Cisco Asa 5505无法访问ASDM

发布于 2022-08-31 09:13:42 字数 5245 浏览 18 评论 0

我是asa5505,系统版本8.2.5 asdm版本6.4.5
但是始终无法连接asdm的https服务。抓包分析是无法建立ssl握手。
附上配置文件

: Written by enable_15 at 03:31:58.492 UTC Sat Sep 6 2008
!
ASA Version 8.2(5)
!
firewall transparent
hostname ciscoasa
enable password m4djH3NUFbYRKDvk encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
 switchport access vlan 2
!
interface Ethernet0/2
 switchport access vlan 2
!
interface Ethernet0/3
 switchport access vlan 2
 shutdown
!
interface Ethernet0/4
 switchport access vlan 2
!
interface Ethernet0/5
 switchport access vlan 2
!
interface Ethernet0/6
 switchport access vlan 2
 shutdown
!
interface Ethernet0/7
!
interface Vlan1
 nameif outside
 security-level 0
!
interface Vlan2
 nameif inside
 security-level 100
!
regex Kill_VOD "(youku|tudou|bilibili|56|youtube|acfun|letv|pps)\.(com|cn|tv|net
)"
ftp mode passive
access-list acl_out extended permit icmp any any
access-list acl_out extended permit tcp any any
access-list acl_out extended permit udp any any
access-list acl_out extended permit igmp any any
access-list acl_out extended permit gre any any
pager lines 24
logging enable
logging console informational
mtu outside 1500
mtu inside 1500
ip address 192.168.124.1 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-645.bin
asdm history enable
arp timeout 14400
access-group acl_out in interface outside
access-group acl_out in interface inside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.124.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet 192.168.124.0 255.255.255.0 inside
telnet timeout 5
ssh timeout 5
console timeout 0
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
username admin password sqqq3dujvuSEcre8 encrypted
!
class-map type regex match-all BlackList
 match regex Kill_VOD
class-map type inspect http match-all HTTP_BlackList
 match request header host regex class BlackList
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum client auto
  message-length maximum 512
policy-map type inspect http http_inspect_policy
 parameters
 class HTTP_BlackList
  drop-connection
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
  inspect ip-options
  inspect icmp
  inspect http http_inspect_policy
  inspect pptp
!
service-policy global_policy global
prompt hostname context
no call-home reporting anonymous
Cryptochecksum:c0353d67ac644ad151d86723fb17760b

目录文件

ciscoasa(config)# dir

Directory of disk0:/

130    -rwx  15390720    01:47:16 May 23 2012  asa825-k8.bin
13     drwx  2048        01:47:28 May 23 2012  coredumpinfo
131    -rwx  17232256    03:40:30 Sep 06 2008  asdm-645.bin
3      drwx  2048        01:52:32 May 23 2012  log
12     drwx  2048        01:53:00 May 23 2012  crypto_archive
133    -rwx  2048        00:00:00 Jan 01 1980  FSCK0000.REC
134    -rwx  4096        00:00:00 Jan 01 1980  FSCK0001.REC
135    -rwx  4096        00:00:00 Jan 01 1980  FSCK0002.REC
136    -rwx  4096        00:00:00 Jan 01 1980  FSCK0003.REC
137    -rwx  4096        00:00:00 Jan 01 1980  FSCK0004.REC
138    -rwx  6144        00:00:00 Jan 01 1980  FSCK0005.REC
139    -rwx  6144        00:00:00 Jan 01 1980  FSCK0006.REC
140    -rwx  6144        00:00:00 Jan 01 1980  FSCK0007.REC
141    -rwx  22528       00:00:00 Jan 01 1980  FSCK0008.REC
142    -rwx  38912       00:00:00 Jan 01 1980  FSCK0009.REC
143    -rwx  34816       00:00:00 Jan 01 1980  FSCK0010.REC
144    -rwx  43008       00:00:00 Jan 01 1980  FSCK0011.REC
145    -rwx  2048        00:00:00 Jan 01 1980  FSCK0012.REC
146    -rwx  26624       00:00:00 Jan 01 1980  FSCK0013.REC
147    -rwx  2048        00:00:00 Jan 01 1980  FSCK0014.REC
148    -rwx  26624       00:00:00 Jan 01 1980  FSCK0015.REC
149    -rwx  2048        00:00:00 Jan 01 1980  FSCK0016.REC
151    -rwx  26624       00:00:00 Jan 01 1980  FSCK0017.REC
152    -rwx  2048        00:00:00 Jan 01 1980  FSCK0018.REC
153    -rwx  26624       00:00:00 Jan 01 1980  FSCK0019.REC
154    -rwx  2048        00:00:00 Jan 01 1980  FSCK0020.REC
155    -rwx  26624       00:00:00 Jan 01 1980  FSCK0021.REC
156    -rwx  2048        00:00:00 Jan 01 1980  FSCK0022.REC

128573440 bytes total (95365120 bytes free)

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文