r> access-list 102 permit icmp any host 193.196.5.107 time-exceeded access-list 102 permit icmp any host 193.196.5.107 traceroute access-list 102 permit icmp any host 193.196.5.107 unreachable access-list 102 deny ip any any ! ip inspect name FIWA http java-list 50 ! JavaScript ablehnen nach ACL 50 ip inspect name FIWA realaudio timeout 3600 ip inspect name FIWA smtp timeout 3600 ip inspect name FIWA tftp timeout 30 ip inspect name FIWA ftp timeout 3600 ip inspect name FIWA udp timeout 15 ip inspect name FIWA tcp timeout 3600 ! no access-list 50 access-list 50 permit any log 评:虽然是很好.但是访问列表过多,一旦被DOS一攻可能路由器马上瘫痪…重启…所以我认为要在前面加多一台Router来做个TCP Intercept 来拦截DOS攻击.如下: 假如管理到个服务器群网络上192.168.111.0 & 页码:[1] [2] [3] [4] [5] [6] [7] 第6页、共7页 |