16-4
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 16 Identifying Traffic with Access Lists
Access List Overview
hostname(config)#
access-group INSIDE in interface inside
If you want to allow an outside host to access an inside host, you can apply an inbound access list on the
outside interface. You need to specify the translated address of the inside host in the access list because
that address is the address that can be used on the outside network (see
Figure 16-2
).
Figure 16-2
IP Addresses in Access Lists: NAT used for Destination Addresses
See the following commands for this example:
hostname(config)#
access-list OUTSIDE extended permit ip host 209.165.200.225 host
209.165.201.5
hostname(config)#
access-group OUTSIDE in interface outside
209.165.200.225
Inside
Outside
Static NAT
209.165.201.5
10.1.1.34
ACL
Permit from
209.165.200.225
to
209.165.201.5
104636
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......