跳至主要內容
  • Hostloc 空間訪問刷分
  • 售賣場
  • 廣告位
  • 賣站?

4563博客

全新的繁體中文 WordPress 網站
  • 首頁
  • 请问怎么用 nftables 限制速率?为什么我添加的规则总是不符合我的预期?
未分類
13 2 月 2020

请问怎么用 nftables 限制速率?为什么我添加的规则总是不符合我的预期?

请问怎么用 nftables 限制速率?为什么我添加的规则总是不符合我的预期?

資深大佬 : skinny 24

操作系统:debian buster (stable) 运行环境:virtualbox 虚拟机 网络设置:bridge nftables 版本:0.9.0 

ping 命令:psping64 -t -i 0 192.168.1.177

比如,我想限制每秒只处理一个 icmp echo-request,规则配置文件如下:

#!/usr/sbin/nft -f flush ruleset  define ICMP_TYPES = {     destination-unreachable,     time-exceeded,     parameter-problem,     router-solicitation,     router-advertisement }  define ICMPV6_TYPES = {     destination-unreachable,     packet-too-big,     time-exceeded,     parameter-problem,     mld-listener-query,     mld-listener-report,     mld-listener-done,     mld-listener-reduction,     nd-router-solicit,     nd-router-advert,     nd-neighbor-solicit,     nd-neighbor-advert,     ind-neighbor-solicit,     ind-neighbor-advert,     mld2-listener-report }   table inet filter {     chain input {         type filter hook input priority 0; policy drop;          iif lo accept         ct state invalid drop         ct state { established, related } accept          icmp type echo-request limit rate 1/second accept          icmpv6 icmpv6 type $ICMPV6_TYPES accept         icmp icmp type $ICMP_TYPES accept          ip protocol igmp accept          tcp dport { ssh } accept     }      chain forward {         type filter hook forward priority 0; policy drop;     }      chain output {         type filter hook output priority 0; policy accept;     } }  

使用 fast ping 工具测试时,平均间隔 0.68ms 左右,且 0% loss 。 我尝试过添加下面的规则试图抛弃超过限制的,结果没有变化。

icmp type echo-request limit rate over 1/second drop 

还尝试过 burst <num> packets 语句,也没有用。

大佬有話說 (0)

文章導覽

上一篇文章
下一篇文章

AD

其他操作

  • 登入
  • 訂閱網站內容的資訊提供
  • 訂閱留言的資訊提供
  • WordPress.org 台灣繁體中文

51la

4563博客

全新的繁體中文 WordPress 網站
返回頂端
本站採用 WordPress 建置 | 佈景主題採用 GretaThemes 所設計的 Memory
4563博客
  • Hostloc 空間訪問刷分
  • 售賣場
  • 廣告位
  • 賣站?
在這裡新增小工具