You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes集群中UFW拦截ICMPv6 Type133路由请求的解决咨询

Kubernetes节点cni0接口ICMPv6 Type133流量被UFW拦截问题

问题现象

Kubernetes集群工作节点上,往返cni0接口的请求被UFW拦截,UFW日志如下:

[1422854.977853] [UFW BLOCK] IN=cni0 OUT=cni0 PHYSIN=vethe715bd6d PHYSOUT=vetha18e0dfb MAC=33:33:00:00:00:02:9e:f5:29:98:19:e8:86:dd SRC=fe80:0000:0000:0000:9cf5:29ff:fe98:19e8 DST=ff02:0000:0000:0000:0000:0000:0000:0002 LEN=56 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=133 CODE=0

已尝试添加UFW接口规则,但未生效:

Anywhere on cni0           ALLOW       Anywhere
Anywhere (v6) on cni0      ALLOW       Anywhere (v6)

查看ip6tables规则,发现已有针对部分ICMPv6类型的放行规则,但未覆盖Type133:

Chain ufw6-before-output (1 references)
target     prot opt source               destination
ACCEPT     all      anywhere             anywhere
DROP       all      anywhere             anywhere             rt type:0
ACCEPT     all      anywhere             anywhere             ctstate RELATED,ESTABLISHED
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp destination-unreachable
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp packet-too-big
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp time-exceeded
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp parameter-problem
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp echo-request
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp echo-reply
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp router-solicitation HL match HL == 255
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp neighbour-advertisement HL match HL == 255
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp neighbour-solicitation HL match HL == 255
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmp router-advertisement HL match HL == 255
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmptype 141 HL match HL == 255
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmptype 142 HL match HL == 255
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 130
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 131
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 132
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 143
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmptype 148 HL match HL == 255
ACCEPT     ipv6-icmp    anywhere             anywhere             ipv6-icmptype 149 HL match HL == 255
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 151 HL match HL == 1
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 152 HL match HL == 1
ACCEPT     ipv6-icmp    fe80::/10            anywhere             ipv6-icmptype 153 HL match HL == 1

需求:通过UFW或直接配置iptables放行该类流量。


解决方案

方法1:直接通过ip6tables添加规则

直接在ufw6-before-output链中添加放行ICMPv6 Type133(MLD查询报文)的规则:

sudo ip6tables -A ufw6-before-output -p ipv6-icmp --icmpv6-type 133 -s fe80::/10 -j ACCEPT

若需永久生效,将规则写入UFW自定义规则文件:

  1. 编辑/etc/ufw/before6.rules,在ufw6-before-output链的现有ICMPv6规则后添加:
    -A ufw6-before-output -p ipv6-icmp --icmpv6-type 133 -s fe80::/10 -j ACCEPT
    
  2. 重启UFW:
    sudo ufw reload
    

方法2:调整UFW规则优先级

添加更具体的UFW规则,确保优先级高于默认拦截策略:

sudo ufw allow in on cni0 proto ipv6-icmp from fe80::/10 to any icmp6-type 133
sudo ufw allow out on cni0 proto ipv6-icmp from fe80::/10 to any icmp6-type 133

重载UFW使规则生效:

sudo ufw reload

验证规则

执行以下命令确认规则已生效:

ip6tables -L ufw6-before-output -v

检查输出中是否存在针对icmptype 133的ACCEPT规则。


内容的提问来源于stack exchange,提问作者Lucas_Derks

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 03:25:35