Routing firewall instance: Restrict internal network to use QQ

  
When the QQ client logs in, the external network port number is UDP port 8000, TCP port 80 and 443. Generally speaking, it is not recommended to directly block the 80 and 443 ports unless you do not want to browse the web. So our approach is to combine the router's domain name filtering and IP filtering functions. In the following introduction, the QQ version used is QQ2010. 1. Set the domain name filtering: Through the view of the QQ connection information, the domain name information of the server used by the current QQ login is as follows: UDP server: sz.tencent.comsz2.tencent.comsz3.tencent.comsz4.tencent.comsz5.tencent.comsz6. Tencent.comsz7.tencent.comsz8.tencent.comsz9.tencent.comTCP server: tcpconn.tencent.comtcpconn2.tencent.comtcpconn3.tencent.comtcpconn4.tencent.comtcpconn5.tencent.comtcpconn6.tencent.com will also use qq.com Related information, so set up domain name filtering on the router to prohibit domain name resolution for these servers. Set domain name filtering on the router to prohibit domain name resolution for these servers: 1) Enable domain name filtering. 2) Filter domain name requests for tencent.com and qq.com. If domain name filtering is enabled, QQ login can be successfully disabled. Then set the IP address to filter, otherwise you need to continue to set the IP address filtering. 2. Set IP address filtering: First, you must find out which IP addresses need to be filtered. We can get the IP address of the login server that needs to be filtered by the following method: When the QQ login is successful, enter the QQ setting: Click <; network connection & rdquo;, view “ Login server & rdquo;, the IP address shown here is the IP address we want to filter. Then we start to set the IP address filtering: 1) After the IP address filtering setting is completed, try to log in to QQ again. Continue to find the IP address of the server that can log in through the above method, and continue to add the address segment where the IP address can be added to filter. Off, loop this process until QQ can't log in. Here we filter the following IP address segments, QQ can not log in: After setting the domain name filtering and IP address filtering above, QQ login can be restricted. However, it should be noted that when setting the IP address filtering, we filter the IP address segment, so some normal IP addresses that are not QQ servers are also filtered out. If it happens, the destination IP address that needs to be connected is also filtered. In this case, we can simply split the address segment we restricted above into multiple segments, not including the IP address we need to access. With qq server address: 219.133.40.15 218.17.209.23 202.104.129.252 218.18.95.153 202.104.129.25161.144.238.145 202.104.129.253 61.141.194.203 202.104.129.254 218.18.95.16561.144.238.146 219.133.40.91 211.248.99.252 218.17.217.66 61.144 .238.156219.133.40.89 219.133.40.115 219.133.40.90 219.133.40.113 219.133.40.114210.22.12.126 61.141.194.223 61.172.249.135 202.104.128.233 202.96.170.164218.17.217.103 218.66.59.233 61.141.194.207 202.96.170.163 202.96.170.166202 .96.140.18 202.96.140.119 202.96.140.8 202.96.140.12 218.18.95.221219.133.45.15 61.141.194.224 218.17.209.42 61.141.194.227 218.18.95.171219.133.49.6 219.133.49.73 219.133.48.56 219.133.40.215 219.133.38.132219.133.38 .30 219.133.40.177 219.133.38.232 219.133.38.29 219.133.48.88219.133.38.31 219.133.60.34QQ servers are divided into three categories: 1. UDP 8000 port class 13: the fastest, the most servers. QQ will send UDP packets to these 11 servers, and choose the one with the fastest response as the connection server. The names of the six servers start with SZ, the domain suffix is ​​tencent.com, and the domain name corresponds to IP as sz sz2 : 61.144.238.145 61.144.238.146 61.144.238.156sz3 sz4 sz6 sz7 : 202.104.129.251 202.104.129.254 202.104.129.252202.104.129 .253sz5 : 61.141.194.203 202.96.170.166 218.18.95.221 219.133.45.1561.141.194.224 202.96.170.1642, TCP HTTP connection server 4, using HTTP 80 and 443 port connection These four server names start with tcpconn, the domain suffix is Tencent.com, the domain name and IP correspond to tcpconn tcpconn3 218.17.209.23tcpconn2 tcpconn4 218.18.95.153 61.141.194.227 218.18.95.1713, member VIP login server, use HTTP 443 secure connection server IP 218.17.209.42 to know these server addresses, all blocked OK, no one can go to QQ, the agent software talks about it. If it can be, then it is to add a new server! See one kill one! Hey! QQ: In the current default port is 4000, send UDP, However, 1024-8000, 8001, and 28120 are also used for UDP transmission. All banned! This article comes from [System Home] www.xp85.com
Copyright © Windows knowledge All Rights Reserved