设置Router阻击红色代码!

来源:互联网 发布:厦门入学积分怎么算法 编辑:程序博客网 时间:2024/04/30 06:21

class-map match-any iissucks
match protocol http url "*cmd.exe*"
match protocol http url "*.ida*"
match protocol http url "*root.exe*"
match protocol http url "*mem_bin*"
match protocol http url "*vti_bin*"
match protocol http url "*msadc*"
match protocol http url "*winnt*"
!
!
policy-map mark-http-crap
class iissucks
set ip dscp 1


access-list 131 deny ip any any dscp 1 log
access-list 131 permit ip any any


Outside interface:
service-policy input mark-http-crap


Inside interface:
ip access-group 131 out

 
原创粉丝点击