关于nftables规则默认裁决的技术咨询
关于nftables规则默认裁决的技术咨询
嘿,我来帮你理清这个nftables默认裁决的问题!先把你的配置贴出来方便分析:
#!/usr/sbin/nft -f add table ip filter_4 add chain ip filter_4 input { type filter hook input priority filter; policy drop; } add chain ip filter_4 new_in_4 { comment "New input IPv4 traffic" } # Note it's goto not jump! (thus no way out of new_in_4 chain) add rule ip filter_4 input ct state new goto new_in_4 # Is this block drop or accept rule? add rule ip filter_4 new_in_4 log prefix "some comment: "
咱们一步步拆解关键点:
首先,nftables里单条规则如果没写accept/drop这类明确裁决,默认是continue——意思是执行完这条规则后,接着处理当前链的下一条规则。
然后看链的处理逻辑:
- 像
input这种带hook的「基础链」,如果所有规则都走完还没得到明确裁决,就会用链本身配置的policy(你这里设的是drop)。 - 而
new_in_4这种普通链,它的处理结果取决于你是用jump还是goto调用它:- 用
jump的话,普通链处理完会回到原链,继续执行调用位置之后的规则; - 用
goto的话,普通链处理完不会返回原链,直接触发基础链的policy。
- 用
回到你的配置:new_in_4里只有一条log规则,没有任何明确裁决,所以执行完这条log后,链里就没其他规则了。又因为你用的是goto跳转过来的,不会回到input链继续处理,直接就触发了input链的drop策略。
总结一下:这条带log的规则最终会让匹配的流量被丢弃,因为没有显式允许,最后会落到input链的默认drop策略上。
备注:内容来源于stack exchange,提问作者metablaster
相关产品推荐
相关产品推荐

