防火墙入侵于检测——————4、思科安全设备

用户接口

防火墙访问模式
思科防火墙有4个安全管理访问模式:

Unprivileged
Privileged
Configuration
Monitor 


AccessPrivilege Mode


访问配置模式:configure terminal 命令


help 命令


文件管理


查看和保存你的配置


ClearingRunning Configuration


ClearingStartup Configuration


Reloadthe Configuration: reload Command


FileSystem


DisplayingStored Files: System and Configuration


SelectingBoot System File


Verifyingthe Startup System Image


Security Appliance Security Levels

Functionsof the Security Appliance: Security Algorithm

Implements stateful connection control through the securityappliance.
Allows one-way (outbound) connectionswith a minimum number of configuration changes. An outbound connection is aconnection originating from a host on a more-protected interface and destinedfor a host on a less-protected network.
Monitors return packets to ensure thatthey are valid.
Randomizes the first TCP sequence numberto minimize the risk of attack.


SecurityLevel Example


Basic Security ApplianceConfiguration


AssigningHostname to Security Appliance: Changing the CLI Prompt


BasicCLI Commands for Security Appliances 


interface Command and Subcommands


Assignan Interface Name:nameifSubcommand


AssignInterface IP Address: ipaddress Subcommand


DHCP-AssignedAddress



Assigna Security Level: security-level SubCommands


Assignan Interface Speed and Duplex: speed and duplex SubCommands


ASAManagement Interface


NetworkAddress Translation 


EnableNAT Control 


nat Command


nat 0

nat 0 命令:
防火墙不对通过它的数据包进行地址转换。 

pixfirewall(conifg)#nat(inside) 1 10.0.0.0 255.0.0.0
pixfirewall(conifg)#nat (inside) 0 192.168.0.0 255.255.255.0

global Command


Configurea Static Route: route Command


HostName-to-IP-AddressMapping: name Command


ConfigurationExample


ConfigurationExample (Cont.)


ConfigurationExample (Cont.)


ExaminingSecurity Appliance Status

show Commands


show memory Command


show cpu usage Command


show version Command


show ip address Command


show interface Command


show nameifCommand


show run natCommand


show run global Command


show xlateCommand


ping Command


show route Command


Setting Time and Using NTP Support

clock Command


SettingDaylight Saving Time and Time Zones


ntp Command


Summary


Summary(Cont.)


LabVisual Objective




参考:CISCO

  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

FLy_鹏程万里

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值