firewall {
5 u; l3 @2 N& h filter saynotovirus: ^" T- H' I, J3 \% A; N, c
{: Q8 x9 E2 e8 g3 M$ ~3 h0 I7 ~
term& ` o- o; K. [: r/ S: F- w
udp-deny {! }! h% Z" t7 K
from {
6 y' n5 N' A$ M" Q8 o protocol udp;2 z! y; F' m# H- A; w
port [ 135 137 138 139 445 593 1434 1433 4444 ];// 这里是病毒的端口号
4 B' X! f" p7 r5 E2 { }- g( W4 V- l. B+ Q- X" r) \2 [$ P, W5 m
then {& H& I" G$ M/ b$ O( A' q3 [
count virus-upd-deny;
: s) Y, T6 @- m" |3 @" s& ^ discard;
* c, g/ \0 Z; [/ r }( j5 b5 Z$ a9 d# F( Y' U
}
( ^1 I( I& i' j- W4 W& q4 k# Z term* j! E. X* H, s3 H9 b
tcp-deny {
& n4 p6 i2 e: V5 {/ s( M from {
7 X/ e5 X( E: b) ^- V1 H( [% @9 i* i protocol tcp;
1 u; A4 J& t5 {- A- E0 [+ I( J port [ 135 138 139 445 593 3333 5800 5900 ];& j4 k. t. B' o1 j2 s
}
. c: a6 n4 x1 c7 H6 l then {
r& r v7 N- L& w$ ^) w9 q8 C count virus-tcp-deny;- e! o/ Y6 Q3 ]6 n [8 ^( @) G3 j
discard;
, I' c, H+ N. c m4 ?3 ?+ Z }
$ N0 |- B y! g3 i }
! u0 Y \$ S! Y% l+ X- O$ P" _7 s term others
+ q5 q0 g X6 E! I+ T, y3 e {
/ b# V% d9 W; e0 K. d' A then accept;4 r. u' x# C. H# h- G4 d& D
}; o- F& T6 ~+ R; `. R, S0 ?
}/ b- I' A2 s1 W/ l }/ j
}
, b8 K O: U/ V# y ge-2/3/0 {
0 @, S$ J ]0 h; d- ? vlan-tagging;
L& d f7 v& g6 v/ H2 d unit 10 {5 B; S6 |/ e/ {/ L: `, Z% ~; @7 M* h4 l
description "ge-1/3/0.10,to-c6506-01 ge-3/1";6 Z$ U$ w! d* l2 W1 {
vlan-id 10;
- s$ J% Y* c" G family inet {
# J- c1 z5 ]. m; m* l filter {
. f/ b7 T5 Q- ?8 v input saynotovirus;0 w/ o( G9 T: m) j8 x' ?% T/ M
output: `* @- U% O! I& f
saynotovirus;% _& l/ _! s/ ^
}$ m, F* j- Y9 Q& T8 _' X
address 161.112.10.105/30;* d) j2 {; j2 S7 r
}; r0 F, A* Q3 A- b0 b
} |