了解Windows防火墙的优缺点
日期:2007年6月18日 作者: 查看:[大字体 中字体 小字体]-
Learn the pros and cons of Windows Firewall
了解Windows防火墙的优缺点《endurer注:pros and cons 正反面,优缺点,利弊》
英文来源:http://techrepublic.com.com/5100-1009_11-6063367.html?tag=nl.e101
by Michael Mullins CCNA, MCP
作者:Michael Mullins CCNA, MCP
翻译:endurer 2006-04-28 第1版
KeyWords: Security applications/tools Firewalls Security Internet
关键字:安全应用程序/工具 防火墙 安全 Internet
Takeaway:
Is Windows Firewall up to the task of securing your network? Mike Mullins has his douBTs. In this edition of Security Solutions, he delves into the details of Windows Firewall and weighs its pros and cons.
概述:Windows防火墙胜任您的网络安全任务吗?Mike Mullins有疑。在这期安全解决方法中,他深入研究Windows防火墙的细节,并权衡其优缺点。《endurer注:1。up to 一直到,等于;正在做(直到,相当于,胜任,该由...决定)
2。delve into 钻研, 深入研究》
Windows Firewall debuted with the release of Windows XP, and Windows XP Service Pack 2 enabled this feature by default. This host-based stateful firewall replaced Windows' Internet Connection Firewall.
Windows防火墙随着Windows XP的发布初次登场,Windows XP Service Pack 2默认增强了特性。该主机型运用状态(检测)防火墙替代了WindowsInternet连接防火墙。Stateful firewall 是一种新型防火墙技术,请点击参考:防火墙新生代:Stateful-inspection(http://www.bupt.edu.cn/regnet/document/network/firewall1.htm)
This feature's default configuration rejects incoming IP traffic unless you've specifically allowed it. To configure or adjust the Windows Firewall settings, go to Start Control Panel, and double-click the Windows Firewall applet. Let's take a closer look at the various settings.
这个特性的默认配置拒绝来访IP流量,除非您已经特别允许。要配置或调整Windows防火墙设置,开始-->设置-->控制面板,双击Windows防火墙程序。
Know your options
弄清选项On the General tab, you can use the On and Off radio buttons to enable or disable Windows Firewall. You can also choose to disallow exceptions.
在常规选项卡,您可以使用启用或禁用单选按钮来启用或禁用Windows防火墙。您也可以选择禁用例外。The Exceptions tab includes a list of programs and services that you can select or deselect to allow or remove Access to the network. You can also add or delete ports (both TCP and UDP).
例外选项卡包含一个程序和服务列表,您可以选定或者取消选定来允许或去掉网络访问权。你也可以添加或删除端口(TCP和UDP均可)。When adding programs or ports, you also have the following options to limit the scope of access: Any Computer (Including Those On The Internet), My Network (Subnet) Only, or Custom List, which allows you to choose a mix of IP addresses and subnets.
在添加程序或端口时,你也有下列选项来限制访问范围:一些计算机(包括Internet上),仅限我的网络(子网),或自定义序列,这个自定义序列允许您选择IP地址和子网集合。《endurer注:1。custom list 【微软】自定义序列》
On the Advanced tab, you can choose which connections the firewall will apply to, and you can specify logging features. You can also control, with some granularity, how the firewall handles Internet Control Message Protocol (ICMP) packets.
在高级选项卡,您可以选择防火墙应用到哪个连接,并能指定登录特性。您也能较精确地控制防火墙如何处理Internet控制消息协议 (ICMP)包。Finally, if you get completely lost and make changes that prevent the computer from connecting to the Internet, you can click the Restore Defaults button. This removes all of your changes, returning Windows Firewall to the Microsoft default state.
最后,如果您完全迷路并使防止计算机连接到Internet的更改,可以点击恢复默认按钮。这将清除您所做的一切修改,让Windows防火墙回复到微软默认状态。《endurer注:1。get lost 迷路》
Know how to adjust the settings
了解怎么调整设置You can use the method described above to manually change the Windows Firewall settings. However, you can also use a variety of methods more suited for enterprise deployments. Here are some of your options:
您可以用上述方法手动更改Windows防火墙设置。然而,你也可以使用多种更适合企业部署的方法。这是一些选择:- Unattend.txt: You can use this text file used during unattended setup when deploying multiple systems that have similar configurations.
Unattend.txt:在布署有相似配置的多个系统时,您可以在无人值守时使用这个文本文件 - Netfw.ini: You can modify and deploy this file via login scripts or a control system sUCh as Systems Management Server (SMS). You can find this file in the %windir%\Inf folder.
Netfw.ini: 您可以修改并通过登录脚本或诸如Windows系统配置管理解决方案(SMS)之类的控制系统来部署。您可以在%windir%\Inf找到这个文件。 - Netsh: You can execute this command at the command prompt or through a scripted batch file deployed at login.
folder.Netsh: 您可以在命令提示符,或通过布署的登录时脚本批处理文件来执行这个命令。 - Group Policy: In an Active Directory environment you can use Group Policy to deploy Windows Firewall configurations. Update existing Group Policy Objects with the Windows Firewall policy settings from the updated System.adm template included with Windows XP SP2. You can find these new settings under Computer Configuration Administrative Templates Network Network Connections.
组策略:在活动目录环境中,您可以使用组策略来布署Windows防火墙配置。利用Windows XP SP2包含的已升级的System.adm模板中的Windows防火墙策略设置来更新现存组策略对象。您可以在计算机配置-->管理模板-->网络-->网络连接里找到这些新设置。
- Unattend.txt: You can use this text file used during unattended setup when deploying multiple systems that have similar configurations.
- [1] [2] [3] 下一页
-
- 了解Windows防火墙的优缺点 相关文章:
- ·了解Windows防火墙的优缺点
- 了解Windows防火墙的优缺点 相关软件
- 特别声明:本站除部分特别声明禁止转载的专稿外的其他文章可以自由转载,但请务必注明出处和原始作
- 者.文章版权归文章原始作者所有.对于被本站转载文章的个人和网站,我们表示深深的谢意。如果本站转
- 载的文章有版权问题请联系编辑人员,我们尽快予以更正. 转载请注明来源:http://www.hackhome.com
精品推荐
热点TOP10
特别推荐
- ·怎样申请并实现有线电视上网
- ·计算机基本知识
- ·认识千兆以太网和路由交换机技术
- ·3389基础知识
- ·调制解调器错误代码一览
- ·WCDMA与TD-SCDMA终端射频测试差异性分析
- ·什么是网桥(Gate Bridge)
- ·IPC$详细介绍
- ·内网知识:无法共享文件之解决办法
- ·布线工程施工方法--配线架的打法
- ·Windows NT网络命令NET大全
- ·RPR技术原理及其应用
- ·光缆施工现场及验收的检测方法与标准
- ·TD-SCDMA远程覆盖与室内覆盖技术要点分析
- ·业务影响分析表是灾难恢复的指导纲要
- ·SIP简介,第1部分:SIP初探
- ·解读主流宽带接入技术发展
- ·什么是模式识别
- ·SIP RFCs and Drafts
- ·从海底缆的机械性能试验看光单元内铠装的必然性
