Cisco Cisco ASA 5555-X Adaptive Security Appliance 产品宣传页

下载
页码 904
 
21-9
Cisco ASA Series 
일반적인 작업 CLI 구성 가이드
 
21 
장     정책 기반 라우팅 
  
정책 기반 라우팅 예
정책 기반 라우팅 작업
위에서 나온 테스트 설정을 사용하여 다양한 일치 기준 및 set 작업을 지닌 정책 기반 라우팅을 구
성하고 이 라우팅이 평가 및 적용되는 방식을 확인하십시오.
먼저, 설정과 관련된 모든 디바이스에 대해 기본 구성부터 시작합니다. 여기에서, A, B, C, D는 
ASA 
디바이스로 간주되고 H1, H2는 IOS 라우터로 간주됩니다.
ASA-A:
ciscoasa(config)# interface GigabitEthernet0/0
ciscoasa(config-if)# nameif inside
ciscoasa(config-if)# security-level 100
ciscoasa(config-if)# ip address 15.1.1.60 255.255.255.0
ciscoasa(config)# interface GigabitEthernet0/1
ciscoasa(config-if)# no shut
ciscoasa(config)# interface GigabitEthernet0/1.1
ciscoasa(config-if)# vlan 391
ciscoasa(config-if)# nameif outside
ciscoasa(config-if)# security-level 0
ciscoasa(config-if)# ip address 25.1.1.60 255.255.255.0
ciscoasa(config)# interface GigabitEthernet0/1.2
ciscoasa(config-if)# vlan 392
ciscoasa(config-if)# nameif dmz
ciscoasa(config-if)# security-level 50
ciscoasa(config-if)# ip address 35.1.1.60 255.255.255.0
ASA-B:
ciscoasa(config)# interface GigabitEthernet0/0
ciscoasa(config-if)# no shut