Cisco PIX 525 Specifikace Strana 381

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 466
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 380
10-27
Cisco PIX Firewall and VPN
78-15033-01
Chapter 10 Using PIX Firewall Failover
Failover Configuration Examples
failover ip address outside 209.165.201.2
failover ip address inside 192.168.2.2
failover ip address state 192.168.253.2
failover link state
failover
global (outside) 1 209.165.201.3 netmask 255.255.255.224
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) 209.165.201.5 192.168.2.5 netmask 255.255.255.255 0 0
access-list acl_out permit tcp any 209.165.201.5 eq 80
access-group acl_out in interface outside
route outside 0 0 209.165.201.4 1
LAN-Based Failover Example
Figure 10-3 shows the network diagram for a failover configuration using an Ethernet failover link.
Figure 10-3 LAN-Based Failover Configuration
Internet
209.165.201.4
192.168.254.1
192.168.253.1
192.168.254.2
192.168.253.2
192.168.2.5
192.168.2.1
209.165.201.1
209.165.201.2
192.168.2.2
Switch
Switch
Switch
failover
state
outside
inside
PAT: 209.165.201.3
PIX Firewall
Primary Unit
PIX Firewall
Secondary Unit
Static: 209.165.201.5
Web Server
87932
Example 10-2 (primary unit) and Example 10-3 (secondary unit) list the typical commands in a
LAN-based failover configuration.
Example 10-2 LAN-Based Failover Configuration: Primary Unit
interface ethernet0 100full
interface ethernet1 100full
interface ethernet2 100full
interface ethernet3 100full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 failover security10
nameif ethernet3 state security20
enable password farscape encrypted
password crichton encrypted
Zobrazit stránku 380
1 2 ... 376 377 378 379 380 381 382 383 384 385 386 ... 465 466

Komentáře k této Příručce

Žádné komentáře