Quantcast
Channel: АнтиCISCO
Viewing all articles
Browse latest Browse all 3086

Проблемы с NAT на 5525-х

$
0
0
Добрый день коллеги. Прошу помощи, в силу слабоумия, выражающегося в слабом владении навыками укрощения циски 5525-х. Трансляция в и-нет от всех ходит прекрасно. А вот пробросить 80 порт на вэб-сервер внутри никак не получается. Возможно это поможет - всю настройку я проводил при помощи ASDM 7.1 Привожу свой конфиг: : Saved : ASA Version 9.1(1) ! hostname gw domain-name sm.local enable password ***y4XqtsN04Ifxi encrypted passwd ***QnbNIdI.2KYOU encrypted names ! interface GigabitEthernet0/0 nameif outside security-level 0 ip address 195.146.79.182 255.255.255.252 ! interface GigabitEthernet0/1 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/2 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/3 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/4 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/5 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/6 shutdown no nameif no security-level no ip address ! interface GigabitEthernet0/7 nameif inside security-level 0 ip address 10.8.0.1 255.255.255.0 ! interface Management0/0 management-only nameif mng security-level 100 ip address 192.168.2.1 255.255.255.0 ! boot system disk0:/asa911-smp-k8.bin ftp mode passive clock timezone MSK/MSD 3 clock summer-time MSK/MDD recurring last Sun Mar 2:00 last Sun Oct 3:00 dns server-group DefaultDNS domain-name sm.local same-security-traffic permit inter-interface object network krym_srvr host 10.8.0.101 object service web service tcp source eq www destination eq www description web-interface object service rdp service tcp source eq 3128 destination eq 3128 description rdp object network pfsense host 10.8.0.2 description pfsense-nating access-list outside_access_in extended permit tcp any 10.8.0.0 255.255.255.0 eq www access-list inside_access_in extended permit ip any any pager lines 24 mtu outside 1500 mtu inside 1500 mtu mng 1500 no failover icmp unreachable rate-limit 1 burst-size 1 asdm image disk0:/asdm-711-52.bin no asdm history enable arp timeout 14400 no arp permit-nonconnected nat (inside,outside) source dynamic pfsense interface nat (inside,outside) source static krym_srvr interface no-proxy-arp nat (outside,outside) source static any interface destination static interface krym_srvr service web web net-to-net no-proxy-arp access-group outside_access_in in interface outside access-group inside_access_in in interface inside route outside 0.0.0.0 0.0.0.0 195.146.79.181 1 timeout xlate 3:00:00 timeout pat-xlate 0:00:30 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:01:00 timeout floating-conn 0:00:00 dynamic-access-policy-record DfltAccessPolicy user-identity default-domain LOCAL http server enable http 10.8.0.0 255.255.255.0 inside http 192.168.2.0 255.255.255.0 mng http authentication-certificate inside http authentication-certificate mng no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart crypto ipsec security-association pmtu-aging infinite crypto ca trustpool policy telnet timeout 5 ssh 192.168.2.0 255.255.255.0 mng ssh timeout 5 console timeout 0 management-access mng threat-detection basic-threat threat-detection statistics access-list no threat-detection statistics tcp-intercept ssl encryption 3des-sha1 aes128-sha1 aes256-sha1 rc4-md5 rc4-sha1 null-sha1 username cisco password 3USUcOPFUiMCO4Jk encrypted privilege 5 ! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum client auto message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp inspect ip-options ! service-policy global_policy global privilege cmd level 3 mode exec command perfmon privilege cmd level 5 mode exec command dir privilege cmd level 3 mode exec command ping privilege cmd level 3 mode exec command who privilege cmd level 3 mode exec command logging privilege cmd level 3 mode exec command failover privilege cmd level 3 mode exec command vpn-sessiondb privilege cmd level 3 mode exec command packet-tracer privilege cmd level 5 mode exec command export privilege show level 5 mode exec command import privilege show level 5 mode exec command running-config privilege show level 3 mode exec command reload privilege show level 3 mode exec command mode privilege show level 3 mode exec command firewall privilege show level 3 mode exec command asp privilege show level 3 mode exec command cpu privilege show level 3 mode exec command interface privilege show level 3 mode exec command clock privilege show level 3 mode exec command dns-hosts privilege show level 3 mode exec command access-list privilege show level 3 mode exec command logging privilege show level 3 mode exec command vlan privilege show level 3 mode exec command ip privilege show level 3 mode exec command failover privilege show level 3 mode exec command asdm privilege show level 3 mode exec command arp privilege show level 3 mode exec command ipv6 privilege show level 3 mode exec command route privilege show level 3 mode exec command ospf privilege show level 3 mode exec command aaa-server privilege show level 3 mode exec command aaa privilege show level 3 mode exec command eigrp privilege show level 3 mode exec command crypto privilege show level 3 mode exec command ssh privilege show level 3 mode exec command vpn-sessiondb privilege show level 3 mode exec command vpn privilege show level 3 mode exec command dhcpd privilege show level 3 mode exec command blocks privilege show level 3 mode exec command wccp privilege show level 3 mode exec command dynamic-filter privilege show level 3 mode exec command webvpn privilege show level 3 mode exec command service-policy privilege show level 3 mode exec command module privilege show level 3 mode exec command uauth privilege show level 3 mode exec command compression privilege show level 3 mode configure command interface privilege show level 3 mode configure command clock privilege show level 3 mode configure command access-list privilege show level 3 mode configure command logging privilege show level 3 mode configure command ip privilege show level 3 mode configure command failover privilege show level 5 mode configure command asdm privilege show level 3 mode configure command arp privilege show level 3 mode configure command route privilege show level 3 mode configure command aaa-server privilege show level 3 mode configure command aaa privilege show level 3 mode configure command crypto privilege show level 3 mode configure command ssh privilege show level 3 mode configure command dhcpd privilege show level 5 mode configure command privilege privilege clear level 3 mode exec command dns-hosts privilege clear level 3 mode exec command logging privilege clear level 3 mode exec command arp privilege clear level 3 mode exec command aaa-server privilege clear level 3 mode exec command crypto privilege clear level 3 mode exec command dynamic-filter privilege cmd level 3 mode configure command failover privilege clear level 3 mode configure command logging privilege clear level 3 mode configure command arp privilege clear level 3 mode configure command crypto privilege clear level 3 mode configure command aaa-server prompt hostname context no call-home reporting anonymous Cryptochecksum:060cbcfeee46ad53f7d7cea8157ac6e5 : end asdm image disk0:/asdm-711-52.bin no asdm history enable Помогите уважаемые знатоки.

Viewing all articles
Browse latest Browse all 3086