No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

AR Router Troubleshooting Guide

This Product Documentation provides guidance for maintaining AR Enterprise Router, covering common information collection and fault diagnostic commands, typical fault troubleshooting guide, and troubleshooting.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
How Do I Disable an Interface Prone to Be Attacked?

How Do I Disable an Interface Prone to Be Attacked?

Huawei enterprise AR routers forbid the use of ports 135, 137, 139, and 445 to prevent risks. Before the configuration, you need to check whether services are running on these ports to avoid service interruption. The configurations are as follows:

# Create ACL rules for high-risk ports.

<Huawei> system-view
[Huawei] acl number 3000
[Huawei-acl-adv-3000] rule 5 permit tcp  destination-port eq  135
[Huawei-acl-adv-3000] rule 10 permit tcp  destination-port eq  137
[Huawei-acl-adv-3000] rule 15 permit tcp  destination-port eq  139
[Huawei-acl-adv-3000] rule 20 permit tcp  destination-port eq  445
[Huawei-acl-adv-3000] rule 25 permit udp  destination-port eq  135
[Huawei-acl-adv-3000] rule 30 permit udp  destination-port eq  137
[Huawei-acl-adv-3000] rule 35 permit udp  destination-port eq  139
[Huawei-acl-adv-3000] rule 40 permit udp  destination-port eq  445
[Huawei-acl-adv-3000] quit

# Create a traffic policy.

[Huawei] traffic classifier virus operator or
[Huawei-classifier-virus] if-match acl 3000
[Huawei-classifier-virus] quit
[Huawei] traffic behavior virus
[Huawei-behavior-virus] deny
[Huawei-behavior-virus] quit
[Huawei] traffic policy virus
[Huawei-trafficpolicy-virus] classifier virus behavior virus
[Huawei-trafficpolicy-virus] quit

# Apply the traffic policy on an interface of the private gateway. For example, the interface of the private gateway is VLANIF10. If the private network uses physical interfaces, apply the traffic policy on the corresponding physical interface. If multiple interfaces are used, apply the traffic policy on these interfaces one by one.

[Huawei] interface vlanif 10
[Huawei-Vlanif10] traffic-policy virus inbound
Translation
Download
Updated: 2019-05-10

Document ID: EDOC1000079719

Views: 453576

Downloads: 4311

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next