Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
access-list DoS extended permit udp host 1.1.1.1 interface outside eq isakmp
access-list DoS extended permit udp host 1.1.1.1 interface outside eq 4500
access-list DoS extended deny udp any interface outside eq isakmp
access-list DoS extended deny udp any interface outside eq 4500
access-group DoS in int outside control-plane
access-list ipsec-dmz extended permit ip 192.168.1.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list ipsec-dmz extended permit ip 192.168.1.0 255.255.255.0 any
access-list ipsec-outside extended permit ip host 192.168.1.100 10.1.0.0 255.255.0.0
access-list ipsec-outside extended deny ip host 192.168.1.100 any
access-list ipsec-outside extended permit ip 192.168.1.0 255.255.255.0 any
access-list host-100-dc permit ip host 192.168.1.100 10.1.0.0 255.255.0.0
access-list host-100-internet permit ip host 192.168.1.100 any
route dmz 0.0.0.0 0.0.0.0 Nhop track 1
route outside 0.0.0.0 0.0.0.0 NHop 100
no nat-control
global (outside) 1 interface outside
nat (inside) 0 access-list host-100-dc
nat (inside) 1 access-list host-100-internet
access-list DoS extended permit udp host 1.1.1.1 interface outside eq isakmp
access-list DoS extended permit udp host 1.1.1.1 interface outside eq 4500
access-list DoS extended deny udp any interface outside eq isakmp
access-list DoS extended deny udp any interface outside eq 4500
access-group DoS in int outside control-plane
interface dmz
security-level 100
interface inside
security-level 100
same-security-traffic permit inter-interface
access-list ipsec-dmz extended permit ip 192.168.1.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list ipsec-dmz extended permit ip 192.168.1.0 255.255.255.0 any
access-list ipsec-outside extended permit ip host 192.168.1.100 10.1.0.0 255.255.0.0
access-list ipsec-outside extended deny ip host 192.168.1.100 any
access-list ipsec-outside extended permit ip 192.168.1.0 255.255.255.0 any
access-list host-100-dc permit ip host 192.168.1.100 10.1.0.0 255.255.0.0
access-list host-100-dc permit ip 192.168.1.0 255.255.255.128 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.192 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.224 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.240 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.248 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.252 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.254 any
access-list host-100-dc permit ip 192.168.1.0 255.255.255.255 any
route dmz 0.0.0.0 0.0.0.0 Nhop track 1
route outside 0.0.0.0 0.0.0.0 NHop 100
nat-control
global (outside) 1 interface
nat (inside) 0 access-list host-100-dc
nat (inside) 1 192.168.1.100 255.255.255.255
Задачка с ASA. Задачка давалась на Cisco Challenge Cisco Expo 2009