cisco 28xx 安全配置示例

!---Enable the authentication, authorization, and accounting (AAA) access control model.

aaa new-model
!
!---Identify the Cisco Secure Authentication Control Server (ACS) as a member of a

!---AAA server group. In this example, the AAA server group is called "SJ."

aaa group server tacacs+ SJ
server 192.168.101.119
!
!---Enable AAA authentication at login and specify the authentication methods to try.

aaa authentication login default local group SJ none
!---Restrict user access to the network:

!---(a) Run authorization to determine if the user is allowed to run an EXEC shell.

!---(b) Enable authorization that applies specific security policies on a per-user basis.

!---You must use the "aaa authorization auth-proxy" command together with the

!---"ip auth-proxy <name>" command (later in this configuration). Together, these

!---commands set up the authorization policy to be retrieved by the firewall.

aaa authorization exec default group SJ none
aaa authorization auth-proxy default group SJ
!---Make sure that the same session ID is used for each AAA accounting service type

!---within a call.

aaa session-id common
.
.
.
!---Define a set of inspection rules. In this example, the set is called "myfw."

!---Include each protocol that you wa
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值