分类: 系统运维
2013-02-06 13:48:39
配置 NBAR |
1.定 义流量 |
en |
conf t |
class-map XXX |
match protocol edonkey |
2.定 义策略 |
policy-map XXX |
class XXX |
police 200000 2000 conform-action drop exceed-action dr |
3.应用 |
int s1/1 |
serivce-policy input/output XXX |
e.g. |
用NBAR禁止下载mp3 |
class-map mp3 |
match protocol http url "*.mp3" |
class-map exe |
match protocol http url "*.exe" |
policy-map deny-download-virus |
class mp3 |
police 2000000 conf drop ex drop |
class exe |
police 2000000 conf drop ex drop |
int e0 |
service-policy input deny-download-virus |
用NBAR禁止P2P |
class-map P2P-useage |
match protocol gnutella |
match protocol gnutella file-transfer "*" |
match protocol fasttrack |
match protocol fasttrack file-transfer "*" |
match nspster non-std |
match kazaa2 |
match protocol socks |
exit |
policy-map mark-P2P |
class P2P-usage |
set dscp 2 |
exit |
ip access-list extended block-P2P |
deny ip any any dscp 2 log |
permit ip any any |
exit |
inter e1 |
services-policy input mark-P2P |
ip access-group block-P2P out |
exit |
inter s0 |
service-policy input mark-P2P |
ip access-group block-P2P out |