You are on page 1of 3

int vlan2

ip address 192.168.2.1 255.255.255.0


//zona militarizada
int vlan3
ip address 192.168.3.1 255.255.255.0
security-level 50
int et 0/2
switchport access vlan 3
*******************************************************
config t
interface vlan 1
ip address 192.168.1.1 255.255.255.0
exit
interface vlan 2
ip address 192.168.2.1 255.255.255.0
exit
interface ethernet 0/1
switchport access vlan 1
no shut
interface ethernet 0/2
switchport access vlan 2
no shut

class-map clase1
match default-inspection-traffic
exit
policy-map global_policy
class clase1

inspect icmp
//iocmp es el tipo de paquete ping
service-policy global_policy global

***********************
DMZ

*******************
config t
int vlan3
no forward interface vlan1
nameif DMZ
security-level 50
ip address 192.168.3.1 255.255.255.0
exit
config t
interface ethernet 0/3
switchport access vlan3
no shutdown
exit

********************
config t
access-list acl1 exyended permit icmp any any
***********************
config t
access-group acl1 out interface dmz

*********************************
object network obj1
host 192.168.3.2

nat(dmz,outside) static 192.168.2.22

****************
policy-map global_policy
class clase1
inspect dns
inspect http

config t
access-list acl1 extended permit tcp any any
access-list acl1 extended permit udp any any

You might also like