<output id="r87xx"></output>
    1. 
      
      <mark id="r87xx"><thead id="r87xx"><input id="r87xx"></input></thead></mark>
        •   

               當(dāng)前位置:首頁(yè)>管理咨詢>網(wǎng)絡(luò)管理維護(hù)技巧:如何限制撥入VPN用戶的訪問權(quán)限 查詢:
               
          網(wǎng)絡(luò)管理維護(hù)技巧:如何限制撥入VPN用戶的訪問權(quán)限

                  測(cè)試環(huán)境:ASA5520asa723-18-k8.bin:使用如下配置完全滿足需求,當(dāng)用戶撥入VPN后只能訪問內(nèi)部資源,不能訪問外部資源

                  但用這個(gè)配置模板,到正式環(huán)境,就死活限制不了撥入的VPN用戶訪問互聯(lián)網(wǎng)!

                  ====================================================================================================

                  測(cè)試環(huán)境:ASA5520asa723-18-k8.bin

                  tunnel-grouptestzttypeipsec-ra

                  tunnel-grouptestztipsec-attributes

                  pre-shared-key*

                  group-policyzttestinternal

                  group-policyzttestattributes

                  vpn-simultaneous-logins100

                  vpn-idle-timeoutnone

                  vpn-session-timeoutnone

                  vpn-filtervaluedeny-access-internet

                  split-tunnel-network-listvalueDeny-access-internet

                  access-listdeny-access-internetextendedpermitip192.168.1.0255.255.255.0200.1.0.0255.255.0.0

                  access-listdeny-access-internetextendedpermitip192.168.1.0255.255.255.0172.25.90.0255.255.255.0

                  access-listdeny-access-internetextendedpermitip192.168.1.0255.255.255.0100.1.0.0255.255.0.0

                  access-listdeny-access-internetextendeddenyip192.168.1.0255.255.255.0any

                  access-listDeny-access-internetextendedpermitip172.25.90.0255.255.255.0192.168.1.0255.255.255.0

                  access-listDeny-access-internetextendedpermitip100.1.0.0255.255.0.0192.168.1.0255.255.255.0

                  access-listDeny-access-internetextendedpermitip200.1.0.0255.255.0.0192.168.1.0255.255.255.0

                  access-listDeny-access-internetextendeddenyipany192.168.1.0255.255.255.0

                  usernamekakakapassword69eXZQeiMSKhVvOtencrypted

                  usernamekakakaattributes

                  vpn-group-policyzttest

                  vpn-tunnel-protocolIPSec

                  vpn-framed-ip-address192.168.1.100255.255.255.0

                  測(cè)試成功:用戶kakaka只能訪問內(nèi)網(wǎng),不能訪問互聯(lián)網(wǎng)

                  =================================================================================[netxpage]

                  正式環(huán)境:ASA5540asa723-18-k8.bin

                  tunnel-grouptestzttypeipsec-ra

                  tunnel-grouptestztipsec-attributes

                  pre-shared-key*

                  group-policyzttestinternal

                  group-policyzttestattributes

                  vpn-simultaneous-logins100

                  vpn-idle-timeoutnone

                  vpn-session-timeoutnone

                  vpn-filtervaluedeny-access-internet

                  split-tunnel-network-listvalueDeny-access-internet

                  access-listdeny-access-internetextendedpermitiphost172.25.230.188172.0.0.0255.0.0.0

                  access-listdeny-access-internetextendedpermitiphost172.25.230.18810.0.0.0255.0.0.0

                  access-listdeny-access-internetextendeddenyiphost172.25.230.188any

                  access-listDeny-access-internetextendedpermitip172.0.0.0255.0.0.0host172.25.230.188

                  access-listDeny-access-internetextendedpermitip10.0.0.0255.0.0.0host172.25.230.188

                  access-listDeny-access-internetextendeddenyipanyhost172.25.230.188

                  usernamekakakapassword69eXZQeiMSKhVvOtencrypted

                  usernamekakakaattributes

                  vpn-group-policyzttest

                  vpn-tunnel-protocolIPSec

                  vpn-framed-ip-address172.25.230.188255.255.255.0

                  測(cè)試失?。河脩鬹akaka既能訪問內(nèi)網(wǎng),又能訪問互聯(lián)網(wǎng),暈,沒有限制?。?/p>

                  解決方法:我在5540設(shè)備上的group-policyzttestattributes中添加了

                  split-tunnel-policyexcludespecified,就OK了,限制了用戶訪問互聯(lián)網(wǎng),只能訪問內(nèi)網(wǎng)

                  此命令的意思:Excludeonlynetworksspecifiedbysplit-tunnel-network-list(排除上公網(wǎng)的用戶)

                   


          IT主管須謹(jǐn)記的19條軍規(guī)IT運(yùn)維管理為何陷入人力成本困境?
          HR必知的三種薪酬設(shè)計(jì)理念網(wǎng)管經(jīng)驗(yàn)實(shí)例:交換機(jī)頻繁掉線的分析與解決
          提升虛擬化網(wǎng)絡(luò)性能管理的三個(gè)技巧十個(gè)云計(jì)算的常見疑惑問題
          透明化是IT運(yùn)維管理的關(guān)鍵網(wǎng)絡(luò)管理員經(jīng)驗(yàn)之談:如何布控修企業(yè)監(jiān)控
          如何制定新員工培訓(xùn)計(jì)劃方案IT運(yùn)維管理經(jīng)驗(yàn)之路由器都限速如何設(shè)置
          兩招解決IT運(yùn)維日志管理難題網(wǎng)絡(luò)運(yùn)維管理技巧之:小處著眼 降低企業(yè)網(wǎng)絡(luò)運(yùn)維工作負(fù)擔(dān)
          山東電力開啟IT運(yùn)維管理“智能模式”專家剖析:網(wǎng)絡(luò)虛擬化的本質(zhì)與泡沫
          綜合布線如何防護(hù)電磁干擾數(shù)據(jù)中心管理者必備的交換機(jī)高級(jí)功能
          信息發(fā)布:廣州名易軟件有限公司 http://m.jetlc.com
          • 勁爆價(jià):
            不限功能
            不限用戶
            1998元/年

          • 微信客服

            <output id="r87xx"></output>
          1. 
            
            <mark id="r87xx"><thead id="r87xx"><input id="r87xx"></input></thead></mark>
              • 91在线视频 | 爱搞搞电影 | 性饥渴熟妇乱子伦 | 字幕一区二区三区四区五区在线看 | 激情啪啪五月天 | 爱爱无码免费视频 | 91亚洲精品久久久久蜜桃 | 日本黄色视频在线看 | 操逼免费在线视频 | 中国国产黄色视频 |