search
HomeOperation and MaintenanceWindows Operation and MaintenanceThe reason why it is very slow to open websites in the server or unable to access external websites after setting the IP security policy in win2008 R2

This article mainly introduces the reasons why it is very slow to open websites in the server or unable to access external websites after win2008 R2 sets the IPsecurity policy. Friends in need can refer to it

win2008R2 After setting the IP security policy, the reason why opening the website in the server is very slow and the speed is only a few KB

is because the shutdown policy in the IP security policy sets the original address "Any IP" to the target address "Any IP" Any UDP port is closed;

is changed to the original address "My IP address" to the target address "Any IP" UDP port is closed and reopened For UDP port 53, just go from my IP to DNS IP! This is used to resolve domain names!

Operation idea: prohibit all users from accessing port 1433, and only allow individual IP access. (The priority allowed in the security policy is greater than the prohibited)

1. Add "IP filtering" rules
IP filtering rules are used to set which IPs need to be restricted.
Open [Administrative Tools], click [Local Security Policy], select "IP Security Policy, on Local Computer"
Right-click menu, select [Manage IP Filter List and Filter Operations]
1) First Add a rule for "all IPs" to access port 1433, name: prohibit all IPs from accessing 1433
2) Add a rule for "specific IPs" to access port 1433, name: allow specific IPs to access 1433

2. Add the "Filter Operation" rule
Filter operation is a supplement to the IP filtering rules and is used to clarify whether to allow or block restricted IPs.
In "IP Security Policy, Local Computer", right-click the menu, select [Manage IP filter list and filter operations], select "Manage filter operations"
Create two rules, one to allow and one to intercept .

3. Create the "IP Security Policy" entry
After the IP filtering rules and operation rules have been created, now we need to combine these rules.
The "IP Security Policy" is the container that contains these rules.
In "IP Security Policy, on Local Computer", right-click the menu and select "Create IP Security Policy", name: Guardian IP Policy

4. Add IP filtering rules to "IP Security Policy"
1) Add the filtering rule of "Ban all IP access to 1433" and select the interception mode.
2) Add the filtering rule of "Allow specific IP to access 1433" and select the release mode.

After the filtering rules are added, enable the security policy to take effect.

If you need more restrictive rules, first create IP filtering rules according to process 1, and then add them to the "IP Security Policy" entry according to process 4.

The above is the detailed content of The reason why it is very slow to open websites in the server or unable to access external websites after setting the IP security policy in win2008 R2. For more information, please follow other related articles on the PHP Chinese website!

Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

mPDF

mPDF

mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

SublimeText3 English version

SublimeText3 English version

Recommended: Win version, supports code prompts!

WebStorm Mac version

WebStorm Mac version

Useful JavaScript development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

SublimeText3 Linux new version

SublimeText3 Linux new version

SublimeText3 Linux latest version