实验目的: 验证ASA8.3( 包含 8.3) 以后 和ASA8.3 以前 NAT和ACL 执行 顺序 。 拓扑: 一 8.3 以前 配置: access-list acl-outside extended permit tcp any host 202.1.1.10 eq telnet access-list acl-outside extended permit icmp any any nat-control
实验目的:
验证ASA8.3( 包含 8.3) 以后 和ASA8.3 以前 NAT和ACL 执行 顺序 。
拓扑:
650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448462830.jpg" >
一 8.3 以前
650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448463171.jpg" >
配置:
access-list acl-outside extended permit tcp any host 202.1.1.10 eq telnet
access-list acl-outside extended permit icmp any any
nat-control
static (inside,outside) 202.1.1.10 192.168.1.1 netmask 255.255.255.255
access-group acl-outside in interface outside
使用的是转化 以后 的IP(202.1.1.10)
验证:
650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448463532.jpg" > 650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448463873.jpg" >
二 8.3 以后
650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448464204.jpg" >
配置
access-list acl-outside extended permit tcp any host 192.168.1.1 eq telnet
access-list acl-outside extended permit icmp any any
object network Static-Outside-Address
host 202.1.1.10
object network Static-Inside-Address
host 192.168.1.1
object network Static-Inside-Address
nat (Inside,Outside) static Static-Outside-Address
access-group acl-outside in interface outside
验证
650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448464545.jpg" > 650) this.width=650;" onmousedown="" onmousemove="" onmouseout="" onmouseover="" onmouseup="" onreset="" onresize="" onselect="" onsubmit="" onunload="" src="http://cdn.verydemo测试数据/upload/2013_06_07/13705448464886.jpg" >
结论:
ASA8.3( 包含 8.3) 以后 是NAT后ACL和ASA8.3 以前 是先ACL后NAT。
(责任编辑:http://HdhCmsTestverydemo测试数据)查看更多关于ASA8.3(包含8.3)以后和ASA8.3以前NAT和ACL执行顺序的详细内容...