Hi All ,
Voici ma config d'ACL sécurisé , qui passe tous les test grc et pc flank and co.... , j'aimerais encore booster ces régles mais je n'ai sais pas quoi rajouter , merci de votre aide
Code :
- ip nat translation timeout 3600
- ip nat translation tcp-timeout 3600
- ip nat translation udp-timeout 1200
- ip nat translation finrst-timeout 300
- ip nat translation syn-timeout 120
- ip nat translation dns-timeout 300
- ip nat translation icmp-timeout 120
- ip nat translation max-entries 4096
- ip nat inside source list 1 interface Dialer1 overload
- ip nat inside source list 102 interface Dialer1 overload
- ip nat inside source static tcp 10.0.0.1 9999 interface Dialer1 9999
- ip nat inside source static udp 10.0.0.1 10000 interface Dialer1 10000
- ip nat inside source static tcp 10.0.0.1 10002 interface Dialer1 10002
- ip nat inside source static tcp 10.0.0.1 10003 interface Dialer1 10003
- ip classless
- ip route 0.0.0.0 0.0.0.0 Dialer1
- ip http server
- !
- access-list 102 remark flux sortant
- access-list 102 permit ip 10.0.0.0 0.255.255.255 any
- access-list 102 deny udp any any eq netbios-ns
- access-list 102 deny udp any any eq netbios-dgm
- access-list 102 deny udp any any eq netbios-ss
- access-list 102 deny tcp any any eq 135
- access-list 102 deny udp any any eq 135
- access-list 102 deny tcp any any eq 139
- access-list 102 deny ip any any
- access-list 111 remark Flux Entrant
- access-list 111 deny ip 10.0.0.0 0.255.255.255 any
- access-list 111 deny ip 127.0.0.0 0.255.255.255 any
- access-list 111 deny ip host 0.0.0.0 any
- access-list 111 deny ip any host 255.255.255.255
- access-list 111 deny ip host 255.255.255.255 any
- access-list 111 permit tcp any any eq 10003
- access-list 111 permit tcp any any eq 10002
- access-list 111 permit udp any any eq 10000
- access-list 111 permit tcp any any eq 9999
- access-list 111 permit icmp any any administratively-prohibited
- access-list 111 permit icmp any any unreachable
- access-list 111 permit icmp any any packet-too-big
- access-list 111 permit icmp any any source-quench
- access-list 111 permit icmp any any ttl-exceeded
- access-list 111 deny icmp any any
- access-list 111 permit udp any eq isakmp any eq isakmp
- access-list 111 permit gre any any
- access-list 111 deny ip any any
- dialer-list 1 protocol ip permit
|
Thx
Sinon je recherche un bon forum cisco(anglais ou espagnol) car les forums cisco fr ne sont pas très actifs je trouvent
Message édité par kamui le 17-05-2004 à 23:43:25