網(wǎng)絡(luò)技術(shù)是從1990年代中期發(fā)展起來的新技術(shù),它把互聯(lián)網(wǎng)上分散的資源融為有機(jī)整體,實(shí)現(xiàn)資源的全面共享和有機(jī)協(xié)作,使人們能夠透明地使用資源的整體能力并按需獲取信息。資源包括高性能計(jì)算機(jī)、存儲(chǔ)資源、數(shù)據(jù)資源、信息資源、知識(shí)資源、專家資源、大型數(shù)據(jù)庫、網(wǎng)絡(luò)、傳感器等。 當(dāng)前的互聯(lián)網(wǎng)只限于信息共享,網(wǎng)絡(luò)則被認(rèn)為是互聯(lián)網(wǎng)發(fā)展的第三階段。 什么才是軟路由防火墻呢?如何進(jìn)行軟路由防火墻的配置呢?也許很多人還不是特別的了解,其實(shí)軟路由防火墻的主要作用就是保證我們的網(wǎng)絡(luò)安全,阻止黑客、病毒以及其他潛在的網(wǎng)絡(luò)危害,下面我們就介紹一下軟路由防火墻策略的配置語句。
- add chain=input connection-state=established action=accept \
- comment="Established connections" disabled=no
- add chain=input connection-state=related action=accept comment="Related \
- connections" disabled=no
- add chain=input connection-state=invalid action=drop comment="Drop invalid \
- connections" disabled=no
- add chain=input action=jump jump-target=viruses comment="!!!Viruse \
- detection!!!" disabled=no
- add chain=input protocol=udp action=accept comment="UDP protocol" disabled=no
- add chain=input protocol=icmp action=accept comment="ICMP protocol" \
- disabled=no
- add chain=input src-address=192.168.1.0/24 action=accept comment="From local \
- netword 192.168.1.0/24" disabled=no
- add chain=input protocol=tcp dst-port=1723 action=accept comment="Allow PPTP" \
- disabled=no
- add chain=input protocol=gre action=accept comment="" disabled=no
- add chain=input protocol=tcp dst-port=21 action=accept comment="Allow \
- FTP,SSH,TELNET,WEB,WINBOX to router" disabled=no
- add chain=input protocol=tcp dst-port=22 action=accept comment="" disabled=no
- add chain=input protocol=tcp dst-port=23 action=accept comment="" disabled=no
- add chain=input protocol=tcp dst-port=80 action=accept comment="" disabled=no
- add chain=input protocol=tcp dst-port=8291 action=accept comment="" \
- disabled=no
- add chain=input protocol=tcp dst-port=9998 action=accept comment="Allow \
- digital video recorder TCP:9998 UDP:9998" disabled=no
- add chain=input protocol=udp dst-port=9998 action=accept comment="" \
- disabled=no
- add chain=input action=drop comment="Drop everything else" disabled=no
- add chain=forward connection-state=established action=accept \
- comment="Established connections" disabled=no
- add chain=forward connection-state=related action=accept comment="Related \
- connections" disabled=no
- add chain=forward connection-state=invalid action=drop comment="Drop invalid \
- connections" disabled=no
- add chain=forward action=jump jump-target=viruses comment="!!!Viruse \
- detection!!!" disabled=no
- add chain=forward protocol=udp action=accept comment="UDP protocol" \
- disabled=no
- add chain=forward protocol=icmp action=accept comment="ICMP protocol" \
- disabled=no
- add chain=forward src-address=192.168.1.0/24 action=accept comment="From local \
- netword 192.168.1.0/24" disabled=no
- add chain=forward action=drop comment="Drop everything else" disabled=no
- add chain=output connection-state=established action=accept \
- comment="Established connections" disabled=no
- add chain=output connection-state=related action=accept comment="Related \
- connections" disabled=no
- add chain=output connection-state=invalid action=drop comment="Drop invalid \
- connections" disabled=no
- add chain=viruses protocol=tcp dst-port=135-139 action=drop comment="Drop port \
- TCP/UDP 135-139" disabled=no
- add chain=viruses protocol=udp dst-port=135-139 action=drop comment="" \
- disabled=no
-
網(wǎng)絡(luò)的神奇作用吸引著越來越多的用戶加入其中,正因如此,網(wǎng)絡(luò)的承受能力也面臨著越來越嚴(yán)峻的考驗(yàn)―從硬件上、軟件上、所用標(biāo)準(zhǔn)上......,各項(xiàng)技術(shù)都需要適時(shí)應(yīng)勢,對(duì)應(yīng)發(fā)展,這正是網(wǎng)絡(luò)迅速走向進(jìn)步的催化劑。
|