我们有一个相当基本的ACL和NAT规则,允许RDP入站和NAT到局域网IP(所有的IP都用IP代替)
object network STATIC-PAT-RDP host IP access-list outside_access_in extended permit object TerminalServices any object IP log debugging access-list OUTSIDE-IN remark Allow RDP access-list OUTSIDE-IN extended permit tcp any object STATIC-PAT-RDP eq 3389 object network STATIC-PAT-RDP nat (inside,outside) static interface service tcp 3389 3389 access-group OUTSIDE-IN in interface outside
但是,连接在遇到WAN接口时将被丢弃:
7 May 05 2015 11:37:56 IP 4335 IP 3389 TCP request discarded from IP to outside:IP
我以前从未见过这个设备 – 通过netstat -ano监听3389,我可以在内部使用RDP。