我这个版本不支持这个命令
system-view
# 创建高级ACL匹配内网DNS UDP53的AAAA查询
acl number 3001
rule deny udp source any destination any eq domain dns-type aaaa
rule permit udp source any destination any eq domain
# 应用到内网trust域接口入方向(示例内网口G1/0/0)
interface GigabitEthernet 1/0/0
packet-filter 3001 inbound
dns-type aaaa 精准匹配仅查询 IPv6 记录的 DNS 报文,普通 A 记录 IPv4 解析完全不受影响。# 删除全局IPv6 DNS服务器(如有配置)
undo ipv6 dns server all
# 查看确认无IPv6 DNS
display ipv6 dns server
acl number 3002
rule deny udp source any eq domain destination any dns-type aaaa
rule permit udp source any eq domain destination any
# 应用到外网untrust接口入方向(出口光猫对接口G1/0/1)
interface GigabitEthernet 1/0/1
packet-filter 3002 inbound
system-view
undo ipv6
# 验证IPv6已关闭
display ipv6 interface brief
# 所有接口无IPv6地址、无IPv6转发
security-policy
rule name BLOCK_IPV6_DNS
source-zone trust
destination-zone untrust
service udp-domain
application dns
dns-type aaaa
action deny
rule name BLOCK_IPV6_DNS_RETURN
source-zone untrust
destination-zone trust
service udp-domain
application dns
dns-type aaaa
action deny
system-view
# 1. 内网拦截终端AAAA查询
acl number 3001
rule deny udp source any destination any eq domain dns-type aaaa
rule permit udp source any destination any eq domain
interface GigabitEthernet 1/0/0 # 替换为你的内网trust接口
packet-filter 3001 inbound
# 2. 外网拦截上游返回的AAAA应答
acl number 3002
rule deny udp source any eq domain destination any dns-type aaaa
rule permit udp source any eq domain destination any
interface GigabitEthernet 1/0/1 # 替换为对接光猫的untrust出口接口
packet-filter 3002 inbound
# 3. 删除所有IPv6 DNS服务器
undo ipv6 dns server all
# 4. 全局关闭IPv6协议栈(核心根治)
undo ipv6
# 5. 安全策略兜底拦截AAAA DNS
security-policy
rule name BLOCK_IPV6_DNS
source-zone trust
destination-zone untrust
service udp-domain
application dns
dns-type aaaa
action deny
rule name BLOCK_IPV6_DNS_RETURN
source-zone untrust
destination-zone trust
service udp-domain
application dns
dns-type aaaa
action deny
return
save
# 强制查询IPv6 AAAA记录,请求会直接超时
nslookup -type=aaaa www.baidu.com
# 正常查询IPv4 A记录,可正常返回IP
nslookup -type=a www.baidu.com
-type=aaaa 请求无响应、超时;-type=a 解析正常。# 查看ACL匹配计数,确认AAAA报文被丢弃
display acl 3001
display acl 3002
# 确认无IPv6 DNS服务器
display ipv6 dns server
# 确认IPv6全局关闭
display current-configuration | include undo ipv6
# 查看安全策略拦截计数
display security-policy statistics rule BLOCK_IPV6_DNS
undo ipv6:设备仍会转发 IPv6 报文,终端拿到 IPv6 地址后发起 IPv6 访问,业务依然故障;AK-9150设备的ACL不支持这些匹配
AK-9150设备的ACL不支持这些匹配
<Sysname> system-view[Sysname] undo dns resolve[Sysname] interface GigabitEthernet 1/0/1[Sysname-GigabitEthernet1/0/1] undo dhcpv6 server dns-server[Sysname-GigabitEthernet1/0/1] undo ipv6 nd ra dns[Sysname] security-policy ip
[Sysname-security-policy-ip] rule 0 name Block-IPv6-DNS
[Sysname-security-policy-ip-Block-IPv6-DNS] source-zone trust
[Sysname-security-policy-ip-Block-IPv6-DNS] destination-zone untrust
[Sysname-security-policy-ip-Block-IPv6-DNS] service udp-dns
[Sysname-security-policy-ip-Block-IPv6-DNS] action drop
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
我这个版本不支持这个命令