防火墙win7防火墙设置的问题(The problem of win7 firewall settings)

win7防火墙设置  时间:2021-02-28  阅读:()

win7防火墙设置的问题The problem of win7 firewall settingsThe problem of win7 firewall settings

Win7 Professional Edition

Control panel - > system and security - >Windows Firewall - >Advanced Settings

For example, to let other machines can access the port 1521 isa new rule in the inbound rules.

Select the inbound rules - "right -" new rules "- type rules(port) -"TCP or UDP, open ports, behind the wizard prompts canbe filled by. Www.2cto.com

Pay attention to the rules in a name, easy to find after thename, such as: the release of 1521.

After completing the configuration, can find a rule for thegreen effect, then you can use other machines to access thetest.

Some firewall configuration problem for reference:

In the security on the win7 than the windows XP has been greatlyimproved, we now take a look at some of the design aspects ofthe firewall in win7.

About win7 firewall.

In the setting of the win7 firewall, we need to pay attention

to these problems.

1, we must first turn off the win7 automatic restore function.Automatic reduction called intelligent win7 reduction, whensetting up a firewall for me

Is very depressed, I do not know what' s wrong. Because aftera restart when it is set to restore it. Do I think the trojan,So also uninstall the software 360. Turn off the automaticreduction of operation is as follows: click Start - controlpanel - System - system protection

Select the local disk (C:) (system) -closed. One possible UAC,you need to enter the administrator password.

2, start - enter CMD in the search programs and files in thebox, showing the presence of the cmd.exe program, right clickin the www.2cto. com administrator

If you are already running status, administrator, UAC promptsyou to yes or no, if not the administrator, you need to enterthe administrator

Password. Now at the command line. Run the secpol.msc, open thelocal security policy dialog box. Note the difference betweenwin7 and Win XP

In Win XP, the administrator account must have administratorprivileges, they are consistent. But in win7, although theadministrator account, but still

To run the program as ordinary account. From CMD can also seeif the administrator, it will display the administrator, if thegeneral body

That is not displayed. But if you take a administrator accountto run the program, you are running with administratorprivileges. This is

The difference between administrator and other administratoraccount. In the win7 administrator is disabled by default.3, navigate to the Windows firewall with advanced security.Right click the Windows firewall with advanced security - lgpo- attribute point open

The properties dialog box. For home users, the general publicdomain, special, set to the same, actually if you only use thepublic network

The network, you only need to set the public profile tab. Butfor simple, we set it as consistent. Firewall status: enabled(recommended) ;

Inbound connections: block all connections; outboundconnections: stop. We do not choose the default settings, thedefault security settings below us.

For home users, if you choose inbound connections: stop allconnections,

Your computer may not make the server will stop,

EMule, KuGoo, and many other functions of the software, if youdon' t want to be so strict, for example, you want to use remotedesktop, set for the inbound connection:

Stop (default) . We do not use the default connection out of thestation, stop using.

We conducted a simple introduction to these two.

Inbound connections if the default value, then in accordancewith the rules of the inbound connection is allowed, if set toblock all connections, so as

Where inbound connections are prohibited, even if it is notconnected to conform to the rules of the machine. So in suchcircumstances, not remote desktop

Use。

If set to allow outbound connections (default) , any program canaccess the Internet, this is not what we want, we only hopeWe allow the program to access the internet.

A good point to determine. If no accident, then any program atthis time will not be able to access the Internet. (if IE,indicating that it has been added

Into the rules of the. We would not need IE access rules. )

4 point, inbound and outbound rules can see the rules, thefollowing is empty. Because we are not allowed to access thenetwork program. The inbound rules we do not www.2cto. comWe need to set up, because the front has prevented allconnections, the design is useless.

The station is that we need to set the rules, otherwise how canwe use the Internet? Right click the station -- a new rule --Rule dialog box, select the program

Enter the systempath in this process in the next step, the nextstep, followed by set to allow the connection, in the name ofthe input "to allow system access

Network, complete. You can modify this rule we establish therules on the right side of the box. Wedo not need tobemodifiedfor system. Note that if you are in a time when the InternetYour network of a private network, you need special tick ratherthan the public. After this rule configuration is good, the restis similar.

We need to build three rules, to lay a good foundation for theinternet. The other two rules are as follows:

Name: DNS (1) allows programs and services; - thisprogram:%SystemRoot%\System32\svchost.exe; protocol and port- protocol type: UDP

Local port: 1024-65535, remote port: 53; senior public.

(2) Name: allow back; procedures and service: all meet thespecified conditions and procedures; protocol port andprotocol type: ICMPv4; senior public.

And in front of that allow system to access the network, a totalof three. Well, this phase is complete.

5 point control panel --windows firewall --windows advancedsettings, UAC control dialog box, asking you to confirm whetheror not to continue, if not the administrator

Ask you to enter the administrator password. Open the advancedwindows security firewall on the local computer, the inboundconnections, outbound connections, and we

In the Group Policy under the same setting, same. The three ruleis set in front of the US, this can not be changed. groupThe strategy is set higher than the setting.

We have derived the rules here saved in a file for laterretrieval, if you understand, don

Do not need to recover, here is just in case you made a mistakeof reduction. Then delete delete (or to ban are forbidden, donot need to

Derived) . Of course we are located in front of the three is notdeleted. Point out of the stationrule, anewrule is as follows

Name: "IE is allowed access to the Internet" programs andservices:%ProgramFi les%\Internet; Explorer\iexplore.exe;protocol and port, protocol type: TCP, 1024-65535, remote portlocal port: 80; senior public.

The open IE, you can see, the internet.

The other is similar, so, only after we allow the program toaccess a network.

QQ setting: www. 2cto.com

Name: QQ is allowed access to the Internet; protocol and port- protocol type: UDP, remote port: 8000, senior public.If you QQ were set up as above will be landing in the port numberQQ landing interface named QQ. If you do not specify a remoteport number, do not have.

If you're not sure for a program with arbitrary port number.Use the port number after some more stringent restrictions.From our previous settings can be seen, only system is open.The svchost.exe port is open, and it only

Andremote port 53 communication is essentially closed. Becausethe horse is not possible with the remote port 53 communication.In the group policy setting, I'm not sure whether to open system.When I first most, if not open, if not like the internet.

And now I don't have this rule as it can. The remaining two isto open. You can't get on the internet.

简单测评v5.net的美国cn2云服务器:电信双程cn2+联通AS9929+移动直连

v5.net一直做独立服务器这块儿的,自从推出云服务器(VPS)以来站长一直还没有关注过,在网友的提醒下弄了个6G内存、2核、100G SSD的美国云服务器来写测评,主机测评给大家趟雷,让你知道v5.net的美国云服务器效果怎么样。本次测评数据仅供参考,有兴趣的还是亲自测试吧! 官方网站:https://v5.net/cloud.html 从显示来看CPU是e5-2660(2.2GHz主频),...

无忧云:服务器100G高防云服务器,bgpBGP云,洛阳BGP云服务器2核2G仅38.4元/月起

无忧云怎么样?无忧云值不值得购买?无忧云,无忧云是一家成立于2017年的老牌商家旗下的服务器销售品牌,现由深圳市云上无忧网络科技有限公司运营,是正规持证IDC/ISP/IRCS商家,主要销售国内、中国香港、国外服务器产品,线路有腾讯云国外线路、自营香港CN2线路等,都是中国大陆直连线路,非常适合免备案建站业务需求和各种负载较高的项目,同时国内服务器也有多个BGP以及高防节点。目前,四川雅安机房,4...

HostYun 新增可选洛杉矶/日本机房 全场9折月付19.8元起

关于HostYun主机商在之前也有几次分享,这个前身是我们可能熟悉的小众的HostShare商家,主要就是提供廉价主机,那时候官方还声称选择这个品牌的机器不要用于正式生产项目,如今这个品牌重新转变成Hostyun。目前提供的VPS主机包括KVM和XEN架构,数据中心可选日本、韩国、香港和美国的多个地区机房,电信双程CN2 GIA线路,香港和日本机房,均为国内直连线路,访问质量不错。今天和大家分享下...

win7防火墙设置为你推荐
雅特士西安法士特主要是生产什么?公司是什么样的?站长故事科学家的故事200字flash导航条如何制作flash导航条工信部备案怎样在工信部进行域名备案?要详细显卡温度多少正常显卡温度多少正常数码资源网手机练习打字的软件童之磊华硕的四核平板电脑,怎么样?godaddygodaddy域名怎样使用淘宝网页显示不正常淘宝网显示不正常ios系统iOS系统是什么
vps侦探 鲁诺vps 香港ufo wavecom 优惠码 gomezpeer godaddy支付宝 网站实时监控 免费网络电视 商家促销 彩虹ip 免费全能主机 网通服务器 网购分享 沈阳主机托管 东莞服务器托管 广州虚拟主机 腾讯服务器 windowssever2008 winserver2008 更多