目前遇到问题为:设备发送特定的radius探测报文到radius容器不通, 在宿主机能抓到包,容器内部抓不到包
目前问题已经明确,我们来看下正常情况下报文是怎样的!!
// 00:0c:29:cc:1c:df 为宿主机 eth0mac地址
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING:rule:2 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING_direct:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING_ZONES_SOURCE:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING:rule:4 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING_ZONES:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public:rule:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public_log:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public:rule:2 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public_deny:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public_allow:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PRE_public:return:4 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: raw:PREROUTING:policy:5 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING:rule:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING_direct:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING:rule:2 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING_ZONES_SOURCE:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING_ZONES:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public:rule:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public_log:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public:rule:2 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public_deny:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public_allow:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PRE_public:return:4 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:PREROUTING:policy:4 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING:rule:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING_direct:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING:rule:2 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING_ZONES_SOURCE:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING_ZONES:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public:rule:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public_log:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public:rule:2 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public_deny:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public:rule:3 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public_allow:return:1 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PRE_public:return:4 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:PREROUTING:rule:4 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:DOCKER:rule:6 IN=ens33 OUT= MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.1.206 LEN=415 TOS=0x00 PREC=0x00 TTL=255 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:FORWARD:rule:1 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:FORWARD_direct:return:1 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:FORWARD:policy:2 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: filter:FORWARD:rule:1 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: filter:DOCKER-USER:return:1 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: filter:FORWARD:rule:2 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: filter:DOCKER-ISOLATION-STAGE-1:return:3 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: filter:FORWARD:rule:8 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: filter:DOCKER:rule:4 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: security:FORWARD:rule:1 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: security:FORWARD_direct:return:1 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: security:FORWARD:policy:2 IN=ens33 OUT=br-64a467b94a3c MAC=00:0c:29:cc:1c:df:3c:c7:86:ad:a9:d7:08:00 SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:POSTROUTING:rule:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:POSTROUTING_direct:return:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: mangle:POSTROUTING:policy:2 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING:rule:3 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING_direct:return:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING:rule:4 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING_ZONES_SOURCE:return:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING:rule:5 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING_ZONES:rule:2 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker:rule:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker_log:return:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker:rule:2 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker_deny:return:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker:rule:3 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker_allow:return:1 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POST_docker:return:4 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
[Thu Sep 21 18:10:39 2023] TRACE: nat:POSTROUTING:policy:11 IN= OUT=br-64a467b94a3c SRC=192.168.1.240 DST=192.168.222.2 LEN=415 TOS=0x00 PREC=0x00 TTL=254 ID=19651 PROTO=UDP SPT=49338 DPT=1812 LEN=395
//宿主机桥接口br-64a467b94a3c的mac地址:02:42:56:3a:35:9c(-->192.168.222.1) 容器内部etho地址:02:42:c0:a8:de:02(-->192.168.222.2)
//veth6910cc3 为宿主机和容器内部直连的接口 此接口桥接在br-64a467b94a3c 下
[Thu Sep 21 18:10:39 2023] ebtable/nat-OUTPUT IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.240 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=49338 DPT=1812
[Thu Sep 21 18:10:39 2023] ebtable/filter-OUTPUT IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.240 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=49338 DPT=1812
[Thu Sep 21 18:10:39 2023] ebtable/nat-POSTROUTE IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.240 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=49338 DPT=1812
[Thu Sep 21 18:10:39 2023] ebtable/broute-BROUTING IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.1, IP tos=0x00, IP proto=17 SPT=57536 DPT=53
[Thu Sep 21 18:10:39 2023] ebtable/nat-PREROUTE IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.1, IP tos=0x00, IP proto=17 SPT=57536 DPT=53
[Thu Sep 21 18:10:39 2023] ebtable/filter-INPUT IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.1, IP tos=0x00, IP proto=17 SPT=57536 DPT=53
[Thu Sep 21 18:10:39 2023] ebtable/broute-BROUTING IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.1, IP tos=0x00, IP proto=17 SPT=48261 DPT=53
[Thu Sep 21 18:10:39 2023] ebtable/nat-PREROUTE IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.1, IP tos=0x00, IP proto=17 SPT=48261 DPT=53
[Thu Sep 21 18:10:39 2023] ebtable/filter-INPUT IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.1, IP tos=0x00, IP proto=17 SPT=48261 DPT=53
[Thu Sep 21 18:10:39 2023] ebtable/nat-OUTPUT IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.1 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=53 DPT=57536
[Thu Sep 21 18:10:39 2023] ebtable/filter-OUTPUT IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.1 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=53 DPT=57536
[Thu Sep 21 18:10:39 2023] ebtable/nat-POSTROUTE IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.1 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=53 DPT=57536
[Thu Sep 21 18:10:39 2023] ebtable/nat-OUTPUT IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.1 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=53 DPT=48261
[Thu Sep 21 18:10:39 2023] ebtable/filter-OUTPUT IN= OUT=veth6910cc3 MAC source = 02:42:56:3a:35:9c MAC dest = 02:42:c0:a8:de:02 proto = 0x0800 IP SRC=192.168.1.1 IP DST=192.168.222.2, IP tos=0x00, IP proto=17 SPT=53 DPT=48261
//发包:
/*容器内部路由
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 192.168.222.1 0.0.0.0 UG 0 0 0 eth0
192.168.222.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.222.2 netmask 255.255.255.0 broadcast 192.168.222.255
ether 02:42:c0:a8:de:02 txqueuelen 0 (Ethernet)
*/
[Thu Sep 21 19:45:44 2023] ebtable/broute-BROUTING IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.240, IP tos=0x00, IP proto=17 SPT=1812 DPT=49338
[Thu Sep 21 19:45:44 2023] ebtable/nat-PREROUTE IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.240, IP tos=0x00, IP proto=17 SPT=1812 DPT=49338
[Thu Sep 21 19:45:44 2023] ebtable/filter-INPUT IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.240, IP tos=0x00, IP proto=17 SPT=1812 DPT=49338
大概流程是:
从物理网卡上来,进过prerouting的raw mangle nat后最后做了DNAT, 然后forward 到br-64a467b94a3c 接口, 此时会过mangle、filter、security 等table, 然后进入POSTROUTING的mangle、nat, 此时相当于将报文发送给br-64桥接口。
可以看到报文流向如下图 红色箭头所示
容器回包流程
[Thu Sep 21 19:59:49 2023] ebtable/broute-BROUTING IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.240, IP tos=0x00, IP proto=17 SPT=1812 DPT=49338
[Thu Sep 21 19:59:49 2023] ebtable/nat-PREROUTE IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.240, IP tos=0x00, IP proto=17 SPT=1812 DPT=49338
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING:rule:3 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING_direct:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING:rule:4 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING_ZONES_SOURCE:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING:rule:5 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING_ZONES:rule:2 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker:rule:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker_log:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker:rule:2 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker_deny:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker:rule:3 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker_allow:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PRE_docker:return:4 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: raw:PREROUTING:policy:6 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING:rule:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING_direct:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING:rule:2 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING_ZONES_SOURCE:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING:rule:3 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING_ZONES:rule:2 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker:rule:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker_log:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker:rule:2 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker_deny:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker:rule:3 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker_allow:return:1 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PRE_docker:return:4 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:PREROUTING:policy:4 IN=br-64a467b94a3c OUT= PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] ebtable/filter-INPUT IN=veth6910cc3 OUT= MAC source = 02:42:c0:a8:de:02 MAC dest = 02:42:56:3a:35:9c proto = 0x0800 IP SRC=192.168.222.2 IP DST=192.168.1.240, IP tos=0x00, IP proto=17 SPT=1812 DPT=49338
[Thu Sep 21 19:59:49 2023] TRACE: mangle:FORWARD:rule:1 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:FORWARD_direct:return:1 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:FORWARD:policy:2 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:FORWARD:rule:1 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:DOCKER-USER:return:1 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:FORWARD:rule:2 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:DOCKER-ISOLATION-STAGE-1:rule:2 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:DOCKER-ISOLATION-STAGE-2:return:3 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:DOCKER-ISOLATION-STAGE-1:return:3 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: filter:FORWARD:rule:9 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: security:FORWARD:rule:1 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: security:FORWARD_direct:return:1 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: security:FORWARD:policy:2 IN=br-64a467b94a3c OUT=ens33 PHYSIN=veth6910cc3 MAC=02:42:56:3a:35:9c:02:42:c0:a8:de:02:08:00 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:POSTROUTING:rule:1 IN= OUT=ens33 PHYSIN=veth6910cc3 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:POSTROUTING_direct:return:1 IN= OUT=ens33 PHYSIN=veth6910cc3 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
[Thu Sep 21 19:59:49 2023] TRACE: mangle:POSTROUTING:policy:2 IN= OUT=ens33 PHYSIN=veth6910cc3 SRC=192.168.222.2 DST=192.168.1.240 LEN=48 TOS=0x00 PREC=0x00 TTL=63 ID=20230 PROTO=UDP SPT=1812 DPT=49338 LEN=28
容器发包到外网流程如下:
对于报文经过接口tcpdump 抓包如下:
[root@localhost ~]# tcpdump -i any udp port 1812 -nne
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
20:39:50.516301 In 3c:c7:86:ad:a9:d7 ethertype IPv4 (0x0800), length 431: 192.168.1.240.49338 > 192.168.1.206.1812: RADIUS, Access-Request (1), id: 0xc8 length: 387
20:39:50.516562 Out 02:42:56:3a:35:9c ethertype IPv4 (0x0800), length 431: 192.168.1.240.49338 > 192.168.222.2.1812: RADIUS, Access-Request (1), id: 0xc8 length: 387
20:39:50.516615 Out 02:42:56:3a:35:9c ethertype IPv4 (0x0800), length 431: 192.168.1.240.49338 > 192.168.222.2.1812: RADIUS, Access-Request (1), id: 0xc8 length: 387
20:39:51.746327 P 02:42:c0:a8:de:02 ethertype IPv4 (0x0800), length 64: 192.168.222.2.1812 > 192.168.1.240.49338: RADIUS, Access-Reject (3), id: 0xc8 length: 20
20:39:51.746327 In 02:42:c0:a8:de:02 ethertype IPv4 (0x0800), length 64: 192.168.222.2.1812 > 192.168.1.240.49338: RADIUS, Access-Reject (3), id: 0xc8 length: 20
20:39:51.746430 Out 00:0c:29:cc:1c:df ethertype IPv4 (0x0800), length 64: 192.168.1.206.1812 > 192.168.1.240.49338: RADIUS, Access-Reject (3), id: 0xc8 length: 20
对于 Host to Contaienr
对于 Container to Host
对于 Contaienr to Container
部分内容转载自:https://www.hwchiu.com/iptables-1.html
http代理服务器(3-4-7层代理)-网络事件库公共组件、内核kernel驱动 摄像头驱动 tcpip网络协议栈、netfilter、bridge 好像看过!!!! 但行好事 莫问前程 --身高体重180的胖子