8-Amaliy ish Mavzu: Tarmoq marshruzatorida dmz ni o’rnatish. Ishdan maqsad




Download 373,5 Kb.
bet2/3
Sana15.05.2024
Hajmi373,5 Kb.
#234792
1   2   3
Bog'liq
8-chi ish

Ishni bajarish tartibi

  1. Cisco packet tracer dasturi ishga tushiriladi.

  2. Laboratoriya ishi uchun cisco 2960 kommutatori, 2911 marshruzatori, ASA0 5505 firewalli, server va kompyuterlar tanlanadi.

  3. Quyida keltirilgan topologiya quriladi.

  4. Qurilgan topologiya testlab ko`riladi.



8.1-rasm. Tadqiq qilinayotgan tarmoq topologiyasi
ASA0 ga quyidagi buyruqlar ketma ketligi kiritiladi.
ciscoasa>en
ciscoasa#conf t
ciscoasa#no dhcpd enable inside
ciscoasa#no dhcpd address 192.168.1.5-192.168.1.36 inside
ciscoasa(config)#interface vlan 1
ciscoasa(config-if)#ip address 192.168.100.1 255.255.255.0
ciscoasa(config-if)#exit
ciscoasa(config)#dhcpd enable inside
ciscoasa(config)#dhcpd address 192.168.100.22-192.168.100.50 inside
ciscoasa(config)#dhcpd dns 8.8.8.8
ciscoasa(config)#interface vlan 2
ciscoasa(config-if)#ip address 195.158.18.18 255.255.255.0
ciscoasa(config-if)#exit
ciscoasa(config)#route outside 0.0.0.0 0.0.0.0 195.158.18.1
ciscoasa(config)#object network NAT
ciscoasa(config-network-object)#subnet 192.168.100.0 255.255.255.0
ciscoasa(config-network-object)#nat (inside,outside) dynamic outside
ciscoasa(config-network-object)#exit
ciscoasa(config)#class-map qoida
ciscoasa(config-if)#match default-inspection-traffic
ciscoasa(config-if)#exit
ciscoasa(config)#policy-map toplam
ciscoasa(config)#class qoida
ciscoasa(config)#inspect http
ciscoasa(config)#inspect icmp
ciscoasa(config)#exit
ciscoasa(config)#service-policy toplam global
ciscoasa(config)#exit
ciscoasa(config)#enable salom
ciscoasa(config)#username admin password tatu123


ciscoasa(config)#hostname Doston-Jumayev

Doston-Jumayev(config)#domain-name tatu.uz


Doston-Jumayev(config)#sh 192.168.100.0 255.255.255.0 inside
^
% Invalid input detected at '^' marker.
Doston-Jumayev(config)#ssh 192.168.100.0 255.255.255.0 inside
Doston-Jumayev(config)#aaa authentication ssh console LOCAL
Doston-Jumayev(config)#aaa authentication telnet console LOCAL
Doston-Jumayev(config)#ssh 8.8.8.8 255.255.255.255 outside
Doston-Jumayev(config)#nterface vlan 3
^
% Invalid input detected at '^' marker.
Doston-Jumayev(config)#interface vlan 3
Doston-Jumayev(config-if)#no forward interface vlan 1
Doston-Jumayev(config-if)#nameif DMZ
INFO: Security level for "DMZ" set to 0 by default.
Doston-Jumayev(config-if)#ip address 192.168.70.1 255.255.255.0
Doston-Jumayev(config-if)#exit
Doston-Jumayev(config)#interface vlan 3
Doston-Jumayev(config-if)#security-level 70
Doston-Jumayev(config-if)#exit
Doston-Jumayev(config)#object network DMZ
Doston-Jumayev(config-network-object)#nat (DMZ,outside) static 195.158.18.88
ERROR: empty object/object-group(s) detected. NAT Policy is not downloaded
Doston-Jumayev(config-network-object)#exit
Doston-Jumayev#conf t
Doston-Jumayev(config)#access-list DMZ permit icmp any host 195.158.18.88
Doston-Jumayev(config)#access-group DMZ in interface outside
Doston-Jumayev(config)#access-list DMZ permit tcp any host 195.158.10.88 eq www
Doston-Jumayev(config)#end
Doston-Jumayev#

ROUTERga quyida buyruqlar ketma ketligi kiritiladi.


continue with configuration dialog? [yes/no]: no
Router>enable
Router#conf t
Router(config)#interface gigabitEthernet 0/1
Router(config-if)#no shutdown
Router(config-if)#ip address 195.158.18.1 255.255.255.0
Router(config-if)#exit
Router(config)#interface gigabitEthernet 0/0
Router(config-if)#no shutdown
Router(config-if)#ip address 8.8.8.1 255.255.255.0
Router(config-if)#do wr



8.2-rasm. Qurilgan topologiyani testlash

Download 373,5 Kb.
1   2   3




Download 373,5 Kb.

Bosh sahifa
Aloqalar

    Bosh sahifa



8-Amaliy ish Mavzu: Tarmoq marshruzatorida dmz ni o’rnatish. Ishdan maqsad

Download 373,5 Kb.