You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于nftables规则默认裁决的技术咨询

关于nftables规则默认裁决的技术咨询

嘿,我来帮你理清这个nftables默认裁决的问题!先把你的配置贴出来方便分析:

#!/usr/sbin/nft -f

add table ip filter_4

add chain ip filter_4 input {
    type filter hook input priority filter; policy drop;
}

add chain ip filter_4 new_in_4 {
    comment "New input IPv4 traffic"
}

# Note it's goto not jump! (thus no way out of new_in_4 chain)
add rule ip filter_4 input ct state new goto new_in_4

# Is this block drop or accept rule?
add rule ip filter_4 new_in_4 log prefix "some comment: "

咱们一步步拆解关键点:

首先,nftables里单条规则如果没写accept/drop这类明确裁决,默认是continue——意思是执行完这条规则后,接着处理当前链的下一条规则。

然后看链的处理逻辑:

  • 像input这种带hook的「基础链」,如果所有规则都走完还没得到明确裁决,就会用链本身配置的policy(你这里设的是drop)。
  • 而new_in_4这种普通链,它的处理结果取决于你是用jump还是goto调用它:
    • 用jump的话,普通链处理完会回到原链,继续执行调用位置之后的规则;
    • 用goto的话,普通链处理完不会返回原链,直接触发基础链的policy。

回到你的配置:
new_in_4里只有一条log规则,没有任何明确裁决,所以执行完这条log后,链里就没其他规则了。又因为你用的是goto跳转过来的,不会回到input链继续处理,直接就触发了input链的drop策略。

总结一下:这条带log的规则最终会让匹配的流量被丢弃,因为没有显式允许,最后会落到input链的默认drop策略上。

备注:内容来源于stack exchange,提问作者metablaster

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 06:33:03