Monday, March 28, 2011

Cisco ASA 防火墙 SSL VPN 尝试


1、SSL VPN根基设置装备摆设 interface Ethernet0/0 nameif outsideBT4破解无线收集密码教程 security-level 0 ip address 198.1.1.1 255.255.255.0 ! interface Ethernet0/1 nameif inside security-level 100ubuntu 11.04 安装 ip address 172.30.1.97 255.255.255.0 ! ip local pool ssl-user 192.168.12.1-192.168.12.254 ! access-list go-vpn extended permit ip 172.30.1.0 255.255.255.0 192.168.12.0 … 继续阅读

1、SSL VPN根基设置装备摆设 interface Ethernet0/0 nameif outsideBT4破解无线收集密码教程 security-level 0 ip address 198.1.1.1 255.255.255.0 ! interface Ethernet0/1 nameif inside security-level 100ubuntu 11.04 安装 ip address 172.30.1.97 255.255.255.0 ! ip local pool ssl-user 192.168.12.1-192.168.12.254 ! access-list go-vpn extended permit ip 172.30.1.0 255.255.255.0 192.168.12.0 255.255.255.0 ! global (outside) 1 interface nat (inside) 0 access-list go-vpn nat (inside) 1 172.30.1.0 255.255.255.0 route outside 0.0.0.0 0.0.0.0 198.1.1.2 1 ! username wanglinlin password kc0imQBKBLfYhNFb encrypted ! group-policy mysslvpn-group-policy internal group-policy mysslvpn-group-policy attributes vpn-tunnel-protocol webvpn webvpn svc enableUbuntu 输入法安装 ! tunnel-group mysslvpn-group type webvpn tunnel-group mysslvpn-group general-attributes address-pool ssl-user default-group-policy mysslvpn-group-policy tunnel-group mysslvpn-group webvpn-attributes group-alias mysslvpn enable ! webvpn enable outside svc image disk0:/sslclient-win-1.1.1.164.pkg 1 svc enable tunnel-group-list enable 2、开启地道分手 access-list split-ssl extended permit ip 172.30.1.0 255.255.255.0 any ! group-policy mysslvpn-group-policy attributes split-tunnel-policy tunnelspecified split-tunnel-network-list value split-ssl 手记:这个尝试花了我半天时刻,地道分手总起不来,万分无奈之下只有将ssl vpn client进级,结不美观居然成功了!原本使用的SVC版本为:sslclient-win-1.1.0.154.pkgLinux 论坛 思科论坛 转发至微博





Published by
Published by xFruits
Original source : http://www.vpn123.tk/?p=198...

No comments:

Post a Comment