SSG5的設定. - 資安

By Bennie
at 2010-09-21T22:24
at 2010-09-21T22:24
Table of Contents
大家好,小弟最近在設定SSG5時遇到一個怪問題.
就是小弟的環境裡有3個實體IP,其中兩個IP分派給兩台SERVER.
所以小弟就設定成...
10.1.1.1 ->SSG5的外部IP
10.1.1.2 ->指給MAIL
10.1.1.3 ->指給OTHER
內部的IP為
192.168.1.254 ->SSG5的內部IP
192.168.1.200 ->MAIL SERVER
192.168.1.201 ->APP OTHER
就小弟所知道的,就是先把SSG5的主要IP設定好.
然後去MIP裡把192.168.1.254設定跟10.1.1.1在一起
再來去設定VIP.
VIP1:10.1.1.2
service:
192.168.1.200 port:25
192.168.1.200 port:110
192.168.1.200 port:80 (web mail)
policy:
untrust any ->trust VIP(10.1.1.2) service:mutile 25,110,80
trust any<->any
設定完後,內部上網沒有問題,但是外部要連線到內部的mail server都進不來.
小弟有把log勾起來,也看不到任何連線進來的log...(DNS有設定了)
請問這樣子是什麼問題嗎??
謝謝.
--
就是小弟的環境裡有3個實體IP,其中兩個IP分派給兩台SERVER.
所以小弟就設定成...
10.1.1.1 ->SSG5的外部IP
10.1.1.2 ->指給MAIL
10.1.1.3 ->指給OTHER
內部的IP為
192.168.1.254 ->SSG5的內部IP
192.168.1.200 ->MAIL SERVER
192.168.1.201 ->APP OTHER
就小弟所知道的,就是先把SSG5的主要IP設定好.
然後去MIP裡把192.168.1.254設定跟10.1.1.1在一起
再來去設定VIP.
VIP1:10.1.1.2
service:
192.168.1.200 port:25
192.168.1.200 port:110
192.168.1.200 port:80 (web mail)
policy:
untrust any ->trust VIP(10.1.1.2) service:mutile 25,110,80
trust any<->any
設定完後,內部上網沒有問題,但是外部要連線到內部的mail server都進不來.
小弟有把log勾起來,也看不到任何連線進來的log...(DNS有設定了)
請問這樣子是什麼問題嗎??
謝謝.
--
Tags:
資安
All Comments

By Kama
at 2010-09-23T05:29
at 2010-09-23T05:29

By Olive
at 2010-09-23T12:32
at 2010-09-23T12:32

By Kama
at 2010-09-27T11:06
at 2010-09-27T11:06

By Skylar Davis
at 2010-09-28T00:15
at 2010-09-28T00:15

By Anonymous
at 2010-09-28T10:11
at 2010-09-28T10:11

By Blanche
at 2010-10-02T11:10
at 2010-10-02T11:10

By Necoo
at 2010-10-03T18:53
at 2010-10-03T18:53

By Ethan
at 2010-10-07T15:19
at 2010-10-07T15:19

By Yedda
at 2010-10-08T22:12
at 2010-10-08T22:12

By Regina
at 2010-10-12T21:24
at 2010-10-12T21:24
Related Posts
鎖白目室友的迅雷

By Emily
at 2010-09-18T13:13
at 2010-09-18T13:13
有推荐的 UTM 嗎 ? 20人以下企業 ...

By Rosalind
at 2010-09-17T16:48
at 2010-09-17T16:48
請問有關於botnet指揮方式

By William
at 2010-09-11T21:56
at 2010-09-11T21:56
nikto是否有自動排程功能?

By Agatha
at 2010-09-03T00:24
at 2010-09-03T00:24
是否可查詢"電腦曾做過什麼?"

By Todd Johnson
at 2010-09-02T17:50
at 2010-09-02T17:50