
3-14
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 3 Controlling Network Access and Use
Access Control Configuration Example
To view the current entries in a specific MAC list, enter the following command:
show mac-list [mcl-id]
If you omit the MAC list identifier, the system displays all currently configured MAC lists.
To clear all the entries on a MAC list, enter the following command:
clear mac-list [mclid]
If you omit the MAC list identifier, the system clears all the currently configured MAC lists.
Access Control Configuration Example
This section provides an example of how to implement access control and includes the following topics:
• Basic Configuration, page 3-14
• Authentication and Authorization, page 3-16
• Managing Access to Services, page 3-16
• Adding Comments to ACLs, page 3-18
Basic Configuration
Figure 3-3 illustrates the network configuration used in this example.
Figure 3-3 Two Interfaces with NAT—Access Control
34780
Global pool
209.165.201.6-8
209.165.201.10 (PAT)
209.165.200.225-254
Internet
Intel
Internet
Phone
Outside
Sun Mail host
NT SNMP
BSDI NT TACACS+
server
209.165.201.1
PIX Firewall
RIP 10.1.1.1
209.165.201.3209.165.201.2
10.1.1.3 10.1.1.11 10.1.1.12
209.165.201.4 209.165.201.5
BSDI
192.168.3.1
Komentarze do niniejszej Instrukcji