请把完整的规则设上,如果只设部分,当然不能上啦:
modify fwl global blistprotect enable attackprotect enable dosprotect enable maxtcpconn 15 maxicmpconn 15 maxsinglehostconn 20
create ipf rule entry ruleid 3 ifname public dir in act accept transprot eq num 6 destport eq num 80 seclevel medium logtag "Web in"
create ipf rule entry ruleid 700 ifname public dir out act accept transprot eq num 6 destport eq num 80 seclevel medium logtag "WEB 80"
create ipf rule entry ruleid 702 ifname public dir out act accept transprot eq num 6 destport eq num 443 seclevel medium logtag "web 443"
create ipf rule entry ruleid 704 ifname public dir out act accept transprot eq num 6 destport eq num 110 seclevel medium logtag "POP"
create ipf rule entry ruleid 706 ifname public dir out act accept transprot eq num 6 destport eq num 1995 seclevel medium logtag "POP SSL"
create ipf rule entry ruleid 708 ifname public dir out act accept transprot eq num 6 destport eq num 995 seclevel medium logtag "POP SSL"
create ipf rule entry ruleid 710 ifname public dir out act accept transprot eq num 6 destport eq num 465 seclevel medium logtag "SMTP SSL465"
create ipf rule entry ruleid 712 ifname public dir out act accept transprot eq num 6 destport eq num 25 seclevel medium logtag "SMTP25"
create ipf rule entry ruleid 714 ifname public dir out act accept transprot eq num 6 destport eq num 21 seclevel medium logtag "FTP"
create ipf rule entry ruleid 716 ifname public dir in act accept transprot eq num 6 destport eq num 21 seclevel medium logtag "ftp in"
create ipf rule entry ruleid 718 ifname public dir out act accept transprot eq num 6 srcport eq num 21 seclevel medium logtag "ftp out"
create ipf rule entry ruleid 720 ifname public dir in act accept transprot eq num 6 destport eq num 23 seclevel medium logtag "telnet in"
create ipf rule entry ruleid 722 ifname public dir out act accept transprot eq num 6 srcport eq num 23 seclevel medium logtag "telnet out"
create ipf rule entry ruleid 724 ifname public dir out act accept transprot eq num 6 destport eq num 7708 seclevel medium logtag "shares1"
create ipf rule entry ruleid 726 ifname public dir out act accept transprot eq num 6 destport eq num 7709 seclevel medium logtag "shares2"
create ipf rule entry ruleid 728 ifname public dir out act accept transprot eq num 6 destport eq num 8601 seclevel medium logtag "shares3"
create ipf rule entry ruleid 730 ifname public dir out act accept transprot eq num 6 destport eq num 8003 seclevel medium logtag "shares4"
create ipf rule entry ruleid 732 ifname public dir out act accept transprot eq num 6 destport eq num 8004 seclevel medium logtag "shares5"
create ipf rule entry ruleid 734 ifname public dir out act accept transprot eq num 6 destport eq num 8015 seclevel medium logtag "shares6"
create ipf rule entry ruleid 740 ifname public dir out act accept transprot eq num 6 destport eq num 8000 seclevel medium logtag "ChinaGame"
create ipf rule entry ruleid 750 ifname public dir out act accept transprot eq num 6 destport eq num 29000 seclevel medium logtag "Perfect1"
create ipf rule entry ruleid 780 dir out destaddr eq 219.133.60.243 seclevel medium logtag "QQ backdoor"
create ipf rule entry ruleid 800 ifname public dir out transprot eq num 6 todfrom 10:00:00 todto 22:59:00 seclevel medium logtag "Deny TCP"
create ipf rule entry ruleid 810 ifname public dir out act accept transprot eq num 17 destport eq num 53 seclevel medium logtag "DNS53"
create ipf rule entry ruleid 812 ifname public dir out act accept transprot eq num 17 destport eq num 123 seclevel medium logtag "Time123"
create ipf rule entry ruleid 900 ifname public dir out transprot eq num 17 todfrom 10:00:00 todto 22:59:00 seclevel medium logtag "Deny UDP"
modify ipf global seclevel medium pubdefact accept dmzdefact accept