防火牆入侵於檢測——————4、思科安全裝置

FLy_鵬程萬里發表於2018-06-20

使用者介面

防火牆訪問模式
思科防火牆有4個安全管理訪問模式:

Unprivileged
Privileged
Configuration
Monitor 


AccessPrivilege Mode


訪問配置模式:configure terminal 命令


help 命令


檔案管理


檢視和儲存你的配置


ClearingRunning Configuration


ClearingStartup Configuration


Reloadthe Configuration: reload Command


FileSystem


DisplayingStored Files: System and Configuration


SelectingBoot System File


Verifyingthe Startup System Image


Security Appliance Security Levels

Functionsof the Security Appliance: Security Algorithm

Implements stateful connection control through the securityappliance.
Allows one-way (outbound) connectionswith a minimum number of configuration changes. An outbound connection is aconnection originating from a host on a more-protected interface and destinedfor a host on a less-protected network.
Monitors return packets to ensure thatthey are valid.
Randomizes the first TCP sequence numberto minimize the risk of attack.


SecurityLevel Example


Basic Security ApplianceConfiguration


AssigningHostname to Security Appliance: Changing the CLI Prompt


BasicCLI Commands for Security Appliances 


interface Command and Subcommands


Assignan Interface Name:nameifSubcommand


AssignInterface IP Address: ipaddress Subcommand


DHCP-AssignedAddress



Assigna Security Level: security-level SubCommands


Assignan Interface Speed and Duplex: speed and duplex SubCommands


ASAManagement Interface


NetworkAddress Translation 


EnableNAT Control 


nat Command


nat 0

nat 0 命令:
防火牆不對通過它的資料包進行地址轉換。 

pixfirewall(conifg)#nat(inside) 1 10.0.0.0 255.0.0.0
pixfirewall(conifg)#nat (inside) 0 192.168.0.0 255.255.255.0

global Command


Configurea Static Route: route Command


HostName-to-IP-AddressMapping: name Command


ConfigurationExample


ConfigurationExample (Cont.)


ConfigurationExample (Cont.)


ExaminingSecurity Appliance Status

show Commands


show memory Command


show cpu usage Command


show version Command


show ip address Command


show interface Command


show nameifCommand


show run natCommand


show run global Command


show xlateCommand


ping Command


show route Command


Setting Time and Using NTP Support

clock Command


SettingDaylight Saving Time and Time Zones


ntp Command


Summary


Summary(Cont.)


LabVisual Objective




參考:CISCO

相關文章