iptables规则无法允许特定ZeroTier VPN后端IP通信的问题排查求助
iptables规则无法允许特定ZeroTier VPN后端IP通信的问题排查求助
我现在遇到一个iptables配置的问题,折腾了好久都没搞明白,想请教下各位大佬。
环境信息
- 我的主机有两个网络接口:WiFi(wlp0s20f3)和ZeroTier站点到站点VPN(ztklh3tu4b)
- 两个网卡的详细信息如下:
root@host:~# ifconfig wlp0s20f3 wlp0s20f3: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 192.168.1.38 netmask 255.255.255.0 broadcast 192.168.1.255 inet6 fe80::a098:2166:78af:d78d prefixlen 64 scopeid 0x20<link> ether ac:12:03:ab:6e:31 txqueuelen 1000 (Ethernet) RX packets 1071869 bytes 1035656551 (1.0 GB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 911450 bytes 134092251 (134.0 MB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
root@host:~# ifconfig ztklh3tu4b ztklh3tu4b: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 2800 inet 10.147.18.192 netmask 255.255.255.0 broadcast 10.147.18.255 inet6 fe80::f8f6:d1ff:fe3d:4f09 prefixlen 64 scopeid 0x20<link> ether fa:f6:d1:3d:4f:09 txqueuelen 1000 (Ethernet) RX packets 8836 bytes 1146994 (1.1 MB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 667 bytes 281732 (281.7 KB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
需求与配置的iptables规则
我想要阻止主机的所有入站和出站流量,仅允许和VPN后端的特定IP(10.147.18.80)通信,于是配置了以下规则:
iptables -P INPUT DROP iptables -P OUTPUT DROP iptables -P FORWARD DROP iptables -A INPUT -s 10.147.18.80 -j ACCEPT iptables -A OUTPUT -d 10.147.18.80 -j ACCEPT
问题现象
配置完成后,我无法ping通10.147.18.80,ping结果如下:
root@host:~# ping 10.147.18.80 PING 10.147.18.80 (10.147.18.80) 56(84) bytes of data. ^C --- 10.147.18.80 ping statistics --- 6 packets transmitted, 0 received, 100% packet loss, time 5097ms
(测试ping公网8.8.8.8也是全丢包,这符合预期,但连目标VPN IP也不通就很奇怪)
更诡异的是,如果我把规则里的IP换成8.8.8.8,一切就正常了——主机只能和8.8.8.8通信,其他所有地址都连不上,完全符合我的规则预期。
已做的排查信息
- 查看iptables规则链状态:
root@host:~# iptables -nvL Chain INPUT (policy DROP 23 packets, 4560 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * 10.147.18.80 0.0.0.0/0 Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy DROP 330 packets, 25776 bytes) pkts bytes target prot opt in out source destination 8 672 ACCEPT all -- * * 0.0.0.0/0 10.147.18.80
从输出能看到,出站数据包已经被允许发送(有8个包、672字节的统计),但没有收到任何回复数据包。
- 本地tcpdump抓包:
tcpdump: data link type LINUX_SLL2 tcpdump: listening on any, link-type LINUX_SLL2 (Linux cooked v2), snapshot length 262144 bytes 13:28:32.323064 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17342, offset 0, flags [DF], proto ICMP (1), length 84) 10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 1, length 64 13:28:33.330145 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17567, offset 0, flags [DF], proto ICMP (1), length 84) 10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 2, length 64 13:28:34.354178 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17694, offset 0, flags [DF], proto ICMP (1), length 84) 10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 3, length 64 13:28:35.378135 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17714, offset 0, flags [DF], proto ICMP (1), length 84) 10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 4, length 64
可以看到主机确实从ZeroTier接口发送了ICMP请求包,但在目标IP(10.147.18.80)上抓包,完全看不到这些请求包进来。
求助问题
我实在搞不懂问题出在哪,为什么换成公网IP就正常,VPN内的IP反而不行?有没有大佬能帮我分析下可能的原因,或者下一步该怎么排查?
备注:内容来源于stack exchange,提问作者Muhammad Saboor
相关产品推荐
相关产品推荐

