我需要找到一种方法来强化我的网络,以便所有瞻博网络路由器拒绝 Web 管理和任何专门针对它们的 http / https 流量。
到目前为止,这是我想出的:
edit
delete system services web-management
edit firewall family inet filter local_web_filter
set term block_web from destination-address 127.0.0.1/32
set term block_web from port http
set term block_web from port https
set term block_web then log
set term block_web then reject tcp-reset
set term default-term then accept
set interfaces lo0 unit 0 family inet filter input local_web_filter
set interfaces lo0 unit 0 family inet address 127.0.0.1/32
commit
write memory
我几乎没有配置瞻博网络路由器的经验,因此非常感谢任何帮助。