Erika
2008-01-26, 11:55 AM
WinXP/2000/2003下关闭这些网络端口:
第一步,点击“开始”菜单/设置/控制面板/管理工具,双击打开“本地安全策略”,选中“IP安全策略,在本地计算机”,(或者运行gpedit.msc)在右边窗格的空白位置右击鼠标,弹出快捷菜单,选择“创建IP安全策略”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854806215.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854806215.jpg)
弹出一个向导。在向导中点击“下一步”按钮,
http://img.pconline.com.cn/images/bbs4/20081/9/1199854813545.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854813545.jpg)
为新的安全策略命名为关闭指定端口策略;再按“下一步”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854843136.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854843136.jpg)
则显示“安全通信请求”画面,在画面上把“激活默认响应规则”左边的钩去掉
http://img.pconline.com.cn/images/bbs4/20081/9/1199854864902.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854864902.jpg)
点击“完成”按钮就创建了一个新的IP安全策略。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854872207.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854872207.jpg)
在“属性”对话框中,把“使用添加向导”左边的钩去掉,然后单击“添加”按钮添加新的规则。随后弹出“新规则属性”对话框。在画面上点击“添加”按钮
http://img.pconline.com.cn/images/bbs4/20081/9/1199854891735.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854891735.jpg)
弹出IP筛选器列表窗口;把“使用添加向导”左边的钩去掉, 再点添加
http://img.pconline.com.cn/images/bbs4/20081/9/1199854900248.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854900248.jpg)
进入“筛选器属性”对话框,首先看到的是寻址,源地址选“任何IP地址”,目标地址选“我的IP地址”
http://img.pconline.com.cn/images/bbs4/20081/9/1199854910143.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854910143.jpg)
点击“协议”选项卡,在“选择协议类型”的下拉列表中选择“TCP”,然后在“到此端口”下的文本框中输入“445”,点击“确定”按钮,这样就添加了一个屏蔽TCP445(RPC)端口的筛选器,它可以防止外界通过445端口连上你的电脑。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854922038.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854922038.jpg)
点击“确定”后回到筛选器列表的对话框,可以看到已经添加了一条策略,重复以上步骤继续添加TCP137、139、445、593端口和UDP135、139、445端口,为它们建立相应的筛选器。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854932844.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854932844.jpg)
重复以上步骤添加TCP1025、2745、3127、6129、3389端口的屏蔽策略,建立好上述端口的筛选器,最后点击“确定”按钮。
返回到“新规则属性”对话框中,选择“关闭端口的筛选列表”,然后点击其左边的圆圈上加一个点,表示已经激活。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854943462.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854943462.jpg)
点击“筛选器操作”选项卡。在“筛选器操作”选项卡中,把“使用添加向导”左边的钩去掉,点击“添加”按钮。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854965968.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854965968.jpg)
在“新筛选器操作属性”的“安全措施”选项卡中,选择“阻止”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854975158.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854975158.jpg)
然后点击“确定”按钮。再点应用,之后关闭。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854987539.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854987539.jpg)
返回到箦略属性窗口,应用关闭!
http://img.pconline.com.cn/images/bbs4/20081/9/1199854997127.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854997127.jpg)
在“本地安全策略”窗口,用鼠标右击新添加的IP安全策略,然后选择“指派”。
第一步,点击“开始”菜单/设置/控制面板/管理工具,双击打开“本地安全策略”,选中“IP安全策略,在本地计算机”,(或者运行gpedit.msc)在右边窗格的空白位置右击鼠标,弹出快捷菜单,选择“创建IP安全策略”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854806215.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854806215.jpg)
弹出一个向导。在向导中点击“下一步”按钮,
http://img.pconline.com.cn/images/bbs4/20081/9/1199854813545.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854813545.jpg)
为新的安全策略命名为关闭指定端口策略;再按“下一步”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854843136.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854843136.jpg)
则显示“安全通信请求”画面,在画面上把“激活默认响应规则”左边的钩去掉
http://img.pconline.com.cn/images/bbs4/20081/9/1199854864902.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854864902.jpg)
点击“完成”按钮就创建了一个新的IP安全策略。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854872207.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854872207.jpg)
在“属性”对话框中,把“使用添加向导”左边的钩去掉,然后单击“添加”按钮添加新的规则。随后弹出“新规则属性”对话框。在画面上点击“添加”按钮
http://img.pconline.com.cn/images/bbs4/20081/9/1199854891735.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854891735.jpg)
弹出IP筛选器列表窗口;把“使用添加向导”左边的钩去掉, 再点添加
http://img.pconline.com.cn/images/bbs4/20081/9/1199854900248.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854900248.jpg)
进入“筛选器属性”对话框,首先看到的是寻址,源地址选“任何IP地址”,目标地址选“我的IP地址”
http://img.pconline.com.cn/images/bbs4/20081/9/1199854910143.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854910143.jpg)
点击“协议”选项卡,在“选择协议类型”的下拉列表中选择“TCP”,然后在“到此端口”下的文本框中输入“445”,点击“确定”按钮,这样就添加了一个屏蔽TCP445(RPC)端口的筛选器,它可以防止外界通过445端口连上你的电脑。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854922038.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854922038.jpg)
点击“确定”后回到筛选器列表的对话框,可以看到已经添加了一条策略,重复以上步骤继续添加TCP137、139、445、593端口和UDP135、139、445端口,为它们建立相应的筛选器。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854932844.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854932844.jpg)
重复以上步骤添加TCP1025、2745、3127、6129、3389端口的屏蔽策略,建立好上述端口的筛选器,最后点击“确定”按钮。
返回到“新规则属性”对话框中,选择“关闭端口的筛选列表”,然后点击其左边的圆圈上加一个点,表示已经激活。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854943462.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854943462.jpg)
点击“筛选器操作”选项卡。在“筛选器操作”选项卡中,把“使用添加向导”左边的钩去掉,点击“添加”按钮。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854965968.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854965968.jpg)
在“新筛选器操作属性”的“安全措施”选项卡中,选择“阻止”。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854975158.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854975158.jpg)
然后点击“确定”按钮。再点应用,之后关闭。
http://img.pconline.com.cn/images/bbs4/20081/9/1199854987539.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854987539.jpg)
返回到箦略属性窗口,应用关闭!
http://img.pconline.com.cn/images/bbs4/20081/9/1199854997127.jpg (http://softbbs.pconline.com.cn/viewpic.jsp?imgUrl=http%3A%2F%2Fimg.pconline.com.cn%2Fimages%2Fbbs4%2F20081%2F9%2F1199854997127.jpg)
在“本地安全策略”窗口,用鼠标右击新添加的IP安全策略,然后选择“指派”。