华为Firewall配置不当处理记录,外网口开启了https访问管理被攻击,无法访问WEB管理界面

早期为了求方便,在外网入口开放了https访问管理,一直没出什么问题,直到今天想看一个配置时发现无法开启网页.
检查及排除步骤记录一下:

  1. 确认Firewall还活着,排除Client问题
  2. 确认Firewall上面的业务没问题,开始处理检查处理web服务不能用的问题
  3. telnet 进去看了一下log,没发现有什么特别的,以为只是WEB服务死了,重启了服务,不管用
  4. 考虑是否有配置更改,检查配置
  5. 怀疑被攻击,检查,确认是有外部类DDOS攻击,更改配置等…
    相关命令:
[KSYOFW01]undo web-manager enable //停掉http 服务
[KSYOFW01]web-manager enable  //打开服务
[KSYOFW01]interface Vlanif 100
[KSYOFW01-Vlanif100]disp this
#
interface Vlanif100
 alias vlan100
 ip address 192.168.0.2 255.255.255.0
 service-manage https permit
 service-manage ping permit
 service-manage ssh permit
 service-manage snmp permit
 service-manage telnet permit
#
return
[KSYOFW01] display security-policy rule destination 192.168.0.2 //先找一下有多少针对内网接口的策略
RULE ID RULE NAME                      STATE      ACTION     HITTED
-------------------------------------------------------------------------------
0       default                        enable     deny       153466519
2       VPN_TVLAN_KVLAN                enable     permit     2292
7       AllowAccessInternet            enable     permit     86723930
10      溼恀俋厙諉諳華硊               enable     permit     2882487
11      囀厙溼恀                       enable     permit     1032981
12      local to local                 enable     permit     155932
13      trust to local                 enable     permit     28476
-------------------------------------------------------------------------------
[KSYOFW01]display security-policy rule "trust to local" //此处可看出对内网接口的访问策略没问题
  (28476 times matched)
 rule name "trust to local"
  source-zone trust
  destination-zone local
  action permit
[KSYOFW01]disp tcp status //果然发现了鬼
11:34:35  2019/05/10
TCPCB    Tid/Soid Local Add:port        Foreign Add:port      VPNID  State
1418256c  93 /1    0.0.0.0:23             0.0.0.0:0             14849 Listening
0fc04558  129/257  0.0.0.0:80             0.0.0.0:0             14849 Listening
1426dbec  129/3    0.0.0.0:8443           0.0.0.0:0             14849 Listening
0fc08c08  93 /26   192.168.0.2:23          192.168.8.144:63558    0     Establishe
d
0fbff4e8  129/0    14.34.15.18:8443     128.199.36.85:41021   0     Syn_Rcvd
0fc08998  129/0    14.34.15.18:8443     128.199.36.85:43817   0     Syn_Rcvd
0fc03a60  129/0    14.34.15.18:8443     128.199.36.85:46907   0     Syn_Rcvd
0fbfddc0  129/0    14.34.15.18:8443     128.199.36.85:50634   0     Syn_Rcvd
0fc05c80  129/0    14.34.15.18:8443     128.199.36.85:54334   0     Syn_Rcvd
0fc004c0  129/0    14.34.15.18:8443     128.199.36.85:55323   0     Syn_Rcvd
14265984  129/0    14.34.15.18:8443     128.199.36.85:63193   0     Syn_Rcvd
0fbfe030  129/0    14.34.15.18:8443     174.138.106.64:50255  0     Syn_Rcvd
[KSYOFW01] interface GigabitEthernet 1/0/0
[KSYOFW01-GigabitEthernet1/0/0]disp this
#
interface GigabitEthernet1/0/0
 link-group 1
 alias CT
 ip address 14.34.15.18 255.255.255.248
 reverse-route nexthop 14.34.15.17
 ipsec policy ipsec4112451459 auto-neg
 service-manage https permit
 service-manage ssh permit
 gateway 14.34.15.17
 anti-ddos flow-statistic enable
#
return
[KSYOFW01-GigabitEthernet1/0/0]service-manage https deny
[KSYOFW01-GigabitEthernet1/0/0]q
[KSYOFW01]undo web-manager enable //再停掉http 服务
[KSYOFW01]web-manager enable  //重打开服务,搞定
[KSYOFW01] interface GigabitEthernet 1/0/0
[KSYOFW01-GigabitEthernet1/0/0]undo service-manage enable //还是老实一点,外网接口的全关了吧
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值