Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

ÓʼþÍøÂ簲ȫ

ϵͳ°²È« | ÓʼþÈí¼þ©¶´ | °²È«»ù´¡ | Êý×ÖÇ©Ãû | ¹¥·À¼¼Êõ | ²¡¶¾¹«¸æ | ²¡¶¾²éɱ | ISA Server | ·À»ðǽ |
Ê×Ò³ > ÓʼþÍøÂ簲ȫ > ÈíÓ²¼þ·À»ðǽ > ´òÔìÆóÒµ¼á¹ÌµÄ³Çǽ PIX·À»ðÇ½ÌØÊâÅäÖà > ÕýÎÄ

´òÔìÆóÒµ¼á¹ÌµÄ³Çǽ PIX·À»ðÇ½ÌØÊâÅäÖÃ

³ö´¦£ºÈüµÏÍø ×÷ÕߣºÈüµÏÍø ʱ¼ä£º2007-5-20 22:20:18

¡¡Ñ¡Ôñ¸ßµµÍ걸µÄÍøÂ簲ȫÉ豸ÊÇÿһ¸ö³É¹¦ÆóÒµ±Ø²»¿ÉÉÙµÄ×éÍøÉèÊ©£¬µ«ÊÇʵ¼ÊÉϸü¶àÍøÂçÖдæÔÚµÄÍþвÀ´×ÔÓÚÆóÒµÄÚ²¿£¬Òò´Ë½ö½ö±£»¤ÍøÂç×齨µÄ±ß½çÊÇÔ¶Ô¶²»¹»µÄ£¬½¨Á¢Ò»¸öÒ»Ì廯¡¢¶à²ã´ÎµÄ°²È«Ìåϵ½á¹¹¿ÉÒÔÌṩ¸üΪ³¹µ×ºÍʵ¼ÊµÄ±£»¤£¬
Ìá¸ßÆóÒµÄÚ²¿°²È«·À·¶Òâʶ²ÅÊǽâ¾öÆóÒµÍøÂ簲ȫµÄÖØÖÐÖ®ÖС£

PIX·À»ðǽ¼ò½é

¡¡¡¡PIX£¨Private Internet Exchange£©·À»ðǽÊÇCisco²úƷϵÁÐÖгƵÃÉÏٮٮÕߵķÀ»ðǽ²úÆ·¡£PIX·À»ðǽ¿ÉÒÔ²¿Ê𵽸÷ÖÖ¸÷ÑùµÄÉè¼Æ·½°¸ÖС£¼òµ¥µÄÇé¿öÈçÏ£¬PIX·À»ðǽ¿ÉÄÜÖ»ÓÐÁ½¸ö½Ó¿Ú£¬Ò»¸ö½Ó¿ÚÁ¬½ÓÖÁÊܱ£»¤µÄÄÚ²¿ÍøÂ磨ÄÚ²¿½Ó¿Ú£©£¬¶øÁíÒ»¸ö½Ó¿ÚÔòÁ¬½Óµ½¹«¹²ÍøÂ磨Íⲿ½Ó¿Ú£©£¬Ò»°ãÀ´Ëµ¾ÍÊÇÖ¸ÒòÌØÍø¡£ÕâÀïËùνµÄÄÚ²¿ºÍÍⲿ¾ßÓÐÌØ±ðµÄÒâÒ壬ÇÒ¸÷¸ö½Ó¿ÚÔÚPIX·À»ðǽÅäÖÃÖзֱð±»ÃüÃûΪInside½Ó¿Ú£¨ÄÚ²¿£©ºÍOutside½Ó¿Ú£¨Íⲿ£©¡£

¡¡¡¡ÎªÁËÈù«Ë¾Äܹ»ÀûÓÃÓëÒòÌØÍøµÄÁ¬½Ó£¬Í¨³£Ä³Ð©·þÎñÆ÷±ØÐë¶ÔÓÚÍⲿÊÀ½çÊǿɷÃÎʵģ¬ÕâЩ¿É·ÃÎʵķþÎñÆ÷°üÀ¨DNS¡¢SMTPÒÔ¼°ÆóÒµÄܹ»ÓµÓеÄÈκι«ÓÃWeb·þÎñÆ÷¡£DNS·þÎñÆ÷±ØÐëÊǿɷÃÎʵģ¬ÕâÑù²ÅÄܽ«Ö÷»úÃû×Öת»»³É¿ÉÓÃÓÚÊý¾Ý±¨Ñ°Ö·µÄIPµØÖ·¡£ËäÈ»ÕâЩ·þÎñÆ÷¿ÉÒÔ·ÅÔÚ·À»ðǽ֮ºóµÄÄÚ²¿ÍøÂçÖУ¬µ«ÊÇÇ¿ÁÒ½¨Òé²»ÒªÕâÑù×ö¡£ÒòΪÕâЩÖ÷»úÖеÄÈÎÒâһ̨Êܵ½ÇÖº¦ºó£¬¶¼»áµ¼ÖÂÈëÇÖÕßÄܹ»·½±ãµÄ·ÃÎʵ½ÄÚ²¿ÍøÂç¡£¶øÈç¹ûÕâЩ·þÎñÆ÷·ÅÖÃÔÚDMZÖУ¬ÔòPIX·À»ðǽÄܹ»ÔÊÐíÄÚ²¿Óû§²»¼ÓÏÞÖÆµÄ·ÃÎÊÕâЩÖ÷»ú£¬¶øÍ¬Ê±ÏÞÖÆÍⲿÓû§À´·ÃÎÊÕâЩÖ÷»ú¡£

¡¡¡¡´ÓÊг¡ËùÕ¼·Ý¶îÀ´Ëµ£¬×´Ì¬Êý¾Ý±¨·À»ðǽÊÇÖ÷µ¼ÀàÐ͵ķÀ»ðǽ²úÆ·¡£´ó¶àÊýµÄÊг¡¶¼ÏÔʾ£¬PIX·À»ðǽ»òChechpointÈí¼þ¹«Ë¾µÄFirewall¾­³£Õ¼¾ÝÊг¡ÖеĵÚһλ¡£ÔÚPIX·À»ðǽµÄ¾ßÌåÅäÖÃÖй²ÓÐ58¸öPIX¶ÀÓÐÌØÐÔ£¬ÕâÐ©ÌØÐÔÖÐÓÐЩ¹¦Äܷdz£Ã÷ÏÔ£¬¶øÓÐЩȴÂÔÏÔÒþ±Î£»ÓÐÐ©ÌØÐÔÊÇĬÈÏÆô¶¯µÄ£¬¶øÓÐЩÔòÐèÒªÊÖ¶¯½øÐÐÅäÖá£ÏÂÃæÎÒÃǾÍÀ´¿´ÏÂһЩÔÚÆóÒµ×éÍøÖÐÐèÒªÌØ±ð¡°¹Ø×¢¡±ÌØÐÔµÄÅäÖ÷½·¨£¬ÒÔ±ã³ä·ÖÀûÓÃPIX·À»ðǽ£¬ÎªÆóÒµÍøÂçÌá¸ß°²È«ÏµÊý¡£

ÊÖ¶¯ÅäÖÃTCP Intercept

¡¡¡¡Ë¼¿Æ´ÓIOS 11.2°æ±¾ÖÐÊ×´ÎÔÚ·ÓÉÆ÷²úÆ·ÖÐÒýÓÃÁËTCP Intercept(TCP½Ø»ñ)ÌØÐÔ£¬ÔÚPIX5.2ÒÔÉϰ汾ÖÐÒ²ÒýÈëÁËÏàͬµÄÌØÐÔ£¬Õâ¸ö¹¦ÄÜÌØÐÔËäÈ»ÊÇĬÈÏÆôÓõ쬵«ÊÇÈÔÐèҪһЩÊÖ¶¯ÉèÖá£

¡¡¡¡¸ÃÌØÐÔÄܹ»ÎªÒþ²ØÔÚ·À»ðǽºóµÄÖ÷»úÉ豸Ìṩ±£»¤£¬µÖÓù³ÉΪ¡°SYN·ººé¡±µÄÌØ¶¨ÀàÐÍÍøÂç¹¥»÷¡£Ê¹ÓÃSYN·ººé£¬¹¥»÷Õßͨ¹ýºÃÏñ·¢×Ô²»´æÔÚ»ò²»¿É´ïÖ÷»úµÄÁ¬½ÓÇëÇó£¬ÓÐЧµÄʹÊܺ¦ÏµÍ³¸ººÉ¹ýÖØ£¬´Ó¶ø´ïµ½¾Ü¾øÏòÄ¿±êÖ÷»úÌṩ·þÎñµÄÄ¿µÄ¡£SYN·ÀºéÇÉÃîµÄÀûÓÃÁ˲Ù×÷ϵͳΪÿÌõеÄTCPÁ¬½ÓÇëÇó·ÖÅäÄÚ´æºÍÆäËû×ÊÔ´µÄÔ­Àí¡£¼´Ê¹Ö÷»úºÍ·þÎñÆ÷Äܹ»Ö§³Ö´óÁ¿µÄÁ¬½Ó£¬ËüÃÇËùÄÜ´¦ÀíµÄδÍê³ÉÁ¬½ÓµÄÊýÄ¿ÈÔÈ»ÊÇÓÐÏ޵ġ£

¡¡¡¡ÓÉÓÚTCPÊÇË«ÏòºÍȫ˫¹¤µÄ£¬ËùÒÔËüÔÚÁ½¸ö·½ÏòÉ϶¼Òª½¨Á¢Á¬½Ó¡£ÎªÁ˽¨Á¢´Ó·þÎñÆ÷µ½¿Í»§¶ËµÄÁ¬½Ó£¬·þÎñÆ÷ÉèÖÃSYNλ²¢°üÀ¨Ëû×Ô¼ºµÄ˳ÐòºÅÒÔ±ãÇëÇó½¨Á¢´Ó·þÎñÆ÷µ½¿Í»§¶ËµÄÁ¬½Ó£¬·þÎñÆ÷ÉèÖÃSYNλÖóÐÔØ¶ÔÀ´×Ô¿Í»§¶ËµÄ³õʼÁ¬½ÓÇëÇóµÄÈ·ÈÏ£¨ACK룩µÄ·Ö¶ÎÖØ²¢·¢Ë͸ø¿Í»§¶Ë¡£´Ëºó£¬·þÎñÆ÷µÈ´ýµÚ3²½£º´Ó¿Í»§¶Ë·¢À´µÄ¶Ô·þÎñÆ÷µ½¿Í»§¶ËµÄÁ¬½ÓÇëÇóµÄÈ·ÈÏ¡£Õâ¸ö¹ý³Ìͨ³£±»³ÉΪTCPµÄ¡°3´ÎÎÕÊÖ¡±¡£

¡¡¡¡Èç¹ûÓ¦´ðÕß·þÎñÆ÷ûÓÐÔÚÌØ¶¨µÄTCPʱ¼ä¼ä¸ôÄÚ½ÓÊÕµ½Ó¦´ð£¬ÄÇô·þÎñÆ÷»áÖØ´«ÉèÖÃÓÐSYNºÍACKλµÄ·Ö¶Î¡£¸ù¾Ý¾ßÌåµÄTCPʵÏÖ£¬ÖØ´«µÄ´ÎÊýÒ»°ãÊÇ4´Î£¬ÖØ´«µÄʱ¼ä¼ä¸ô¿ªÊ¼ÊÇ1Ã룬ȻºóÒ»´Î¼Ó±¶¡£Èç¹û·þÎñ³ÖÐøµÄ½ÓÊÜÁ¬½ÓÇëÇó£¬ÄÇô×ÊÔ´¿ÉÄܺܿì¾Í»á±»ÕâЩ°ë¿ª·ÅµÄÇëÇóºÄ¾¡£¬ÕâÑù¾Í²»ÄÜÔÙ½ÓÊÜÆäËû´«ÈëÇëÇ󣬴Ӷø¾Ü¾øÁËÄÇÏî·þÎñ¡£

¡¡¡¡TCP Interceptͨ¹ýÆôÓôËÌØÐÔʵÏÖ±£»¤µÄÖ÷»úÉ豸½Ø»ñÁ¬½Ó£¬ÒÔ¼°¶ÔÁ¬½ÓÇëÇó½øÐÐÓ¦´ðÀ´½â¾öÕâ¸öÎÊÌâ¡£Ëü´ú±í¿Í»§¶Ë½¨Á¢ÁË´ÓPIXµ½Êܱ£»¤µÄÖ÷»úµÄµÚ¶þÌõÁ¬½Ó¡£Èç¹û¿Í»§¶ËÕý³£µÄÍê³ÉÁ¬½Ó£¬ÄÇôPIX·À»ðǽ͸Ã÷µØ½«ÕâÁ½ÌõÁ¬½Ó½áºÏÔÚÒ»Æð£¬×îºóµÄ½á¹ûÊǽ¨Á¢ÁËÒ»ÌõÔÚ¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄÖ±½ÓÁ¬½Ó¡£

¡¡¡¡PIX·À»ðǽʹÓÃÁ˸ü¶ÌµÄ³¬Ê±Ê±¼ä¼ä¸ô£¬¶øÇÒÈç¹ûÔÚÕâ¸öʱ¼ä¼ä¸ôÄÚÁ¬½ÓûÓÐÍê³É£¬ÄÇôPIX¾Í»á·ÅÆúÓë¿Í»§¶ËµÄδÍê³ÉÁ¬½Ó£¬²¢ÇÒÏòÊܱ£»¤µÄ·þÎñÆ÷·¢ËÍRST룬½áÊøPIXµ½·þÎñÆ÷µÄÁ¬½Ó£¬´Ó¶øÊͷŵô·þÎñÆ÷×ÊÔ´¡£³ýÁ˸ü¶ÌµÄ³¬Ê±Ö®Í⣬TCP Intercept»¹¼ÓÈëÁË¿ÉÅäÖõÄãÐÖµ¡£ãÐÖµ»á¶ÔÁ¬½Ó×ÜÊýÒÔ¼°×î½ü1·ÖÖÓÄÚµÄÁ¬½ÓËÙÂʽøÐÐ¼à¿Ø¡£Èç¹ûÕâÁ½¸öÖ¸±êÖÐÈκÎÒ»¸ö³¬¹ýÁËãÐÖµ£¬TCP Intercept¶¼»á´Ó×î¾ÃµÄÁ¬½Ó¿ªÊ¼¶Ïµô°ë¿ª·ÅµÄÁ¬½Ó£¬ÖªµÀÁ¬½ÓµÄÊýÄ¿»òËÙÂʽµµ½ãÐÖµÒÔÏ¡£

¡¡¡¡ÔÚPIX·À»ðǽÉÏ£¬°ë¿ª·ÅÁ¬½Ó³Æ×÷³õÆÚÁ¬½Ó¡£ãÐÖµ¿ÉÒÔͨ¹ýstaticÃüÁîµÄ¿ÉÑ¡²ÎÊý½øÐÐÉèÖá£ãÐֵĬÈÏֵΪ0£¬ÕâÑù¾ÍÓÐЧµÄ½ûÓÃÁËTCP Intercept¡£¶øÈô½«ÕâЩ³õÆÚÁ¬½Ó²ÎÊýÉèÖÃΪÈκηÇÁãÊýÖµ£¬¾Í¿ÉÒÔÆôÓÃTCP Intercept¡£ËüÓÐЧµÄÌæ´úÁ˳Æ×÷Flood DefenderµÄ¾ÉPIXÌØÐÔ¡£Õâ¸ö¾ÉÌØÐÔÖ»ÔÊÐí¶Ôÿ¸öÖ÷»úºÍ·þÎñÉϵijõÆÚÁ¬½Ó×ÜÊý½øÐÐÏÞÖÆ¡£

PIXÌØÊâÓ¦ÓÃÅäÖÃ

¡¡¡¡PIX·À»ðǽ֧³ÖºÜ¶àÐèҪijÖÖÌØÊâÐÎʽ´¦ÀíµÄ±ê×¼»òÆÕͨӦÓã¬ÆäÖÐһЩҪÇó¶ÔASA״̬±íËùά»¤µÄÐÅÏ¢×÷һЩÐ޸ģ¬ÒÔ±ãÔÚ״̬Êý¾Ý±¨¹ýÂË»·¾³ÖпÉÒÔʹÓá£ÁíÍâһЩÓÉÓÚ±»NATÐÞ¸ÄÁËIPµØÖ·£¬ËùÒÔ¿ÉÄÜÐèÒª¶ÔÒ»¸ö»ò¶à¸öÉϲãЭÒéÍ·×ֶνøÐе÷Õû¡£»¹ÓÐÒ»×é²¢²»×ñÑ­ËùÆÚÍûµÄ·¢ËÍÕߺͽÓÊÜÕß½»»»µÄ¶Ô³ÆÄ£Ê½¡£¶ÔÓÚ´ó¶àÊýÓ¦ÓÃÀ´Ëµ£¬¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼ä½»»»µÄIPÊý¾Ý±¨¾ßÓÐÏàͬµÄÔ´ºÍÄ¿µÄIPµØÖ·ÒÔ¼°TCP/UDP¶Ë¿ÚºÅ£¬Ö»²»¹ýÿ´Î½»»»¹ý³ÌÖз¢ËÍÕߺͽÓÊÕÕߵĽÇÉ«ÕýºÃÏà·´¡£½ÓÏÂÀ´ÎÒÃǽ«¶ÔÕâÐ©ÌØÊâÇé¿ö½øÐÐÏêϸ½éÉÜ¡£

1¡¢ Java Applet·âËø

¡¡¡¡PIX·À»ðǽʹµÃÍøÂç¹ÜÀíÔ±Äܹ»¹ýÂ˵ô¿ÉÄÜÓꦵÄJavaС³ÌÐò¡£¿ÉÒÔ¸ù¾ÝÄÚ²¿¿Í»§¶ËµÄÔ´µØÖ·¡¢Íⲿ·þÎñÆ÷µÄÄ¿µÄµØÖ·£¬»òÕßͬʱ¸ù¾ÝÁ½Õߣ¬À´¶ÔJava¹ýÂ˽øÐж¨Òå¡£ÃüÁîÓï·¨Öаüº¬·´ÑÚÂ룬Ëü¿ÉÒÔÓÃÀ´¶¨Òåµ¥¸öµÄµØÖ·»òµØÖ··¶Î§¡£µ±ÆôÓÃÁËJava¹ýÂ˺ó£¬PIX·À»ðǽ¾Í»áËÑË÷º¬ÓÐJavaС³ÌÐò±ê¼Ç£¨Ê®Áù½øÖÆ×Ö·û´®0 x CEFE BABE£©µÄhttpÊý¾Ý±¨¡£

¡¡¡¡ÆôÓÃJava¹ýÂ˵ÄÅäÖÃÃüÁîµÄÒ»¸öʵÀýÈçÏ£º

¡¡¡¡Filter java 80 10.1.1.0 255.255.255 0.0.0.0.0.0.0.0

¡¡¡¡¶ÔÉÏÃæÃüÁîµÄ½âÊÍÈçÏ£ºÈç¹û·ÃÎʶ˿Ú80£¬ÄÇô×ÓÍø10.1.1.0£¨Ò»¸ö½ÏΪ°²È«µÄ½Ó¿Ú£©ÖеÄËùÓпͻ§¶Ë¶¼»á½ûÖ¹´Ó°²È«ÐÔ¼¶±ð½ÏµÍµÄ½Ó¿ÚÉ̵ÄÈκÎÖ÷»ú£¨0.0.0.0.0.0.0.0£©ÉÏÏÂÔØJavaС³ÌÐò¡£ÕâÀïµÄ0.0.0.0.0.0.0.0 Ò²¿ÉÒÔËõд³Æ0 0

2¡¢ActiveX

¡¡¡¡ÓëActiveXÓйصÄÍøÂ簲ȫÎÊÌâÀàËÆÓÚJavaÎÊÌâ¡£ActiveX¿Ø¼þÓÉ¿ÉǶÈëµ½WebÒ³ÖеĶÔÏó×é³É£¬ÕâЩ¿Õ¼äÄܹ»ÏÂÔØµ½¿Í»§¶Ë¼ÆËã»úÖÐÔËÐС£ActiveXµÄ¹ýÂË¿ÉÒÔͨ¹ý×¢Ê͵ôHTMLÃüÁîµÄÒýÓÃÀ´ÊµÏÖ¡£ËùÓõ½µÄÃüÁîÓ﷨ʵ¼ÊÉÏÓëJava¹ýÂËʹÓõÄÃüÁîÏàͬ£¬Ö»²»¹ýÊÇÓÃfilter activex¡­´úÌæÁËfilter java¡­¡£

3¡¢ URL¹ýÂË

¡¡¡¡ÀûÓÃÓëWebsense¹«Ë¾ºÏ×÷£¬CiscoÌṩÁ˽«WebsenseµÄOpen ServerÄÚÈݹýÂË·þÎñÆ÷ÓëPIX·À»ðǽÅäºÏʹÓõÄÄÜÁ¦¡£Websense±»ºÜ¶à×éÖ¯ÓÃÓÚÉèÖúÍÔöÇ¿×÷ÎªÍøÂ簲ȫ²ßÂÔµÄÒ»¸ö×é³É²¿·ÖµÄÒòÌØÍø·ÃÎʲßÂÔ(IAP)¡£WebsenseÀûÓÃÒ»¸öÓɳ¬¹ý150ÍòµÄÕ¾µã¹¹³ÉµÄÖ÷Êý¾Ý¿â¶ÔÒòÌØÍøÄÚÈݽøÐйýÂË¡£¶Ô·ÃÎʵľܾø£¨·âËø£©¿ÉÒÔ¸ù¾ÝÓû§¡¢ÍÅÌå»òÕßʱ¼äÀ´ÉèÖá£

¡¡¡¡URL¹ýÂËÔÊÐíPIX·À»ðǽ½«Websense·þÎñÆ÷¶¨ÒåµÄIAP³öÕ¾Óû§ËùÇëÇóµÄURL½øÐбȽϡ£ÏÂÃæµÄÀý×ÓʹÓõØÖ·Îª10.2.2.2µÄWebsense·þÎñÆ÷¹ýÂ˵ô³ý×ÓÍø10.1.1.0ÉϵÄÓû§Ö®ÍâµÄËùÓгöÕ¾·ÃÎÊ¡£µÚ3ÐÐÖ»ÔÚÀýÍâÇé¿öʱ²ÅÐèÒª£¬·ñÔòËüÊÇ¿ÉÑ¡µÄ¡£

url-server host 10.2.2.2

filter url http 0000

filter url except 10.1.1.0 255.255.255.0

¡¡¡¡¿ØÖÆÍ¨¹ýPIX·À»ðǽµÄÁ÷Á¿

¡¡¡¡ÓÉÓÚ·À»ðǽµÄÖ÷ҪĿµÄÊÇ·âËø£¬ÖÁÉÙÊÇÒª¿ØÖƶÔÊܱ£»¤ÍøÂçµÄ·ÃÎÊ£¬ËùÒÔÓ¦µ±¹Ø×¢µÄÊÇ´«ÈëµÄÊý¾Ý±¨¡£°Ñ´«ÈëÁ÷Á¿»òÈëÕ¾Á÷Á¿¶¨ÒåΪ´Ó°²È«ÐԽϲîµÄ½Ó¿Ú½øÈëPIX·À»ðǽºÍ´Ó°²È«ÐԽϸߵĽӿÚÀ뿪PPIX·À»ðǽµÄÊý¾Ý±¨¡£ÀàËÆµÄ£¬°Ñ´«³öÁ÷Á¿»ò³öÕ¾Á÷Á¿¶¨ÒåΪ´Ó°²È«ÐԽϸߵĽӿڽøÈëPIX·À»ðǽºÍ´Ó°²È«ÐԽϲîµÄ½Ó¿ÚÀ뿪PIX·À»ðǽµÄÊý¾Ý±¨¡£ÆäÖÐÖ»ÓÐÒ»¸ö½Ó¿Ú±»ÃüÃûΪInside£¨°²È«¼¶±ð£½100£©£¬Ò²Ö»ÓÐÒ»¸ö½Ó¿Ú±»ÃüÃûΪOutside£¨°²È«¼¶±ð£½0£©¡£ÕâÊÇÒòΪÔÚËùÓнӿÚÖУ¬ÕâÁ½¸ö½Ó¿ÚÊÇÓÀÔ¶·Ö±ð´¦ÔÚ×îÄÚ²¿ºÍ×îÍⲿµÄ¡£¸ù¾Ý¾ßÌåµÄ°²È«¼¶±ð£¬ÆäËûDMZ»òÍâΧ½Ó¿ÚÏà¶ÔÓÚÁíÍâµÄ½Ó¿Ú¿ÉÄÜÊÇÄÚ²¿µÄ£¬Ò²¿ÉÄÜÊÇÍⲿµÄ£¬µ«ÊÇËûÃÇÏà¶ÔÓÚInside½Ó¿Ú¶øÑÔ×ÜÊÇÍⲿµÄ£¬¶ÔÓÚOutside½Ó¿Ú¶øÑÔÔò×ÜÊÇÄÚ²¿µÄ¡£

¡¡¡¡ÔÚPIX·À»ðǽ5.2֮ǰµÄ°æ±¾ÖУ¬ÓÃÀ´¶¨ÒåÔÊÐíÁ÷Á¿µÄЭÒé²ÎÊýµÄÃüÁîÊÇconduitÃüÁî¡£ConduitÃüÁîµÄÓï·¨¿´ÆðÀ´·Ç³£ÏñÀ©Õ¹·ÃÎÊÁбíËùʹÓõĸñʽ£¬²»¹ýÔÚÃüÁîµÄÓï·¨ÖУ¬Ô´µØÖ·ºÍÄ¿µÄµØÖ·µÄλÖÃÕýºÃÏà·´¡£´Ó5.2°æ±¾¿ªÊ¼£¬´«Í³µÄÀ©Õ¹·ÃÎÊÁбí´úÌæÁËconduitÃüÁĿǰ£¬¾¡¹ÜCiscoÍÆ¼öʹÓÃеĸñʽ£¬µ«ÊÇʵ¼ÊÉÏÕâÁ½ÖÖÃüÁî¸ñʽ¶¼¿ÉÒÔʹÓá£

¡¡¡¡ÎªÁ˶ÔÈ¥ÍùÕâЩ·þÎñÆ÷µÄÁ÷Á¿¶¨ÒåÏàÓ¦µÄͨµÀ£¬¿ÉÒԹ涨·þÎñÆ÷µÄIPµØÖ·×÷ΪĿµÄµØÖ·£¬²¢¹æ¶¨HTTP¡¢DNSºÍSMTP×÷ΪĿµÄ¶Ë¿ÚºÅ£¬µ«ÊÇͨ³£²¢²»ÖªµÀÔ´µØÖ·ºÍÔ´¶Ë¿ÚºÅ¡£ÏÂÃæÊÇÒ»¸ö·ÃÎÊÁбíµÄÀý×Ó£¬ÔÚÕâ¸öÀý×ÓÖУ¬IPµØÖ·Îª10.1.1.1µÄ·þÎñÆ÷Äܹ»ÌṩËùÓÐ3ÖÖ·þÎñ¡£

Access-list dmz permit tcp any host 10.1.1.1 eq http

Access-list dmz permit tcp any host 10.1.1.1 eq smtp

Access-list dmz permit tcp any host 10.1.1.1 eq do main

¡¡¡¡ÉÏÃæËùÁз½·¨¾Í¾ÙÀý¶øÑÔÊÇÒѾ­×ã¹»ÁË£¬µ«ÊÇÔÚ°²È«·½Ã滹Ҫ½øÒ»²½ÉèÖá£ÒòΪ²¢²»ÄÜÔ¤ÖªÍⲿÓû§½«Ê¹ÓÃÄÄЩԴIPµØÖ·ºÍÔ´¶Ë¿Ú£¬ËùÒÔ±ØÐëÔÚACLÖй涨ÔÊÐíʹÓÃËùÓеÄÔ­µØÖ·ºÍÔ´¶Ë¿Ú¡£

Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • MDaemonʹÓü¼ÇÉ´óÈ«--ÈçºÎÅäÖÃwindowsµÄ·À»ðǽ
  • Õþ¸®ÍøÕ¾WEBÓ¦Ó÷À»ðÇ½ÍøÕ¾·ÀºÚ·À´Û¸Ä½â¾ö·½°¸
  • Ëó×ÓÓãÀ¬»øÓʼþ·À»ðǽ¿ìËÙ°²×°Ö¸ÄÏ
  • ÃîÓÃDNS½âÎöʵÏÖ·À»ðǽ¿Í»§µÄÖØ¶¨Ïò
  • À¬»øÓʼþÓ²¼þ·À»ðǽѡ¹º½éÉÜÖ¸ÄÏ
  • Á˽âGFW£¨¹ú¼Ò·À»ðǽ£©
  • BarracudaÀ¬»øÓʼþ·À»ðǽldap_test.cgi¿çÕ¾½Å±¾Â©¶´
  • ÎÞÐè·À»ðǽ Ò»Õб£ÄãµçÄÔ°²È«
  • dzÎö·À»ðǽÓë·ÓÉÆ÷°²È«ÅäÖÃ
  • ÈçºÎͨ¹ýISA2006·À»ðǽ·¢²¼ÆôÓÃÁËSSLµÄOWA
  • Ò»¸ö˼¿ÆPIX·À»ðǽµÄʵ¼ÊÓ¦ÓÃÅäÖÃ
  • ÅäÖÃWindows Server 2008¸ß¼¶·À»ðǽ
  • [ͼ½â]ÈçºÎÉèÖôúÀí·þÎñÆ÷£¿
  • Kerio Winroute Firewall 6.01 VPNʹÓÃÏê½â
  • Kerio WinRoute Firewall°²×°È«¹¥ÂÔ
  • Kerio Network MonitorÍêȫʹÓý̳Ì
  • CISCO PIX ·À»ðǽ¼°ÍøÂ簲ȫÅäÖÃ
  • ·ÓÉÆ÷µäÐÍ·À»ðǽÉèÖÃ
  • ¾ª±¬£¡ÌÚѶQQ2003¢óÕýʽ°æ°²È«³öÏÖ©¶´(ͼ)
  • PIX·À»ðǽϵͳ¹ÜÀí
  • Óʼþ·þÎñÆ÷Óë´úÀí·þÎñÆ÷Èí¼þÅäºÏ·½°¸
  • ÍêÕûµÄpix525ÅäÖÃ
  • ÓÃPIX¹¹ÖþͭǽÌú±Ú
  • CISCO PIX515E ·À»ðǽµÄÉèÖÃ
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ