Class-map all_ip
match any
Policy-map golobl_policy
Class all_ip
Set connection decrement-ttl
设置好防火墙策略,对access-list进行放行和应用
access-list out_in remark ICMP type 11 for Windows Tracert
access-list out_in extended permit icmp any any time-exceeded
access-list out_in remark ICMP type 3 for Cisco and Linux
access-list out_in extended permit icmp any any unreachable
access-list out_in extended permit icmp any any echo-reply
access-list out_in extended permit icmp any any source-quench
并应用到相应的接口即可
access-group out_in in interface outside_mobile
access-group out_in in interface outside_tel
access-group out_in in interface mobile_vpn
access-group out_in in interface tel_vpn