nwfilter:生成的防火墙规则没有任何意义

我试图为KVMconfigurationnwfilter,但到目前为止,我还没有设法找出一个工作configuration。

networking设置:dom0(Debian 7.1,内核3.2.46-1,libvirt 0.9.12)通过eth0(外部子网192.168.17.0/24的一部分)连接,并有一个附加的子网192.168.128.160/28路由到它的主地址192.168.17.125。

主机的子网在virsh中被configuration为网桥:

<network> <name>foo</name> <forward dev='eth0' mode='route'> <interface dev='eth0'/> </forward> <bridge name='foo-br0' stp='off' delay='0' /> <ip address='192.168.128.161' netmask='255.255.255.240'> </ip> </network> 

domU被configuration为使用该网桥(DomU中configuration的静态IP):

 <interface type='network'> <source network='foo'/> <target dev='vnet0'/> <model type='virtio'/> <filterref filter='test-eth0'> <parameter name='CTRL_IP_LEARNING' value='none'/> <parameter name='IP' value='192.168.128.162'/> </filterref> <alias name='net0'/> <address type='pci' domain='0x0000' bus='0x00' slot='0x03' function='0x0'/> </interface> 

用一个空的filter,连接正常工作。 现在,如果添加文档( http://libvirt.org/formatnwfilter.html#nwfwriteexample )中build议的示例规则集,则传入的 ICMP可以工作(但不传出),并且入站SSHstream量与出站DNS一起被阻止。

链接的规则产生以下iptables链:

 Chain INPUT (policy ACCEPT) target prot opt source destination libvirt-host-in all -- 0.0.0.0/0 0.0.0.0/0 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:67 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:67 Chain FORWARD (policy ACCEPT) target prot opt source destination libvirt-in all -- 0.0.0.0/0 0.0.0.0/0 libvirt-out all -- 0.0.0.0/0 0.0.0.0/0 libvirt-in-post all -- 0.0.0.0/0 0.0.0.0/0 ACCEPT all -- 0.0.0.0/0 192.168.128.160/28 ACCEPT all -- 192.168.128.160/28 0.0.0.0/0 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable Chain OUTPUT (policy ACCEPT) target prot opt source destination Chain FI-vnet0 (1 references) target prot opt source destination RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:22 state ESTABLISHED ctdir ORIGINAL RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:80 state ESTABLISHED ctdir ORIGINAL RETURN icmp -- 0.0.0.0/0 0.0.0.0/0 state NEW,ESTABLISHED ctdir REPLY RETURN udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53 state NEW,ESTABLISHED ctdir REPLY DROP all -- 0.0.0.0/0 0.0.0.0/0 Chain FO-vnet0 (1 references) target prot opt source destination ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 state NEW,ESTABLISHED ctdir REPLY ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 state NEW,ESTABLISHED ctdir REPLY ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 state ESTABLISHED ctdir ORIGINAL ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp spt:53 state ESTABLISHED ctdir ORIGINAL DROP all -- 0.0.0.0/0 0.0.0.0/0 Chain HI-vnet0 (1 references) target prot opt source destination RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:22 state ESTABLISHED ctdir ORIGINAL RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:80 state ESTABLISHED ctdir ORIGINAL RETURN icmp -- 0.0.0.0/0 0.0.0.0/0 state NEW,ESTABLISHED ctdir REPLY RETURN udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53 state NEW,ESTABLISHED ctdir REPLY DROP all -- 0.0.0.0/0 0.0.0.0/0 Chain libvirt-host-in (1 references) target prot opt source destination HI-vnet0 all -- 0.0.0.0/0 0.0.0.0/0 [goto] PHYSDEV match --physdev-in vnet0 Chain libvirt-in (1 references) target prot opt source destination FI-vnet0 all -- 0.0.0.0/0 0.0.0.0/0 [goto] PHYSDEV match --physdev-in vnet0 Chain libvirt-in-post (1 references) target prot opt source destination ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 PHYSDEV match --physdev-in vnet0 Chain libvirt-out (1 references) target prot opt source destination FO-vnet0 all -- 0.0.0.0/0 0.0.0.0/0 [goto] PHYSDEV match --physdev-out vnet0 

如果我从文档( http://libvirt.org/formatnwfilter.html#nwfwriteexample2nd )的第二个示例中尝试第二个filterset,则生成的防火墙规则的意义就更小了。

引用,它应该做什么:

  • 只打开VM接口的TCP端口22和80
  • 允许虚拟机从接口发送pingstream量,但不让虚拟机在接口上ping通
  • 允许虚拟机执行DNS查找(UDP端口53)
  • 启用一个ftp服务器(主动模式)在虚拟机内运行

它能做什么:

  • 打开所有传入的端口
  • 允许虚拟机被ping通
  • 阻止所有传出stream量(除了ICMP,但我怀疑这只是因为ICMP过滤根本不起作用,见上文)
  • 防止FTP服务器在主动模式下运行

我没有修改任何包含nwfilter规则集或networking堆栈的任何其他部分。 我如何让nwfilter正常运行?