Chinaunix

标题: 那位大虾能讲讲防火强的配置 [打印本页]

作者: lishuang_13    时间: 2006-02-21 13:12
标题: 那位大虾能讲讲防火强的配置
那位大虾能讲讲防火强的配置,我这有些防火强的配置文档,但看不懂,请高人指教,
我的电子邮件:lishuang_13@126.com

配置:
-------------------------------------------------------------------------------------
set vrouter trust-vr sharable
unset vrouter "trust-vr" auto-route-export
set service "fangbingdu-3" protocol udp src-port 0-65535 dst-port 135-135 timeout never
set service "remote-desktop" protocol tcp src-port 0-65535 dst-port 3389-3389 timeout never
set service "VNC-1" protocol tcp src-port 0-65535 dst-port 5800-5800 timeout never
set service "VNC-2" protocol tcp src-port 0-65535 dst-port 5900-5900 timeout never
set service "fangbingdu-1" protocol tcp src-port 0-65535 dst-port 135-135 timeout never
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 136-136
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 137-137
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 138-138
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 139-139
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 445-445
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 4444-4444
set service "fangbingdu-1" + tcp src-port 0-65535 dst-port 69-69
set service "fangbingdu-2" protocol udp src-port 0-65535 dst-port 136-136 timeout never
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 138-138
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 139-139
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 389-389
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 445-445
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 1433-1433
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 1434-1434
set service "fangbingdu-2" + udp src-port 0-65535 dst-port 4444-4444
set service "app-mobile" protocol tcp src-port 0-65535 dst-port 5630-5630 timeout never
set service "app-mobile" + udp src-port 0-65535 dst-port 5630-5630
set service "app-mobile" + tcp src-port 0-65535 dst-port 6666-6666
set service "app-mobile" + udp src-port 0-65535 dst-port 6666-6666
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"




欢迎光临 Chinaunix (http://bbs.chinaunix.net/) Powered by Discuz! X3.2