验证思科防火墙的连接性
Ping测试:Firewall# ping [if_name] host [data pattern] [repeat count] [size bytes] [timeout seconds] [validate]ITPUB个人空间"P*CP'n
YL0F
ARP缓存检查:
Yvl~;BR0show arpITPUB个人空间q0Z3Xy[ Y/j }r2y
路由表检查:
I(u+X(zA,zl7Qv^0show route
[`8@5Mo4ER&r[0Traceroute测试:ITPUB个人空间4g!rg;Tnq4f h
traceroute命令前提配置ITPUB个人空间6Q mcMng&{
Firewall(config)# access-list acl_name permit icmp any any eq echoITPUB个人空间 R7@r TC~9J!wM['g
Firewall(config)# access-list acl_name permit icmp any any eq echo-reply
m&g6kc%|6\$nS0Firewall(config)# access-list acl_name permit icmp any any eq unreachableITPUB个人空间y%l J-GB"vL'D
Firewall(config)# access-list acl_name permit icmp any any eq time-exceededITPUB个人空间W:_$J9tl2A~:_NZ
Firewall(config)# access-list acl_name permit udp any range 32768 65535 any range 33434 33523
is:m:N+s7Wt(E(xh0Firewall(config)# access-list acl_name permit udp any dns_address eq domain (可选)ITPUB个人空间0B?qnn'|+N
ACL检查:ITPUB个人空间tZ](O;h\9u.h8r
show access-group, show access-listITPUB个人空间| H b D/F2DmF/I rS
NAT验证:
"[k ~L~"|O'e8w0Firewall# show xlate [detail] [global | local ip1[-ip2] [netmask mask]] lport | gport port[-port]] [interface if1[,if2][,ifn]] [state static [,dump] [,portmap] [,norandomseq] [,identity]] [debug] [count]ITPUB个人空间zS9n0Naq&JL'S6S
Firewall# show xlate [{global | local} ip1[-ip2] [netmask mask]] [{lport | gport} port[-port]] [interface if1[,if2][,ifn]] [state {static | portmap | identity | norandomseq}] [debug] [detail]
[,GDU)U_0Firewall# show conn [state state_type] [{foreign | local} ip1[-ip2] netmask mask] [long] [{lport | fport} port1[-port2]] [protocol {tcp | udp}]监控特定主机:
9VM'NA%I!]/L0Firewall# show local-host [ip_address] [all] [detail]
/eF2FL;~M#R't0Firewall# clear xlate global global_ip [netmask mask] [gport global_port]ITPUB个人空间 Z,P k8Cj
Firewall# clear xlate local local_ip [netmask mask] [lport local_port]ITPUB个人空间r T2?'s$e4s"v'hT
Firewall# clear xlate interface if_name_1[,if_name_2]ITPUB个人空间L7@u0[efO
Firewall# clear xlateITPUB个人空间0l%VD&R)xo4w1@
超时参数:
4v Bpb)DlB0Firewall(config)# timeout xlate hh[:mm[:ss]]
JT4es'\X#~0Firewall(config)# timeout conn hh[:mm[:ss]]ITPUB个人空间5oSC.C8P&^.N3v
Firewall(config)# half-closed hh[:mm[:ss]]ITPUB个人空间_^)Q EM vK`
Firewall(config)# udp hh[:mm[:ss]]ITPUB个人空间 kr(hO1?!J$xM,n
Shun检查:
ARP缓存检查:
Yvl~;BR0show arpITPUB个人空间q0Z3Xy[ Y/j }r2y
路由表检查:
I(u+X(zA,zl7Qv^0show route
[`8@5Mo4ER&r[0Traceroute测试:ITPUB个人空间4g!rg;Tnq4f h
traceroute命令前提配置ITPUB个人空间6Q mcMng&{
Firewall(config)# access-list acl_name permit icmp any any eq echoITPUB个人空间 R7@r TC~9J!wM['g
Firewall(config)# access-list acl_name permit icmp any any eq echo-reply
m&g6kc%|6\$nS0Firewall(config)# access-list acl_name permit icmp any any eq unreachableITPUB个人空间y%l J-GB"vL'D
Firewall(config)# access-list acl_name permit icmp any any eq time-exceededITPUB个人空间W:_$J9tl2A~:_NZ
Firewall(config)# access-list acl_name permit udp any range 32768 65535 any range 33434 33523
is:m:N+s7Wt(E(xh0Firewall(config)# access-list acl_name permit udp any dns_address eq domain (可选)ITPUB个人空间0B?qnn'|+N
ACL检查:ITPUB个人空间tZ](O;h\9u.h8r
show access-group, show access-listITPUB个人空间| H b D/F2DmF/I rS
NAT验证:
"[k ~L~"|O'e8w0Firewall# show xlate [detail] [global | local ip1[-ip2] [netmask mask]] lport | gport port[-port]] [interface if1[,if2][,ifn]] [state static [,dump] [,portmap] [,norandomseq] [,identity]] [debug] [count]ITPUB个人空间zS9n0Naq&JL'S6S
Firewall# show xlate [{global | local} ip1[-ip2] [netmask mask]] [{lport | gport} port[-port]] [interface if1[,if2][,ifn]] [state {static | portmap | identity | norandomseq}] [debug] [detail]
[,GDU)U_0Firewall# show conn [state state_type] [{foreign | local} ip1[-ip2] netmask mask] [long] [{lport | fport} port1[-port2]] [protocol {tcp | udp}]监控特定主机:
9VM'NA%I!]/L0Firewall# show local-host [ip_address] [all] [detail]
/eF2FL;~M#R't0Firewall# clear xlate global global_ip [netmask mask] [gport global_port]ITPUB个人空间 Z,P k8Cj
Firewall# clear xlate local local_ip [netmask mask] [lport local_port]ITPUB个人空间r T2?'s$e4s"v'hT
Firewall# clear xlate interface if_name_1[,if_name_2]ITPUB个人空间L7@u0[efO
Firewall# clear xlateITPUB个人空间0l%VD&R)xo4w1@
超时参数:
4v Bpb)DlB0Firewall(config)# timeout xlate hh[:mm[:ss]]
JT4es'\X#~0Firewall(config)# timeout conn hh[:mm[:ss]]ITPUB个人空间5oSC.C8P&^.N3v
Firewall(config)# half-closed hh[:mm[:ss]]ITPUB个人空间_^)Q EM vK`
Firewall(config)# udp hh[:mm[:ss]]ITPUB个人空间 kr(hO1?!J$xM,n
Shun检查: