one) Set the lifetime 
HKEY_LOCAL_MACHINE Program CurrentControlSet Companies Tcpip ParametersDefaultTTL REG_DWORD 0-0xff (0-255 decimal, default 128) 
Description: Specifies the outgoing IP packets to set the default time to live (TTL) worth. TTL decides the IP packet in the network before reaching the target greatest time for you to survive. It certainly limits the IP packet permitted to pass just before disposal number of routers. sometimes use this value to detect the remote host operating program. 
2) ICMP redirect messages to prevent the attack 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Companies  Tcpip 
 ParametersEnableICMPRedirects REG_DWORD 0x0 (default is 0x1) 
Description: This parameter controls whether or not Windows 2000 will alter its route table in response to network gadgets (like a router) to mail ICMP redirect messages to it, are often utilised to perform bad issues. Win2000 the default worth is one, that response to ICMP redirect concept. 
three) prohibit the response to ICMP packets 
 route advertisement
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Solutions  Tcpip 
 Parameters  Interfaces  interface 
PerformRouterDiscovery REG_DWORD 0x0 (default is 0x2) 
Description: Consequently suggested to turn off response of circular route ICMP packets. Win2000 the default worth is two, that once the DHCP sends the router learn choice enabled. 
four) to avoid SYN flood attacks 
HKEY_LOCAL_MACHINE  Program  CurrentControlSet  Companies 
 Tcpip  ParametersSynAttackProtect REG_DWORD 0x2 (default is 0x0) 
Description: SYN assault protection, which includes lowering the quantity of SYN-ACK re-transmission, distribution of resources to minimize the retention time. Route cache entry resources allocation delayed until finally a connection is made. If synattackprotect = 2, then the connection instructions AFD three-way handshake has been delayed to total. Note that only TcpMaxHalfOpen and TcpMaxHalfOpenRetried set out of array, the safety actions will likely be taken. 
5) prohibit the C $, D $ Default reveal 
 a class
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Companies  lanmanserver 
 ParametersAutoShareServer, REG_DWORD, 0x0 
six) prohibit the sharing of ADMIN $ default 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Companies  lanmanserver 
 ParametersAutoShareWks, REG_DWORD, 0x0 
7) limit the IPC $ default share 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Control 
 Lsarestrictanonymous REG_DWORD 0x0 default 
0x1 anonymous end users can not enumerate the nearby user record 
0x2 anonymous consumers can not connect the device IPC $ share 
Note: do not advise the use of 2, may well trigger some of your service doesn't start off, such as SQL Server 
eight) don't assistance the IGMP protocol 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Companies  Tcpip 
 ParametersIGMPLevel REG_DWORD 0x0 (default is 0x2) 
Description: The recall under Win9x has a bug, is to use so that others can use IGMP blue screen, modify the registry to fix this bug.Win2000 even though not this bug, but IGMP is not vital, as a result, can nevertheless be removed. To 0 immediately after together with the route print will not see that nasty term of 224.0.0.0. 
9) set arp cache getting older time set 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Companies:  Tcpip 
 ParametersArpCacheLife REG_DWORD 0-0xFFFFFFFF (seconds, default is 120 seconds) 
ArpCacheMinReferencedLife REG_DWORD 0-0xFFFFFFFF (seconds, default is 600) 
Note: If ArpCacheLife higher than or equivalent ArpCacheMinReferencedLife, the reference or references ARP cache entries expire in ArpCacheLife seconds. If ArpCacheLife less than ArpCacheMinReferencedLife, does not refer to goods inside the ArpCacheLife seconds expire, and references to goods in the ArpCacheMinReferencedLife seconds interval. each and every time the outbound packet for the entry from the IP handle, it will refer to ARP cache entries. 
10) prohibit the dead gateway monitoring 
HKEY_LOCAL_MACHINE  Program  CurrentControlSet  Solutions:  Tcpip 
 ParametersEnableDeadGWDetect REG_DWORD 0x0 (default is ox1) 
Note: If you happen to create numerous gateways, then your machine has difficulties in dealing with numerous connections, it'll instantly swap to a backup gateway. At times this is not a good thought, proposed to prohibit dead gateway monitoring. 
11) don't support routing 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Services:  Tcpip 
 ParametersIPEnableRouter REG_DWORD 0x0 (default is 0x0) 
Observe: the worth is set to 0x1 with Win2000 routing can thus result in needless troubles. 
twelve) to complete NAT when changing the exterior port to enlarge the utmost 
HKEY_LOCAL_MACHINE  Program  CurrentControlSet  Companies:  Tcpip 
 ParametersMaxUserPort REG_DWORD 5000-65534 (decimal) (default 0x1388 - decimal 5000) 
Description: When an application requests from the program once the variety of on the market person port, this parameter controls the maximum quantity of ports utilized. Normally, the number of short-term port allocation for the 1024-5000. This parameter is about for the successful outdoors, it is going to utilize the closest legitimate worth (5000 or 65534.) advised the worth of making use of the NAT amplification points. 
13) modify the MAC handle of 
HKEY_LOCAL_MACHINE  System  CurrentControlSet  Control  Class  
Assist to come across the right window for your 
Develop it, in its branches under 0000,
Office 2010 Activation,0001,0002 ... acquire LAN on Motherboard