AR Series routers ' Countermeasures for network viruses _ routers, switches

Source: Internet
Author: User
Tags switches port number
The function of the router is to maintain the connectivity of the network and to forward the packets to the best of its ability. The network virus sends the massive spam message, the router is not able to recognize.
We need to manually configure ACLs, such as the recently popular Shockwave virus, by configuring routers to partially block these spam messages.
Prohibit TCP messages with port number 135
Block UDP messages with port number 69
Prohibit ICMP messages

The above is only auxiliary measures, the fundamental solution is to killing PC virus, install the Microsoft operating system as soon as possible repair

D, upgrade anti-virus tools of the virus library, improve security awareness.



2, common anti-virus ACL, contains common virus port, newly discovered virus, also need to manually add corresponding port

Number, after the configuration of the relevant port issued can.

Virus attacks, may come from the public network, may also come from the intranet.

ACL number 3001

Rule 0 deny TCP Source-port eq 3127

Rule 1 deny TCP Source-port EQ 1025

Rule 2 deny TCP Source-port EQ 5554

Rule 3 deny TCP Source-port EQ 9996

Rule 4 deny TCP Source-port EQ 1068

Rule 5 deny TCP Source-port EQ 135

Rule 6 deny UDP Source-port EQ 135

Rule 7 deny TCP Source-port EQ 137

Rule 8 deny UDP Source-port eq netbios-ns

Rule 9 deny TCP Source-port EQ 138

Rule ten deny UDP Source-port eq NETBIOS-DGM

Rule one deny TCP Source-port EQ 139

Rule deny UDP source-port eq NETBIOS-SSN

Rule deny TCP source-port EQ 593

Rule deny TCP source-port EQ 4444

Rule deny TCP source-port EQ 5800

Rule deny TCP Source-port EQ 5900

Rule deny TCP source-port EQ 8998

Rule deny TCP source-port EQ 445

Rule deny UDP source-port EQ 445

Rule deny UDP source-port EQ 1434

Rule deny TCP destination-port EQ 3127

Rule deny TCP destination-port EQ 1025

Rule deny TCP destination-port EQ 5554

Rule deny TCP destination-port EQ 9996

Rule deny TCP destination-port EQ 1068

Rule deny TCP Destination-port EQ 135

Rule "Deny UDP Destination-port EQ 135

Rule Notoginseng deny TCP Destination-port EQ 137

Rule deny UDP destination-port eq netbios-ns

Rule the deny TCP Destination-port EQ 138

Rule deny UDP destination-port eq NETBIOS-DGM

Rule a deny TCP Destination-port EQ 139

Rule the deny UDP destination-port eq NETBIOS-SSN

Rule a deny TCP Destination-port EQ 593

Rule deny TCP destination-port EQ 4444

Rule deny TCP destination-port EQ 5800

Rule the deny TCP Destination-port EQ 5900

Rule by deny TCP Destination-port eq 8998

Rule $ deny TCP Destination-port EQ 445

Rule deny UDP destination-port EQ 445

Rule is deny UDP destination-port eq 1434

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.