!S1 端口安全
conf tinterface FastEthernet 0/6switchport mode accessspanning-tree portfastspanning-tree bpduguard enableshutdownswitchport port-securityswitchport port-security mac-address stickyno shutdowninterface range f0/2 – 5 , f0/7 – 24 , g0/1 - 2shutdownend
!----------------------------------
!配置 AAA 本地认证
!----------------------------------
!R1
conf tusername Admin01 privilege 15 secret Admin01pa55aaa new-modelaaa authentication login default local enableend
!-------------------------
!配置 SSH
!-------------------------
!R1
conf tip domain-name ccnasecurity.comcrypto key generate rsa1024ip ssh version 2line vty 0 4transport input sshend
!----------------------------
!防御登录攻击
!----------------------------
!R1
conf tlogin block-for 60 attempts 2 within 30login on-failure logend
!---------------------------------
!配置站点间 IPsec VPN
!---------------------------------
!R1
conf taccess-list 101 permit ip 172.20.1.0 0.0.0.255 172.30.3.0 0.0.0.255crypto isakmp policy 10encryption aes 256authentication pre-sharehash shagroup 5lifetime 3600exitcrypto isakmp key ciscovpnpa55 address 10.20.20.1crypto ipsec transform-set VPN-SET esp-aes 256 esp-sha-hmaccrypto map CMAP 10 ipsec-isakmpset peer 10.20.20.1set pfs group5set transform-set VPN-SETmatch address 101exitinterface S0/0/0crypto map CMAPend
!R3
conf taccess-list 101 permit ip 172.30.3.0 0.0.0.255 172.20.1.0 0.0.0.255crypto isakmp policy 10encryption aes 256authentication pre-sharehash shagroup 5lifetime 3600exitcrypto isakmp key ciscovpnpa55 address 10.10.10.1crypto ipsec transform-set VPN-SET esp-aes 256 esp-sha-hmaccrypto map CMAP 10 ipsec-isakmpset peer 10.10.10.1set transform-set VPN-SETmatch address 101exitinterface S0/0/1crypto map CMAPend
!-----------------------------------
!配置防火墙和 IPS 设置
!-----------------------------------
【Packet Tracer - 综合技能练习(配置各种 IOS 功能】!R3
conf t!Firewall configszone security IN-ZONEzone security OUT-ZONEaccess-list 110 permit ip 172.30.3.0 0.0.0.255 anyaccess-list 110 deny ip any anyclass-map type inspect match-all INTERNAL-CLASS-MAPmatch access-group 110exitpolicy-map type inspect IN-2-OUT-PMAPclass type inspect INTERNAL-CLASS-MAPinspectzone-pair security IN-2-OUT-ZPAIR source IN-ZONE destination OUT-ZONEservice-policy type inspect IN-2-OUT-PMAPexitinterface g0/1zone-member security IN-ZONEexitinterface s0/0/1zone-member security OUT-ZONEend
!配置IPS
mkdir ipsdirconf tip ips config location flash:ipsdirip ips name IPS-RULEip ips signature-categorycategory allretired trueexitcategory ios_ips basicretired falseexit
!--------------------------------------------------
!配置 ASA 基本安全性和防火墙设置
!--------------------------------------------------
!CCNAS-ASA
enable
- 眼综合手术 眼综合手术前后对比
- 23西安电子科技大学 西电 833计算机专业基础综合 834 数据结构 计算机组
- 模糊综合评价法用什么软件实现_采用先进算法技术 实现低效资产评估智能化...
- TS流packet header 分析
- 丽格美容
- 歌舞表演
- 网站如何做好seo优化工作,SEO综合查询工具能检测优化效果吗?
- 19个指标评比世界综合实力十大强国:美国第一,中国远超俄罗斯! 世界十大人口大国
- 中国最值得尊敬的高中,综合实力全国百强,每年清华北大超20个 历史上20个中国之最
- 1.2亿成都市城市安全风险综合监测预警平台建设项目