您的位置: 飞扬精品软件园 >> 文章中心 >> 系统教程 >> Win 系统 >> Windows server 2003设置IP安全策略批处理脚本

相关文章链接

最新新闻资讯

    Windows server 2003设置IP安全策略批处理脚本

    Windows server 2003设置IP安全策略批处理脚本


    • 阅览次数: 文章来源: 原文作者: 整理日期: 2010-05-22

    本文介绍了通过命令行脚本添加ipsec安全策略,方便快捷的实现系统自带的防火墙功能。

    REM =================开始================
    netsh ipsec static ^
    add policy name=bim

    REM 添加2个动作,block和permit
    netsh ipsec static ^
    add filteraction name=Permit action=permit
    netsh ipsec static ^
    add filteraction name=Block action=block

    REM 首先禁止所有访问
    netsh ipsec static ^
    add filterlist name=AllAccess
    netsh ipsec static ^
    add filter filterlist=AllAccess srcaddr=Me dstaddr=Any
    netsh ipsec static ^
    add rule name=BlockAllAccess policy=bim filterlist=AllAccess filteraction=Block

    REM 开放某些IP无限制访问
    netsh ipsec static ^
    add filterlist name=UnLimitedIP
    netsh ipsec static ^
    add filter filterlist=UnLimitedIP srcaddr=61.128.128.67 dstaddr=Me
    netsh ipsec static ^
    add rule name=AllowUnLimitedIP policy=bim filterlist=UnLimitedIP filteraction=Permit

    REM 开放某些端口
    netsh ipsec static ^
    add filterlist name=OpenSomePort
    netsh ipsec static ^
    add filter filterlist=OpenSomePort srcaddr=Any dstaddr=Me dstport=20 protocol=TCP
    netsh ipsec static ^
    add filter filterlist=OpenSomePort srcaddr=Any dstaddr=Me dstport=21 protocol=TCP
    netsh ipsec static ^
    add filter filterlist=OpenSomePort srcaddr=Any dstaddr=Me dstport=80 protocol=TCP
    netsh ipsec static ^
    add filter filterlist=OpenSomePort srcaddr=Any dstaddr=Me dstport=3389 protocol=TCP
    netsh ipsec static ^
    add rule name=AllowOpenSomePort policy=bim filterlist=OpenSomePort filteraction=Permit

    REM 开放某些ip可以访问某些端口
    netsh ipsec static ^
    add filterlist name=SomeIPSomePort
    netsh ipsec static ^
    add filter filterlist=SomeIPSomePort srcaddr=Me dstaddr=Any dstport=80 protocol=TCP
    netsh ipsec static ^
    add filter filterlist=SomeIPSomePort srcaddr=61.128.128.68 dstaddr=Me dstport=1433 protocol=TCP
    netsh ipsec static ^
    add rule name=AllowSomeIPSomePort policy=bim filterlist=SomeIPSomePort filteraction=Permit


查看所有评论

网友对Windows server 2003设置IP安全策略批处理脚本的评论

网名:
主题:
内容:
验证码: