码迷,mamicode.com
首页 > 系统相关 > 详细

Cisco ASA - Permit/Deny Traffic Domain name FQDN

时间:2020-04-10 10:36:01      阅读:93      评论:0      收藏:0      [点我收藏+]

标签:ext   domain   ioi   code   ref   entry   ati   follow   main   

refer to:
https://www.fir3net.com/Firewalls/Cisco/cisco-asa-domain-fqdn-based-acls.html

dns domain-lookup outside
DNS server-group China_Telecom_SH_DNS
  name-server 202.96.209.133 202.96.209.5
  domain-name Oneitc.local

object network obj-i1.mallcoo.cn
 fqdn i1.mallcoo.cn
no access-list 200 extended permit ip object-group Reception-Desktop-with-liminatioin object-group Mallcoo-Server log 
no access-list 200 extended deny ip object-group Reception-Desktop-with-liminatioin any log 
no access-list 200 extended permit ip any any log 

access-list 200 extended permit ip object-group Reception-Desktop-with-liminatioin object obj-i1.mallcoo.cn
access-list 200 extended permit ip object-group Reception-Desktop-with-liminatioin object-group Mallcoo-Server log 
access-list 200 extended deny ip object-group Reception-Desktop-with-liminatioin any log 
sh access-list acl-inside
sh dns
dns expire-entry-timer minutes <minute>

Cisco ASA - Permit/Deny Traffic Domain name FQDN

标签:ext   domain   ioi   code   ref   entry   ati   follow   main   

原文地址:https://blog.51cto.com/zhangfang526/2486145

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!