【正文】
few minutes. How many bits in the modulus[512]: 2048 Generating RSA Keys... [OK] Router(Config)/PP TCP SYN的防范。Router(Config) no accesslist 106 Router(Config) accesslist 106 permit tcp any establishedRouter(Config) accesslist 106 deny ip any any Router(Config) interface eth 0/2Router(Configif) description “external Ethernet”Router(Configif) ip address Router(Configif) ip accessgroup 106 inB:通過TCP截取防范。Router(Config) accesslist 107 deny ip host host Router(Config) accesslist 107 permit ip any anyRouter(Config) interface eth 0/2Router(Configif) ip address Router(Configif) ip accessgroup 107 in/PP Smurf進(jìn)攻的防范。對于進(jìn)入ICMP流,我們要禁止ICMP協(xié)議的ECHO、Redirect、Mask request。對于流出的ICMP流,我們可以允許ECHO、Parameter Problem、Packet too big。! outbound ICMP ControlRouter(Config) accesslist 110 deny icmp any any echo Router(Config) accesslist 110 deny icmp any any redirect Router(Config) accesslist 110 deny icmp any any maskrequest Router(Config) accesslist 110 permit icmp any any ! Inbound ICMP ControlRouter(Config) accesslist 111 permit icmp any any echoRouter(Config) accesslist 111 permit icmp any any ParameterproblemRouter(Config) accesslist 111 permit icmp any any packettoobigRouter(Config) accesslist 111 permit icmp any any sourcequenchRouter(Config) accesslist 111 deny icmp any any ! Outbound TraceRoute ControlRouter(Config) accesslist 112 deny udp any any range 33400 34400 ! Inbound TraceRoute ControlRouter(Config) accesslist 112 permit udp any any range 33400 34400 /PP DDoS(Distributed Denial of Service)的防范。建議增加如下配置:(需在所有運(yùn)行BGP的路由器上增加)在每個BGP互連的接口上,增加holdqueue 1500命令,將接口的holdqueue由默認(rèn)的75增加到1500。增加以下有關(guān)TCP的配置,增強(qiáng)BGP的收斂性能。/PP 啟用CAR和系統(tǒng)日志等來增強(qiáng)(略)/PP其他注意事項(xiàng):1,及時的升級IOS軟件,并且要迅速的為IOS安裝補(bǔ)丁。3,要為路由器的配置文件作安全備份。5,要有完備的路由器的安全訪問和維護(hù)記錄日