Skip to content

iptables ​

iptables 的组件名称为 iptables, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
CONFIG_NETFILTER=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Advanced netfilter configuration
CONFIG_NETFILTER_ADVANCED=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Connection mark tracking support
CONFIG_NF_CONNTRACK=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Network Address Translation support
CONFIG_NF_NAT=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
CONFIG_NETFILTER_XTABLES=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
CONFIG_IP_NF_IPTABLES=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> raw table support (required for NOTRACK/TRACE)
CONFIG_IP_NF_RAW=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> Packet mangling
CONFIG_IP_NF_MANGLE=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> iptables NAT support
CONFIG_IP_NF_NAT=y

# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> Packet filtering
CONFIG_IP_NF_FILTER=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_check() {
    is_error=false
    if ! kernel_config_check CONFIG_NETFILTER; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NETFILTER_ADVANCED; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NF_CONNTRACK nf_conntrack; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NF_NAT nf_nat; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_NETFILTER_XTABLES x_tables; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IP_NF_IPTABLES ip_tables; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IP_NF_RAW iptable_raw; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IP_NF_MANGLE iptable_mangle; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IP_NF_NAT iptable_nat; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IP_NF_FILTER iptable_filter; then
        is_error=true
    fi
    if [ "$is_error" == "true" ]; then
        return 1
    fi

    local tables="raw mangle nat filter"

    for table in $tables; do
        local chains

        case $table in
            "raw")
                chains="PREROUTING OUTPUT"
                ;;
            "mangle")
                chains="PREROUTING INPUT FORWARD OUTPUT POSTROUTING"
                ;;
            "nat")
                chains="PREROUTING INPUT OUTPUT POSTROUTING"
                ;;
            "filter")
                chains="INPUT FORWARD OUTPUT"
                ;;
            *)
                echo "invalid table '$table'"
                return 1
                ;;
        esac

        for chain in $chains; do
            if ! iptables_rule_check $table $chain -p tcp --dport 6666 --sport 6666; then
                return 1
            fi
            if ! iptables_rule_check $table $chain -p udp --dport 6666 --sport 6666; then
                return 1
            fi
        done
    done

    return 0
}

iptables MASQUERADE 模块 ​

iptables MASQUERADE 模块的组件名称为 iptables_masquerade, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> MASQUERADE target support
CONFIG_NETFILTER_XT_TARGET_MASQUERADE=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_masquerade_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_TARGET_MASQUERADE xt_MASQUERADE; then
        return 1
    fi

    if ! iptables_rule_check nat POSTROUTING -j MASQUERADE; then
        return 1
    fi
}

iptables connmark 模块 ​

iptables connmark 模块的组件名称为 iptables_connmark, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> ctmark target and match support
CONFIG_NETFILTER_XT_CONNMARK=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_connmark_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_CONNMARK xt_connmark; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m connmark --mark 0x66; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -j CONNMARK --set-mark 0x66; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -j CONNMARK --restore-mark; then
        return 1
    fi
}

iptables addrtype 模块 ​

iptables addrtype 模块的组件名称为 iptables_addrtype, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "addrtype" address type match support
CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_addrtype_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_ADDRTYPE xt_addrtype; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m addrtype --dst-type LOCAL; then
        return 1
    fi
}

iptables multiport 模块 ​

iptables multiport 模块的组件名称为 iptables_multiport, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "multiport" Multiple port match support
CONFIG_NETFILTER_XT_MATCH_MULTIPORT=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_multiport_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_MULTIPORT xt_multiport; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -p udp --dport 6666:6699; then
        return 1
    fi
}

iptables mark 模块 ​

iptables mark 模块的组件名称为 iptables_mark, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> nfmark target and match support
CONFIG_NETFILTER_XT_MARK=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_mark_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MARK xt_mark; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m mark --mark 0x66; then
        return 1
    fi
    if ! iptables_rule_check mangle PREROUTING -j MARK --set-mark 0x66; then
        return 1
    fi
}

iptables comment 模块 ​

iptables comment 模块的组件名称为 iptables_comment, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "comment" match support
CONFIG_NETFILTER_XT_MATCH_COMMENT=y

检查工具为

bash
#!/bin/bash

source ./kernel_config_utils.sh
source ./net_utils.sh

iptables_comment_check() {
    if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_COMMENT xt_comment; then
        return 1
    fi

    if ! iptables_rule_check mangle PREROUTING -m comment --comment "dodo"; then
        return 1
    fi

    return 0
}