Documente Academic
Documente Profesional
Documente Cultură
exa
asa
outside 0
inside 100
dmz 50
this table make entry in conn table but only for tcp and udp
conn table
implicit means it done automatically but can see like in acl last line
deny any any
default means i can see this entry so that i can change or delete
but in implicit i know but i can see so that i cant delete or change
why
as
if entry found here then it will allow and it will not check acl
asa made by pix and concentrator asa web vpn was not there means ssl
r1
int 0/0
ip add 10.11.11.1 255.255.255.0
no sh
ip route 0.0.0.0 0.0.0.0 10.11.11.10
r2
int f0/0
ip add 192.1.20.2 255.255.255.0
no sh
ip route 0.0.0.0 0.0.0.0 192.1.20.10
r3
int f0/0
ip add 192.168.3.3 255.255.255.0
no sh
ip route 0.0.0.0 0.0.0.0 192.168.3.10
r4
int f0/0
ip add 192.168.4.4 255.255.255.0
no sh
ip route 0.0.0.0 0.0.0.0 192.168.4.10
asa
inside or outside not case sensitive if take all capital or small or mix
int e0/0
nameif Outside
ip add 192.1.20.10
no sh
int e0/1
nameif Inside if i use any word instead of inside it will get 0
and if on next line i put inside it will not get 100
as it already get sec level
int e2
nameif dmz
sec 50
ip add 192.168.3.10
no sh
int e3
nameif dmz4
ip add 192.168.3.10
no sh
now al ping
why
diff in acl
on asa
but now on r2
but icmp is up
now on asa
on r2
line vty 0 4
password cisco
login
on asa1
on r1
telnet 192.1.20.2
cisco
okok
on r2
telnet 10.11.11.1
nonnoo
now on r3
telnet 192.168.20.2
okoko
here 50 to 0
on r3
tel 192.168.4.4
nono
on asa
on r3
tel 192.168.4.4
nono
now on asa
now
now on r3
tel 192.168.4.4
yes
on asa
on r3
tel 192.168.4.4
nono
here first same sec will come then acl will come and check