- 论坛徽章:
- 0
|
禁止P2P软件及聊天软件的使用方法\r\n1.从Web页面进入防火墙\r\n找到IPS-Signature-Predefined-P2P\r\n找到要禁止使用的P2P软件点击后面的Edit按钮\r\n \r\n \r\n选中Enable,如果要记录日志就选中Logging,Action里选择Drop。\r\n \r\n \r\n*Note:Action里面的选项的意思分别为:\r\nAction Select an action for the FortiGate unit to take when traffic triggers this signature.\r\n\r\nPass The FortiGate unit lets the packet that triggered the signature pass through the firewall. If logging is disabled and action is set to Pass, the signature is effectively disabled.\r\n\r\nDrop The FortiGate unit drops the packet that triggered the signature. Fortinet recommends using an action other than Drop for TCP connection based attacks.\r\n\r\nReset The FortiGate unit drops the packet that triggered the signature, sends a reset to both the client and the server, and removes the session from the FortiGate session table. Used for TCP connections only. If you set this action for non-TCP connection based attacks, the action will behave as Clear Session. If the Reset action is triggered before the TCP connection is fully established it acts as Clear Session.\r\n\r\nReset Client The FortiGate unit drops the packet that triggered the signature, sends a reset to the client, and removes the session from the FortiGate session table. Used for TCP connections only. If you set this action for non-TCP connection based attacks, the action will behave as Clear Session. If the Reset Client action is triggered before the TCP connection is fully established it acts as Clear Session.\r\n\r\nReset Server The FortiGate unit drops the packet that triggered the signature, sends a reset to the server, and removes the session from the FortiGate session table. Used for TCP connections only. If you set this action for non-TCP connection based attacks, the action will behave as Clear Session. If the Reset Server action is triggered before the TCP connection is fully established it acts as Clear Session.\r\n\r\nDrop Session The FortiGate unit drops the packet that triggered the signature and drops any other packets in the same session.\r\n\r\nClear Session The FortiGate unit drops the packet that triggered the signature, removes the session from the FortiGate session table, and does not send a reset.\r\n\r\nPass Session The FortiGate unit lets the packet that triggered the signature and all other packets in the session pass through the firewall.\r\n\r\n2.在Firewall-Protection Profile里面定义一条或者选择一条保护内容表来使用刚才定义的IPS。\r\n \r\n\r\n在内容保护表里面选中IPS中刚才所定义的特征(IPS Signature)\r\n \r\n\r\n3在对外访问的策略中启用保护内容表选项,并且选择刚才定义的保护内容表。 \r\n \r\n\r\n如果要禁用即时聊天软件,比如QQ和MSN等软件只需在第一步中的IPS-Signature-Predefined-im里选择您要阻挡的聊天软件就可以了.然后接着第二步操作.\r\n \r\n![]() |
|