refer to:
https://www.fir3net.com/Firewalls/Cisco/cisco-asa-domain-fqdn-based-acls.html
dns domain-lookup outside
DNS server-group China_Telecom_SH_DNS
name-server 202.96.209.133 202.96.209.5
domain-name Oneitc.local
object network obj-i1.mallcoo.cn
fqdn i1.mallcoo.cn
no access-list 200 extended permit ip object-group Reception-Desktop-with-liminatioin object-group Mallcoo-Server log
no access-list 200 extended deny ip object-group Reception-Desktop-with-liminatioin any log
no access-list 200 extended permit ip any any log
access-list 200 extended permit ip object-group Reception-Desktop-with-liminatioin object obj-i1.mallcoo.cn
access-list 200 extended permit ip object-group Reception-Desktop-with-liminatioin object-group Mallcoo-Server log
access-list 200 extended deny ip object-group Reception-Desktop-with-liminatioin any log
sh access-list acl-inside
sh dns
dns expire-entry-timer minutes <minute>
原文地址:https://blog.51cto.com/zhangfang526/2486145
时间: 2024-10-10 08:56:38