一、檢查路由器的利用率網絡
Input queue: 0/75/223681684/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue :0/40 (size/max) 5 minute input rate 444000 bits/sec, 183 packets/sec 5 minute output rate 708000 bits/sec, 139 packets/sec 43289439 packets input, 4150615869 bytes Received 9225 broadcasts, 0 runts, 0 giants, 0 throttles 3645805 input errors, 0 CRC, 0 frame, 3645805 overrun, 0 ignored |
2:54:56: IP: s=180.93.127.229 (FastEthernet0/0), d=193.151.73.76 (FastEthernet0 1), g=211.138.74.97, len 40, forward 2:54:56: TCP src=1232, dst=80, seq=1632305152, ack=0, win=16384 SYN 2:54:56: IP: s=180.93.128.205 (FastEthernet0/0), d=193.151.73.76 (FastEthernet0 1), g=211.138.74.97, len 40, forward 2:54:56: TCP src=1839, dst=80, seq=1144193024, ack=0, win=16384 SYN 2:54:56: IP: s=180.93.129.212 (FastEthernet0/0), d=193.151.73.76 (FastEthernet0 1), g=211.138.74.97, len 40, forward 2:54:56: TCP src=1116, dst=80, seq=1918435328, ack=0, win=16384 SYN 2:54:56: IP: s=180.93.130.223 (FastEthernet0/0), d=193.151.73.76 (FastEthernet0 1), g=211.138.74.97, len 40, forward 2:54:56: TCP src=1302, dst=80, seq=1559429120, ack=0, win=16384 SYN |
! --- 禁止ICMP協議 access-list 115 deny icmp any any echo access-list 115 deny icmp any any echo-reply ! --- 禁止衝擊波135端口的數據包. access-list 115 deny tcp any any eq 135 access-list 115 deny udp any any eq 135 access-list 115 deny udp any any eq 4444 ! --- 禁止TFTP應用的端口的數據包 access-list 115 deny udp any any eq 69 ! --- 禁止其餘微軟的有漏洞的協議端口. access-list 115 deny udp any any eq 137 access-list115denyudpanyanyeq138 access-list115denytcpanyanyeq139 access-list115denyudpanyanyeq139 access-list115denytcpanyanyeq445 access-list115denytcpanyanyeq593 ! --- 容許其餘的IP包經過路由器端口. access-list 115 permit ip any any ! --- 把以上的訪問列表應用的端口上. interface ip access-group 115 in ip access-group 115 out |