配置愛快路由器的ACL規則


配置愛快路由器的ACL規則

id=1 enabled=yes comment=阻止訪問路由 action=drop dir=input ctdir=0 iinterface=any ointerface=any src_addr= dst_addr= protocol=any src_port= dst_port= week=1234567 time=00:00-23:59
id=2 enabled=yes comment=限制端口映射 action=drop dir=forward ctdir=1 iinterface=any ointerface=any src_addr= dst_addr= protocol=any src_port= dst_port= week=1234567 time=00:00-23:59
id=3 enabled=yes comment=允許ICMP action=accept dir=input ctdir=0 iinterface=any ointerface=any src_addr= dst_addr= protocol=icmp src_port= dst_port= week=1234567 time=00:00-23:59
id=4 enabled=yes comment=內網要DNS來上網 action=accept dir=input ctdir=0 iinterface=any ointerface=any src_addr= dst_addr= protocol=udp src_port=53 dst_port= week=1234567 time=00:00-23:59
id=5 enabled=yes comment=可上網的內網IP action=accept dir=forward ctdir=1 iinterface=any ointerface=any src_addr=192.168.0.0-192.168.255.255 dst_addr= protocol=any src_port= dst_port= week=1234567 time=00:00-23:59
id=6 enabled=yes comment=允許管理路由器 action=accept dir=input ctdir=0 iinterface=any ointerface=any src_addr=106.111.0.0-106.111.255.255,39.172.91.235,115.218.0.0-115.218.255.255,192.168.0.0-192.168.255.255 dst_addr= protocol=any src_port= dst_port= week=1234567 time=00:00-23:59
id=7 enabled=yes comment=允許訪問端口映射 action=accept dir=forward ctdir=1 iinterface=any ointerface=any src_addr=106.111.0.0-106.111.255.255,39.172.91.235,115.218.0.0-115.218.255.255 dst_addr= protocol=any src_port= dst_port= week=1234567 time=00:00-23:59

保存成acl.txt導入策略即可


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM