You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iptables规则无法允许特定ZeroTier VPN后端IP通信的问题排查求助

iptables规则无法允许特定ZeroTier VPN后端IP通信的问题排查求助

我现在遇到一个iptables配置的问题,折腾了好久都没搞明白,想请教下各位大佬。

环境信息

  • 我的主机有两个网络接口:WiFi(wlp0s20f3)和ZeroTier站点到站点VPN(ztklh3tu4b)
  • 两个网卡的详细信息如下:
root@host:~# ifconfig wlp0s20f3
wlp0s20f3: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
inet 192.168.1.38  netmask 255.255.255.0  broadcast 192.168.1.255
inet6 fe80::a098:2166:78af:d78d  prefixlen 64  scopeid 0x20<link>
ether ac:12:03:ab:6e:31  txqueuelen 1000  (Ethernet)
RX packets 1071869  bytes 1035656551 (1.0 GB)
RX errors 0  dropped 0  overruns 0  frame 0
TX packets 911450  bytes 134092251 (134.0 MB)
TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
root@host:~# ifconfig ztklh3tu4b
ztklh3tu4b: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 2800
inet 10.147.18.192  netmask 255.255.255.0  broadcast 10.147.18.255
inet6 fe80::f8f6:d1ff:fe3d:4f09  prefixlen 64  scopeid 0x20<link>
ether fa:f6:d1:3d:4f:09  txqueuelen 1000  (Ethernet)
RX packets 8836  bytes 1146994 (1.1 MB)
RX errors 0  dropped 0  overruns 0  frame 0
TX packets 667  bytes 281732 (281.7 KB)
TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

需求与配置的iptables规则

我想要阻止主机的所有入站和出站流量,仅允许和VPN后端的特定IP(10.147.18.80)通信,于是配置了以下规则:

iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP

iptables -A INPUT -s 10.147.18.80 -j ACCEPT
iptables -A OUTPUT -d 10.147.18.80 -j ACCEPT

问题现象

配置完成后,我无法ping通10.147.18.80,ping结果如下:

root@host:~# ping 10.147.18.80
PING 10.147.18.80 (10.147.18.80) 56(84) bytes of data.
^C
--- 10.147.18.80 ping statistics ---
6 packets transmitted, 0 received, 100% packet loss, time 5097ms

(测试ping公网8.8.8.8也是全丢包,这符合预期,但连目标VPN IP也不通就很奇怪)

更诡异的是,如果我把规则里的IP换成8.8.8.8,一切就正常了——主机只能和8.8.8.8通信,其他所有地址都连不上,完全符合我的规则预期。

已做的排查信息

  1. 查看iptables规则链状态:
root@host:~# iptables -nvL
Chain INPUT (policy DROP 23 packets, 4560 bytes)
pkts bytes target     prot opt in     out     source               destination
0     0 ACCEPT     all  --  *      *       10.147.18.80         0.0.0.0/0

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target     prot opt in     out     source               destination

Chain OUTPUT (policy DROP 330 packets, 25776 bytes)
pkts bytes target     prot opt in     out     source               destination
8   672 ACCEPT     all  --  *      *       0.0.0.0/0            10.147.18.80

从输出能看到,出站数据包已经被允许发送(有8个包、672字节的统计),但没有收到任何回复数据包。

  1. 本地tcpdump抓包:
tcpdump: data link type LINUX_SLL2
tcpdump: listening on any, link-type LINUX_SLL2 (Linux cooked v2), snapshot length 262144 bytes
13:28:32.323064 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17342, offset 0, flags [DF], proto ICMP (1), length 84)
10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 1, length 64
13:28:33.330145 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17567, offset 0, flags [DF], proto ICMP (1), length 84)
10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 2, length 64
13:28:34.354178 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17694, offset 0, flags [DF], proto ICMP (1), length 84)
10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 3, length 64
13:28:35.378135 ztklh3tu4b Out IP (tos 0x0, ttl 64, id 17714, offset 0, flags [DF], proto ICMP (1), length 84)
10.147.18.192 > 10.147.18.80: ICMP echo request, id 61, seq 4, length 64

可以看到主机确实从ZeroTier接口发送了ICMP请求包,但在目标IP(10.147.18.80)上抓包,完全看不到这些请求包进来。

求助问题

我实在搞不懂问题出在哪,为什么换成公网IP就正常,VPN内的IP反而不行?有没有大佬能帮我分析下可能的原因,或者下一步该怎么排查?

备注:内容来源于stack exchange,提问作者Muhammad Saboor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 12:57:44