最佳答案
常规的就这些 445 135 137 139
防火墙封堵高危端口
object-group service 高危端口
0 service tcp destination eq 445
20 service tcp destination eq 135
30 service tcp destination range 137 139
security-policy ip
rule 2 name 高危端口
source-zone Trust
destination-zone Untrust
service 高危端口
或者
在命令行你这样配置就行。配置完成后到web页面刷新一下,你就能看到对应的策略了
rule 350 name deny-OUT-IN-HighRiskPort
source-zone Untrust
destination-zone Trust
destination-zone Local
service-port tcp source eq 135
service-port tcp destination eq 135
service-port tcp destination eq 137
service-port tcp destination eq 138
service-port tcp destination eq 139
service-port tcp destination eq 445
service-port tcp source eq 137
service-port tcp source eq 138
service-port tcp source eq 139
service-port tcp source eq 445
service-port udp source eq 135
service-port udp destination eq 135
service-port udp destination eq 445
service-port udp source eq 445
#
rule 400 name deny-IN-OUT-HighRiskPort
source-zone Trust
source-zone Local
destination-zone Untrust
service-port tcp source eq 135
service-port tcp destination eq 135
service-port tcp destination eq 137
service-port tcp destination eq 138
service-port tcp destination eq 139
service-port tcp destination eq 445
service-port tcp source eq 137
service-port tcp source eq 138
service-port tcp source eq 139
service-port tcp source eq 445
service-port udp source eq 135
service-port udp destination eq 135
service-port udp destination eq 445
service-port udp source eq 445
(0)
您好,参考命令如下:
sys
acl a 3000
ru 10 den tcp destination-port eq 3389
ru 100 per ip
int g 1/0/1
pa 3000 in
(0)
暂无评论
object-group service gaowei-port
0 service tcp destination range 135 139
50 service tcp destination eq 445
60 service tcp destination eq 3389
70 service udp destination range 135 139
120 service udp destination eq 445
130 service udp destination eq 3389
#
security-policy ip
rule 0 name
counting enable
service gaowei-port
(0)
暂无评论
object-group service gaowei-port
0 service tcp destination range 135 139
50 service tcp destination eq 445
60 service tcp destination eq 3389
70 service udp destination range 135 139
120 service udp destination eq 445
130 service udp destination eq 3389
#
security-policy ip
rule 0 name
counting enable
service gaowei-port
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论