華三接入交換機埠部分安全措施
1.通過ACL封禁高危埠及按需放通訪問內容
可在埠下呼叫ACL或者在埠對應vlan的三層口下呼叫ACL
#
acl number 3200
rule 210 deny tcp destination-port eq 135
rule 220 deny tcp destination-port eq 137
rule 230 deny tcp destination-port eq 138
rule 240 deny tcp destination-port eq 139
rule 250 deny tcp destination-port eq 445
rule 260 deny udp destination-port eq 135
rule 270 deny udp destination-port eq netbios-ns
rule 280 deny udp destination-port eq netbios-dgm
rule 290 deny udp destination-port eq netbios-ssn
rule 300 deny udp destination-port eq 445
rule 400 permit ip source 192.168.10.0 0.0.0.255 destination 192.168.20.0 0.0.0.255
rule 1000 deny tcp
rule 2000 deny udp
#
2.埠下繫結IP地址和MAC地址,防止非法使用者接入
#
ip verify source ip-address mac-address
ip source binding ip-address 192.168.1.1 mac-address 0021-5236-3250
#
3.埠下開啟廣播和組播風暴抑制功能,本例限制的是每秒允許轉發的最大廣播包數
#
broadcast-suppression pps 6400
multicast-suppression pps 6400
#
4.若交換機開啟STP,埠下將埠設定為邊緣埠並開啟BPDU保護
#
stp edged-port enable
stp port bpdu-protection enable
#