data:image/s3,"s3://crabby-images/19353/193537b9f3c5d62280499dd0ccfebe19c13eecd3" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 301"
15-3
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 15 Permitting or Denying Network Access
Inbound and Outbound Access List Overview
Then, if you want to allow only certain hosts on the inside networks to access a web server on the outside
network, you can create a more restrictive access list that allows only the specified hosts and apply it to
the outbound direction of the outside interface (see
Figure 15-1
). See the
“IP Addresses Used for Access
Lists When You Use NAT” section on page 13-3
for information about NAT and IP addresses. The
outbound access list prevents any other hosts from reaching the outside network.
Figure 15-2
Outbound Access List
See the following commands for this example:
hostname(config)#
access-list INSIDE extended permit ip any any
hostname(config)#
access-group INSIDE in interface inside
hostname(config)#
access-list HR extended permit ip any any
hostname(config)#
access-group HR in interface hr
hostname(config)#
access-list ENG extended permit ip any any
hostname(config)#
access-group ENG in interface eng
hostname(config)#
access-list OUTSIDE extended permit tcp host 209.165.201.4
host 209.165.200.225 eq www
hostname(config)#
access-list OUTSIDE extended permit tcp host 209.165.201.6
host 209.165.200.225 eq www
hostname(config)#
access-list OUTSIDE extended permit tcp host 209.165.201.8
host 209.165.200.225 eq www
hostname(config)#
access-group OUTSIDE out interface outside
Web Server:
209.165.200.225
Inside
HR
Eng
Outside
Static NAT
209.165.201.4
10.1.1.14
Static NAT
209.165.201.6
10.1.2.67
Static NAT
209.165.201.8
10.1.3.34
ACL Outbound
Permit HTTP from
209.165.201.4
,
209.165.201.6
,
and
209.165.201.8
to
209.165.200.225
Deny all others
132944
ACL Inbound
Permit from
any
to
any
ACL Inbound
Permit from
any
to
any
ACL Inbound
Permit from
any
to
any
FWSM
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......