博威---云架构决胜云计算

 找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 2479|回复: 3

ASA/PIX/FWSM 实施关注事项 绝对重要!!!

[复制链接]
发表于 2008-5-23 07:55:00 | 显示全部楼层 |阅读模式
ASA/PIX/FWSM 实施关注事项 绝对重要!!!


§Enable ip verify reverse-path on all interfaces
§Set embryonic and maximum connection counts on static and nat statements; for 7.2.1+ use per-client-max
    nat (inside) 1 10.0.0.0 255.0.0.0 tcp 50 50 udp 50
                                                             con enb
Configure logging to syslog server (but be carefull on tcp syslog)
§Baseline CPU load, connection counts, xlate counts, and traffic (per interface)
§Disable telnet access, use SSH for management access
§Enable authentication for management access (console/SSH/Telnet/enable); use TACACS+ or RADIUS with LOCAL as the Fallback
§Restrict DMZ access inbound to your internal networks
 楼主| 发表于 2008-5-23 07:55:11 | 显示全部楼层
相关排错命令总结


PIX/ASA/FWSM:
§Syslog
§Debug icmp trace
§Show xlate/show conn/show local-host
§Show service policy/show asp-drop
§Packet capture
§http capture for webvpn
IOS security:
    Trace in the encrypted packet.
    jump up/down in isakmp/ipsec
ACS/ACSSE
    package.cab/debug on NAS
……
& experiences & knowledge & lab
 楼主| 发表于 2008-5-23 07:55:23 | 显示全部楼层
排错的时候 应该考虑什么?


§Always formulate an accurate and detailed problem description before troubleshooting(which host, which account, which kind of application, which error message)
§Ensure you have set your trace levels properly
and gathered the appropriate traces after a
problem occurs (security products is far more trivial than IOS routers at this point)
§Use all the tools at your disposal to make searching through traces easier and quicker
发表于 2008-7-3 15:24:05 | 显示全部楼层
强烈支持,好文章要顶
您需要登录后才可以回帖 登录 | 注册

本版积分规则

小黑屋|手机版|Archiver|boway Inc. ( 冀ICP备10011147号 )

GMT+8, 2024-11-24 06:31 , Processed in 0.225357 second(s), 17 queries .

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回复 返回顶部 返回列表