No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


AR Router Troubleshooting Guide

This Product Documentation provides guidance for maintaining AR Enterprise Router, covering common information collection and fault diagnostic commands, typical fault troubleshooting guide, and troubleshooting.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
How Do I Prevent Ransomware Viruses?

How Do I Prevent Ransomware Viruses?


  1. Create ACL rules for high-risk ports.

    <Huawei> system-view
    [Huawei] acl 3000
    [Huawei-acl-adv-3000] rule 5 permit tcp destination-port eq 135
    [Huawei-acl-adv-3000] rule 10 permit tcp destination-port eq 137
    [Huawei-acl-adv-3000] rule 15 permit tcp destination-port eq 139
    [Huawei-acl-adv-3000] rule 20 permit tcp destination-port eq 445
    [Huawei-acl-adv-3000] rule 25 permit udp destination-port eq 135
    [Huawei-acl-adv-3000] rule 30 permit udp destination-port eq 137
    [Huawei-acl-adv-3000] rule 35 permit udp destination-port eq 139
    [Huawei-acl-adv-3000] rule 40 permit udp destination-port eq 445
    [Huawei-acl-adv-3000] quit
  2. Create a traffic policy.

    [Huawei] traffic classifier virus operator or // Create a traffic classifier.
    [Huawei-classifier-virus] if-match acl 3000
    [Huawei-classifier-virus] quit
    [Huawei] traffic behavior virus // Create a traffic behavior and configure the deny action for packets.
    [Huawei-behavior-virus] deny
    [Huawei-behavior-virus] quit
    [Huawei] traffic policy virus // Create a traffic policy and bind the traffic classifier and traffic behavior to the traffic policy.
    [Huawei-trafficpolicy-virus] classifier virus behavior virus
    [Huawei-trafficpolicy-virus] quit
  3. Apply the traffic policy to an intranet interface.

    [Huawei] interface gigabitethernet 0/0/2
    [Huawei-GigabitEthernet0/0/2] traffic-policy virus outbound // Apply the traffic policy to the outbound direction of an intranet gateway interface.

More Information

The case of preventing ransomware viruses provides the method of disabling TCP port 445. For details, see the configuration procedure.

Updated: 2019-08-09

Document ID: EDOC1000079719

Views: 494444

Downloads: 4527

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Previous Next