English
 电子信箱
 加入收藏

  冰盾防火墙 >> 支持与下载 >> 技术文章 >> 如何在 Windows Server 2003 中加固 TCP/IP 堆栈以抵御拒绝服务攻击(2)

 

如何在 Windows Server 2003 中加固 TCP/IP 堆栈以抵御拒绝服务攻击(2)

冰盾防火墙 2007-11-28

 

    For Windows Server 2003(文件名后缀为.txt,右击后选择目标另存为,保存后修改文件扩展名为.reg再导入注册表即可),或者将以下内容复制后导入到注册表中:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
"SynAttackProtect"=dword:1
"TcpMaxPortsExhausted"=dword:5
"TcpMaxHalfOpen"=dword:500
"TcpMaxHalfOpenRetried"=dword:400
"TcpMaxConnectResponseRetransmissions"=dword:2
"TcpMaxDataRetransmissions"=dword:2
"EnablePMTUDiscovery"=dword:0
"KeepAliveTime"=dword:300000
"NoNameReleaseOnDemand"=dword:1
"DefaultTTL"=dword:256
"EnableDeadGWDetect"=dword:0
"DisableIPSourceRouting"=dword:1
"EnableFragmentChecking"=dword:1
"EnableMulticastForwarding"=dword:0
"IPEnableRouter"=dword:0
"EnableAddrMaskReply"=dword:0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters]
"EnableICMPRedirect"=dword:0
"EnableDynamicBacklog"=dword:1
"MinimumDynamicBacklog"=dword:20
"MaximumDynamicBacklog"=dword:20000
"DynamicBacklogGrowthDelta"=dword:10
 
    For Windows 2000(文件名后缀为.txt,右击后选择目标另存为,保存后修改文件扩展名为.reg再导入注册表即可),或者将以下内容复制后导入到注册表中:
---------------------------------------------------------------------------------
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
 
"SynAttackProtect"=dword:2
"TcpMaxPortsExhausted"=dword:5
"TcpMaxHalfOpen"=dword:500
"TcpMaxHalfOpenRetried"=dword:400
"TcpMaxConnectResponseRetransmissions"=dword:2
"TcpMaxDataRetransmissions"=dword:2
"EnablePMTUDiscovery"=dword:0
"KeepAliveTime"=dword:300000
"NoNameReleaseOnDemand"=dword:1
"DefaultTTL"=dword:256
"EnableDeadGWDetect"=dword:0
"DisableIPSourceRouting"=dword:1
"EnableFragmentChecking"=dword:1
"EnableMulticastForwarding"=dword:0
"IPEnableRouter"=dword:0
"EnableAddrMaskReply"=dword:0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters]
"EnableICMPRedirect"=dword:0
"EnableDynamicBacklog"=dword:1
"MinimumDynamicBacklog"=dword:20
"MaximumDynamicBacklog"=dword:20000
"DynamicBacklogGrowthDelta"=dword:10

 


最新内容: 相关内容:
如何在 Windows Server 2003 中加固 TCP/IP 堆栈以抵御拒绝服务攻击[2007-11-27]
不可不知 DDoS的攻击原理与防御方法[2007-11-26]
修改注册表防范DDOS攻击[2007-11-22]
防御DDoS分布式拒绝服务[2007-11-19]
DDoS攻击的原理及工具介绍[2007-11-14]
arp攻击原理也可以这样理解[2007-11-13]
如何在 Windows Server 2003 中加固 TCP/IP 堆栈以抵御拒绝服务攻击[2007-11-27]
防御DDoS分布式拒绝服务[2007-11-19]
拒绝服务DDos攻击方式分析及防御策略的部署[2007-01-27]
分布式拒绝服务攻击(DDoS)原理及防范[2007-01-25]
防御额外访问量带来的拒绝服务式攻击[2007-01-12]
监测分布式拒绝服务[2006-11-22]