outside上开个环回口:
lo 0 1.1.1.1
inside 上开个环回口:
lo 0 2.2.2.2
允许2.2.2.2 --> 1.1.1.1 能ping 、telnet
ASA配置:
route Outside 1.1.1.1 255.255.255.255 202.100.1.1 1
route Inside 2.2.2.2 255.255.255.255 10.1.1.1 1
access-list out_in permit tcp any host 2.2.2.2 eq telnet
access-list out_in permit icmp host 1.1.1.1 host 2.2.2.2
access-group out_in in interface Outside
测试:
Outside.R1#ping 2.2.2.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Inside.R2#ping 1.1.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
测试失败。
通过抓包分析了一下:
发现src是202.100.1.1
顿时明白:
Outside.R1#ping 2.2.2.2 source loopback 0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
Packet sent with a source address of 1.1.1.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/25/40 ms
Inside.R2#ping 1.1.1.1 source loopback 0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:
Packet sent with a source address of 2.2.2.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/29/52 ms