- Ziva zvinongedzo uye zviteshi zvine netstat uye sefa nematunhu kana maprotocol kuti uone zviitiko zvisingaite.
- Vhara network uye IPs kubva kuCMD/PowerShell uchishandisa netsh uye yakanyatsotsanangurwa Firewall mitemo.
- Simbisa perimeter neIPsec uye GPO kutonga, uye tarisa pasina kudzima iyo Firewall sevhisi.
- Dzivisa mhedzisiro paSEO uye usability nekubatanidza kuvharira neCAPTCHAs, chiyero chechiyero uye CDN.
¿Nzira yekuvharisa sei fungidziro yekubatanidza network kubva kuCMD? Kana komputa ikatanga kushanda zvishoma nezvishoma kana iwe ukaona zvisina kujairika network chiitiko, kuvhura iyo yekuraira nekukurumidza uye kushandisa mirairo kazhinji ndiyo inokurumidza nzira yekudzora zvakare. Nemirairo mishoma chete, unogona tsvaga uye vhara zvinongedzo zvinofungirwaOngorora madoko akavhurika uye simbisa kuchengetedzeka kwako pasina kuisa chero chinhu chekuwedzera.
Muchinyorwa chino iwe unowana yakakwana, inoshanda gwara rakavakirwa pazvishandiso zvemuno (CMD, PowerShell, uye zvinoshandiswa senge netstat uye netsh). Uchaona kuti sei ziva zvikamu zvinoshamisaNdeapi metric yekutarisa, maitiro ekuvharisa chaiwo Wi-Fi network, uye maitiro ekugadzira mitemo muWindows Firewall kana kunyange FortiGate, zvese zvinotsanangurwa mumutauro wakajeka uye wakatwasuka.
Netstat: kuti chii, ndechei, uye nei ichiramba ichikosha
Zita rekuti netstat rinobva ku "network" uye "statistics", uye basa rayo ndere kupa chaizvo. nhamba uye mamiriro ekubatanidza munguva chaiyo. Yakave yakabatanidzwa muWindows neLinux kubva kuma90, uye iwe unogona zvakare kuiwana mune mamwe masisitimu senge macOS kana BeOS, kunyangwe isina graphical interface.
Kuimhanyisa mukoni kunotendera iwe kuti uone inoshanda yekubatanidza, madoko ari kushandiswa, emunharaunda uye kure kero, uye, kazhinji, tarisiro yakajeka yezviri kuitika muTCP/IP yako stack. Kuva neizvi immediate network scan Inokubatsira kugadzirisa, kuongorora, uye kusimudza chiyero chekuchengetedza komputa yako kana sevha.
Kuongorora kuti ndeapi maturusi anobatana, ndeapi madoko akavhurika, uye kuti router yako yakagadziriswa sei kwakakosha. Ne netstat, iwe zvakare unowana routing matafura uye nhamba neprotocol zvinokutungamirira kana chimwe chinhu chikasawedzera: traffic yakawandisa, kukanganisa, kuwandisa, kana kubatanidza zvisina mvumo.
Zano rinobatsira: Usati waita ongororo yakakomba netstat, vhara chero zvikumbiro zvausingade uye kunyange Tangazve kana zvichiitaNenzira iyi iwe unodzivirira ruzha uye kuwana chaiyo mune izvo zvinonyanya kukosha.

Impact pakuita uye maitiro akanaka ekushandisa
Kumhanya netstat pachayo hakuzopaza PC yako, asi kuishandisa zvakanyanya kana neakawandisa paramita kamwechete kunogona kupedza CPU uye ndangariro. Kana iwe uchimhanyisa uchienderera kana kusefa gungwa re data, iyo system mutoro unowedzera uye kuita kungatambura.
Kuti uderedze maitiro ayo, igumise kune chaiwo mamiriro uye gadzirisa-tuta paramita. Kana iwe uchida kuenderera kuyerera, ongorora mamwe chaiwo ekutarisa maturusi. Uye rangarira: zvishoma zvakawandisa apo chinangwa chiri chekuongorora chiratidzo chaicho.
- Deredza kushandiswa kunguva dzaunonyatso kuida tarisa zvinobatanidzwa kana nhamba.
- Sefa chaizvo kuratidza chete ruzivo rwakakosha.
- Dzivisa kuronga kuurayiwa panguva pfupi saturate zviwanikwa.
- Funga nezvezvishandiso zvakatsaurirwa kana iwe uchitsvaga real time monitoring more advanced.
Zvakanakira uye zvisingakwanisi kushandisa netstat
Netstat inoramba yakakurumbira pakati pevatariri uye matekiniki nekuti inopa Pakarepo kuonekwa kwezvibatanidza uye zviteshi zviri kushandiswa nemaapplication. Mumasekondi iwe unogona kuona kuti ndiani ari kutaura naani uye kuburikidza nepi madoko.
Inobatsira zvakare kutarisa uye kugadzirisa matambudzikoCongestion, mabhodhoro, zvinoramba zvichibatana… zvese zvinobuda pachena kana iwe ukatarisa mastatus akakodzera uye manhamba.
- Kukurumidza kuona yekubatanidza kusingatenderwi kana kupindira kunobvira.
- Session tracking pakati pevatengi nemaseva kuti awane kuparara kana latencies.
- Performance evaluation neprotocol yekuisa pamberi pekuvandudzwa kwavanenge vane simba guru.
Uye chii chisingaite zvakanaka kudaro? Iyo haipe chero data (hachisicho chinangwa chayo), kuburitsa kwayo kunogona kuve kwakaomarara kune vasiri-tekinoroji vashandisi, uye mu nharaunda yakakura kwazvo kwete yekuyera seyakasarudzika system (SNMP, semuenzaniso). Uyezve, kushandiswa kwayo kwave kuderera mukufarira PowerShell uye zvimwe zvemazuva ano zvekushandisa zvine zvinobuda zvakajeka.
Maitiro ekushandisa netstat kubva kuCMD uye kuverenga zvawanikwa

Vhura CMD semaneja (Tanga, nyora “cmd”, tinya-kurudyi, Mhanya semutungamiriri) kana shandisa Terminal mukati Windows 11. Wobva wanyora netstat uye tinya Enter kuti utore mufananidzo wenguva yacho.
Iwe uchaona makoramu ane protocol (TCP/UDP), kero dzemuno uye dziri kure dzine zviteshi zvadzo, uye nzvimbo yemamiriro (KUTEERERA, KUSIMBISA, TIME_WAIT, nezvimwewo). Kana iwe uchida nhamba panzvimbo yemazita echiteshi, mhanya netstat -n kuti uwane kuverenga kwakananga.
Periodic updates? Unogona kuitaurira kuti imutsidze ese X masekonzi panguva: semuenzaniso, netstat -n 7 Ichagadzirisa zvinobuda mumasekonzi manomwe ega ega kuti uone shanduko yehupenyu.
Kana iwe uchingofarira hukama hwakasimba, sefa zvinobuda ne findstr: netstat | findstr AKASIMBISAChinja kuti KUTEERERA, CLOSE_WAIT kana TIME_WAIT kana uchida kuona dzimwe matunhu.
Inobatsira netstat parameters yekuongorora
Aya magadzirirwo anotendera iwe kuderedza ruzha uye tarisa pane zvauri kutsvaga:
- -a: inoratidza inoshanda uye isingashande yekubatanidza uye yekuteerera ports.
- -e: interface packet statistics (inouya / inobuda).
- -f: inogadzirisa uye inoratidza iri kure FQDNs (anonyatso kwanisa mazita emazita).
- -n: inoratidza isina kugadziriswa port uye IP nhamba (nekukurumidza).
- -o: inowedzera PID yemaitiro anochengetedza kubatana.
- -p X: mafirita neprotocol (TCP, UDP, tcpv6, tcpv4...).
- -q: mubvunzo wakabatana kuteerera uye kusateerera zviteshi.
- -sNhamba dzakarongwa neprotocol (TCP, UDP, ICMP, IPv4/IPv6).
- -r: ikozvino routing tafura yehurongwa.
- -t: ruzivo nezve kubatanidza mune yekurodha state.
- -x: NetworkDirect yekubatanidza ruzivo.
Mienzaniso inoshanda yehupenyu hwezuva nezuva
Kunyora madoko akavhurika uye zvinongedzo nePID yavo, mhanya netstat -anoNeiyo PID unogona kuyambuka-referensi maitiro muTask Manager kana nemidziyo yakaita seTCPView.
Kana iwe uchingofarira IPv4 kubatana, sefa neprotocol ne netstat -p IP uye uchachengetedza ruzha pakubuda.
Global manhamba neprotocol inobva netstat -sIpo kana iwe uchida chiitiko cheiyo interfaces (yakatumirwa / yakagamuchirwa) ichashanda netstat -e kuva nenhamba chaidzo.
Kuti utsvage dambudziko neremote name resolution, batanidza netstat -f nekusefa: semuenzaniso, netstat -f | findstr mydomain Ichadzoka chete izvo zvinoenderana neiyo domain.
Kana Wi-Fi ichinonoka uye netstat yakazara nekubatanidza zvisinganzwisisike
A classic kesi: inononoka kubhurawuza, yekumhanyisa bvunzo inotora nguva kuti itange asi inopa zvakajairika manhamba, uye kana uchimhanya netstat, zvinotevera zvinoonekwa: akawanda ekubatanidza AKASIMAKazhinji mhosva ndeye browser (Firefox, semuenzaniso, nekuda kwenzira yekubata zvigadziko zvakawanda), uye kunyangwe ukavhara windows, maitiro ekumashure anogona kuramba achichengetedza masesheni.
Kuita sei? Kutanga, zvienzanise ne netstat -ano Cherechedza maPIDs. Wobva watarisa muTask Manager kana neProcess Explorer/TCPView ndeapi maitiro ari kuseri kwayo. Kana iyo yekubatanidza uye maitiro achiita seanofungira, funga kuvharira IP kero kubva kuWindows Firewall. shandisa antivirus scan Uye, kana njodzi ichiita seyakakwira kwauri, bvisa midziyo kwenguva pfupi kubva kunetiweki kusvika yave pachena.
Kana mafashama ezvikamu akaramba mushure mekuisazve bhurawuza, tarisa mawedzero, wodzima kwenguva pfupi kuwiriranisa, uye ona kana vamwe vatengi (senharembozha yako) vachinonokawo: izvi zvinonongedza dambudziko. network/ISP dambudziko pane software yemuno.
Rangarira kuti netstat haisi chaiyo-nguva yekutarisa, asi unogona kutevedzera imwe nayo netstat -n 5 kuzorodza masekonzi mashanu ega ega. Kana iwe uchida inoenderera uye yakanyanya kunaka pani, tarisa TCPVona kana mamwe akazvipira kutarisa mamwe maitiro.
Vimba chaiyo Wi-Fi network kubva kuCMD
Kana paine network dziri padyo dzausingade kuona kana kuti mudziyo wako uedze kushandisa, unogona kusefa kubva pane consoleMurairo unokubvumira vhara imwe SSID chaiyo uye zvibate pasina kubata graphical panel.
Vhura CMD semutungamiri uye kushandiswa:
netsh wlan add filter permission=block ssid="Nombre real de la red" networktype=infrastructure
Mushure mekuimhanyisa, iyo network inonyangarika kubva pane rondedzero yeanowanikwa network. Kuti utarise zvawavharira, tanga netsh wlan show filters permit=blockUye kana uchizvidemba, zvibvise ne:
netsh wlan delete filter permission=block ssid="Nombre real de la red" networktype=infrastructure

Vhara kero dzeIP dzinofungidzirwa neWindows Firewall
Kana iwe ukaona kuti imwe kero yeruzhinji IP iri kuyedza kuita zvekufungira kupesana nemasevhisi ako, mhinduro yekukurumidza ndeye gadzira mutemo unovhara Zvisungo izvozvo. Mune graphical console, wedzera mutemo wetsika, uise kune "Zvirongwa zvose", protocol "Chero", tsanangura maIPs ari kure kuti avhare, tarisa "Block the connection" uye shandisa kune domain/private/public.
Unoda otomatiki here? NePowerShell, unogona kugadzira, kugadzirisa, kana kudzima mitemo pasina kudzvanya. Semuyenzaniso, kuvhara inobuda Telnet traffic uye wodzoreredza inotenderwa kure IP kero, unogona kushandisa mitemo ne Nyowani-NetFirewallRule uye wozogadzirisa ne Set-NetFirewallRule.
# Bloquear tráfico saliente de Telnet (ejemplo)
New-NetFirewallRule -DisplayName "Block Outbound Telnet" -Direction Outbound -Program %SystemRoot%\System32\telnet.exe -Protocol TCP -LocalPort 23 -Action Block
# Cambiar una regla existente para fijar IP remota
Get-NetFirewallPortFilter | ?{ $_.LocalPort -eq 80 } | Get-NetFirewallRule | ?{ $_.Direction -eq "Inbound" -and $_.Action -eq "Allow" } | Set-NetFirewallRule -RemoteAddress 192.168.0.2
Kugadzirisa mitemo nemapoka kana kudzima mitemo yekuvharisa muhuwandu, vimba Gonesa/Dzivisa/Bvisa-NetFirewallRule uye mumibvunzo ine wildcards kana mafirita nezvivakwa.
Zvakanakisa maitiro: Usadzima iyo Firewall sevhisi
Microsoft inopa zano kumisa iyo Firewall sevhisi (MpsSvc). Kuita izvi kunogona kukonzera Start menu nyaya, matambudziko ekuisa maapplication emazuvano, kana mamwe matambudziko. activation kukanganisa Nerunhare. Kana, senyaya yemutemo, iwe unofanirwa kudzima ma profiles, ita izvozvo pafirewall kana GPO kumisikidza level, asi siya iyo sevhisi ichimhanya.
Profiles (domain/private/public) uye default zviito (kubvumira/block) zvinogona kusetwa kubva pamutsetse wemirairo kana firewall console. Kuchengeta izvi zvisizvo zvakatsanangurwa zvinodzivirira maburi asingaite pakugadzira mitemo mitsva.
FortiGate: Vhara SSL VPN kuyedza kubva kune inofungidzira yeruzhinji IPs
Kana iwe ukashandisa FortiGate uye ukaona yakundikana kuedza kupinda kune yako SSL VPN kubva kune isingazivikanwe IPs, gadzira kero dziva (semuenzaniso, blacklistipp) uye wedzera maIP ese anopokana ipapo.
Pane koni, isa iyo SSL VPN marongero ne config vpn ssl kugadzirisa uye inoshanda: set source-address "blacklistipp" y set source-address-negate gonesa. Uine ratidza Unosimbisa kuti yashandiswa. Nenzira iyi, kana mumwe munhu achibva kune iwo maIPs, kubatana kunorambwa kubva pakutanga.
Kutarisa traffic ichirova iyo IP uye port, unogona kushandisa ongorora sniffer packet chero "host XXXX uye port 10443" 4, uye na tora vpn ssl monitor Iwe unotarisa zvikamu zvinotenderwa kubva kuIPs zvisina kubatanidzwa mune iyo rondedzero.
Imwe nzira ndeye SSL_VPN> Dzivirira Kupinda> Dzimisa kuwana kune chaiwo mahostNekudaro, mune iyo kesi kurambwa kunoitika mushure mekupinda zvitupa, kwete nekukurumidza sekunge kuburikidza nekoni.
Dzimwe nzira kune netstat yekuona uye kuongorora traffic
Kana iwe uchitsvaga imwe nyaradzo kana ruzivo, kune zvishandiso zvinokupa. mifananidzo, mafirita epamberi, uye kubatwa kwakadzama zvepakeji:
- Wireshark: traffic kubatwa uye kuongororwa pamatanho ese.
- iproute2 (Linux): zvinoshandiswa kubata TCP/UDP uye IPv4/IPv6.
- GlassWireOngororo yetiweki ine firewall manejimendi uye yakatarisana nekuvanzika.
- Uptrends Uptime MonitorKuenderera mberi kwekutarisa saiti uye zviziviso.
- Germain UX: kutarisisa kwakanangana neakamira semari kana hutano.
- ateraRMM suite nekutarisa uye kuwana kure.
- CloudsharkWebhu analytics uye screenshot kugovera.
- iptraf / iftop (Linux): Chaiyo-nguva traffic kuburikidza neyakanyanya intuitive interface.
- ss (Socket Statistics) (Linux): yazvino, yakajeka imwe nzira kune netstat.
IP kuvharira uye maitiro ayo paSEO, pamwe nekuderedza nzira
Kuvharisa maIPs anehasha zvine musoro, asi chenjera nazvo vhara injini yekutsvaga botsNekuti unogona kurasikirwa indexing. Kuvharisa nyika kunogonawo kusabvisa vashandisi vari pamutemo (kana VPNs) uye kuderedza kuoneka kwako mune mamwe matunhu.
Kuwedzera matanho: wedzera CAPTCHAs Kuti umise bots, shandisa rate capping kudzivirira kushungurudzwa uye isa CDN kuderedza DDoS nekugovera mutoro kumativi akaparadzirwa node.
Kana yako yekutambira ichishandisa Apache uye uine geo-blocking inogoneswa pane server, unogona redirect kushanya kubva kune imwe nyika uchishandisa .htaccess ine mutemo wekunyora patsva (generic muenzaniso):
RewriteEngine on
RewriteCond %{ENV:GEOIP_COUNTRY_CODE} ^CN$
RewriteRule ^(.*)$ http://tu-dominio.com/pagina-de-error.html [R=301,L]
Kuvharisa IPs pane yekutambira (Plesk), unogona zvakare kugadzirisa .htaccess uye ramba kero dzakananga, nguva dzose uine chekare chekuchengetedza faira kuitira kana iwe uchida kudzorera shanduko.
Tonga Windows Firewall zvakadzama uchishandisa PowerShell uye netsh
Kupfuura kugadzira mitemo yega, PowerShell inokupa kutonga kwakazara: tsanangura default profiles, gadzira/shandura/dzima mitemo uye shanda uchipesana neActive Directory GPOs ine cached sessions kuti uderedze mutoro pane domain controllers.
Mienzaniso inokurumidza: kugadzira mutemo, kushandura kero yayo iri kure, kugonesa/kumisa mapoka ese, uye bvisa mitemo yekuvhara mune imwe nhanho. Iyo modhi yakatarisana nechinhu inobvumira kubvunza mafirita ezviteshi, maapplication, kana kero uye ketani mhinduro nemapaipi.
Kutonga zvikwata zviri kure, vimba nazvo WinRM uye parameters -CimSessionIzvi zvinokutendera kuti unyore mitemo, shandura, kana kudzima zvinyorwa pane mamwe machina pasina kusiya koni yako.
Mhosho muzvinyorwa? Shandisa -ErrorAction ChinyararireEndererai mberi kudzvinyirira "mutemo hauna kuwanikwa" pakudzima, -WhatIf kuongorora uye -Simbisa Kana iwe uchida kusimbiswa kune chimwe nechimwe chinhu. With -Verbose Iwe uchange uine mamwe mashoko pamusoro pekuita.
IPsec: Kutendeseka, encryption, uye policy-based isolation
Paunenge uchingoda yakatendeseka kana yakavharidzirwa traffic kuti upfuure, unosanganisa Firewall uye IPsec mitemoGadzira mitemo yemaitiro ekufambisa, tsanangura cryptographic seti uye nzira dzechokwadi, uye dzibatanidze nemitemo yakakodzera.
Kana mumwe wako achida IKEv2, unogona kuzvitsanangura mumutemo weIPsec nekusimbiswa nechitupa chemudziyo. Izvi zvinogonekawo. kopi mitemo kubva kune imwe GPO kuenda kune imwe uye yavo yakabatana seti kuti ikurumidze kutumirwa.
Kuparadzanisa nhengo dzedomasi, shandisa mitemo inoda humbowo hwetraffic inouya uye inoda kuti iite traffic inobuda. Unogonawo zvinoda kuva nhengo mumapoka ine SDDL cheni, inorambidza kupinda kune vane mvumo vashandisi / zvishandiso.
Zvishandiso zvisina kunyorwa (senge telnet) zvinogona kumanikidzwa kushandisa IPsec kana iwe ukagadzira "bvumira kana yakachengeteka" mutemo wefirewall uye IPsec mutemo iwoyo. Inoda kuvimbiswa uye encryptionNenzira iyo hapana chinofamba zvakajeka.
Yakasimbiswa bypass uye endpoint chengetedzo
Yakatemerwa bypass inobvumira traffic kubva kune vanovimbwa nevashandisi kana zvishandiso kudarika mitemo yekuvharira. Useful for kugadzirisa uye kuongorora maseva pasina kuvhura zviteshi zvepasirese.
Kana iwe uchitsvaga kumagumo-kusvika-kumagumo chengetedzo kune akawanda maapplication, pane kugadzira mutemo kune yega yega, fambisa iyo mvumo kune IPsec layer ine runyorwa rwemakina / evashandisi mapoka anotenderwa mukugadziriswa kwepasirese.
Kubata netstat kuona kuti ndiani anobatanidza, kusimudzira netsh uye PowerShell kumisikidza mitemo, uye kuyera neIPsec kana perimeter firewalls seFortiGate inokupa kutonga kunetiweki yako. Iine CMD-yakavakirwa Wi-Fi mafirita, yakanyatsogadzirwa IP kuvharira, SEO precaution, uye mamwe maturusi kana iwe uchida kwakawanda kudzika ongororo, unozogona tsvaga zvinofungirwa kubatana nenguva uye vavhare pasina kukanganisa mashandiro ako.
Aida nezve tekinoroji kubva achiri mudiki. Ini ndinoda kuva nemazuva ano muchikamu uye, pamusoro pezvose, kutaura nezvazvo. Ndokusaka ndakazvipira kutaurirana pane tekinoroji uye vhidhiyo mutambo mawebhusaiti kwemakore mazhinji ikozvino. Unogona kundiwana ndichinyora nezve Android, Windows, MacOS, iOS, Nintendo kana chero imwe nyaya ine hukama inouya mupfungwa.