国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁(yè) > 學(xué)院 > 網(wǎng)絡(luò)通信 > 正文

CISCO 防御沖擊波方法

2019-11-05 00:09:24
字體:
來(lái)源:轉(zhuǎn)載
供稿:網(wǎng)友

  ! --- block TFTP
  
  access-list 115 deny udp any any eq 69
  
  ! --- block W32.Blaster related PRotocols
  
  access-list 115 deny tcp any any eq 135
  access-list 115 deny udp any any eq 135
  
  ! --- block other vulnerable MS protocols
  
  access-list 115 deny udp any any eq 137
  access-list 115 deny udp any any eq 138
  access-list 115 deny tcp any any eq 139
  access-list 115 deny udp any any eq 139
  access-list 115 deny tcp any any eq 445
  access-list 115 deny tcp any any eq 593
  
  ! --- block remote access due to W32.Blaster
  
  access-list 115 deny tcp any any eq 4444
  
  ! --- Allow all other traffic -- insert
  ! --- other existing access-list entries here
  
  access-list 115 permit ip any any
  
  interface
  
  ip access-group 115 in
  ip access-group 115 out
  
  另外,阻止非法地址的命令是:
  
  Router(config)# interface
  Router(if-config)# no ip unreachables
  
  假如此命令不能禁止,可參考下面這個(gè)命令:
  
  Elab(config)# ip icmp rate-limit unreachable
  VACL on the CatOS
  
  ! --- block TFTP
  set security acl ip BLASTER deny udp any any eq 69
  
  ! --- block vulnerable MS protocols
  ! --- Blaster related
  set security acl ip BLASTER deny tcp any any eq 135
  set security acl ip BLASTER deny udp any any eq 135
  
  ! --- Non-blaster related
  
  set security acl ip BLASTER deny tcp any any eq 137
  set security acl ip BLASTER deny udp any any eq 137
  set security acl ip BLASTER deny tcp any any eq 138
  set security acl ip BLASTER deny udp any any eq 138
  set security acl ip BLASTER deny tcp any any eq 139
  set security acl ip BLASTER deny udp any any eq 139
  set security acl ip BLASTER deny tcp any any eq 593
  
  ! --- block remote access due to W32.Blaster
  
  set security acl ip BLASTER deny tcp any any eq 4444
  
  ! --- Allow all other traffic
  ! --- insert other existing access-list entries here
  
  set security acl ip BLASTER permit any any
  
  ! -- applies both inbound and outbound
  
  commit security acl BLASTER
  set security acl map BLASTER
  PIX
  
  access-list acl_inside deny udp any any eq 69
  access-list acl_inside deny tcp any any eq 135
  access-list acl_inside deny udp any any eq 135
  access-list acl_inside deny tcp any any eq 137
  access-list acl_inside deny udp any any eq 137
  access-list acl_inside deny tcp any any eq 138
  access-list acl_inside deny udp any any eq 138
  access-list acl_inside deny tcp any any eq 139
  access-list acl_inside deny udp any any eq 139
  access-list acl_inside deny tcp any any eq 445
  access-list acl_inside deny tcp any any eq 593
  access-list acl_inside deny tcp any any eq 4444
  !
--- insert previously configured acl statements here,
  ! --- or permit all other traffic out
  
  access-list acl_inside permit ip any any
  
  access-group acl_inside in interface inside

發(fā)表評(píng)論 共有條評(píng)論
用戶(hù)名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 娱乐| 甘南县| 海伦市| 永康市| 宁德市| 金门县| 武汉市| 宜兰市| 常熟市| 青海省| 余姚市| 驻马店市| 鄢陵县| 宜阳县| 资兴市| 镇康县| 余庆县| 灌南县| 岳阳市| 洛川县| 广平县| 名山县| 彰化市| 吴桥县| 盐亭县| 湾仔区| 罗城| 华安县| 奈曼旗| 三门县| 桓台县| 舒城县| 长春市| 澳门| 娱乐| 密云县| 景德镇市| 台湾省| 临西县| 孝义市| 潍坊市|