Debian 11下firewalld+nftables规则不生效问题及hosts文件修改后的疑问
Debian 11下firewalld+nftables规则不生效问题及hosts文件修改后的疑问
原问题描述
我在一台Debian 11服务器上(未运行NetworkManager)尝试用firewalld开放端口,用的是之前在其他机器上成功运行过的命令,不管加不加--permanent参数都试过了。用nft list ruleset能看到规则确实已经加载,但机器上的服务始终无法被外部访问:VNC Viewer提示「连接被计算机拒绝」,就连我在11000端口运行的Python echo服务器也连不上,说明这不是某个服务的问题,是端口开放的问题。我试过显式给firewalld指定网卡接口,也重启过机器,但都没用。到底为啥这些端口没开放?
执行sudo firewall-cmd --list-all的输出:
public (active) target: default icmp-block-inversion: no interfaces: enp4s0f0 sources: services: dhcpv6-client http https ldap ldaps nfs postgresql rsyncd ssh vnc-server ports: 1024-65535/tcp 1024-65535/udp protocols: forward: no masquerade: no forward-ports: source-ports: icmp-blocks: rich rules:
执行sudo nft list table inet firewalld的输出:
table inet firewalld { chain raw_PREROUTING { type filter hook prerouting priority raw + 10; policy accept; icmpv6 type { nd-router-advert, nd-neighbor-solicit } accept meta nfproto ipv6 fib saddr . iif oif missing drop } chain mangle_PREROUTING { type filter hook prerouting priority mangle + 10; policy accept; jump mangle_PREROUTING_POLICIES_pre jump mangle_PREROUTING_ZONES jump mangle_PREROUTING_POLICIES_post } chain mangle_PREROUTING_POLICIES_pre { jump mangle_PRE_policy_allow-host-ipv6 } chain mangle_PREROUTING_ZONES { iifname "enp4s0f0" goto mangle_PRE_public goto mangle_PRE_public } chain mangle_PREROUTING_POLICIES_post { } chain filter_INPUT { type filter hook input priority filter + 10; policy accept; ct state { established, related } accept ct status dnat accept iifname "lo" accept jump filter_INPUT_POLICIES_pre jump filter_INPUT_ZONES jump filter_INPUT_POLICIES_post ct state { invalid } drop reject with icmpx type admin-prohibited } chain filter_FORWARD { type filter hook forward priority filter + 10; policy accept; ct state { established, related } accept ct status dnat accept iifname "lo" accept ip6 daddr { ::/96, ::ffff:0.0.0.0/96, 2002::/24, 2002:a00::/24, 2002:7f00::/24, 2002:a9fe::/32, 2002:ac10::/28, 2002:c0a8::/32, 2002:e000::/19 } reject with icmpv6 type addr-unreachable jump filter_FORWARD_POLICIES_pre jump filter_FORWARD_IN_ZONES jump filter_FORWARD_OUT_ZONES jump filter_FORWARD_POLICIES_post ct state { invalid } drop reject with icmpx type admin-prohibited } chain filter_OUTPUT { type filter hook output priority filter + 10; policy accept; oifname "lo" accept ip6 daddr { ::/96, ::ffff:0.0.0.0/96, 2002::/24, 2002:a00::/24, 2002:7f00::/24, 2002:a9fe::/32, 2002:ac10::/28, 2002:c0a8::/32, 2002:e000::/19 } reject with icmpv6 type addr-unreachable jump filter_OUTPUT_POLICIES_pre jump filter_OUTPUT_POLICIES_post } chain filter_INPUT_POLICIES_pre { jump filter_IN_policy_allow-host-ipv6 } chain filter_INPUT_ZONES { iifname "enp4s0f0" goto filter_IN_public goto filter_IN_public } chain filter_INPUT_POLICIES_post { } chain filter_FORWARD_POLICIES_pre { } chain filter_FORWARD_IN_ZONES { iifname "enp4s0f0" goto filter_FWDI_public goto filter_FWDI_public } chain filter_FORWARD_OUT_ZONES { oifname "enp4s0f0" goto filter_FWDO_public goto filter_FWDO_public } chain filter_FORWARD_POLICIES_post { } chain filter_OUTPUT_POLICIES_pre { } chain filter_OUTPUT_POLICIES_post { } chain filter_IN_public { jump filter_IN_public_pre jump filter_IN_public_log jump filter_IN_public_deny jump filter_IN_public_allow jump filter_IN_public_post meta l4proto { icmp, ipv6-icmp } accept } chain filter_IN_public_pre { } chain filter_IN_public_log { } chain filter_IN_public_deny { } chain filter_IN_public_allow { tcp dport 22 ct state { new, untracked } accept ip6 daddr fe80::/64 udp dport 546 ct state { new, untracked } accept tcp dport 80 ct state { new, untracked } accept tcp dport 443 ct state { new, untracked } accept tcp dport 389 ct state { new, untracked } accept tcp dport 636 ct state { new, untracked } accept tcp dport 2049 ct state { new, untracked } accept tcp dport 5432 ct state { new, untracked } accept tcp dport 873 ct state { new, untracked } accept udp dport 873 ct state { new, untracked } accept tcp dport 5900-5903 ct state { new, untracked } accept tcp dport 1024-65535 ct state { new, untracked } accept udp dport 1024-65535 ct state { new, untracked } accept } chain filter_IN_public_post { } chain filter_FWDO_public { jump filter_FWDO_public_pre jump filter_FWDO_public_log jump filter_FWDO_public_deny jump filter_FWDO_public_allow jump filter_FWDO_public_post } chain filter_FWDO_public_pre { } chain filter_FWDO_public_log { } chain filter_FWDO_public_deny { } chain filter_FWDO_public_allow { } chain filter_FWDO_public_post { } chain filter_FWDI_public { jump filter_FWDI_public_pre jump filter_FWDI_public_log jump filter_FWDI_public_deny jump filter_FWDI_public_allow jump filter_FWDI_public_post meta l4proto { icmp, ipv6-icmp } accept } chain filter_FWDI_public_pre { } chain filter_FWDI_public_log { } chain filter_FWDI_public_deny { } chain filter_FWDI_public_allow { } chain filter_FWDI_public_post { } chain mangle_PRE_public { jump mangle_PRE_public_pre jump mangle_PRE_public_log jump mangle_PRE_public_deny jump mangle_PRE_public_allow jump mangle_PRE_public_post } chain mangle_PRE_public_pre { } chain mangle_PRE_public_log { } chain mangle_PRE_public_deny { } chain mangle_PRE_public_allow { } chain mangle_PRE_public_post { } chain filter_IN_policy_allow-host-ipv6 { jump filter_IN_policy_allow-host-ipv6_pre jump filter_IN_policy_allow-host-ipv6_log jump filter_IN_policy_allow-host-ipv6_deny jump filter_IN_policy_allow-host-ipv6_allow jump filter_IN_policy_allow-host-ipv6_post } chain filter_IN_policy_allow-host-ipv6_pre { } chain filter_IN_policy_allow-host-ipv6_log { } chain filter_IN_policy_allow-host-ipv6_deny { } chain filter_IN_policy_allow-host-ipv6_allow { icmpv6 type nd-neighbor-advert accept icmpv6 type nd-neighbor-solicit accept icmpv6 type nd-router-advert accept icmpv6 type nd-redirect accept } chain filter_IN_policy_allow-host-ipv6_post { } chain mangle_PRE_policy_allow-host-ipv6 { jump mangle_PRE_policy_allow-host-ipv6_pre jump mangle_PRE_policy_allow-host-ipv6_log jump mangle_PRE_policy_allow-host-ipv6_deny jump mangle_PRE_policy_allow-host-ipv6_allow jump mangle_PRE_policy_allow-host-ipv6_post } chain mangle_PRE_policy_allow-host-ipv6_pre { } chain mangle_PRE_policy_allow-host-ipv6_log { } chain mangle_PRE_policy_allow-host-ipv6_deny { } chain mangle_PRE_policy_allow-host-ipv6_allow { } chain mangle_PRE_policy_allow-host-ipv6_post { } }
问题解决(但有疑问)
后来我尝试了一个操作,居然解决了端口无法访问的问题:把/etc/hosts里类似下面的这行注释掉,重启机器后,防火墙就正常开放了预期的端口:
#127.0.1.1 my-host.domain.edu my-host
我会想到这么试是因为之前关闭防火墙测试时发现,服务绑定到空字符串''就能正常接受连接,但绑定到主机名my-host就不行——这时候服务只绑定到了127.0.1.1这个本地回环地址,而不是服务器的外部IP。
不过我现在搞不懂的是:为什么修改/etc/hosts文件会影响firewalld的行为?我明明已经在firewalld里指定了规则要应用的网卡接口啊。
备注:内容来源于stack exchange,提问作者elliotta
相关产品推荐
相关产品推荐

