firewall {
filter saynotovirus {
term udp-deny {
from {
protocol udp;
port [ 135 137 138 139 445 593 1434 1433 4444 ];
}
then {
count virus-upd-deny;
discard;
}
}
term tcp-deny {
from {
protocol tcp;
port [ 135 138 139 445 593 3333 5800 5900 ];
}
then {
count virus-tcp-deny;
discard;
}
}
term others {
then accept;
}
}
}
ge-2/3/0 {
vlan-tagging;
unit 10 {
desc
ription "ge-1/3/0.10,to-c6506-01 ge-3/1";
vlan-id 10;
family inet {
filter {
input saynotovirus;
output saynotovirus;
}
address 61.12.0.105/30;
}
}
作者:晓河流水
http://dontcry.spaces.live.com/