键词:安全防护防火墙VPN""/>ChoosetheinterfacetoterminateWebVPNusers>Enable>Apply.2ChooseServersandURLs>AddEnteranameforthelistofserversaccessiblebyWebVPN.ClicktheAddbutton.TheAddServerorURLdialogueboxdisplays.Enterthename
2、ofeachserver.Thisisthenamethattheclientsees.ChoosetheURLdrop-downmenuforeachserverandchoosetheappropriateprotocol.AddserverstoyourlistfromtheAddServerorURLdialogueboxandclickOK.ClickApply>Save.3ExpandGeneralintheleftmenuofASDM.ChooseGroupPolicy>Add.ChooseAddInternalGroupPolicy.Uncheck
3、theTunnelingProtocols:Inheritcheckbox.ChecktheWebVPNcheckbox.ChoosetheWebVPNtab.UnchecktheInheritcheckbox.Choosefromthelistoffeatures.ClickOK>Apply.4ChoosetheTunnelGroupintheleftcolumn.ClicktheEditbutton.ClicktheGroupPolicydrop-downmenu.ChoosethepolicythatwascreatedinStep3.Itisimporta
4、nttonotethatifnewGroupPoliciesandTunnelGroupsarenotcreated,thedefaultsareGroupPolicy1andDefaultWEBVPNGroup.ClicktheWebVPNtab.ChooseNetBIOSServers.ClicktheAddbutton.FillintheIPaddressoftheWINS/NBNSserver.ClickOK>OK.FollowthepromptsApply>Save>Yestowritetheconfiguration.命令行配置ciscoasa#sho
5、wrunning-configBuildingconfiguration...ASAVersion7.2(1)hostnameciscoasadomain-namecisco.comenablepassword9jNfZuG3TC5tCVH0encryptednamesdns-guardinterfaceEthernet0/0nameifoutsidesecurity-level0ipaddress172.22.1.160255.255.255.0interfaceEthernet0/1nameifinsidesecurity-level100ipaddress1
6、0.2.2.1255.255.255.0interfaceEthernet0/2nameifDMZ1security-level50noipaddressinterfaceManagement0/0descriptionForMgtonlyshutdownnameifMgtsecurity-level0ipaddress10.10.10.1255.255.255.0management-onlypasswd2KFQnbNIdI.2KYOUencryptedftpmodepassivednsserver-groupDefaultDNSdomain-namecisco
7、.compagerlines24loggingenableloggingasdminformationalmtuoutside1500mtuinside1500mtuDMZ11500mtuMgt1500icmppermitanyoutsideasdmimagedisk0:/asdm521.binnoasdmhistoryenablearptimeout14400global(outside)1interfacenat(inside)110.2.2.0255.255.255.0routeoutside0.0.0.00.0.0.0172.22.1.11timeoutx
8、late3
此文档下载收益归作者所有