Cisco Cisco IPS 4360 Sensor Libro bianco

Pagina di 79
58
Appendix B: Configuration Example 
August 2012 Series
58
object network dmz-webserver-ISPa
 host 192.168.16.100
 description NAT the webserver in the DMZ to the outside address 
on ISP A
object network dmz-webserver-ISPb
 host 192.168.17.100
 description NAT the webserver in the DMZ to the outside address 
on ISP B
object network outside-webserver-ISPb
 host 172.17.130.100
 description Webserver on ISP B
object network dmz-cvo-1
 host 192.168.18.20
object network outside-cvo-1
 host 172.16.130.2
object network dmz-dmvpn-1
 host 192.168.18.10
 description NAT the primary DMVPN hub router in the DMZ to ISP A
object network outside-dmvpn-ISPa
 host 172.16.130.1
 description DMVPN hub router on ISP A
object network dmz-dmvpn-2
 host 192.168.18.11
 description NAT the secondary DMVPN hub router in the DMZ to ISP 
B
object network outside-dmvpn-ISPb
 host 172.17.130.1
 description DMVPN hub router on ISP B
object network dmz-esa-ISPa
 host 192.168.17.25
 description NAT the ESA in the DMZ to the outside address on ISP 
A
object network outside-esa-ISPa
 host 172.16.130.25
 description ESA on ISP A
object network internal-dns
 host 10.4.48.10
 description DNS in the internal data center
object network internal-exchange
 host 10.4.48.25
 description Exchange server in the internal datacenter
object network internal-ntp
 host 10.4.48.17
 description NTP server in the internal data center
object network 5505-pool
 subnet 10.4.156.0 255.255.252.0
 description 5505 Teleworker Subnet
object network internal-network
 subnet 10.4.0.0 255.254.0.0
 description The organization’s internal network range
object network dmz-guests-network-ISPa
 subnet 192.168.28.0 255.255.252.0
object network guest-wlc-1
 host 192.168.19.54
 description Dedicated DMZ WLC
object network internal-acs
 host 10.4.48.15
 description Internal ACS
object network internal-dhcp
 host 10.4.48.10
 description DC DHCP
object network internal-flex-WLC7500-1
 host 10.4.46.68
 description Primary  FlexConnect Controller
object network internal-flex-WLC7500-2
 host 10.4.46.69
 description Secondary FlexConnect Controller
object network internalWLC5508-1
 host 10.4.46.64
 description Primary HQ Controller
object network internalWLC5508-2
 host 10.4.46.65
 description Secondary HQ Controller
object network outside-cvo-2