国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁(yè) > 學(xué)院 > 網(wǎng)絡(luò)通信 > 正文

CISCO 防御沖擊波方法

2019-11-05 00:09:24
字體:
來(lái)源:轉(zhuǎn)載
供稿:網(wǎng)友

  ! --- block TFTP
  
  access-list 115 deny udp any any eq 69
  
  ! --- block W32.Blaster related PRotocols
  
  access-list 115 deny tcp any any eq 135
  access-list 115 deny udp any any eq 135
  
  ! --- block other vulnerable MS protocols
  
  access-list 115 deny udp any any eq 137
  access-list 115 deny udp any any eq 138
  access-list 115 deny tcp any any eq 139
  access-list 115 deny udp any any eq 139
  access-list 115 deny tcp any any eq 445
  access-list 115 deny tcp any any eq 593
  
  ! --- block remote access due to W32.Blaster
  
  access-list 115 deny tcp any any eq 4444
  
  ! --- Allow all other traffic -- insert
  ! --- other existing access-list entries here
  
  access-list 115 permit ip any any
  
  interface
  
  ip access-group 115 in
  ip access-group 115 out
  
  另外,阻止非法地址的命令是:
  
  Router(config)# interface
  Router(if-config)# no ip unreachables
  
  假如此命令不能禁止,可參考下面這個(gè)命令:
  
  Elab(config)# ip icmp rate-limit unreachable
  VACL on the CatOS
  
  ! --- block TFTP
  set security acl ip BLASTER deny udp any any eq 69
  
  ! --- block vulnerable MS protocols
  ! --- Blaster related
  set security acl ip BLASTER deny tcp any any eq 135
  set security acl ip BLASTER deny udp any any eq 135
  
  ! --- Non-blaster related
  
  set security acl ip BLASTER deny tcp any any eq 137
  set security acl ip BLASTER deny udp any any eq 137
  set security acl ip BLASTER deny tcp any any eq 138
  set security acl ip BLASTER deny udp any any eq 138
  set security acl ip BLASTER deny tcp any any eq 139
  set security acl ip BLASTER deny udp any any eq 139
  set security acl ip BLASTER deny tcp any any eq 593
  
  ! --- block remote access due to W32.Blaster
  
  set security acl ip BLASTER deny tcp any any eq 4444
  
  ! --- Allow all other traffic
  ! --- insert other existing access-list entries here
  
  set security acl ip BLASTER permit any any
  
  ! -- applies both inbound and outbound
  
  commit security acl BLASTER
  set security acl map BLASTER
  PIX
  
  access-list acl_inside deny udp any any eq 69
  access-list acl_inside deny tcp any any eq 135
  access-list acl_inside deny udp any any eq 135
  access-list acl_inside deny tcp any any eq 137
  access-list acl_inside deny udp any any eq 137
  access-list acl_inside deny tcp any any eq 138
  access-list acl_inside deny udp any any eq 138
  access-list acl_inside deny tcp any any eq 139
  access-list acl_inside deny udp any any eq 139
  access-list acl_inside deny tcp any any eq 445
  access-list acl_inside deny tcp any any eq 593
  access-list acl_inside deny tcp any any eq 4444
  !
--- insert previously configured acl statements here,
  ! --- or permit all other traffic out
  
  access-list acl_inside permit ip any any
  
  access-group acl_inside in interface inside

發(fā)表評(píng)論 共有條評(píng)論
用戶(hù)名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 静海县| 民权县| 绥芬河市| 济宁市| 伊宁市| 芦山县| 延津县| 深泽县| 冷水江市| 衡水市| 卫辉市| 广安市| 克拉玛依市| 屯昌县| 台北县| 宜兰县| 项城市| 宁海县| 离岛区| 赣榆县| 当雄县| 新兴县| 新乐市| 芜湖市| 监利县| 梁平县| 青铜峡市| 开化县| 郯城县| 孟津县| 隆安县| 金溪县| 顺昌县| 黑龙江省| 林芝县| 渑池县| 咸阳市| 临沧市| 巴林右旗| 安义县| 鹰潭市|