Skip to content

iptables ​

iptables 的组件名称为 iptables, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
CONFIG_NETFILTER=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Advanced netfilter configuration
CONFIG_NETFILTER_ADVANCED=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Connection mark tracking support
CONFIG_NF_CONNTRACK=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Network Address Translation support
CONFIG_NF_NAT=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
CONFIG_NETFILTER_XTABLES=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_check() {
    is_error=false
    if ! kernel_config_check CONFIG_NETFILTER; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NETFILTER_ADVANCED; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NF_CONNTRACK nf_conntrack; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NF_NAT nf_nat; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NETFILTER_XTABLES x_tables; then
        is_error=true
    fi
    if [ "$is_error" == "true" ]; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -p tcp --dport 6666 --sport 6666; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -p udp --dport 6666 --sport 6666; then
        return 1
    fi
}

iptables MASQUERADE 模块 ​

iptables MASQUERADE 模块的组件名称为 iptables_masquerade, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> MASQUERADE target support
CONFIG_NETFILTER_XT_TARGET_MASQUERADE=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_masquerade_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_TARGET_MASQUERADE xt_MASQUERADE; then
        return 1
    fi

    if ! iptables_rule_check nat POSTROUTING -j MASQUERADE; then
        return 1
    fi
}

iptables connmark 模块 ​

iptables connmark 模块的组件名称为 iptables_connmark, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> ctmark target and match support
CONFIG_NETFILTER_XT_CONNMARK=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_connmark_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_CONNMARK xt_connmark; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m connmark --mark 0x66; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -j CONNMARK --set-mark 0x66; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -j CONNMARK --restore-mark; then
        return 1
    fi
}

iptables addrtype 模块 ​

iptables addrtype 模块的组件名称为 iptables_addrtype, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "addrtype" address type match support
CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_addrtype_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_ADDRTYPE xt_addrtype; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m addrtype --dst-type LOCAL; then
        return 1
    fi
}

iptables multiport 模块 ​

iptables multiport 模块的组件名称为 iptables_multiport, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "multiport" Multiple port match support
CONFIG_NETFILTER_XT_MATCH_MULTIPORT=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_multiport_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_MULTIPORT xt_multiport; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -p udp --dport 6666:6699; then
        return 1
    fi
}

iptables mark 模块 ​

iptables mark 模块的组件名称为 iptables_mark, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> nfmark target and match support
CONFIG_NETFILTER_XT_MARK=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_mark_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MARK xt_mark; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m mark --mark 0x66; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -j MARK --set-mark 0x66; then
        return 1
    fi
}

iptables comment 模块 ​

iptables comment 模块的组件名称为 iptables_comment, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "comment" match support
CONFIG_NETFILTER_XT_MATCH_COMMENT=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_comment_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_COMMENT xt_comment; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m comment --comment "dodo"; then
        return 1
    fi

    return 0
}

iptables tcpmss 模块 ​

iptables tcpmss 模块的组件名称为 iptables_tcpmss, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "TCPMSS" target support
CONFIG_NETFILTER_XT_TARGET_TCPMSS=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "tcpmss" match support
CONFIG_NETFILTER_XT_MATCH_TCPMSS=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_tcpmss_check() {
    local is_error

    is_error=false
    if ! kernel_config_check CONFIG_NETFILTER_XT_TARGET_TCPMSS xt_TCPMSS; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_TCPMSS xt_tcpmss; then
        is_error=true
    fi
    if [ "$is_error" == "true" ]; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -p tcp -m tcpmss --mss 666; then
        return 1
    fi
    if ! iptables_rule_check filter FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 666; then
        return 1
    fi

    return 0
}