楼主: 柯林
收起左侧

[其他相关] 【补充额外意见】三五分钟搞定一个普通用户的基本应用设置

  [复制链接]
w99308702
发表于 2012-12-22 11:25:11 | 显示全部楼层
我第一次设置防火墙,但是看懂啊卡饭上有这些端口设置
综合以上防火墙所拦截端口:
怎么单独设置传入和传出啊
禁止TCP本地端口传入,协议:TCP,方向:传入,本地端口:
0,22,23,25,31,41,58,79,80,107,110,111,113,119,121,135,137,138,139,143,146,311,443,445,513,531,544,548,555,556,666,911,999,1001,1010,1011,1012,1015,1024,1025,1026,1027,1028,1029,1030,1042,1045,1057,1090,1095,1097,1098,1099,1234,1243,1245,1345,1349,1492,1524,1600,1807,1831,1981,1999,2000,2001,2002,2003,2004,2005,2023,2115,2140,2565,2583,2773,2774,2801,3024,3129,3150,3389.3700,4092,4267,4567,4590,4899,5000,5001,5168,5321,5333,5400,5401,5402,5550,5554,5555,5556,5557,5569,5742,6400,6670,6711,6771,6776,6939,6969,6970,7000,7215,7300,7301,7306,7307,7308,7597,7626,7789,9408,9535,9872,9873,9874,9875,9898,9989,10067,10167,10168,10520,10607,11000,11223,12076,12223,12345,12346,12361,12362,12363,12631,13000,14500,14501,14502,14503,15000,15382,16484,16772,16969,17072,17166,19191,19864,20001,20002,20023,20034,21544,22222,23005,23006,23023,23032,23456,23476,23477,25685,25686,25982,26274,27374,29104,30001,30003,30029,30100,30101,30102,30103,30133,30947,31337,31338,31339,31666,31785,31787,31788,31789,31791,31792,32100,32418,33333,33577,33777,33911,34342,34555,35555,40421,40422,40423,40424,40425,40426,41337,41666,47262,49301,50130,50505,50766,51996,53001,54283,54320,54321,55165,57341,58339,60000,60411,61348,61466,61603,63485,65390,65432,65535

禁止UDP本地端口传入,协议:UDP,方向:传入,本地端口:0,31,41,53,67,111,135,137,138,139,146,161,445,666,999,1027,1042,1561,1900,2140,2989,3129,3150,3700,4006,5168,6670,6771,8225,9872,9873,9874,9875,10067,10167,22226,26274,27374,31337,31785,31787,31788,31789,31791,31792,34555,40421,40422,40423,40425,40426,47262,54320,54321,60000

禁止TCP本地端口传出,协议:TCP,方向:传出,本地端口:0,22,23,31,41,58,59,107,111,121,146,137,138,139,146,311,445,531,544,548,555,556,666,911,999,1001,1010,1011,1012,1015,1024,1025,1026,1027,1028,1029,1030,1042,1045,1057,1090,1095,1097,1098,1099,1234,1243,1245,1345,1349,1492,1524,1600,1807,1831,1981,1999,2000,2001,2002,2003,2004,2005,2023,2115,2140,2565,2583,2773,2774,2801,3024,3129,3150,3389,3700,4092,4267,4567,4590,4899,5000,5001,5168,5321,5333,5400,5401,5402,5550,5554,5555,5556,5557,5569,5742,6400,6670,6711,6771,6776,6939,6969,6970,7000,7215,7300,7301,7306,7307,7308,7597,7626,7789,9408,9535,9872,9873,9874,9875,9898,9989,10067,10167,10168,10520,10607,11000,11223,12076,12223,12345,12346,12361,12362,12363,12631,13000,14500,14501,14502,14503,15000,15382,16484,16772,16969,17072,17166,19191,19864,20001,20002,20023,20034,21544,22222,23005,23006,23023,23032,23456,23476,23477,25685,25686,25982,26274,27374,29104,30001,30003,30029,30100,30101,30102,30103,30133,30947,31337,31338,31339,31666,31785,31787,31788,31789,31791,31792,32100,32418,33333,33577,33777,33911,34342,34555,35555,40421,40422,40423,40424,40425,40426,41337,41666,47262,49301,50130,50505,50766,51996,53001,54283,54320,54321,55165,57341,58339,60000,60411,61348,61466,61603,63485,65390,65432,65535

禁止UDP本地端口传出,协议:UDP,方向:传出,本地端口:0,31,41,68,135,137,138,139,146,445,666,999,1027,1042,1561,2140,2989,3129,3150,3700,4006,5168,6670,6771,8225,9872,9873,9874,9875,10067,10167,22226,26274,27374,31337,31785,31787,31788,31789,31791,31792,34555,40421,40422,40423,40425,40426,47262,54320,54321,60000
w99308702
发表于 2012-12-22 11:26:59 | 显示全部楼层
柯林 发表于 2012-12-22 11:14
1就是只允许连出 禁止连入
2是如果你用p2p软件,就允许这些软件开放的端口连入,其他的禁止连入,当p2p软 ...

比如迅雷,那我怎么知道迅雷的端口呢??下载完毕怎么阻止他的端口啊
柯林
 楼主| 发表于 2012-12-22 11:28:32 | 显示全部楼层
w99308702 发表于 2012-12-22 11:21
hips要不要开启,怎么设置啊
还有沙箱怎么设置啊

hips看你的需要,要救开启,个人建议开启——隐私文件保护这些需要用到。
设置:

沙箱一般不用设置,除非你要强制把某些程序运行在里面,或者对某些文件或注册表的操作不入沙。

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
柯林
 楼主| 发表于 2012-12-22 11:30:25 | 显示全部楼层
w99308702 发表于 2012-12-22 11:26
比如迅雷,那我怎么知道迅雷的端口呢??下载完毕怎么阻止他的端口啊

不用你操心,毛豆自动检测和处理。
柯林
 楼主| 发表于 2012-12-22 11:33:52 | 显示全部楼层
w99308702 发表于 2012-12-22 11:25
我第一次设置防火墙,但是看懂啊卡饭上有这些端口设置
综合以上防火墙所拦截端口:
怎么单独设置传入和传 ...

毫无必要 那是没有状态检测的墙 才需要人为添加硬性阻止  
这里提倡添加的阻止135 137 139等端口,是因为系统默认启用了相关服务,这些端口是处于打开状态的,而我们很难关闭这些服务,可以用防火墙阻止的方法来切断网络而不必禁用服务。
w99308702
发表于 2012-12-22 11:33:55 | 显示全部楼层
柯林 发表于 2012-12-22 11:28
hips看你的需要,要救开启,个人建议开启——隐私文件保护这些需要用到。
设置:

已经设置好文件夹保护了,谢谢,很有成就感,以前我用麦咖啡企业版设置防读写删的,哈哈现在也会用毛豆设置隐私区域了
w99308702
发表于 2012-12-22 11:36:21 | 显示全部楼层
柯林 发表于 2012-12-22 11:33
毫无必要 那是没有状态检测的墙 才需要人为添加硬性阻止  
这里提倡添加的阻止135 137 139等端口,是因为 ...

我看到你UDP 没有阻止139??我刚才是按你的图片设置的端口
88865ff
发表于 2012-12-22 11:47:19 | 显示全部楼层
为什么我的V6行为防御里没有完全虚拟化?
yejian9237
发表于 2012-12-22 11:49:55 | 显示全部楼层
88865ff 发表于 2012-12-22 11:47
为什么我的V6行为防御里没有完全虚拟化?

论坛有帖子,要添加一个注册表

评分

参与人数 1人气 +1 收起 理由
柯林 + 1 感谢解答: )

查看全部评分

w99308702
发表于 2012-12-22 12:05:08 | 显示全部楼层
Comodo Dragon虚拟桌面要设置什么不?我想把不安全的软件运行到里面去
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-20 10:38 , Processed in 0.124177 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表