الموقع العربي الاول للعبة Silkroad Online

الموقع العربي الاول للعبة Silkroad Online (https://silkroad4arab.com/vb/index.php)
-   قسم الشروحات و البرامج المستخدمة في عمل السيرفرات الخاصة (https://silkroad4arab.com/vb/forumdisplay.php?f=289)
-   -   @@@احمي سيرفيرك من الدودس اتاك من غير برامج@@@ (https://silkroad4arab.com/vb/showthread.php?t=466901)

HeMa 01-12-2012 11:34 PM

@@@احمي سيرفيرك من الدودس اتاك من غير برامج@@@
 
We will Explain How to block ping On Your Server and incoming and outcoming ICMP .

(IP Security)

To block all PING traffic to and From a computer you need to create an IPSec policy that will block all ICMP traffic.
Check to see if the computer responds to PING requests by pinging it:

http://www.petri.co.il/images/ipsec_ping24.jpg

To configure a single computer follow these steps:

http://www.petri.co.il/images/add_snapin.gif

Configuring IP Filter Lists and Filter actions
1. Open an MMC window (Start > Run > MMC).

http://www.petri.co.il/images/ipsec_snapin.gif

2. Add the IP Security and Policy Management Snap-In.

http://www.petri.co.il/images/ipsec_snapin1.gif

3. In the Select which computer this policy will manage window select the local computer (or any other policy depending upon Your needs). Click Close then click Ok.

http://www.petri.co.il/images/ipsec_filters.gif

4. Right-click IP Security Policies in the left pane of the MMC console. Select Manage IP Filter Lists and Filter Actions.

http://www.petri.co.il/images/ipsec_filters1.gif

5. You do not need to configure a specific IP Filter for ICMP (the protocol used by PING) because such a filter already exists by default - All ICMP Traffic.

http://www.petri.co.il/images/ipsec_filters1.gif
However you might want to configure a more specific IP Filter for ICMP. For example, lets say you wish to prevent a Server From answering all PINGS except for specific PINGs sent by a specific computer used by the Help Desk department. In that case you should add a new IP Filter and use Your defined source and Destination IP Addresses, and the ICMP protocol

6. In the Manage IP Filter Lists and Filter actions review Your filters and if all are set, click on the Manage Filter Actions tab. Now we need to add a filter action that will block our designated traffic, so click Add.

http://www.petri.co.il/images/ipsec_filters17.gif


7. In the Welcome screen click Next.
8. In the Filter Action Name type Block and click Next.

http://www.petri.co.il/images/ipsec_filters19.gif

9. In the Filter Action General Options click Block then click on Next.

http://www.petri.co.il/images/ipsec_filters20.gif
10. Back in the Manage IP Filter Lists and Filter actions review Your filters and if all are set, click on the Close button. You can add Filters and Filter Actions at any time.

http://www.petri.co.il/images/ipsec_filters21.gif


Next step is to configure the IPSec Policy and to assign it.


Configuring the IPSec Policy

In the same MMC console right-click IP Security Policies on Local Computer and select Create IP Security Policy.

http://www.petri.co.il/images/ipsec_policy.gif


2. In the Welcome screen click Next
3. In the IP Security Policy Name enter a descriptive name, such as "Block PING". Click Next

http://www.petri.co.il/images/ipsec_policy21.gif
4. In the Request for Secure Communication window click to clear the Active the Default Response Rule check-box. Click Next


http://www.petri.co.il/images/ipsec_policy3.gif

5. In the Completing IP Security Policy Wizard window, click Finish.

http://www.petri.co.il/images/ipsec_policy4.gif

6. We now need to add the various IP Filters and Filter Actions to the new IPSec Policy. In the new IPSec Policy window click Add to begin adding the IP Filters and Filter Actions.
http://www.petri.co.il/images/ipsec_policy22.gif
7. In the Welcome window click Next.
8. In the Tunnel Endpoint make sure the default setting is selected and click Next.

http://www.petri.co.il/images/ipsec_policy7.gif

9. In the Network Type windows select All Network Connections and click Next

http://www.petri.co.il/images/ipsec_policy8.gif
10. In the IP Filter List window select "All ICMP Traffic" (or any other IP Filter configured in step #5 at the beginning of this article). If, for some reason, you did not previously configure the right IP Filter, then you can press Add and begin adding it now. When done, click Next.

http://www.petri.co.il/images/ipsec_policy23.gif

In the Filter Action window select "Block". Again, if you did not previously configure the right Filter Action, you can now press Add and begin adding it now. When done, click Next.

http://www.petri.co.il/images/ipsec_policy10.gif
Notice how the IP Filter has been added.

http://www.petri.co.il/images/ipsec_policy24.gif

Again, you can add any combination of IP Filters and Filter Actions you like.
Notice that you cannot change their order like in other full-featured firewalls. Even so, this configuration works perfectly as you will soon discover.
The next phase is to assign the IPSec Policy.

Assigning the IPSec Policy
In the same MMC console, right-click the new IPSec Policy and select Assign.
http://www.petri.co.il/images/ipsec_policy25.gif

Done, you can now test the configuration by trying to surf to restricted and unrestricted websites.

SOme Question : Why block ping to Protect myself From DDoS attack or other attacks
cuz, let me talk about ddos, let me say that the answer how to DDoS via CMD commands
Start > Run > ping 127.0.0.1 -t -l 65500
Change 127.0.0.1 for ip of Server or site u need to crash it ا

يا جدعان انا ماليش في القصص دي
بس قولت اخدمكم يعني ماحدش يعملي اسبام ويسالني انا بخدمكم كدا
لقيت الموضوع دا في سكاي قولت والنبي مش خسارة فيكم :)
لو تمام ومصبوط ياريت مشرفين القسم يثبتوه لو ليه اهميه:)


ღ♥CarLeTo♥ღ 01-12-2012 11:36 PM

شرح جامد يا Hema
عاش يا وحش

GM]7oDa] 01-12-2012 11:40 PM

ايوة يا عم :) تشكر

aaaaa200123 01-12-2012 11:42 PM

تسلم

Arafa 01-12-2012 11:45 PM

استمر :clapping: بس مش الانجلش مخالف .... فا الى يطبق على الاعضاء يطبق على المشرفين و المراقبين قبلهم

HeMa 01-12-2012 11:47 PM

شكرا يا رجاله نورتو الموضوع

TYKE 02-12-2012 12:08 AM

اشطة ياحجج

CriZ 02-12-2012 12:21 AM

English increase
Contrary to
But Nice

Mr Z!dane 02-12-2012 01:01 AM

مش بطال بس للاسف مفيش مكان نعينك فية معانا ههههههههه برة القسم :bye1:

Arafa 02-12-2012 01:29 AM

يثبت 2 Days تقديرا لمجهودك

omarahmed500 02-12-2012 04:43 AM

تمام يا معلم

Zenger 02-12-2012 05:49 AM

تسلم يامعلم سبقتني في الموضوع ده

بس الناس تاخد بالها في 6 صوره محد يعمل block ip trafic

اشتغل ICMP

JanGanSRO 02-12-2012 07:34 AM

اقتباس:

المشاركة الأصلية كتبت بواسطة hema (المشاركة 4450965)
we will explain how to block ping on your server and incoming and outcoming icmp .

(ip security)

to block all ping traffic to and from a computer you need to create an ipsec policy that will block all icmp traffic.
Check to see if the computer responds to ping requests by pinging it:

http://www.petri.co.il/images/ipsec_ping24.jpg

to configure a single computer follow these steps:

http://www.petri.co.il/images/add_snapin.gif

configuring ip filter lists and filter actions
1. Open an mmc window (start > run > mmc).

http://www.petri.co.il/images/ipsec_snapin.gif

2. Add the ip security and policy management snap-in.

http://www.petri.co.il/images/ipsec_snapin1.gif

3. In the select which computer this policy will manage window select the local computer (or any other policy depending upon your needs). Click close then click ok.

http://www.petri.co.il/images/ipsec_filters.gif

4. Right-click ip security policies in the left pane of the mmc console. Select manage ip filter lists and filter actions.

http://www.petri.co.il/images/ipsec_filters1.gif

5. You do not need to configure a specific ip filter for icmp (the protocol used by ping) because such a filter already exists by default - all icmp traffic.

http://www.petri.co.il/images/ipsec_filters1.gif
however you might want to configure a more specific ip filter for icmp. For example, lets say you wish to prevent a server from answering all pings except for specific pings sent by a specific computer used by the help desk department. In that case you should add a new ip filter and use your defined source and destination ip addresses, and the icmp protocol

6. In the manage ip filter lists and filter actions review your filters and if all are set, click on the manage filter actions tab. Now we need to add a filter action that will block our designated traffic, so click add.

http://www.petri.co.il/images/ipsec_filters17.gif


7. In the welcome screen click next.
8. In the filter action name type block and click next.

http://www.petri.co.il/images/ipsec_filters19.gif

9. In the filter action general options click block then click on next.

http://www.petri.co.il/images/ipsec_filters20.gif
10. Back in the manage ip filter lists and filter actions review your filters and if all are set, click on the close button. You can add filters and filter actions at any time.

http://www.petri.co.il/images/ipsec_filters21.gif


next step is to configure the ipsec policy and to assign it.


configuring the ipsec policy

in the same mmc console right-click ip security policies on local computer and select create ip security policy.

http://www.petri.co.il/images/ipsec_policy.gif


2. In the welcome screen click next
3. In the ip security policy name enter a descriptive name, such as "block ping". Click next

http://www.petri.co.il/images/ipsec_policy21.gif
4. In the request for secure communication window click to clear the active the default response rule check-box. Click next


http://www.petri.co.il/images/ipsec_policy3.gif

5. In the completing ip security policy wizard window, click finish.

http://www.petri.co.il/images/ipsec_policy4.gif

6. We now need to add the various ip filters and filter actions to the new ipsec policy. In the new ipsec policy window click add to begin adding the ip filters and filter actions.
http://www.petri.co.il/images/ipsec_policy22.gif
7. In the welcome window click next.
8. In the tunnel endpoint make sure the default setting is selected and click next.

http://www.petri.co.il/images/ipsec_policy7.gif

9. In the network type windows select all network connections and click next

http://www.petri.co.il/images/ipsec_policy8.gif
10. In the ip filter list window select "all icmp traffic" (or any other ip filter configured in step #5 at the beginning of this article). If, for some reason, you did not previously configure the right ip filter, then you can press add and begin adding it now. When done, click next.

http://www.petri.co.il/images/ipsec_policy23.gif

in the filter action window select "block". Again, if you did not previously configure the right filter action, you can now press add and begin adding it now. When done, click next.

http://www.petri.co.il/images/ipsec_policy10.gif
notice how the ip filter has been added.

http://www.petri.co.il/images/ipsec_policy24.gif

again, you can add any combination of ip filters and filter actions you like.
Notice that you cannot change their order like in other full-featured firewalls. Even so, this configuration works perfectly as you will soon discover.
The next phase is to assign the ipsec policy.

assigning the ipsec policy
in the same mmc console, right-click the new ipsec policy and select assign.
http://www.petri.co.il/images/ipsec_policy25.gif

done, you can now test the configuration by trying to surf to restricted and unrestricted websites.

some question : Why block ping to protect myself from ddos attack or other attacks
cuz, let me talk about ddos, let me say that the answer how to ddos via cmd commands
start > run > ping 127.0.0.1 -t -l 65500
change 127.0.0.1 for ip of server or site u need to crash it ا

يا جدعان انا ماليش في القصص دي
بس قولت اخدمكم يعني ماحدش يعملي اسبام ويسالني انا بخدمكم كدا
لقيت الموضوع دا في سكاي قولت والنبي مش خسارة فيكم :)
لو تمام ومصبوط ياريت مشرفين القسم يثبتوه لو ليه اهميه:)


الله ينور يا معلم شغل جامد جدا الكوبى دة

بس على فكرة فى خطوة ناقصه الصورة بتاعتها مكانتش فى الموضوع اللى انت جايبو اصلا من ساعه ما صاحبو نزلو على المنتدى اللى انت جايب الموضوع ده منو و لغايه دلوقتى انا مش عارف ايه هى الخطوة الناقصه دى لو تعرفها ياريت تقولى عليها

●♥ Marwan1337 ♥● 02-12-2012 01:56 PM

جـــارى التجـــربة .... :)

elfr3on2010 02-12-2012 04:44 PM

تسلم
اكثر من رائع


الساعة الآن 01:18 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions, Inc.