Rozdíly
Zde můžete vidět rozdíly mezi vybranou verzí a aktuální verzí dané stránky.
| Obě strany předchozí revize Předchozí verze Následující verze | Předchozí verze | ||
|
cisco:policy-map [23.04.2010 07:33] mtalma |
cisco:policy-map [13.03.2020 18:43] (aktuální) |
||
|---|---|---|---|
| Řádek 140: | Řádek 140: | ||
| zone-pair security zp-WAN-To-LAN source WAN destination LAN | zone-pair security zp-WAN-To-LAN source WAN destination LAN | ||
| | | ||
| + | exit | ||
| + | </ | ||
| + | |||
| + | ===== WAN-FW ===== | ||
| + | < | ||
| + | ip access-list extended port_https | ||
| + | | ||
| + | exit | ||
| + | ip access-list extended port_ssh | ||
| + | | ||
| + | exit | ||
| + | ip access-list extended port_cmd | ||
| + | | ||
| + | exit | ||
| + | access-list 110 remark ACL na Cisco - Datron | ||
| + | access-list 110 permit ip 212.158.133.128 0.0.0.31 any | ||
| + | |||
| + | class-map type inspect match-any self-cls-access | ||
| + | match access-group name port_https | ||
| + | match access-group name port_ssh | ||
| + | match access-group name port_cmd | ||
| + | exit | ||
| + | |||
| + | class-map type inspect match-all self-access | ||
| + | match class-map self-cls-access | ||
| + | match access-group 110 | ||
| + | exit | ||
| + | |||
| + | policy-map type inspect WAN_self | ||
| + | class type inspect self-access | ||
| + | no drop | ||
| + | inspect | ||
| + | exit | ||
| + | class class-default | ||
| + | exit | ||
| + | |||
| + | zone security WAN | ||
| + | exit | ||
| + | zone security LAN | ||
| + | exit | ||
| + | |||
| + | zone-pair security zp-WAN-self source WAN destination self | ||
| + | | ||
| + | exit | ||
| + | </ | ||
| + | |||
| + | ===== FW-WAN ===== | ||
| + | < | ||
| + | class-map type inspect match-any cls-icmp-access | ||
| + | match protocol icmp | ||
| + | match protocol tcp | ||
| + | match protocol udp | ||
| + | exit | ||
| + | |||
| + | class-map type inspect match-all icmp-access | ||
| + | match class-map cls-icmp-access | ||
| + | exit | ||
| + | |||
| + | policy-map type inspect self_WAN | ||
| + | class type inspect icmp-access | ||
| + | no drop | ||
| + | inspect | ||
| + | exit | ||
| + | class class-default | ||
| + | no drop | ||
| + | pass | ||
| + | exit | ||
| + | exit | ||
| + | |||
| + | zone-pair security zp-self-WAN source self destination WAN | ||
| + | | ||
| exit | exit | ||
| </ | </ | ||
