Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
Опять же внутренняя локальная сеть способствует распространению вирусов
да и о паразитном траффике завирусованных клиентов не стоит забывать.
A lower profile_id gives the rule a higher priority. In case of a
conflict in the rules entered for different profiles, the rule with the highest priority (lowest profile_id) will take precedence.
## CPU Filter
delete cpu access_profile profile_id 1
## — Deny Multicast traffic
create cpu access_profile profile_id 1 ip destination_ip_mask 240.0.0.0
config cpu access_profile profile_id 1 add access_id 1 ip destination_ip 224.0.0.0 port 1-28 deny
enable cpu_interface_filtering
## ACL
delete access_profile all
## — Deny clients with BRAS MAC's
create access_profile ethernet source_mac FF-FF-FF-FF-FF-00 profile_id 1
config access_profile profile_id 1 add access_id auto_assign ethernet source_mac 00-18-82-AD-34-00 port 1-24 deny
## — Deny fake PPPoE Servers on clients ports
## — PPPoE Discovery (0x8863) + Active Discovery Offer (PADO) (0x07)
create access_profile packet_content_mask offset_0-15 0x0 0x0 0x0 0xffff00ff profile_id 2
config access_profile profile_id 2 add access_id auto_assign packet_content offset 12 0x88630007 port 1-24 deny
## — Deny PPPoE Session (0x8864) + Protocol IP (0x0021),
## — Version 4 + Destination port 135,137,138,139,445
create access_profile packet_content_mask offset_0-15 0x0 0x0 0x0 0xffff0000 offset_16-31 0x0 0xfffff000 0x0 0x0 offset_32-47 0x0 0x0 0x0 0xffff0000 profile_id 3
config access_profile profile_id 3 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 44 0x00870000 port 1-28 deny
config access_profile profile_id 3 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 44 0x00890000 port 1-28 deny
config access_profile profile_id 3 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 44 0x008a0000 port 1-28 deny
config access_profile profile_id 3 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 44 0x008b0000 port 1-28 deny
config access_profile profile_id 3 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 44 0x01bd0000 port 1-28 deny
## — Deny PPPoE Session (0x8864) + Protocol IP (0x0021), Version 4 + Protocol: TCP (0x06), UDP (0x11) +
## — Destination port TCP/53, UDP/67, UDP/1900, TCP/2869
create access_profile packet_content_mask offset_0-15 0x0 0x0 0x0 0xffff0000 offset_16-31 0x0 0xfffff000 0x00000000 0x000000ff offset_32-47 0x0 0x0 0x0 0xffff0000 profile_id 4
config access_profile profile_id 4 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 28 0x00000006 offset 44 0x00350000 port 1-28 deny
config access_profile profile_id 4 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 28 0x00000011 offset 44 0x00430000 port 1-28 deny
config access_profile profile_id 4 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 28 0x00000011 offset 44 0x076c0000 port 1-28 deny
config access_profile profile_id 4 add access_id auto_assign packet_content offset 12 0x88640000 offset 20 0x00214000 offset 28 0x00000006 offset 44 0x0b350000 port 1-28 deny
## — Permit EtherType PPPoE Discovery (0x8863), PPPoE Session (0x8864)
create access_profile ethernet ethernet_type profile_id 5
config access_profile profile_id 5 add access_id auto_assign ethernet ethernet_type 0x8863 port 1-28 permit
config access_profile profile_id 5 add access_id auto_assign ethernet ethernet_type 0x8864 port 1-28 permit
## — Deny broadcasts
create access_profile ethernet destination_mac ff-ff-ff-ff-ff-ff profile_id 6
config access_profile profile_id 6 add access_id auto_assign ethernet destination_mac ff-ff-ff-ff-ff-ff port 1-24 deny
## — Deny IPv6 EtherType
create access_profile ethernet ethernet_type profile_id 7
config access_profile profile_id 7 add access_id auto_assign ethernet ethernet_type 0x86dd port 1-28 deny
## — Deny all
create access_profile ethernet source_mac 00-00-00-00-00-00 profile_id 8
config access_profile profile_id 8 add access_id auto_assign ethernet source_mac 00-00-00-00-00-00 port 1-24 deny
## — Other
config traffic control 1-24 broadcast enable multicast enable unicast disable action drop threshold 64 countdown 0 time_interval 5
config filter dhcp_server ports 1-24 state enable
config traffic_segmentation 1-24 forward_list 25-28
enable flood_fdb

Настройка свитчей уровня доступа в сети провайдера