Cisco Asa 5505无法访问ASDM
我是asa5505,系统版本8.2.5 asdm版本6.4.5
但是始终无法连接asdm的https服务。抓包分析是无法建立ssl握手。
附上配置文件
: Written by enable_15 at 03:31:58.492 UTC Sat Sep 6 2008
!
ASA Version 8.2(5)
!
firewall transparent
hostname ciscoasa
enable password m4djH3NUFbYRKDvk encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
switchport access vlan 2
!
interface Ethernet0/2
switchport access vlan 2
!
interface Ethernet0/3
switchport access vlan 2
shutdown
!
interface Ethernet0/4
switchport access vlan 2
!
interface Ethernet0/5
switchport access vlan 2
!
interface Ethernet0/6
switchport access vlan 2
shutdown
!
interface Ethernet0/7
!
interface Vlan1
nameif outside
security-level 0
!
interface Vlan2
nameif inside
security-level 100
!
regex Kill_VOD "(youku|tudou|bilibili|56|youtube|acfun|letv|pps)\.(com|cn|tv|net
)"
ftp mode passive
access-list acl_out extended permit icmp any any
access-list acl_out extended permit tcp any any
access-list acl_out extended permit udp any any
access-list acl_out extended permit igmp any any
access-list acl_out extended permit gre any any
pager lines 24
logging enable
logging console informational
mtu outside 1500
mtu inside 1500
ip address 192.168.124.1 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-645.bin
asdm history enable
arp timeout 14400
access-group acl_out in interface outside
access-group acl_out in interface inside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.124.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet 192.168.124.0 255.255.255.0 inside
telnet timeout 5
ssh timeout 5
console timeout 0
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
username admin password sqqq3dujvuSEcre8 encrypted
!
class-map type regex match-all BlackList
match regex Kill_VOD
class-map type inspect http match-all HTTP_BlackList
match request header host regex class BlackList
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 512
policy-map type inspect http http_inspect_policy
parameters
class HTTP_BlackList
drop-connection
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect icmp
inspect http http_inspect_policy
inspect pptp
!
service-policy global_policy global
prompt hostname context
no call-home reporting anonymous
Cryptochecksum:c0353d67ac644ad151d86723fb17760b
目录文件
ciscoasa(config)# dir
Directory of disk0:/
130 -rwx 15390720 01:47:16 May 23 2012 asa825-k8.bin
13 drwx 2048 01:47:28 May 23 2012 coredumpinfo
131 -rwx 17232256 03:40:30 Sep 06 2008 asdm-645.bin
3 drwx 2048 01:52:32 May 23 2012 log
12 drwx 2048 01:53:00 May 23 2012 crypto_archive
133 -rwx 2048 00:00:00 Jan 01 1980 FSCK0000.REC
134 -rwx 4096 00:00:00 Jan 01 1980 FSCK0001.REC
135 -rwx 4096 00:00:00 Jan 01 1980 FSCK0002.REC
136 -rwx 4096 00:00:00 Jan 01 1980 FSCK0003.REC
137 -rwx 4096 00:00:00 Jan 01 1980 FSCK0004.REC
138 -rwx 6144 00:00:00 Jan 01 1980 FSCK0005.REC
139 -rwx 6144 00:00:00 Jan 01 1980 FSCK0006.REC
140 -rwx 6144 00:00:00 Jan 01 1980 FSCK0007.REC
141 -rwx 22528 00:00:00 Jan 01 1980 FSCK0008.REC
142 -rwx 38912 00:00:00 Jan 01 1980 FSCK0009.REC
143 -rwx 34816 00:00:00 Jan 01 1980 FSCK0010.REC
144 -rwx 43008 00:00:00 Jan 01 1980 FSCK0011.REC
145 -rwx 2048 00:00:00 Jan 01 1980 FSCK0012.REC
146 -rwx 26624 00:00:00 Jan 01 1980 FSCK0013.REC
147 -rwx 2048 00:00:00 Jan 01 1980 FSCK0014.REC
148 -rwx 26624 00:00:00 Jan 01 1980 FSCK0015.REC
149 -rwx 2048 00:00:00 Jan 01 1980 FSCK0016.REC
151 -rwx 26624 00:00:00 Jan 01 1980 FSCK0017.REC
152 -rwx 2048 00:00:00 Jan 01 1980 FSCK0018.REC
153 -rwx 26624 00:00:00 Jan 01 1980 FSCK0019.REC
154 -rwx 2048 00:00:00 Jan 01 1980 FSCK0020.REC
155 -rwx 26624 00:00:00 Jan 01 1980 FSCK0021.REC
156 -rwx 2048 00:00:00 Jan 01 1980 FSCK0022.REC
128573440 bytes total (95365120 bytes free)
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论