ASA系列防火墻限制ftp上傳或下載

Cisco Adaptive Security Appliance Software Version 7.2(2)
access-list ouside-acl extended permit tcp host x.x.x.x host x.x.x.x eq ftp
access-list outbound-ftp extended permit tcp host x.x.x.x host x.x.x.x eq ftp
class-map outbound-ftp-1
 match access-list outbound-ftp
!
policy-map type inspect ftp outbound-ftp-2
 parameters
 match request-command put
  reset
!
policy-map internet-policy
 class outbound-ftp-1
  inspect ftp strict outbound-ftp-2
!
service-policy internet-policy interface inside


Cisco Adaptive Security Appliance Software Version 7.0(7)
access-list inside-acl extended permit tcp host x.x.x.x host x.x.x.x eq ftp
access-list ftp-inside-down-acl extended permit tcp host x.x.x.x host x.x.x.x eq ftp
!
class-map ftp_inside_down_clm
 match access-list ftp-inside-down-acl
!
ftp-map ftpmap_inside_down
 request-command deny put
!
policy-map ftp_inside_down_plm
 class ftp_inside_down_clm
  inspect ftp strict ftpmap_inside_down
!
service-policy internet-policy interface inside

转载于:https://www.cnblogs.com/milo85/archive/2008/06/30/1232630.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值