博威---云架构决胜云计算

 找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 1956|回复: 0

ASA/PIX/FWSM 实施关注事项 绝对重要!!!

[复制链接]
发表于 2007-12-19 13:32:57 | 显示全部楼层 |阅读模式
ASA/PIX/FWSM 实施关注事项 绝对重要!!!

[size=111%]§Enable ip verify reverse-path on all interfaces
[size=111%]§Set embryonic and maximum connection counts on static and nat statements; for 7.2.1+ use per-client-max
    nat (inside) 1 10.0.0.0 255.0.0.0 tcp 50 50 udp 50
                                                             con enb
Configure logging to syslog server (but be carefull on tcp syslog)
[size=111%]§Baseline CPU load, connection counts, xlate counts, and traffic (per interface)
[size=111%]§Disable telnet access, use SSH for management access
[size=111%]§Enable authentication for management access (console/SSH/Telnet/enable); use TACACS+ or RADIUS with LOCAL as the Fallback
[size=111%]§Restrict DMZ access inbound to your internal networks
您需要登录后才可以回帖 登录 | 注册

本版积分规则

小黑屋|手机版|Archiver|boway Inc. ( 冀ICP备10011147号 )

GMT+8, 2024-11-27 22:48 , Processed in 0.113038 second(s), 17 queries .

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回复 返回顶部 返回列表