Cisco PIX 525 Especificaciones Pagina 94

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 466
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 93
2-34
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 2 Establishing Connectivity
Using VLANs with the Firewall
global (outside) 1 209.165.201.10-209.165.201.30
global (outside) 1 209.165.201.5
global (dmz) 1 192.168.0.10-192.168.0.20
nat (inside) 1 10.0.0.0 255.0.0.0
nat (dmz) 1 192.168.0.0 255.255.255.0
static (dmz,outside) 209.165.201.6 webserver netmask 255.255.255.255
access-group acl_out in interface outside
access-group ping_acl in interface inside
access-group ping_acl in interface dmz
no rip inside passive
no rip outside passive
no rip inside default
no rip outside default
route outside 0.0.0.0 0.0.0.0 209.165.201.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00
udp 0:02:00 rpc 0:10:00 h323 0:05:00
sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
no snmp-server location
no snmp-server contact
snmp-server community public
telnet 10.0.0.100 255.255.255.255
telnet timeout 15
Using VLANs with the Firewall
PIX Firewall Version 6.3 introduces support for VLANs. This section describes how to use and
implement VLANs with firewall and includes the following topics:
Overview, page 2-34
Using Logical Interfaces, page 2-35
VLAN Security Issues, page 2-36
Configuring PIX Firewall with VLANs, page 2-36
Managing VLANs, page 2-37
Overview
Virtual LANs (VLANs) are used to create separate broadcast domains within a single switched network.
Some of the benefits of VLANs include the following:
Broadcast control
Improved security
Flexibility
Scalability
A VLAN can be created through software configuration whenever it is needed because no actual
separation is required in the physical or data link network. To create a VLAN, you simply assign ports
on each switch to the new VLAN. However, the VLAN must then be interconnected to the rest of your
network through a router or other device that can forward packets between the ports assigned to the
VLAN.
Vista de pagina 93
1 2 ... 89 90 91 92 93 94 95 96 97 98 99 ... 465 466

Comentarios a estos manuales

Sin comentarios