SlideShare a Scribd company logo
1 of 10
Download to read offline
SEGURIDAD ASA
PROYECTADO POR:
ALEXANDER ZAMBRANO
ANDRES FELIPE PACHECO
FARID ESCOBAR
Servidores en la DMZ
Con ella creamos una
interfaz nueva y una
subred independiente,
pero siempre interna,
para poder controlar
mejor el acceso a los
servidores.
Outside
Inside
DMZ
La DMZ es una subred independiente, separada
de la LAN y de Internet
Tabla de reglas DMZ
COMANDO EN PACKET TRACER
 ciscoasa(config)#interface vlan 2
 ciscoasa(config-if)#ip addres 10.0.0.14 255.255.255.240
 ciscoasa(config)#interface vlan 3
 ciscoasa(config-if)#security-level 50
 ciscoasa(config)#interface vlan 3
 ciscoasa(config-if)#ip address 192.168.100.1 255.255.255.248
 ciscoasa(config-if)#nameif dmz
 ERROR: This license does not allow configuring more than 2 interfaces with
nameif and without a "no forward" command on this interface or on 1
interface(s) with nameif already configured.
COMANDO EN PACKET TRACER
 ciscoasa(config-if)#no forward interface vlan 1 (deniega el trafico de la vlan 1)
 ciscoasa(config-if)#nameif dmz
 ciscoasa(config)#class-map INSIDE-DMZ
 ciscoasa(config-cmap)#match any
 ciscoasa(config)#policy-map POLITICA-INSIDE-DMZ
 ciscoasa(config-pmap)#class INSIDE-DMZ
 ciscoasa(config-pmap-c)#INspect ?
 mode commands/options:
 dns
 ftp
 h323
 http
 icmp
 tftp
COMANDO EN PACKET TRACER
 ciscoasa(config-pmap-c)#INspect icmp
 ciscoasa(config-pmap-c)#exit
 ciscoasa(config)#SERvice-policy POLITICA-INSIDE-DMZ INTerface INside
 ciscoasa(config)#SH RUN
 ciscoasa(config)#OBJECT NETwork LAN
 ciscoasa(config-network-object)#SUBnet 192.168.1.0 255.255.255.0
 ciscoasa(config-network-object)#NAT (INside,Outside) DYnamic Interface
 ciscoasa(config)#OBJECT NETwork DMZ
 ciscoasa(config-network-object)#SUbnet 192.168.100.0 255.255.255.248
COMANDO EN PACKET TRACER
 ciscoasa(config-network-object)#NAT (dmz,outside) dynamic interface
 ciscoasa(config)#object network HTTP-MAIL-FTP
 ciscoasa(config-network-object)#HOSt 192.168.100.2
 ciscoasa(config-network-object)#nat (dmz,outside) static 10.0.0.4
 ciscoasa(config-network-object)#exit
 ciscoasa(config)#access-list ENTRANTE PERmit icmp any host 10.0.0.4 echo
 ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq www
COMANDO EN PACKET TRACER
 ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq ftp
 ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq smtp
 ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq
pop3
 ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 lt ftp
 ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 gt ftp
GRACIAS POR SU
ATENCION

More Related Content

Similar to Servidores en la DMZ.pdf

[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
Nur Shiqim Chok
 
Hacom%20pf sense%20quick start%20guide
Hacom%20pf sense%20quick start%20guideHacom%20pf sense%20quick start%20guide
Hacom%20pf sense%20quick start%20guide
HARRY CHAN PUTRA
 
在Oel5上安装配置oracle gird control 10.2.0.5
在Oel5上安装配置oracle gird control 10.2.0.5在Oel5上安装配置oracle gird control 10.2.0.5
在Oel5上安装配置oracle gird control 10.2.0.5
maclean liu
 
The bryant advantage 150 commands
The bryant advantage 150 commandsThe bryant advantage 150 commands
The bryant advantage 150 commands
Areej Khasawneh
 
CCN3Switching_lab_5_5_2
CCN3Switching_lab_5_5_2CCN3Switching_lab_5_5_2
CCN3Switching_lab_5_5_2
alan moreno
 

Similar to Servidores en la DMZ.pdf (20)

[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
[Cisco Connect 2018 - Vietnam] Anh duc le reap the benefits of sdn with cisco...
 
Ccnas v11 ch02_eb
Ccnas v11 ch02_ebCcnas v11 ch02_eb
Ccnas v11 ch02_eb
 
Hacom%20pf sense%20quick start%20guide
Hacom%20pf sense%20quick start%20guideHacom%20pf sense%20quick start%20guide
Hacom%20pf sense%20quick start%20guide
 
Basic Cisco ASA 5506-x Configuration (Firepower)
Basic Cisco ASA 5506-x Configuration (Firepower)Basic Cisco ASA 5506-x Configuration (Firepower)
Basic Cisco ASA 5506-x Configuration (Firepower)
 
Alcatel vm
Alcatel vmAlcatel vm
Alcatel vm
 
Helpful Juniper Tips and Tricks for New Network Engineers
Helpful Juniper Tips and Tricks for New Network EngineersHelpful Juniper Tips and Tricks for New Network Engineers
Helpful Juniper Tips and Tricks for New Network Engineers
 
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit ModeSetting up Cisco WSA Proxy in Transparent and Explicit Mode
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
 
Manejo de redes
Manejo de redesManejo de redes
Manejo de redes
 
labffbhhhhjjjjjjjjj bnbbnv material.pptx
labffbhhhhjjjjjjjjj bnbbnv material.pptxlabffbhhhhjjjjjjjjj bnbbnv material.pptx
labffbhhhhjjjjjjjjj bnbbnv material.pptx
 
在Oel5上安装配置oracle gird control 10.2.0.5
在Oel5上安装配置oracle gird control 10.2.0.5在Oel5上安装配置oracle gird control 10.2.0.5
在Oel5上安装配置oracle gird control 10.2.0.5
 
Nxll16 basic asa v8.2
Nxll16 basic asa v8.2Nxll16 basic asa v8.2
Nxll16 basic asa v8.2
 
Lab 6.4.1 InterVLAN routing
Lab 6.4.1 InterVLAN routingLab 6.4.1 InterVLAN routing
Lab 6.4.1 InterVLAN routing
 
Securing the network for VMs or Containers
Securing the network for VMs or ContainersSecuring the network for VMs or Containers
Securing the network for VMs or Containers
 
Nxll14 cut through-proxy on asa
Nxll14 cut through-proxy on asaNxll14 cut through-proxy on asa
Nxll14 cut through-proxy on asa
 
Ccna4 cs diaz_&_romero
Ccna4 cs diaz_&_romeroCcna4 cs diaz_&_romero
Ccna4 cs diaz_&_romero
 
The bryant advantage 150 commands
The bryant advantage 150 commandsThe bryant advantage 150 commands
The bryant advantage 150 commands
 
9210 commissioning manual
9210 commissioning manual9210 commissioning manual
9210 commissioning manual
 
Lab6.4.1
Lab6.4.1Lab6.4.1
Lab6.4.1
 
Important cisco-chow-commands
Important cisco-chow-commandsImportant cisco-chow-commands
Important cisco-chow-commands
 
CCN3Switching_lab_5_5_2
CCN3Switching_lab_5_5_2CCN3Switching_lab_5_5_2
CCN3Switching_lab_5_5_2
 

Recently uploaded

1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
QucHHunhnh
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please Practise
AnaAcapella
 

Recently uploaded (20)

Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdf
 
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
On National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsOn National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan Fellows
 
Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please Practise
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
SOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning PresentationSOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning Presentation
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptxSKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
SKILL OF INTRODUCING THE LESSON MICRO SKILLS.pptx
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 

Servidores en la DMZ.pdf

  • 1. SEGURIDAD ASA PROYECTADO POR: ALEXANDER ZAMBRANO ANDRES FELIPE PACHECO FARID ESCOBAR
  • 2. Servidores en la DMZ Con ella creamos una interfaz nueva y una subred independiente, pero siempre interna, para poder controlar mejor el acceso a los servidores. Outside Inside DMZ
  • 3. La DMZ es una subred independiente, separada de la LAN y de Internet
  • 5. COMANDO EN PACKET TRACER  ciscoasa(config)#interface vlan 2  ciscoasa(config-if)#ip addres 10.0.0.14 255.255.255.240  ciscoasa(config)#interface vlan 3  ciscoasa(config-if)#security-level 50  ciscoasa(config)#interface vlan 3  ciscoasa(config-if)#ip address 192.168.100.1 255.255.255.248  ciscoasa(config-if)#nameif dmz  ERROR: This license does not allow configuring more than 2 interfaces with nameif and without a "no forward" command on this interface or on 1 interface(s) with nameif already configured.
  • 6. COMANDO EN PACKET TRACER  ciscoasa(config-if)#no forward interface vlan 1 (deniega el trafico de la vlan 1)  ciscoasa(config-if)#nameif dmz  ciscoasa(config)#class-map INSIDE-DMZ  ciscoasa(config-cmap)#match any  ciscoasa(config)#policy-map POLITICA-INSIDE-DMZ  ciscoasa(config-pmap)#class INSIDE-DMZ  ciscoasa(config-pmap-c)#INspect ?  mode commands/options:  dns  ftp  h323  http  icmp  tftp
  • 7. COMANDO EN PACKET TRACER  ciscoasa(config-pmap-c)#INspect icmp  ciscoasa(config-pmap-c)#exit  ciscoasa(config)#SERvice-policy POLITICA-INSIDE-DMZ INTerface INside  ciscoasa(config)#SH RUN  ciscoasa(config)#OBJECT NETwork LAN  ciscoasa(config-network-object)#SUBnet 192.168.1.0 255.255.255.0  ciscoasa(config-network-object)#NAT (INside,Outside) DYnamic Interface  ciscoasa(config)#OBJECT NETwork DMZ  ciscoasa(config-network-object)#SUbnet 192.168.100.0 255.255.255.248
  • 8. COMANDO EN PACKET TRACER  ciscoasa(config-network-object)#NAT (dmz,outside) dynamic interface  ciscoasa(config)#object network HTTP-MAIL-FTP  ciscoasa(config-network-object)#HOSt 192.168.100.2  ciscoasa(config-network-object)#nat (dmz,outside) static 10.0.0.4  ciscoasa(config-network-object)#exit  ciscoasa(config)#access-list ENTRANTE PERmit icmp any host 10.0.0.4 echo  ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq www
  • 9. COMANDO EN PACKET TRACER  ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq ftp  ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq smtp  ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 eq pop3  ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 lt ftp  ciscoasa(config)#access-list ENTRANTE PERmit tcp any host 10.0.0.4 gt ftp