Step 1 : Add IP Filter and Filter Operations
Click [start] → [Administrative Tools] → [Local Security Policy] to open the "Local Security Settings" dialog box. Right-click the [IP Security Policy, on local computer] option in the left-side console tree of the dialog box and run the [manage IP Filter tables and filters] command. In the displayed dialog box, click the [add] button under the [manage IP Filter list] tab and name the Filter Name "Ping prohibited ", the description language can be "prohibit any other computer from pinging my host", and then click the [add] button. Next, click [next] → [next], select "IP communication Source Address" as [my IP address], and click [next]. select "IP communication target address" as [any IP address], click [next], select "IP protocol type" as [ICMP], and click [next]. Click [finish] → [OK] To End adding. Switch to the [manage Filter Operations] tab, click [add] → [next], and name the filter operation "block all connections ", the description language can be "block all network connections", click [next], and click the [block] option as the action of this filter, click [next] → [finish] → [close] to complete all adding operations.
Step 2 : Create an IP Security Policy
Right-click the [IP Security Policy, on the local computer] option in the console tree, run the [create security policy] command, and then click the [next] button. Name this IP Security Policy "Ping prohibited hosts", the description language is "Deny ping requests from any other computer", and click [next]. Then, select [activate default response rules] and click [next]. In the "default response rule authentication method" dialog box, click [use this string to protect key exchange], and enter a string such as "no ping" in the text box below ", click [next]. Finally, click the [finish] button to end the creation.
Step 3 : Configure IP Security Policies
Click [add] → [next] under the [general] tab in the "Ping prohibited properties" dialog box. By default, click [this rule does not specify a tunnel] and click [next]. click [all network connections] to ensure that all computers cannot ping the host. Click [next]. In the "IP Filter list" box, click [disable Ping], click [next], click [block all connections] in the "Filter Operations" list box, and click [next]. cancel the "Edit attributes" option and click [finish] to end the configuration.
Step 4 : Assign an IP Security Policy
Security policies cannot take effect immediately after they are created. We still need to assign them to play a role. Right-click the [disable host Ping] policy on the right of the "Local Security Settings" dialog box, and execute the "Assign" command to enable this policy. Note: The operations to block ports 135 and 445 are similar.
This article is from 51cto. com technical blog