Kubernetes集群中UFW拦截ICMPv6 Type133路由请求的解决咨询
Kubernetes节点cni0接口ICMPv6 Type133流量被UFW拦截问题
问题现象
Kubernetes集群工作节点上,往返cni0接口的请求被UFW拦截,UFW日志如下:
[1422854.977853] [UFW BLOCK] IN=cni0 OUT=cni0 PHYSIN=vethe715bd6d PHYSOUT=vetha18e0dfb MAC=33:33:00:00:00:02:9e:f5:29:98:19:e8:86:dd SRC=fe80:0000:0000:0000:9cf5:29ff:fe98:19e8 DST=ff02:0000:0000:0000:0000:0000:0000:0002 LEN=56 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=133 CODE=0
已尝试添加UFW接口规则,但未生效:
Anywhere on cni0 ALLOW Anywhere Anywhere (v6) on cni0 ALLOW Anywhere (v6)
查看ip6tables规则,发现已有针对部分ICMPv6类型的放行规则,但未覆盖Type133:
Chain ufw6-before-output (1 references) target prot opt source destination ACCEPT all anywhere anywhere DROP all anywhere anywhere rt type:0 ACCEPT all anywhere anywhere ctstate RELATED,ESTABLISHED ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp destination-unreachable ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp packet-too-big ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp time-exceeded ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp parameter-problem ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp echo-request ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp echo-reply ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp router-solicitation HL match HL == 255 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp neighbour-advertisement HL match HL == 255 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp neighbour-solicitation HL match HL == 255 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp router-advertisement HL match HL == 255 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmptype 141 HL match HL == 255 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmptype 142 HL match HL == 255 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 130 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 131 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 132 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 143 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmptype 148 HL match HL == 255 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmptype 149 HL match HL == 255 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 151 HL match HL == 1 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 152 HL match HL == 1 ACCEPT ipv6-icmp fe80::/10 anywhere ipv6-icmptype 153 HL match HL == 1
需求:通过UFW或直接配置iptables放行该类流量。
解决方案
方法1:直接通过ip6tables添加规则
直接在ufw6-before-output链中添加放行ICMPv6 Type133(MLD查询报文)的规则:
sudo ip6tables -A ufw6-before-output -p ipv6-icmp --icmpv6-type 133 -s fe80::/10 -j ACCEPT
若需永久生效,将规则写入UFW自定义规则文件:
- 编辑
/etc/ufw/before6.rules,在ufw6-before-output链的现有ICMPv6规则后添加:-A ufw6-before-output -p ipv6-icmp --icmpv6-type 133 -s fe80::/10 -j ACCEPT - 重启UFW:
sudo ufw reload
方法2:调整UFW规则优先级
添加更具体的UFW规则,确保优先级高于默认拦截策略:
sudo ufw allow in on cni0 proto ipv6-icmp from fe80::/10 to any icmp6-type 133 sudo ufw allow out on cni0 proto ipv6-icmp from fe80::/10 to any icmp6-type 133
重载UFW使规则生效:
sudo ufw reload
验证规则
执行以下命令确认规则已生效:
ip6tables -L ufw6-before-output -v
检查输出中是否存在针对icmptype 133的ACCEPT规则。
内容的提问来源于stack exchange,提问作者Lucas_Derks
相关产品推荐
相关产品推荐

