【正文】
P攻擊組網(wǎng)S3552P是三層設(shè)備,其中IP:,S3552P上的網(wǎng)關(guān)MAC地址為000fe2003999。[QuidwayGigabitEthernet0/1] packetfilter inbound ipgroup trafficofpayserver3,常見病毒的ACL創(chuàng)建aclacl number 100禁pingrule deny icmp source any destination any用于控制Blaster蠕蟲的傳播rule deny udp source any destination any destinationport eq 69rule deny tcp source any destination any destinationport eq 4444用于控制沖擊波病毒的掃描和攻擊rule deny tcp source any destination any destinationport eq 135rule deny udp source any destination any destinationport eq 135rule deny udp source any destination any destinationport eq netbiosnsrule deny udp source any destination any destinationport eq netbiosdgmrule deny tcp source any destination any destinationport eq 139rule deny udp source any destination any destinationport eq 139rule deny tcp source any destination any destinationport eq 445rule deny udp source any destination any destinationport eq 445rule deny udp source any destination any destinationport eq 593rule deny tcp source any destination any destinationport eq 593用于控制振蕩波的掃描和攻擊rule deny tcp source any destination any destinationport eq 445rule deny tcp source any destination any destinationport eq 5554rule deny tcp source any destination any destinationport eq 9995rule deny tcp source any destination any destinationport eq 9996用于控制 蠕蟲的傳播rule deny udp source any destination any destinationport eq 1434下面的不出名的病毒端口號(hào) (可以不作)rule deny tcp source any destination any destinationport eq 1068rule deny tcp source any destination any destinationport eq 5800rule deny tcp source any destination any destinationpo