ÖÐÎÄ
Ðû²¼Ê±¼ä£º2020-11-02
±¾ÎÄ×÷Õߣº°¢²ý
СÈñ¾³£½Óµ½¿Í»§µÄ·´ÏìÊÇ£¬·À»ðǽ°²ÅźÃÁË¿ÉÊÇÓªÒµÕÕ¾ÉÇ·ºà£¬ÍùÍùÒ»³ïĪչ¡£½ñÌìСÈñ£¬²»²Ø×ÅÒ´×ÅÁË£¬°ÑÊղضàÄêµÄ¼ÑÄ𣬹ÊÕÏСÇÏÃÅÄóöÀ´ÈÃϲ»¶Ð¡ÈñµÄ¸÷ÈËϸƷϸƷ¡£
·À»ðǽµÄÇå¾²¼ì²éÌØÕ÷
ÍøÂçÔ´ÓÚÉúÑÄÈ´ÓÖ¸ßÓÚÉúÑÄ£¬×÷ÎªÍøÂçÌìÏ´óÃŵͦ¶¦Ì¨¸¦µÄ“Çå¾²¼ì²é¹Ù“ÏÂÒ»´ú·À»ðǽ£¬ÓÐËû×Ô¼ºÌØÓеēÇå¾²ÊôÐÔ”£¬×ñÊØÍøÂçÌìϵēÇå¾²¹æÔò”£¬ÎÒÃǾÍÄܸüºÃµÄÔÚ·À»ðǽµÄ¹ÊÕÏÅŲéÀú³ÌÖÐÓÎÈÐÓÐÓà¡£ÕâЩ“Çå¾²ÊôÐÔ”µ¹³ÉÁËÎÒÃÇÔÚʵÑé·À»ðǽÀú³ÌÖеē°í½Åʯ”£¬ËäÈ»ÅŲé¹ÊÕÏÀú³ÌÊÇÍ´¿àµÄ£¬½â¾öÎÊÌâºóµÄ¿ìÀÖÊÇÓÀÔ¶Ãú¿ÌÖµµÃ»ØÎ¶µÄ¡£
·À»ðǽΪÁËÏàÐÅÊý¾Ý°üÊÇ¿ÉÐŵģ¬ÔÚÊÕµ½Êý¾Ý°üµÄʱ¼äÉèÖÃÁËÁ½¸ö“Çå¾²¼ì²éµã”£º
1 ·´Ïò·¾¶¼ì²éReverse Path Forwarding (RPF)
2 Òì²½¼ì²é£¨asymroute£¬Ò²¾ÍÊǸ÷È˳£ËµµÄÅþÁ¬ÍêÕûÐÔ¼ì²é£©
Á½Ïî¼ì²éÖ»Óж¼Çкϣ¬²Å»á¼ÌÐøÆäËûÄ£¿é¼ì²é£¬²»È»Ö±½ÓÑïÆúÊý¾Ý°ü£¬ÄÇÕë¶ÔÕâÁ½¸ö¼ì²éÌØÕ÷ÎÒÃÇÕö¿ªÁÄÁÄ£º
·´Ïò·¾¶¼ì²é
Ëùν·´Ïò·¾¶¼ì²é£¬¼òÆÓ¾ÙÀý£¬¾ÍÊÇÈôÊÇ´ÓÄÚÍø¿Úport31ÊÕµ½Ò»¸öÊý¾Ý°ü£¬·´ÏòµÄ»Ø°ü±ØÐè´ÓÄÚÍø¿Úport31»ØÈ¥£¬Ò²¾ÍÊÇҪȷ±£Ô´½øÔ´³ö£¬·´Ö®ÒÔΪ´ËÊý¾Ý°üΪÓÕÆ°üÖ´ÐÐÑïÆúÐж¯¡£¼ÙÉ裬·À»ðǽÊÕµ½Êý¾Ý°üÊÇsrc_addr_ip->dst_addr_ipΪ172.16.1.16->219.222.191.72£¬·À»ðǽ²»»áÖ´ÐÐÆäËûÄ£¿é¼ì²é£¨ÕâЩģ¿é»áÉæ¼°µ½Ô´Ä¿µÄµØÖ·×ª»»¡¢UTMµÈ£©£¬¶øÊÇÏÈÖ´Ðз´Ïò·¾¶¼ì²é£¬Æ¾Ö¤·´ÏòÁ÷Á¿219.222.191.72->172.16.1.16£¬ÔÚ²éÕÒ·ÓɱíºóÈôÊÇÒ²ÊÇ´Óport31³öÈ¥µÄ£¬ËµÃ÷Á÷Á¿ÊÇÕý³£µÄ£¬¼ÌÐø´¦Öóͷ£ÆäËûÄ£¿é¼ì²é£»ÈôÊDZ£´æÁíÒ»¸ö·ÓÉͨ·ºÃ±È´Óport32³öÈ¥»òÕßÉõÖÁûÓвéÕÒµ½ÏìӦ·ÓÉ£¬Õâ¸ö½«µ¼Ö·´Ïò·¾¶¼ì²éʧ°Ü·À»ðǽִÐÐÑïÆúÐж¯¡£
ʹÓÃdebug flow×¥°üÏÂÁ»á·¢Ã÷ÓиöÌáÐÑΪ£ºreverse path check fail, drop£¬ÌØÊâÏÔÑÛ£¬Õâ¸öÌáÐѾÍÊÇÒò·´Ïò·¾¶¼ì²éʧ°ÜÖ±½ÓÖ´ÐÐÁËÑïÆúÐж¯ÁË£¬ÕâÖÖÇéÐν¨ÒéÊDzéһϷÀ»ðǽÉϵÄ·ÓÉÉèÖÃÎÊÌâ¡£
Ò첽·Óɼì²é
ËùνÒ첽·Óɼì²é£¬¾ÍÊÇҪȷ±£Íù·µÂ·¾¶ÒªÒ»Ö£¬°ü¹ÜÊý¾ÝÅþÁ¬µÄÍêÕûÐÔ¡£È磺tcpµÄÈý´ÎÎÕÊÖµÄÊý¾Ý°ü¶¼Òª¹ý·À»ðǽ£¬Õý³£µÄtcpÈý´ÎÎÕÊÖ½»»¥Àú³ÌÈçÏ£º
ÈôÊÇ·ºÆðÍù·µÂ·¾¶·×ÆçÖµÄÇéÐΣ¬·À»ðǽÒÔΪ±¨ÎÄÓÐÎÊÌâÖ±½ÓÑïÆú¡£
СÈñÏÖÔÚ¾Í˵˵ÕâÁ÷Á¿×ª·¢ÄÇÀï·ºÆðÎÊÌâÁË£¬´ÓÁ÷Á¿×ª·¢À´¿´PC1»á¼û·þÎñÆ÷µÄÁ÷Á¿tcp syn±¨ÎÄת·¢Â·¾¶ÊÇ
PC1->RouterA->NGFW->RouterB->internet->Server£¬»Ø°üsyn+ackµÄת·¢Â·¾¶ÊÇInternet>RouterB>RouterA->PC1£¬Î´¾ÓÉ·À»ðǽ£¬ack±¨ÎÄPC1->RouterA->NGFW(ÑïÆú±¨ÎIJ»×ª·¢)£¬·À»ðǽ·¢Ã÷»á»°×´Ì¬²»ÍêÕû£¨ÎÒûÓп´µ½syn+ack,ÎÒ²»ÐÅÈÎÄ㣩£¬Ö´ÐÐÑïÆúÐж¯¡£
ʹÓÃdebug flowÏÂÁî¶ÔÊý¾ÝÁ÷ÆÊÎöÒ»Ñùƽ³£»áÌáÐÑΪ£º“org dir, ack in state syn_sent, drop”

ËäÈ»ÕâÀïÉÐÓиüÎªÆæÝâµÄÊý¾Ýת·¢Â·¾¶£¬ÈôÊÇÊÇsyn°üת·¢Â·¾¶²»¹ý·À»ðǽ£¬syn+ackµÄ»Ø¸´±¨ÎľÓÉ·À»ðǽ£¬ÕâÖÖÇéÐÎÏ·À»ðǽÊÇÎÞ·¨ÕÒµ½¶ÔÓ¦µÄ»á»°£¨ÎÒûÓп´µ½syn£¬ÎÒѹ¸ù¾ÍûÓÐÄãµÄ»á»°£©£¬Ö±½ÓÑïÆú£¬ÕâÖÖÒ²ÊôÓÚÒ첽·ÓɵÄÒ»ÖÖÌØÊⳡ¾°¡£Ê¹ÓÃdebug flow×¥°üÏÂÁ»á·¢Ã÷ÓиöÌáÐÑΪ£º“no session matched”¡£
ÉÐÓÐÒ»ÖÖ¾ÍÊÇÍù·µµÄ¶þ²ãmac·×ÆçÖÂÎÊÌâÒ²ÊÇÒ첽·Óɼì²éµÄÒ»ÖÖÌØÀýÁË£¬Ò»Ñùƽ³£ÕâÖÖ³¡¾°³£¼ûÓÚ·À»ðǽ͸Ã÷ģʽ°²ÅŵÄʱ¼ä¡£Ò²¾ÍÊÇÈôÊǹý·À»ðǽµÄÊý¾Ý°üÊÇmac1->mac2[pc1->pc2]£¬»Ø°üµÄʱ¼äÊÇmac3->mac1[pc1->pc2]£¬ÕâÖÖÊý¾Ý°üÒ²ÊÇÓÐÎÊÌâµÄ·À»ðǽ²»»áÔÊÐí¹ýµÄ¡£
ÄÇ¿ÉÄܸ÷ÈË»áÎÊСÈñ£¬Ò첽·Óɼì²é¿ÉÒԹرÕÂð£¬ÏÖʵӪҵ³¡¾°²»½¨Ò鹨±ÕµÄ£¬×ö·¨ÊÇÕÒµ½µ¼ÖÂÍù·µÂ·¾¶·×ÆçÖµÄÔµ¹ÊÔÓÉ£¬½«Òì²½ÎÊÌâÖÕ½áµô£¬ÓÉÓÚ·À»ðǽ¹Ø±ÕÒì²½¼ì²éºó£¬¶àÁ´Â·³ö¿ÚµÄ³¡¾°Ô´½øÔ´³ö¹¦Ð§½«²»ÉúЧ£¬´úÀí·À»¤Ààutm¹¦Ð§½«ÎÞ·¨Õý³£ÊÂÇé¡£
ÒªÁìÊÇ£º
#config system settings
#set asymroute enable
#end
´ËÏÂÁî¾ÍÊÇÔÊÐí·À»ðǽ±£´æÒì²½£¬ÕâÑù·À»ðǽ¿ÉÒÔ²»¼ì²éÊý¾Ý°üµÄÅþÁ¬ÍêÕûÐÔÁË¡£
#config system settings
#set tcp-session-without-syn enable (ĬÈÏdisable)
#end
´ËÏÂÁîÊǸæËß·À»ðǽÈôÊDz»ÊÇsynµÄ±¨ÎÄÒ»ÑùÒ²¿ÉÒÔ½¨Éè»á»°¡£
Êý¾Ý°ü´©Ô½·À»ðǽ´¦Öóͷ£Àú³ÌÏê½â
Õý³£µÄÊý¾Ý°ü´©Ô½·À»ðǽ£¬ÐèÒª¾ÓÉÄÄЩÀú³ÌÄØ£¿¿ÉÒÔͨ¹ýdebug flowÏÂÁîÉó²éÕû¸öÍêÕûÀú³Ì¡£
#diagnose debug enable //¿ªÆôdebug
#diagnose debug flow show console enable //ÆôÓÃdebug flowÏÔʾ´òÓ¡£¬ÓÐЩ°æ±¾²»ÐèÒªÇÃ
#diagnose debug flow show function-name enable //ÏÔʾdebug flow ¹¦Ð§Ãû³Æ£¬±ãÓÚ´òÓ¡ÐÅÏ¢Êä³ö£¬ÓÐЩ°æ±¾¿ÉÒÔ²»±ØÇÃ
#diagnose debug flow filter addr 192.168.1.110 //¹ýÂËÌõ¼þ£¬×èÖ¹×¥°üÎÞÓÃÐÅÏ¢¹ý¶à£¬ÕâÀï¹ýÂ˵ØÖ·£¬filter £¿¿ÉÒÔÉó²é¹ýÂËÄÄЩÌõ¼þ
#diagnose debug flow trace start 100 //×îÏÈ×¥100ÌõÊý¾ÝÁ÷
ÏÂÃæÊÇÊý¾Ý°ü´©Ô½·À»ðǽµÄËùÓÐÀú³Ì£¬ÎÒÃÇÒ»ÆðÀ´¿´¿´
id=36871 trace_id=1 msg="vd-root received a packet(proto=6, 192.168.
1.110:51661->119.253.62.131:80) from internal. "id=36871 trace_id=1 msg="allocate a new session-00016920" //internal¿ÚÊÕµ½Êý¾Ý£¬½¨ÉèлỰ
id=36871 trace_id=1 msg="find a route: gw-192.168.118.1 via wan1" //²éÕÒµ½Â·Óɱí
id=36871 trace_id=1 msg="find SNAT: IP-192.168.118.28, port-43333" //¼ì²â±£´æNATÉèÖÃ
id=36871 trace_id=1 msg="Allowed by Policy-1: SNAT" //Æ¥ÅäÕ½ÂÔ,ID1
id=36871 trace_id=1 msg="SNAT 192.168.1.110->192.168.118.28:43333"//×öNAT
id=36871 trace_id=3 msg="vd-root received a packet(proto=6,
119.253.62.131:80->192.168.118.28:43333) from wan1." // Wan1¿ÚÊÕµ½·µ»ØÊý¾Ý°ü
id=36871 trace_id=3 msg="Find an existing session, id-00016920, reply direction"¡¡//Êý¾Ý°üÆ¥Åä»á»°id-0001692
id=36871 trace_id=3 msg="DNAT 192.168.118.28:43333->192.168.1.110:51661" //×ö·´ÏòµÄDNAT
id=36871 trace_id=3 msg="find a route: gw-192.168.1.110 via internal" //²éÕÒ·ÓÉ£¬·¢Ë͵½internal¿Ú
id=36871 trace_id=5 msg="vd-root received a packet(proto=6,192.168.1.110:51661->119.253.62.131:80) frominternal." //internal¿ÚÊÕµ½ºóÐøÊý¾Ý°ü
id=36871 trace_id=5 msg="Find an existing session, id-00016920, original direction" //Æ¥Åä»á»°id-0001692¡¡¡¡
id=36871 trace_id=5 msg="enter fast path" //Ö±½Óת·¢
id=36871 trace_id=5 msg="SNAT 192.168.1.110->192.168.118.28:43333" //NAT
×¥ÍêÊý¾ÝÁ÷ºó¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁî¹Ø±Õ¡£
#diagnose debug flow trace stop //×èÖ¹
#diagnose debug disable //¹Ø±Õ
#diagnose debug reset //ÖØÖÃ
#diagnose debug flow filter clear //¿ÉÒÔÇå¿ÕdebugµÄ¹ýÂËÌõ¼þÉèÖÃ
ͨ¹ýdebug flowÏÂÁîÎÒÃÇ¿ÉÒÔ¿´µ½Ò»¸öÊý¾Ý°üÁ÷Èë·À»ðǽºó£¬¸÷¸öÄ£¿éµÄÏêϸ´¦Öóͷ£ÇéÐΣ¬ÕûÀí³ÉÊý¾Ý°ü´¦Öóͷ£Á÷³ÌͼÈçÏ£º
ÏÂÃæÒ²Ò»²¢ÏÈÈÝһЩСÈñ¾³£Óöµ½µÄdebug flowÒªº¦ÐÅÏ¢ÌáÐÑ£¬ÏÖ×ܽáÈçÏ£º
ÈôÊÇÊÇÕ½ÂԾܾøÁËÊý¾Ý°ü»á¼û£¬»á¿´µ½“Denied by forward policy check”£¬ÐèÒªÖØµãÈ·ÈÏÊÇ·ñÊÇÇå¾²Õ½ÂÔ×èµ²ËùÖ¡£

ÈôÊÇÎÞ·¨Õý³£¹ÜÀí·À»ðǽµÄʱ¼ä£¬debug flowÍùÍù»á·ºÆðÌáÐÑ£¬msg="iprope_in_check() check failed, drop"£¬Ò»Ñùƽ³£»áÓÐÏÂÁÐÈýÖÖ¿ÉÄÜÔµ¹ÊÔÓÉËùÖ£º
1¡¢µ±»á¼ûNGFW¾ÙÐÐÔ¶³Ì¹ÜÀí£¨ping, telnet, ssh ...£©Ê±£¬ÕýÔÚ»á¼ûµÄ·þÎñδÔÚ½Ó¿ÚÉÏÆôÓá£
2¡¢µ±»á¼ûNGFW¾ÙÐÐÔ¶³Ì¹ÜÀíʱ£¨ping, telnet, ssh ...£©£¬ÕýÔÚ»á¼ûµÄ·þÎñÔÚ½Ó¿ÚÉÏÆôÓ㬿ÉÊÇÉèÖÃÁËÊÜÐÅÈεÄÖ÷»ú£¬ÕâЩÖ÷»úÓëÈëÕ¾Êý¾Ý°üµÄÔ´IP²»Æ¥Å䣻
3¡¢µ±Í¨¹ýͳһNGFWµÄÁíÒ»¸ö½Ó¿Ú»á¼ûÓÃÓÚÔ¶³Ì¹ÜÀíµÄNGFW½Ó¿Ú£¨ping£¬telnet£¬ssh ...£©Ê±£¬²»±£´æ·À»ðǽսÂÔ¡£
Õ½ÂÔÐж¯¾Ü¾ø,»òÖÀÖÐÒþº¬Õ½ÂÔ, Êý¾Ý°ü±»¾Ü¾ø£¬Ò»Ñùƽ³£»áÌáÐÑ£ºmsg="Denied by forward policy check"
ÈôÊÇÉæ¼°ALGÏà¹Ø»á»°£¨ÕâÀàÁ÷Á¿Ò»Ñùƽ³£ÊǶ¯Ì¬¶àͨµÀÐÒéÈçftp¡¢sipµÈ£¬´ËÀàÐÒé½ÏÖØ´ó£¬Ð¡ÈñÏ´ÎÔÙ¸ú¸÷ÈË·ÖÏí£¬ÎûÎû£©½«ËÍÖÁ session-helper Ä£¿é´¦Öóͷ££¬Ò»Ñùƽ³£»áÌáÐÑ£ºmsg="run helper-ftp(dir=original)"
¿´µ½ÕâÀСÈñÏàÐÅÄúÒ²ºÍСÈñÒ»Ñùget Á˲»ÉÙ·À»ðǽµÄ×¥°üÏÂÁîÁ˰ɣ¿ÄÇô½ÓÏÂÀ´ÎÒÃǼÌÐøÉîÈ뿴Ͻø½×°æ°¸ÀýÆÊÎö°É¡£
½ø½×°¸ÀýչʾһÏÂÏÂÁîÓкεÈÉñÆæ^-^
ÏÖ³¡·´ÏìµÄÍØÆË¼òÆÓÐÎòÈçÏ£º
È«ÐÂÏÂÒ»´ú·À»ðǽ×ö¶Ë¿ÚÓ³É䣬²¿·ÖISP×¨ÍøIP»á¼û¶Ë¿ÚÓ³ÉäµÄӪҵǷºà¡£»ù´¡µÄÉèÖüì²éҲûÓп´³öÎÊÌâËùÔÚ£¬ÄǽÓÏÂÀ´Ê¹ÓÃǿʢµÄdebug flow¶ÔÆäÊý¾ÝÁ÷¾ÙÐв¶»ñ£¬ÔÚÐÅÏ¢Êä³öÖз¢Ã÷·À»ðǽÍâµØ»Ø¸´ÁËRST±¨ÎÄ£¨Ò²¾ÍÊÇͼÖеÄ...from local. flag [R]£©£¬ÕâµãÉõÊÇ¿ÉÒÉ£¬ËµÃ÷ÎÊÌâÕվɳöÔÚ·À»ðǽµÄÄĸöÄ£¿é´¦Öóͷ£»·½ÚÉÏ¡£
ÄÇÎÒÃÇÒ»Æð¿ª¶¯Í·ÄÔ˼Ë÷Ò»ÏÂʲôÇéÐÎÏ·À»ðǽ»á×Ô¶¯·¢ËÍRST°ü£¿
´ÓÊý¾Ý°üת·¢ÉÏÎÒÃÇ×¢ÖØµ½tcp syn½«Í¨¹ý·À»ðǽ£¬¿ÉÊǵ±ÎüÊÕµ½tcp syn / ackʱ£¬NGFW»á½«tcp rst·¢ËÍ»Øtcp syn / ackµÄʼ·¢Õß¡£
×ÝÈ»±£´æÔÊÐíÁ÷Á¿Í¨¹ýNGFWµÄÕ½ÂÔ£¬ÉèÖùýʧµÄIPpool»òVIP[l7] Ò²»áΪTCPÅþÁ¬Ôì³ÉÅþÁ¬ÎÊÌâ¡££¨Ãû´ÊÚ¹ÊÍ£ºÕâÀïµÄippoolÒ»Ñùƽ³£ÊÇÓÃÔÚÉÏÍø×öÔ´µØÖ·×ª»»µÄʱ¼ä£¬Ò»¸öµØÖ·²»·óÓ㬿ÉÒÔ°ÑÄÚÍøµÄÔ´µØÖ·×ª»»³ÉÒ»¸öµØÖ·¶Î¹æÄ£ÄڵĵØÖ·£¬VIPÊÇ·À»ðǽµÄ¶Ë¿ÚÓ³É䣬Ҳ¾ÍÊǸ÷È˳£ËµµÄÄ¿µÄµØÖ·×ª»»¹ØÏµ£©
Ò»Ñùƽ³£ÕâÖÖÎÊÌâµÄ¿ÉÄÜÐÔÊÇ£ºÍâµØÓÐÏìÓ¦µÄIPµØÖ·£¨ºÃ±ÈÊÇÔ´µØÖ·£©ÁË£¬ÓÉÓÚûÓжÔÓ¦µÄ·þÎñÔÚ¼àÌý£¬»áÈ¥ÏìÓ¦RST±¨ÎÄ£¬Æ¾Ö¤ÕâÖÖÅŲé˼Ð÷È¥¼ì²éÉèÖá£
ÄÇÎÒÃǰÑÎÊÌâµãËø¶¨ÔÚIPPool»òVIPÉÏÖØµãÅŲ飬ͨ¹ýÉèÖÃÉó²éÕÒµ½ÁËÕâ¸öʼ×÷Ù¸Õß¡£½«¶ÔÓ¦¹ýʧµÄÕ½ÂÔÉèÖÃɾ³ýÎÊÌâ½â¾ö¡£
¾È·ÈÏÏÖ³¡Ô´µØÖ·10.85.40.3Ò²¼Óµ½ÁËÐéÄâipÓ³ÉäÀïÁË¡£¹ØÓÚ·À»ðǽÉèÖò»Ì«ÊìϤµÄÍùÍù¿ÉÄ᷺ܻÆðÕâÖÖÏ£ÆæµÄÉèÖã¬ÓÐʱ¼äÕ½ÂÔÒ»¶àÕæµÄÓÃÈâÑÛºÜÇ·ÔÃÄ¿³öÎÊÌâ³öÔÚÄĶù¡£
Ò»Ñùƽ³£·ºÆð·À»ðǽ»Ø¸´...from local. flag [R]µÄÇéÐÎÓÐÈçÏÂÈýÖÖ:
1¡¢½«·þÎñÆ÷µØÖ·ÉèÖõ½ÁËIPpoolÀ
2¡¢½«¿Í»§¶ËIPµØÖ·ÉèÖõ½ÁËIPpoolÀ
3¡¢½«¿Í»§¶ËIPµØÖ·ÉèÖõ½ÁËVIPÀï¡£
×ܽá
Debug flowÏÂÁîÊÇ·À»ðǽʵÑé°²ÅÅÀú³ÌÖÐʹÓÃÆµÂʼ«¸ß£¬²¢ÇÒ¹ÊÕÏÕï¶ÏÎÊÌⶨλÂʿɴï80%×óÓÒ£¬ÕæµÄÊÇËãÉÏÊǰ®Ëµ´óÕæ»°µÄÏÂÁîÁË£¬ÌáÐÑʲôԵ¹ÊÔÓÉÒ»Ñùƽ³£¹ÊÕϾͶ¨Î»³öÀ´ ÁË£¬ÊÇСÈñÁ¦¼öÐèÕÆÎÕµÄÏÂÁѧ»áÁ˾ÍÊÇÕÆÎÕÁËÉϳËÎ书ÁËŶ£¬Ò»ÆðÐÞÁ¶ÆðÀ´°É¡£
