win7防火墙设置的问题The problem of win7 firewall settingsThe problem of win7 firewall settings
Win7 Professional Edition
Control panel - > system and security - >Windows Firewall - >Advanced Settings
For example, to let other machines can access the port 1521 isa new rule in the inbound rules.
Select the inbound rules - "right -" new rules "- type rules(port) -"TCP or UDP, open ports, behind the wizard prompts canbe filled by. Www.2cto.com
Pay attention to the rules in a name, easy to find after thename, such as: the release of 1521.
After completing the configuration, can find a rule for thegreen effect, then you can use other machines to access thetest.
Some firewall configuration problem for reference:
In the security on the win7 than the windows XP has been greatlyimproved, we now take a look at some of the design aspects ofthe firewall in win7.
About win7 firewall.
In the setting of the win7 firewall, we need to pay attention
to these problems.
1, we must first turn off the win7 automatic restore function.Automatic reduction called intelligent win7 reduction, whensetting up a firewall for me
Is very depressed, I do not know what' s wrong. Because aftera restart when it is set to restore it. Do I think the trojan,So also uninstall the software 360. Turn off the automaticreduction of operation is as follows: click Start - controlpanel - System - system protection
Select the local disk (C:) (system) -closed. One possible UAC,you need to enter the administrator password.
2, start - enter CMD in the search programs and files in thebox, showing the presence of the cmd.exe program, right clickin the www.2cto. com administrator
If you are already running status, administrator, UAC promptsyou to yes or no, if not the administrator, you need to enterthe administrator
Password. Now at the command line. Run the secpol.msc, open thelocal security policy dialog box. Note the difference betweenwin7 and Win XP
In Win XP, the administrator account must have administratorprivileges, they are consistent. But in win7, although theadministrator account, but still
To run the program as ordinary account. From CMD can also seeif the administrator, it will display the administrator, if thegeneral body
That is not displayed. But if you take a administrator accountto run the program, you are running with administratorprivileges. This is
The difference between administrator and other administratoraccount. In the win7 administrator is disabled by default.3, navigate to the Windows firewall with advanced security.Right click the Windows firewall with advanced security - lgpo- attribute point open
The properties dialog box. For home users, the general publicdomain, special, set to the same, actually if you only use thepublic network
The network, you only need to set the public profile tab. Butfor simple, we set it as consistent. Firewall status: enabled(recommended) ;
Inbound connections: block all connections; outboundconnections: stop. We do not choose the default settings, thedefault security settings below us.
For home users, if you choose inbound connections: stop allconnections,
Your computer may not make the server will stop,
EMule, KuGoo, and many other functions of the software, if youdon' t want to be so strict, for example, you want to use remotedesktop, set for the inbound connection:
Stop (default) . We do not use the default connection out of thestation, stop using.
We conducted a simple introduction to these two.
Inbound connections if the default value, then in accordancewith the rules of the inbound connection is allowed, if set toblock all connections, so as
Where inbound connections are prohibited, even if it is notconnected to conform to the rules of the machine. So in suchcircumstances, not remote desktop
Use。
If set to allow outbound connections (default) , any program canaccess the Internet, this is not what we want, we only hopeWe allow the program to access the internet.
A good point to determine. If no accident, then any program atthis time will not be able to access the Internet. (if IE,indicating that it has been added
Into the rules of the. We would not need IE access rules. )
4 point, inbound and outbound rules can see the rules, thefollowing is empty. Because we are not allowed to access thenetwork program. The inbound rules we do not www.2cto. comWe need to set up, because the front has prevented allconnections, the design is useless.
The station is that we need to set the rules, otherwise how canwe use the Internet? Right click the station -- a new rule --Rule dialog box, select the program
Enter the systempath in this process in the next step, the nextstep, followed by set to allow the connection, in the name ofthe input "to allow system access
Network, complete. You can modify this rule we establish therules on the right side of the box. Wedo not need tobemodifiedfor system. Note that if you are in a time when the InternetYour network of a private network, you need special tick ratherthan the public. After this rule configuration is good, the restis similar.
We need to build three rules, to lay a good foundation for theinternet. The other two rules are as follows:
Name: DNS (1) allows programs and services; - thisprogram:%SystemRoot%\System32\svchost.exe; protocol and port- protocol type: UDP
Local port: 1024-65535, remote port: 53; senior public.
(2) Name: allow back; procedures and service: all meet thespecified conditions and procedures; protocol port andprotocol type: ICMPv4; senior public.
And in front of that allow system to access the network, a totalof three. Well, this phase is complete.
5 point control panel --windows firewall --windows advancedsettings, UAC control dialog box, asking you to confirm whetheror not to continue, if not the administrator
Ask you to enter the administrator password. Open the advancedwindows security firewall on the local computer, the inboundconnections, outbound connections, and we
In the Group Policy under the same setting, same. The three ruleis set in front of the US, this can not be changed. groupThe strategy is set higher than the setting.
We have derived the rules here saved in a file for laterretrieval, if you understand, don
Do not need to recover, here is just in case you made a mistakeof reduction. Then delete delete (or to ban are forbidden, donot need to
Derived) . Of course we are located in front of the three is notdeleted. Point out of the stationrule, anewrule is as follows
Name: "IE is allowed access to the Internet" programs andservices:%ProgramFi les%\Internet; Explorer\iexplore.exe;protocol and port, protocol type: TCP, 1024-65535, remote portlocal port: 80; senior public.
The open IE, you can see, the internet.
The other is similar, so, only after we allow the program toaccess a network.
QQ setting: www. 2cto.com
Name: QQ is allowed access to the Internet; protocol and port- protocol type: UDP, remote port: 8000, senior public.If you QQ were set up as above will be landing in the port numberQQ landing interface named QQ. If you do not specify a remoteport number, do not have.
If you're not sure for a program with arbitrary port number.Use the port number after some more stringent restrictions.From our previous settings can be seen, only system is open.The svchost.exe port is open, and it only
Andremote port 53 communication is essentially closed. Becausethe horse is not possible with the remote port 53 communication.In the group policy setting, I'm not sure whether to open system.When I first most, if not open, if not like the internet.
And now I don't have this rule as it can. The remaining two isto open. You can't get on the internet.
小渣云 做那个你想都不敢想的套餐 你现在也许不知道小渣云 不过未来你将被小渣云的产品所吸引小渣云 专注于一个套餐的商家 把性价比 稳定性 以及价格做到极致的商家,也许你不相信36元在别人家1核1G都买不到的价格在小渣云却可以买到 8核8G 高配云服务器,并且在安全性 稳定性 都是极高的标准。小渣云 目前使用的是美国超级稳定的ceranetworks机房 数据安全上 每5天备份一次数据倒异地 支持一...
LetBox此次促销依然是AMD Ryzen处理器+NVME硬盘+HDD大硬盘,以前是5TB月流量,现在免费升级到10TB月流量。另外还有返余额的活动,如果月付,月付多少返多少;如果季付或者半年付,返25%;如果年付,返10%。依然全部KVM虚拟化,可自定义ISO系统。需要大硬盘vps、大流量vps、便宜AMD VPS的朋友不要错过了。不过LetBox对帐号审核严格,最好注册邮箱和paypal帐号...
Vultr 商家有新增韩国首尔机房,这个是继日本、新加坡之后的第三个亚洲机房。不过可以大概率知道肯定不是直连中国机房的,因为早期的日本机房有过直连后来取消的。今天准备体验看看VULTR VPS主机商的韩国首尔机房的云服务器的速度和性能。1、全球节点PING速度测试这里先通过PING测试工具看看全球几十个节点的PING速度。看到好像移动速度还不错。2、路由去程测试测试看看VULTR韩国首尔机房的节点...