教程学院
图像设计 多媒体类 机械制图 办公软件 操作系统 系统编程 网站编程 网页制作 数据库类 网络路由 网络工程 网络安全 考试认证
firefox火狐浏览器下载
酷网学院
CAD
AutoCad Cam350 ProEngineer GCcam MATLAB Unigraphics SolidWorks CAXA Solid3000 Cimatron EdgeCAM
系统
安全 防火墙 病毒 WinXP Win2003 Vista
数据库
编程
网络
精彩图库
  当前位置: 库库中文网 · 网络安全教程 · 防火墙教程 · 防火墙基础教程

简略防火墙

学院最新推荐文章
教程推荐
『简略防火墙』如果文章有大量图片,显示会较慢,请等待图片下载完成
 
点击数: 更新时间:2005-6-2 

  interface Ethernet 0/0 ! Mosbach lokal
  ip address 129.143.204.13 255.255.255.252
  description Ethernet zum RZ-Router
  no ip directed-broadcast ! wg. Hacker (denial of service)
  ip inspect FIWA in ! Ueberpruefung des IP-Verkehrs
  ip access-group 101 in ! Anti-Spoofing
  ip access-group 102 out ! zusaetzliches Welt-LAN-Filter wegen Servern
  no shutdown
  !
  no access-list 101
  access-list 101 permit tcp 129.143.204.12 0.0.0.3 any ! RZ-Router Anti-Spoofing
  access-list 101 permit udp 129.143.204.12 0.0.0.3 any ! RZ-Router Anti-Spoofing
  access-list 101 permit icmp 129.143.204.12 0.0.0.3 any ! RZ-Router Anti-Spoofing
  access-list 101 permit tcp 193.196.5.0 0.0.0.255 any ! Netz der BA-Mo Anti-Spoofing
  access-list 101 permit udp 193.196.5.0 0.0.0.255 any ! Netz der BA-Mo Anti-Spoofing
  access-list 101 permit icmp 193.196.5.0 0.0.0.255 any ! Netz der BA-Mo Anti-Spoofing
  access-list 101 deny ip any any
  !
  ! Zulassen von gewissen Diensten auf die Server
  no access-list 102
  !
  access-list 102 permit tcp any any eq 22 ! SSH
  access-list 102 permit tcp any any eq 113 ! Ident
  access-list 102 permit tcp any any eq 487 ! SAFT
  !
  permit tcp any gt 1023 host 193.196.5.107 eq 21 ! FTP-Commands (fuer PASV FTP)
  permit tcp any gt 1023 host 193.196.5.105 eq 21 ! FTP-Commands (fuer PASV FTP)
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 25 ! SMTP zulassen
  access-list 102 permit tcp any host 193.196.5.105 eq 25 ! SMTP zulassen
  !
  access-list 102 permit tcp host 129.143.2.1 host 193.196.5.107 eq 53 ! DNS Zone-Transfer
  access-list 102 permit tcp host 129.206.100.126 host 193.196.5.107 eq 53 ! DNS Zone-Transfer
  access-list 102 permit tcp host 129.206.100.127 host 193.196.5.107 eq 53 ! DNS Zone-Transfer
  access-list 102 permit tcp host 129.143.2.1 host 193.196.5.105 eq 53 ! DNS Zone-Transfer
  access-list 102 permit tcp host 129.206.100.126 host 193.196.5.105 eq 53 ! DNS Zone-Transfer
  access-list 102 permit tcp host 129.206.100.127 host 193.196.5.105 eq 53 ! DNS Zone-Transfer
  
  access-list 102 permit permit tcp any host 193.196.5.107 eq 80 ! WWW
  access-list 102 permit permit tcp any host 193.196.5.105 eq 80 ! WWW
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 119 ! nntp
  access-list 102 permit tcp any host 193.196.5.105 eq 119 ! nntp
  !
  access-list 102 permit udp any host 193.196.5.107 eq 123 ! ntp
  access-list 102 permit udp any host 193.196.5.105 eq 123 ! ntp
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 389 ! ldap
  access-list 102 permit tcp any host 193.196.5.105 eq 389 ! ldap
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 443 ! https
  access-list 102 permit tcp any host 193.196.5.105 eq 443 ! https
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 993 ! Secure-IMAP
  access-list 102 permit tcp any host 193.196.5.105 eq 993 ! Secure-IMAP
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 995 ! Secure-POP3
  access-list 102 permit tcp any host 193.196.5.105 eq 995 ! Secure-POP3
  !
  ! bei geringeren Sicherheitsanforderungen:
  !
  access-list 102 permit tcp any host 193.196.5.107 eq 110 ! POP3 zulassen
  access-list 102 permit tcp any host 193.196.5.105 eq 110 ! POP3 zulassen
  access-list 102 permit udp any host 193.196.5.105 eq 53 ! DNS-Anfragen
  access-list 102 permit udp any host 193.196.5.107 eq 53 ! DNS-Anfragen
  !
  !
  access-list 102 permit icmp any host 193.196.5.107 administratively-prohibited
  access-list 102 permit icmp any host 193.196.5.107 echo
  access-list 102 permit icmp any host 193.196.5.107 echo-reply
  access-list 102 permit icmp any host 193.196.5.107 packet-too-big
  access-list 102 permit icmp any host 193.196.5.107 time-exceeded
  access-list 102 permit icmp any host 193.196.5.107 traceroute
  access-list 102 permit icmp any host 193.196.5.107 unreachable
  access-list 102 deny ip any any
  !
  ip inspect name FIWA http java-list 50 ! JavaScript ablehnen nach ACL 50
  ip inspect name FIWA realaudio timeout 3600
  ip inspect name FIWA smtp timeout 3600
  ip inspect name FIWA tftp timeout 30
  ip inspect name FIWA ftp timeout 3600
  ip inspect name FIWA udp timeout 15
  ip inspect name FIWA tcp timeout 3600
  !
  no access-list 50
  access-list 50 permit any log
  
  评:虽然是很好.但是访问列表过多,一旦被DOS一攻可能路由器马上瘫痪…重启…所以我认为要在前面加多一台Router来做个TCP Intercept 来拦截DOS攻击.如下:
  假如管理到个服务器群网络上192.168.111.0 & 192.168.112.0 内的目标主机的TCP连接请求.使用拦截模式,随机丢弃连接:
  access-list 123 permit tcp any 192.168.111.0 0.0.0.255
  access-liat 123 permit tcp any 192.168.112..0 0.0.0.255
  ip tcp intercept list 123
  ip tcp intercept mode intercept
  ip tcp intercept drop-mode random
  
  做好以后.两个Router在做个HSRP ……..
  
  这样还可以嘛…呵呵….
  
  
】【关闭窗口
·上页:
·下页:
相关文章
     网络安全教程 - 防火墙基础教程
推荐教程Cisco防火墙技术汇总
推荐教程CISCO普遍疑难及解答——防火墙
普通教程最新智能防火墙简略介绍和技术特
普通教程透过防火墙日志看系统安全
普通教程网络防火墙地设定灵活技术
普通教程防火墙技术地资料(6)防火墙技
普通教程防火墙技术地资料(5)选购防火
普通教程防火墙技术地资料(4)新型防火
普通教程防火墙技术地资料(3)防火墙技
普通教程防火墙技术地资料(2)防火墙功
普通教程防火墙技术地资料(1)防火墙技
普通教程【软考】防火墙知识普及(2)
精彩图片汇集
advertisement
关于站点 - 广告服务 - 联系我们 - 版权隐私 - 免责声明 - 合作伙伴 - 程序支持 - 网站地图 - 返回顶部
网站文本地图
版权所有:库库中文 2005-2007 欢迎各种媒体转载我们的原创作品[转载请注明出处]
copyright © 2005-2008 www.QQGB.com online services. all rights reserved. 蜀ICP备05015578
Template designed by Virus. Optimized for 1024x768 to Firefox,Opera and MS-IE6. Site powered by EQL.
红盾
热爱电脑,热爱生活
拥有电脑,拥有生命
让我们享受拥有电脑的时光