电脑技术学习

如何在CISCO路由器上禁止BT下载

dn001

方法有多种,常见的有:

1、找出ip做端口限速(这样做比较麻烦)

2、用NBAR(非常好用)
但是重新启动需要重新调用 tFTP://130.130.122.123/bittorrent.pdlm 这个文件,所以还是用flash卡比较好。假如不调用文件,那就会发生没有match protocol bittorrent

ip nbar pdlm tftp://130.130.122.123/bittorrent.pdlm

class-map match-all bit
;match protocol bittorrent

policy-map limit-bit
class bit
;police cir 240000
; ; conform-action transmit
; ; exceed-action drop


police cir 8000
conform-action ; transimit
exceed-action drop

interface fastethernet 0/1
;service-policy input limit-bit (下载)
;service-policy output limit-bit(上传)
;ip nat outside

interface fastethernet 0/0
;ip nat inside

ip nat inside list 1 pool nbar-pool overload
Access-list 1 permit any
ip nat pool nbar-pool

8000 < 1k
80000 < 4k 5k, 5k 5k
160000 < 16K, 13K
240000 ;<=22k, 24K
800000 <=80K <100K