zoukankan      html  css  js  c++  java
  • (转)防火墙上的object-group命令实际应用。 (2010-11-11 10:03:53)

    RLooo的博客:http://blog.sina.com.cn/s/blog_59879e3a0100o5w1.html

    使用object-group 能大大简化配置工作量,很实用。

    防火墙上的配置:

    object-group service gjlyd tcp
      description used for hai nai guo ji lv you dao server
      port-object eq 445
      port-object eq ftp
      port-object eq 3389
      port-object eq www
      port-object eq 8080
      port-object eq 1433
    object-group network gjlydser
      network-object host 10.9.2.66
      network-object host 10.9.2.67
      network-object host 10.9.2.68

    access-list inside permit tcp host 10.2.57.67 object-group gjlydser object-group gjlyd
    access-list inside permit tcp host 10.2.57.151 object-group gjlydser object-group gjlyd

    输出:(看着很爽)

    access-list inside line 494 permit tcp host 10.2.57.67 object-group gjlydser object-group gjlyd
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.66 eq 445 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.66 eq ftp (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.66 eq 3389 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.66 eq www (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.66 eq 8080 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.66 eq 1433 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.67 eq 445 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.67 eq ftp (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.67 eq 3389 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.67 eq www (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.67 eq 8080 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.67 eq 1433 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.68 eq 445 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.68 eq ftp (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.68 eq 3389 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.68 eq www (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.68 eq 8080 (hitcnt=0)
    access-list inside line 494 permit tcp host 10.2.57.67 host 10.9.2.68 eq 1433 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 object-group gjlydser object-group gjlyd
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.66 eq 445 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.66 eq ftp (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.66 eq 3389 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.66 eq www (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.66 eq 8080 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.66 eq 1433 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.67 eq 445 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.67 eq ftp (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.67 eq 3389 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.67 eq www (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.67 eq 8080 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.67 eq 1433 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.68 eq 445 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.68 eq ftp (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.68 eq 3389 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.68 eq www (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.68 eq 8080 (hitcnt=0)
    access-list inside line 495 permit tcp host 10.2.57.151 host 10.9.2.68 eq 1433 (hitcnt=0)

  • 相关阅读:
    数据结构第四篇——线性表的链式存储之双向链表
    基本概念之引用赋值需要注意什么?
    基本概念之将引用作为函数的参数有哪些特点?
    基本概念之什么是引用?
    基本概念之模板类有什么优势?
    我的第一篇博文
    为CentOS 6 配置本地YUM源
    为CentOS 6 配置本地YUM源
    poj 1990 MooFest
    [置顶] 学生信息管理系统“重复设置”问题
  • 原文地址:https://www.cnblogs.com/paddingtoneyes/p/11610557.html
Copyright © 2011-2022 走看看