IPtables规则阻断apt更新且tcpdump无法捕获丢包问题求助
IPtables规则阻断apt更新且tcpdump无法捕获丢包问题求助
各位好,我遇到一个棘手的问题:我的IPtables规则似乎完全阻断了apt update的正常运行,而且tcpdump还抓不到相关的丢包流量,实在摸不着头绪,想请大家帮忙排查下。
先给大家看执行apt update时的错误输出:
root@vpn:~# apt update Ign:1 https://pkgs.tailscale.com/stable/ubuntu jammy InRelease Ign:2 http://de.archive.ubuntu.com/ubuntu jammy InRelease Ign:3 http://de.archive.ubuntu.com/ubuntu jammy-updates InRelease Ign:1 https://pkgs.tailscale.com/stable/ubuntu jammy InRelease Ign:4 http://de.archive.ubuntu.com/ubuntu jammy-backports InRelease Ign:1 https://pkgs.tailscale.com/stable/ubuntu jammy InRelease Ign:5 http://de.archive.ubuntu.com/ubuntu jammy-security InRelease Err:1 https://pkgs.tailscale.com/stable/ubuntu jammy InRelease Temporary failure resolving 'pkgs.tailscale.com' Ign:2 http://de.archive.ubuntu.com/ubuntu jammy InRelease Ign:3 http://de.archive.ubuntu.com/ubuntu jammy-updates InRelease Ign:4 http://de.archive.ubuntu.com/ubuntu jammy-backports InRelease Ign:5 http://de.archive.ubuntu.com/ubuntu jammy-security InRelease Ign:2 http://de.archive.ubuntu.com/ubuntu jammy InRelease Ign:3 http://de.archive.ubuntu.com/ubuntu jammy-updates InRelease Ign:4 http://de.archive.ubuntu.com/ubuntu jammy-backports InRelease Ign:5 http://de.archive.ubuntu.com/ubuntu jammy-security InRelease Err:2 http://de.archive.ubuntu.com/ubuntu jammy InRelease Temporary failure resolving 'de.archive.ubuntu.com' Err:3 http://de.archive.ubuntu.com/ubuntu jammy-updates InRelease Temporary failure resolving 'de.archive.ubuntu.com' Err:4 http://de.archive.ubuntu.com/ubuntu jammy-backports InRelease Temporary failure resolving 'de.archive.ubuntu.com' Err:5 http://de.archive.ubuntu.com/ubuntu jammy-security InRelease Temporary failure resolving 'de.archive.ubuntu.com' Reading package lists... Done Building dependency tree... Done Reading state information... Done All packages are up to date. W: Failed to fetch http://de.archive.ubuntu.com/ubuntu/dists/jammy/InRelease Temporary failure resolving 'de.archive.ubuntu.com' W: Failed to fetch http://de.archive.ubuntu.com/ubuntu/dists/jammy-updates/InRelease Temporary failure resolving 'de.archive.ubuntu.com' W: Failed to fetch http://de.archive.ubuntu.com/ubuntu/dists/jammy-backports/InRelease Temporary failure resolving 'de.archive.ubuntu.com' W: Failed to fetch http://de.archive.ubuntu.com/ubuntu/dists/jammy-security/InRelease Temporary failure resolving 'de.archive.ubuntu.com' W: Failed to fetch https://pkgs.tailscale.com/stable/ubuntu/dists/jammy/InRelease Temporary failure resolving 'pkgs.tailscale.com' W: Some index files failed to download. They have been ignored, or old ones used instead. root@vpn:~#
我知道apt更新会用到80或443端口的出站流量,而且INPUT链里已经配置了允许ESTABLISHED状态的流量,但还是出现了上面的问题。以下是我的IPtables规则:
先看iptables -S的输出:
root@vpn:~# iptables -S -P INPUT DROP -P FORWARD DROP -P OUTPUT ACCEPT -A INPUT -p icmp -j ACCEPT -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT root@vpn:~#
再看iptables -L -nv的输出:
root@vpn:~# iptables -L -nv Chain INPUT (policy DROP 320 packets, 22536 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 5039 226K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 127 22352 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED Chain FORWARD (policy DROP 80 packets, 4160 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 8759 packets, 869K bytes) pkts bytes target prot opt in out source destination root@vpn:~#
奇怪的是,当这些规则生效时,我用tcpdump几乎看不到任何和apt相关的流量——服务器甚至连尝试连接源地址的数据包都没有,只能看到我本地PC通过22端口SSH连接的流量,以及一些ARP消息。而且内核丢包量很高:
25 packets captured 373 packets received by filter 292 packets dropped by kernel
关键是,被内核丢弃的包我在tcpdump里完全看不到,系统日志里也没有相关记录。
但只要我把所有链的策略改成ACCEPT,并清空所有规则,apt更新就完全正常了,这就让我更困惑了。
补充信息:
- 我制作了一个分屏的tcpdump测试动画(Firewall_tcpdump_split_view),之前的测试动图已经移除,这个动画能更清晰展示测试过程。
- 有朋友问到路由信息,我也贴出来,全程VPN是关闭状态,也没有运行Docker之类的服务,如果需要其他信息可以告诉我,我不太清楚哪些是排查的关键点。
路由信息输出:
root@vpn:~# ip route default via 192.168.178.1 dev ens18 proto static 192.168.178.0/24 dev ens18 proto kernel scope link src 192.168.178.49
备注:内容来源于stack exchange,提问作者Hige Mynx
相关产品推荐
相关产品推荐

