前面講過命令行創建IP安全策略(IPSEC),讓系統更安全,但是IPSEC隻能針對IP、端口、協議等進行簡單限制,而防火牆功能更強大!除了IPSEC的功能,還可以對文件、網卡等進行限制。
操作之前,需要先确定兩個東西,一個是防火牆的服務處于運行狀态:
另一個是防火牆的設置沒有被關閉:
命令操作防火牆示例例1:創建一個名稱為QQ的入站規則和出站規則,并限制它訪問網絡:
netsh advfirewall firewall add rule name="QQ" dir=in program="C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe" action=block
netsh advfirewall firewall add rule name="QQ" dir=out program="C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe" action=block
netsh advfirewall firewall add rule name="QQ" dir=in program="C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe" action=allow
netsh advfirewall firewall add rule name="QQ" dir=out program="C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe" action=allow
netsh advfirewall firewall add rule name="QQ" dir=in program="C:\Program Files (x86)\Tencent\QQ\Bin\QQ.exe" security=authenticate action=allow
netsh advfirewall firewall add rule name="網站端口" dir=out protocol=TCP remoteport=80,443 action=block
netsh advfirewall firewall set rule "網站端口" new enable=no
netsh advfirewall firewall delete rule name="網站端口"
netsh advfirewall firewall add rule name="安全防護" dir=in protocol=TCP localport=135,139,445 action=block
netsh advfirewall firewall add rule name="谷歌DNS" dir=out remoteip=8.8.8.8,8.8.4.4 action=block
限制單個IP訪問本機:
netsh advfirewall firewall add rule name="禁止訪問IP" dir=in remoteip=192.168.1.1 action=block
限制一段IP訪問本機:
netsh advfirewall firewall add rule name="禁止訪問IP" dir=in remoteip=192.168.1.1-192.168.1.100 action=block
限制一個子網訪問本機:
netsh advfirewall firewall add rule name="禁止訪問IP" dir=in remoteip=192.168.1.0/24 action=block
禁止本機ping其它機子:
ipv4:
netsh advfirewall firewall add rule name="ipv4禁Ping" dir=out protocol=icmpv4 action=block
ipv6:
netsh advfirewall firewall add rule name="ipv6禁Ping" dir=out protocol=icmpv6 action=block
禁止其它機子ping本機:
ipv4:
netsh advfirewall firewall add rule name="ipv4禁Ping" dir=in protocol=icmpv4 action=block
ipv6:
netsh advfirewall firewall add rule name="ipv6禁Ping" dir=in protocol=icmpv6 action=block
netsh advfirewall firewall add rule name="無線網絡" dir=out interfacetype=wireless action=block
運行中輸入:wf.msc 回車,可以快速打開防火牆的高級設置:
dir=in 是入站規則。其它主動訪問本機,屬于“入站”
dir=out 是出站規則。本機主動訪問其它,屬于“出站”
限制訪問的規則優先于允許訪問的規則!
,更多精彩资讯请关注tft每日頭條,我们将持续为您更新最新资讯!