PDA

查看完整版本 : windows下关闭不用的端口,防止黑客攻击.禁QQ禁网页后邮件照发


Erika
2008-01-26, 11:55 AM
WinXP/2000/2003下关闭这些网络端口:
第一步,点击“开始”菜单/设置/控制面板/管理工具,双击打开“本地安全策略”,选中“IP安全策略,在本地计算机”,(或者运行gpedit.msc)在右边窗格的空白位置右击鼠标,弹出快捷菜单,选择“创建IP安全策略”。

http://img.pconline.com.cn/images/bbs4/20081/9/1199854806215.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854806215.jpg)



弹出一个向导。在向导中点击“下一步”按钮,

http://img.pconline.com.cn/images/bbs4/20081/9/1199854813545.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854813545.jpg)

为新的安全策略命名为关闭指定端口策略;再按“下一步”。

http://img.pconline.com.cn/images/bbs4/20081/9/1199854843136.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854843136.jpg)







则显示“安全通信请求”画面,在画面上把“激活默认响应规则”左边的钩去掉

http://img.pconline.com.cn/images/bbs4/20081/9/1199854864902.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854864902.jpg)



点击“完成”按钮就创建了一个新的IP安全策略。


http://img.pconline.com.cn/images/bbs4/20081/9/1199854872207.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854872207.jpg)




在“属性”对话框中,把“使用添加向导”左边的钩去掉,然后单击“添加”按钮添加新的规则。随后弹出“新规则属性”对话框。在画面上点击“添加”按钮

http://img.pconline.com.cn/images/bbs4/20081/9/1199854891735.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854891735.jpg)



弹出IP筛选器列表窗口;把“使用添加向导”左边的钩去掉, 再点添加

http://img.pconline.com.cn/images/bbs4/20081/9/1199854900248.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854900248.jpg)



进入“筛选器属性”对话框,首先看到的是寻址,源地址选“任何IP地址”,目标地址选“我的IP地址”

http://img.pconline.com.cn/images/bbs4/20081/9/1199854910143.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854910143.jpg)



点击“协议”选项卡,在“选择协议类型”的下拉列表中选择“TCP”,然后在“到此端口”下的文本框中输入“445”,点击“确定”按钮,这样就添加了一个屏蔽TCP445(RPC)端口的筛选器,它可以防止外界通过445端口连上你的电脑。

http://img.pconline.com.cn/images/bbs4/20081/9/1199854922038.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854922038.jpg)


点击“确定”后回到筛选器列表的对话框,可以看到已经添加了一条策略,重复以上步骤继续添加TCP137、139、445、593端口和UDP135、139、445端口,为它们建立相应的筛选器。

http://img.pconline.com.cn/images/bbs4/20081/9/1199854932844.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854932844.jpg)


重复以上步骤添加TCP1025、2745、3127、6129、3389端口的屏蔽策略,建立好上述端口的筛选器,最后点击“确定”按钮。
返回到“新规则属性”对话框中,选择“关闭端口的筛选列表”,然后点击其左边的圆圈上加一个点,表示已经激活。

http://img.pconline.com.cn/images/bbs4/20081/9/1199854943462.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854943462.jpg)



点击“筛选器操作”选项卡。在“筛选器操作”选项卡中,把“使用添加向导”左边的钩去掉,点击“添加”按钮。

http://img.pconline.com.cn/images/bbs4/20081/9/1199854965968.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854965968.jpg)



在“新筛选器操作属性”的“安全措施”选项卡中,选择“阻止”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854975158.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854975158.jpg)



然后点击“确定”按钮。再点应用,之后关闭。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854987539.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854987539.jpg)



返回到箦略属性窗口,应用关闭!

http://img.pconline.com.cn/images/bbs4/20081/9/1199854997127.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854997127.jpg)


在“本地安全策略”窗口,用鼠标右击新添加的IP安全策略,然后选择“指派”。

Erika
2008-01-26, 11:56 AM
http://img.pconline.com.cn/images/bbs4/20081/9/1199855006663.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199855006663.jpg)


于是重新启动后,电脑中上述网络端口就被关闭了,病毒和黑客再也不能连上这些端口,从而保护了你的电脑。