WINDOWS 2008 采用IP策略解决445,139等病毒攻击问题

@echo off  
title 创建IP安全策略,屏蔽135、139445 . . . 等端口

:: 配置说明文档地址
:: http://blog.csdn.net/lpc_china/article/details/6944432

echo 创建安全策略 
netsh ipsec static delete policy name= 安全策略20170621
netsh ipsec static add policy name=安全策略20170621

echo 创建筛选器是阻止的操作 
netsh ipsec static add filterlist name=阻止20170621


echo 增加过滤条件
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=135 protocol=TCP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=135 protocol=UDP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=137 protocol=TCP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=137 protocol=UDP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=138 protocol=TCP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=138 protocol=UDP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=139 protocol=TCP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=139 protocol=UDP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=445 protocol=TCP
netsh ipsec static add filter filterlist=阻止20170621 srcaddr=any dstaddr=Me dstport=445 protocol=UDP

echo 创建筛选器是允许的操作
netsh ipsec static add filteraction name=FilteraAtion20170621 action=block

echo 建立策略规则
netsh ipsec static add rule name=Rule1 policy=安全策略20170621 filterlist=阻止20170621 filteraction=FilteraAtion20170621

echo 开始添加filterlist
netsh ipsec static add filterlist name=允许20170621
netsh ipsec static add filter filterlist=允许20170621 srcaddr=10.10.14.199 dstaddr=Me dstport=445 protocol=TCP
netsh ipsec static add filter filterlist=允许20170621 srcaddr=10.10.14.199 dstaddr=Me dstport=445 protocol=UDP
netsh ipsec static add filteraction name=FilterbAtion20170621 action=permit 
netsh ipsec static add rule name=Rule2 policy=安全策略20170621 filterlist=允许20170621 filteraction=FilterbAtion20170621   

:: 最重要的一步是激活;
netsh ipsec static set policy name=安全策略20170621 assign=y

pause

生成一个禁止445.bat的文件即可。

转载于:https://www.cnblogs.com/littlehb/p/8511575.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值