一个最典型的Anti-CodeRed设置

来源: 作者: 2006-10-30 出处:pcdog.com

access  iis  ios  

  这是应用在一台2600,IOS12.0以上的
  class-map match-any iissucks
  match protocol http url "*cmd.exe*"
  match protocol http url "*.ida*"
  match protocol http url "*root.exe*"
  match protocol http url "*mem_bin*"
  match protocol http url "*vti_bin*"
  match protocol http url "*msadc*"
  match protocol http url "*winnt*"
  !
  !
  policy-map mark-http-crap
  class iissucks
  set ip dscp 1
  
  access-list 131 deny ip any any dscp 1 log
  access-list 131 permit ip any any
  
  Outside interface:
  service-policy input mark-http-crap
  
  Inside interface:
  ip access-group 131 out

上一篇:CiscoIPSoftphone1.3.4a安装指南
下一篇:企业网新业务的支撑技术