配置 PIX 以允许 DMZ 和内部网络之间的 SMTP

配置 PIX 以允许 DMZ 和内部网络之间的 SMTP

我的 DMZ 中有一个 Web 服务器 ( 193.170.4.2),需要10.77.51.87通过 SMTP 与我们的 Exchange 服务器 ( ) 进行内部通信。我使用了access-list acl-dmz permit tcp host 193.170.4.2 host 10.77.51.87 eq smtp,但没有用。

这是因为 acl-outbound 或 nat ACL 中的拒绝 ip 行吗?如果不是,有人能看出是什么原因造成的吗?我的配置如下:

PIX_6.3(5)_515#
access-group acl-inbound in interface outside
access-group acl-outbound in interface inside
access-group acl-dmz in interface dmz1


PIX_6.3(5)_515#
PIX_6.3(5)_515# sh access-list acl-outbound | in deny
access-list acl-outbound line 86 deny ip 10.0.0.0 255.0.0.0 193.170.4.0 255.255.255.0 (hitcnt=1209)
access-list acl-outbound line 90 deny ip any any (hitcnt=1014022)
PIX_6.3(5)_515#
PIX_6.3(5)_515#
PIX_6.3(5)_515# sh access-list acl-dmz
access-list acl-dmz; 2 elements
access-list acl-dmz line 1 permit udp host 193.170.4.2 host 198.6.1.4 eq domain (hitcnt=5625)
access-list acl-dmz line 2 permit ip host 193.170.4.2 any (hitcnt=1089)
PIX_6.3(5)_515#
PIX_6.3(5)_515#
PIX_6.3(5)_515# sh nat
nat (inside) 0 access-list nonat
nat (inside) 1 10.77.51.80 255.255.255.255 0 0
nat (inside) 1 10.77.51.81 255.255.255.255 0 0
nat (inside) 1 10.77.51.87 255.255.255.255 0 0
nat (inside) 2 10.76.0.0 255.255.0.0 0 0
PIX_6.3(5)_515#
PIX_6.3(5)_515# sh run | in static
static (inside,outside) tcp 195.99.136.85 smtp 10.77.51.87 smtp netmask 255.255.255.255 0 0
static (inside,outside) 195.99.136.81 10.77.51.58 netmask 255.255.255.255 0 0
static (inside,outside) 195.99.136.84 10.77.51.38 netmask 255.255.255.255 0 0
static (dmz1,outside) 212.140.175.173 193.170.4.2 netmask 255.255.255.255 0 0
static (dmz1,inside) 212.140.175.173 193.170.4.2 netmask 255.255.255.255 0 0
static (inside,dmz1) 10.76.0.0 10.76.0.0 netmask 255.255.0.0 0 0
PIX_6.3(5)_515#
PIX_6.3(5)_515#
PIX_6.3(5)_515# sh run | in global
global (outside) 1 195.99.136.85
global (outside) 2 interface
PIX_6.3(5)_515#
PIX_6.3(5)_515#

答案1

我认为拒绝你的问题。

尝试:

access-list line 3 acl-dmz permit tcp host 193.170.4.2 host 10.77.51.87 eq smtp
access-list line 88 acl-outbound permit tcp host 10.77.51.87 host 193.170.4.2

相关内容