用vm虚拟机模拟了一台 ASA设备 
  自适应安全设备软件为 ASA8.25
  asdm镜像为asdm-6.49.bin

用客户端连接时,一定要安装java  jre,版本我是用的是7,6应该也可以。

管理器分为三部分

一  主页面

二  配置部分
     1.设备设置

2.防火墙

3.远端vpn

4.站点到站点vpn

5.设备管理

三  监控部分

第一部分:home主页面

home 主页面

Device  Information 设备信息

general

firewall:防火墙模式(路由模式、透明传输模式)

Device Type :设备类型

context Mode:背景模式 虚拟防火墙(在一个实体防火墙上做出若干个独立的虚拟防火墙)

License 许可证

GTP/GPRS:  GTP/GPRS隧道协议监控(安全通道,两个主机可通过该通道交换数据)

encryption:加密协议

physical interface:物理接口 (unlimited 无限制)

vlans:支持vlan数量

failove:高可用性(故障转移) 
           要求两个进行Failover的设备通过专用的failover线缆和可选的Stateful Failover线缆互相连接
            Active/Active:两个设备可以同时传送流量。这可以让你实现负载均衡。A/A failover只能运行
                                       在多虚拟防火墙模式下。
           Active/Standby:同一时间,只能有一个设备传输流量,另一个设备作为备份用

Interface status  接口状态
……自己看图

System Resources Status 系统资源状态

……自己看图

Traffic Status  流量状态
connections per second usage  每秒连接量
xxx interface traffic usage (kps) xxx接口流量

Latest  ASDM  Syslog  Message 最新的日志信息
点击开启,显示最新的信息状态

Device list
管理设备信息

 第二部分:Configuration 配置部分

五个项目

1.设备设置

2.防火墙

3.远端vpn

4.站点到站点vpn

5.设备管理

首先是第1项目,设备设置

1.Device startup

 
Startup Wizard  启动向导 ……
 
Interface:
     接口配置 右边有add  edit 两个按钮,可以添加和编辑 接口
     里面可以设置ip地址,子网掩码,接口名字,安全级别,  
      双工模式 ,速率 
       也可以配置  MTU大小 ,ip6信息
    CLI 相应设置:  
     asa825(config-if)# ip address 10.0.0.1 255.0.0.0
     asa825(config-if)# nameif  接口名字
     asa825(config-if)# security-level  安全级别
     asa825(config-if)# duplex ?     双工模式 
     asa825(config-if)# speed ?     速率
 
 
 
Device Name/Password
设备名字、域
enable password     进入特权模式密码(asa 取消了enale secret使能密码 ,enable password直接加密)
Telnet Password      通过远程方式(telnet、ssh)访问的密码
 CLI 相应设置:   
  ciscoasa(config)#hostname  xxx                   设备名字
  ciscoasa(config)#domain-name  xxx              域
 ciscoasa(config)#enable password xxx           进入特权模式密码
 ciscoasa(config)#passwd  xxx                          远程方式(telnet、ssh)访问的密码
 
 
 
第三菜单 远端vpn
3.Remote Access VPN
                        
 

 3.2Network Client Access  客户端访问

CLI命令 :
ciscoasa(config)# webvpn
ciscoasa(config-webvpn)# webvpnport 443
enable dianxin
enable liantong
dtls port 443
svc image disk0:/anyconnect-win-2.4.1012-k9.pkg 1
svc enable
tunnel-group-list enable
group-policy iyunshu internal
group-policy iyunshu attributes
dns-server value 202.102.224.68
vpn-tunnel-protocol IPSec
split-tunnel-policy tunnelspecified
split-tunnel-network-list value iyunshu_splitTunnelAcl
group-policy ssl-policy internal
group-policy ssl-policy attributes
vpn-tunnel-protocol svc webvpn
split-tunnel-policy tunnelspecified
split-tunnel-network-list value vpnuser_splitTunnelAcl
address-pools value sslvpnpool
webvpn
svc ask enable default webvpn
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol IPSec l2tp-ipsec
username iyunshu password punVcwIU8fS3jQB1 encrypted privilege 0
username iyunshu attributes
vpn-group-policy iyunshu


3.3 Clientless SSL VPN Access 无客户端访问
ciscoasa(config)# webvpn
ciscoasa(config-webvpn)# ?
 
WebVPN commands:
  anyconnect                       AnyConnect configuration parameters
  anyconnect-essentials    Enable/Disable AnyConnect Essentials
  apcf                                  Load Aplication Profile Customization Framework      (APCF) profile
  auto-signon                    Configure auto-sign to allow login to certain   applications using the WebVPN session credentials
  cache                                  Configure WebVPN cache
  certificate-group-map       Associate a tunnel-group with a certificate map rule
  character-encoding           Configures the character encoding for WebVPN portal   pages
  csd                                    This specifies whether Cisco Secure Desktop is  enabled and the package file name to be used.
  default-idle-timeout     This is the default idle timeout in seconds
  default-language         Default language to use
  dtls                     Configure DTLS for WebVPN
  enable                   Enable WebVPN on the specified interface
  error-recovery           Contact TAC before using this command
  exit                     Exit from WebVPN configuration mode
  file-encoding            Configures the file encoding for a file sharing
                           server
  help                     Help for WebVPN commands
  http-proxy               This is the proxy server to use for HTTP requests
  https-proxy              This is the proxy server to use for HTTPS requests
  internal-password        Adds an option to input a different password for
                           accessing internal servers
  java-trustpoint          Configure WebVPN java trustpoint
  kcd-server               Configure an KCD-Server
  keepout                  Shows Web page when the login is disabled
  memory-size              Configure WebVPN memory size. CHECK MEMORY USAGE
                           BEFORE APPLYING THIS COMMAND. USE ONLY IF ADVISED BY
                           CISCO
  mobile-device            Configure access from mobile devices
  mus                      Configure Mobile User Security
  no                       Remove a WebVPN command or set to its default
  onscreen-keyboard        Adds WebVPN onscreen keyboard for typing password on
                           the WebVPN logon page and internal pages requiring
                           authentication
  port                     WebVPN should listen for connections on the
                           specified port
  port-forward             Configure the port-forward list for WebVPN
  portal-access-rule       Configuration related to portal access rules
  proxy-bypass             Configure proxy bypass
  rewrite                  Configure content rewriting rule
  smart-tunnel             Configure a list of programs to use smart tunnel
  sso-server               Configure an SSO Server
  tunnel-group-list        Configure WebVPN group list dropdown in login page
  tunnel-group-preference  Enable/Disable Tunnel Group Preference
 
 
 
 
 
 
第5菜单 设备管理
5.Device Management
ASDM/HTTPS/Telent/ssh 
这里是配置通过何种方式管理设备

右上角add可以增加访问方式,目前有 asdm/https  ssh   telnet   方式

 
开启http server 直接选中方框
port number 设置http服务端口号  默认为ssl加密的443端口
可以设置 超时时间和session时间
 
CLI 命令:
 
开启telnet 管理
asa825(config)# telnet 192.168.1.0 255.255.255.0 inside
#aaa authentication telnet console LOCAL  (如果使用aaa认证)

开启ssh管理

asa825(config)#hostname ASA          设置主机名

asa825(config)#domain ccie.com       设置域名

asa825(config)# ssh 192.168.1.0 255.255.255.0 inside
asa825(config)# crypto key generate rsa           (打开SSH服务)
#aaa authentication ssh console LOCAL         (如果使用aaa认证)

 
开启https管理
ciscoasa(config)#http server enable                     开启http服务端口号  默认为ssl加密的443端口
ciscoasa(config)#http server enable xxx             开启http服务端口号  为xxx
ciscoasa(config)#http server enable   

ciscoasa(config)# http server ?
   configure mode commands/options:
  enable           Enable the http server required to run Device Manager
  idle-timeout     Idle timeout in minutes (single routed mode only)                       超时时间
  session-timeout  Session timeout in minutes (single routed mode only)         会话时间
 
 

使用ASDM 管理 ciscoASA设备的更多相关文章

  1. (转载)使用 udev 高效、动态地管理 Linux 设备文件

    概述: Linux 用户常常会很难鉴别同一类型的设备名,比如 eth0, eth1, sda, sdb 等等.通过观察这些设备的内核设备名称,用户通常能知道这些是什么类型的设备,但是不知道哪一个设备是 ...

  2. 嵌入式 使用udev高效、动态地管理Linux 设备文件

    本文以通俗的方法阐述 udev 及相关术语的概念.udev 的配置文件和规则文件,然后以 Red Hat Enterprise Server 为平台演示一些管理设备文件和查询设备信息的实例.本文会使那 ...

  3. 【转】使用 udev 高效、动态地管理 Linux 设备文件

    简介: 本文以通俗的方法阐述 udev 及相关术语的概念.udev 的配置文件和规则文件,然后以 Red Hat Enterprise Server 为平台演示一些管理设备文件和查询设备信息的实例.本 ...

  4. 使用 udev 高效、动态地管理 Linux 设备文件

    本文转自:https://www.ibm.com/developerworks/cn/linux/l-cn-udev/index.html 概述: Linux 用户常常会很难鉴别同一类型的设备名,比如 ...

  5. WiFi 统一管理以及设备自动化测试实践

    ATX 安卓设备 WiFi 统一管理以及设备自动化测试实践 (零散知识梳理总结) 此文为转载,感谢作者  目录  众所周知,安卓单台设备的UI自动化测试已经比较完善了,有数不清的自动化框架或者工具.但 ...

  6. 使用 udev 管理 Linux 设备文件

    本文以通俗的方法阐述 udev 及相关术语的概念.udev 的配置文件和规则文件,然后以 Red Hat Enterprise Server 为平台演示一些管理设备文件和查询设备信息的实例.本文会使那 ...

  7. 使用python管理Cisco设备-乾颐堂

    今天发现一个老外使用python写的管理cisco设备的小框架tratto,可以用来批量执行命令. 下载后主要有3个文件: Systems.py 定义了一些不同设备的操作系统及其常见命令. Conne ...

  8. 管理Android设备的唤醒状态

    当一个Android设备闲置时,首先它的屏幕将会变暗,然后关闭屏幕,最后关闭CPU. 这样可以防止设备的电量被迅速消耗殆尽.但是,有时候也会存在一些特例: Apps such as games or ...

  9. 使用室内三维地图引擎ESMap来管理摄像头设备、消防设备和人员轨迹展示

    目前室内三维地图如何轻量化,能够在手机微信.电脑浏览器等平台快速显示地图,显示的地图性能好,转动地图不卡是大家都要面对的问题, 使用室内三维地图引擎ESMap后目前可以不用操心这方面的问题,开发只需要 ...

随机推荐

  1. React16源码解读:开篇带你搞懂几个面试考点

    引言 如今,主流的前端框架React,Vue和Angular在前端领域已成三足鼎立之势,基于前端技术栈的发展现状,大大小小的公司或多或少也会使用其中某一项或者多项技术栈,那么掌握并熟练使用其中至少一种 ...

  2. java项目Jenkins部署

    假设背景: Nginx跳板机服务器:192.168.10.1 Tomcat应用服务器:192.168.10.3 端口:10083 应用名称:appXXX 1.配置跳板机的转发路径 如:192.168. ...

  3. xLua下使用lua-protobuf

    本文发表于程序员刘宇的博客,转载请注明来源:https://www.cnblogs.com/xiaohutu/p/12168781.html protobuf作为一种通用套接字格式,各种插件里,最本质 ...

  4. SSAS Tabular表格模型实现动态权限管理

    最近忽然对SSAS产生了浓厚兴趣,我看博客园上也米有写关于SSAS 2016下表格模型实现动态权限管理的文章,最近鼓捣了一下微软的样例,鼓捣好了,把过程中遇到的一些问题写出来,抛砖引玉,也算给自己一个 ...

  5. Pandas中merge和join的区别

    可以说merge包含了join的操作,merge支持通过列或索引连表,而join只支持通过索引连表,只是简化了merge的索引连表的参数 示例 定义一个left的DataFrame left=pd.D ...

  6. MySQL多表联查以及以及架构

    多表之间关联查询:      据库操作中,多表联合查询是后台开发者常用到的查询语句. JOIN SQL JOIN 子句用于把来自两个或多个表的行结合起来,最常见的 JOIN 类型:SQL INNER ...

  7. 浏览器警告Failed to decode downloaded font和OTS parsing error: Failed to convert *** font to ***

    昨晚,在做一个自己感兴趣的东西时,发现浏览器报警告,Failed to decode downloaded font以及OTS parsing error: Failed to convert *** ...

  8. Tomcat9乱码解决

    在tomcat的解压目录下找到conf,打开进入,logging.properties文件,在该文件中,修改 java.util.logging.ConsoleHandler.encoding = U ...

  9. 【Oracle】分区表详解

    此文从以下几个方面来整理关于分区表的概念及操作: 1.表空间及分区表的概念     2.表分区的具体作用     3.表分区的优缺点     4.表分区的几种类型及操作方法     5.对表分区的维护 ...

  10. copy and swap技巧与移动赋值操作符

    最近在实现一个Delegate类的时候碰到了一个问题,就是copy and swap技巧和移动赋值操作符有冲突. 比如有以下一个类: class Fun { public: Fun(const Fun ...