{"id":1147,"date":"2017-04-25T17:25:16","date_gmt":"2017-04-25T09:25:16","guid":{"rendered":"http:\/\/www.kumouse.com\/?p=1147"},"modified":"2017-04-25T22:26:33","modified_gmt":"2017-04-25T14:26:33","slug":"%e5%88%a9%e7%94%a8-ipset-%e5%b0%81%e7%a6%81%e5%a4%a7%e9%87%8f-ip","status":"publish","type":"post","link":"https:\/\/www.kumouse.com\/?p=1147","title":{"rendered":"\u5229\u7528 ipset \u5c01\u7981\u5927\u91cf IP"},"content":{"rendered":"<h2>\u5229\u7528 ipset \u5c01\u7981\u5927\u91cf IP<\/h2>\n<div class=\"postText\">\n<div id=\"cnblogs_post_body\">\n<p>\u4f7f\u7528 iptables \u5c01 IP\uff0c\u662f\u4e00\u79cd\u6bd4\u8f83\u7b80\u5355\u7684\u5e94\u5bf9\u7f51\u7edc\u653b\u51fb\u7684\u65b9\u5f0f\uff0c\u4e5f\u7b97\u662f\u6bd4\u8f83\u5e38\u89c1\u3002\u6709\u65f6\u5019\u53ef\u80fd\u4f1a\u5c01\u7981\u6210\u5343\u4e0a\u4e07\u4e2a IP\uff0c\u5982\u679c\u6dfb\u52a0\u6210\u5343\u4e0a\u4e07\u6761\u89c4\u5219\uff0c\u5728\u4e00\u53f0\u6ce8\u91cd\u6027\u80fd\u7684\u670d\u52a1\u5668\u6216\u8005\u672c\u8eab\u6027\u80fd\u5c31\u5f88\u5dee\u7684\u8bbe\u5907\u4e0a\uff0c\u8fd9\u5c31\u662f\u4e2a\u95ee\u9898\u4e86\u3002ipset \u5c31\u662f\u4e3a\u4e86\u907f\u514d\u8fd9\u4e2a\u95ee\u9898\u800c\u751f\u7684\u3002<\/p>\n<p>\u5173\u4e8e iptables\uff0c\u8981\u77e5\u9053\u8fd9\u4e24\u70b9\u3002<\/p>\n<ul>\n<li>iptables \u5305\u542b\u51e0\u4e2a\u8868\uff0c\u6bcf\u4e2a\u8868\u7531\u94fe\u7ec4\u6210\u3002\u9ed8\u8ba4\u7684\u662f filter \u8868\uff0c\u6700\u5e38\u7528\u7684\u4e5f\u662f filter \u8868\uff0c\u53e6\u4e00\u4e2a\u6bd4\u8f83\u5e38\u7528\u7684\u662f nat \u8868\u3002\u4e00\u822c\u5c01 IP \u5c31\u662f\u5728 filter \u8868\u7684 INPUT \u94fe\u6dfb\u52a0\u89c4\u5219\u3002<\/li>\n<li>\u5728\u8fdb\u884c\u89c4\u5219\u5339\u914d\u65f6\uff0c\u662f\u4ece\u89c4\u5219\u5217\u8868\u4e2d\u4ece\u5934\u5230\u5c3e\u4e00\u6761\u4e00\u6761\u8fdb\u884c\u5339\u914d\u3002<\/li>\n<\/ul>\n<p>\u8fd9\u50cf\u662f\u5728\u94fe\u8868\u4e2d\u641c\u7d22\u6307\u5b9a\u8282\u70b9\u8d39\u529b\u3002ipset \u63d0\u4f9b\u4e86\u628a\u8fd9\u4e2a O(n) \u7684\u64cd\u4f5c\u53d8\u6210 O(1) \u7684\u65b9\u6cd5\uff1a\u5c31\u662f\u628a\u8981\u5904\u7406\u7684 IP \u653e\u8fdb\u4e00\u4e2a\u96c6\u5408\uff0c\u5bf9\u8fd9\u4e2a\u96c6\u5408\u8bbe\u7f6e\u4e00\u6761 iptables \u89c4\u5219\u3002\u50cf iptable \u4e00\u6837\uff0cIP sets \u662f Linux \u5185\u6838\u4e2d\u7684\u4e1c\u897f\uff0cipset \u8fd9\u4e2a\u547d\u4ee4\u662f\u5bf9\u5b83\u8fdb\u884c\u64cd\u4f5c\u7684\u4e00\u4e2a\u5de5\u5177\u3002<\/p>\n<h2 id=\"\">\u7b80\u5355\u7684\u6d41\u7a0b<\/h2>\n<p>\u53ef\u4ee5\u7528\u8fd9\u51e0\u6761\u547d\u4ee4\u6982\u62ec\u4f7f\u7528 ipset \u548c iptables \u8fdb\u884c IP \u5c01\u7981\u7684\u6d41\u7a0b<\/p>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset create vader hash:ip  \r\niptables -I INPUT -m <span class=\"token keyword\">set --match-set vader src -j DROP  \r\nipset add vader 4.5.6.7  \r\nipset add vader 1.2.3.4  \r\nipset add vader <span class=\"token punctuation\">...  \r\nipset list vader <span class=\"token comment\"># \u67e5\u770b vader \u96c6\u5408\u7684\u5185\u5bb9  \r\n<\/span><\/span><\/span><\/code><\/pre>\n<p>\u4e0b\u9762\u5206\u522b\u5bf9\u5404\u6761\u547d\u4ee4\u8fdb\u884c\u63cf\u8ff0\u3002<\/p>\n<h3 id=\"\">\u521b\u5efa\u4e00\u4e2a\u96c6\u5408<\/h3>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset create vader hash:ip  \r\n<\/code><\/pre>\n<p>\u8fd9\u6761\u547d\u4ee4\u521b\u5efa\u4e86\u540d\u4e3a vader \u7684\u96c6\u5408\uff0c\u4ee5 hash \u65b9\u5f0f\u5b58\u50a8\uff0c\u5b58\u50a8\u5185\u5bb9\u662f IP \u5730\u5740\u3002<\/p>\n<h3 id=\"iptables\">\u6dfb\u52a0 iptables \u89c4\u5219<\/h3>\n<pre class=\" language-bash\"><code class=\" language-bash\">iptables -I INPUT -m <span class=\"token keyword\">set --match-set vader src -j DROP  \r\n<\/span><\/code><\/pre>\n<p>\u5982\u679c\u6e90\u5730\u5740(src)\u5c5e\u4e8e vader \u8fd9\u4e2a\u96c6\u5408\uff0c\u5c31\u8fdb\u884c DROP \u64cd\u4f5c\u3002\u8fd9\u6761\u547d\u4ee4\u4e2d\uff0cvader \u662f\u4f5c\u4e3a\u9ed1\u540d\u5355\u7684\uff0c\u5982\u679c\u8981\u628a\u67d0\u4e2a\u96c6\u5408\u4f5c\u4e3a\u767d\u540d\u5355\uff0c\u6dfb\u52a0\u4e00\u4e2a \u2018!\u2019 \u7b26\u53f7\u5c31\u53ef\u4ee5\u3002<\/p>\n<pre class=\" language-bash\"><code class=\" language-bash\">iptables -I INPUT -m <span class=\"token keyword\">set <span class=\"token operator\">! --match-set yoda src -j DROP  \r\n<\/span><\/span><\/code><\/pre>\n<p>\u5230\u73b0\u5728\u867d\u7136\u521b\u5efa\u4e86\u96c6\u5408\uff0c\u6dfb\u52a0\u4e86\u8fc7\u6ee4\u89c4\u5219\uff0c\u4f46\u662f\u73b0\u5728\u96c6\u5408\u8fd8\u662f\u7a7a\u7684\uff0c\u9700\u8981\u5f80\u96c6\u5408\u91cc\u52a0\u5185\u5bb9\u3002<\/p>\n<h3 id=\"ip\">\u627e\u51fa\u201c\u574f\u201d IP<\/h3>\n<p>\u627e\u51fa\u8981\u5c01\u7981\u7684 IP\uff0c\u8fd9\u662f\u5c01\u7981\u8fc7\u7a0b\u4e2d\u91cd\u8981\u7684\u6b65\u9aa4\uff0c\u4e0d\u8fc7\u4e0d\u662f\u8fd9\u91cc\u7684\u91cd\u70b9\u3002\u7b80\u8981\u8bf4\u660e\u4e00\u4e0b\u4e24\u79cd\u65b9\u6cd5\u601d\u8def\u3002<\/p>\n<pre class=\" language-bash\"><code class=\" language-bash\"><span class=\"token function\">netstat -ntu <span class=\"token operator\">| tail -n +3 | awk <span class=\"token string\">'{print <span class=\"token variable\">$5}' | sort | uniq -c | sort -nr  \r\n<\/span><\/span><\/span><\/span><\/code><\/pre>\n<p>\u76f4\u63a5\u901a\u8fc7 netstat \u7684\u4fe1\u606f\uff0c\u628a\u4e0e\u672c\u5730\u76f8\u5173\u7684\u5404\u79cd\u72b6\u6001\u7684 IP \u90fd\u8ba1\u6570\uff0c\u6392\u5e8f\u5217\u51fa\u6765\u3002<\/p>\n<p>\u6216\u8005\u4ece nginx \u6216\u8005\u5176\u4ed6 web server \u7684\u65e5\u5fd7\u91cc\u627e\u8bf7\u6c42\u6570\u592a\u591a\u7684 IP<\/p>\n<pre class=\" language-bash\"><code class=\" language-bash\"><span class=\"token function\">awk <span class=\"token string\">'{print <span class=\"token variable\">$1}' \/var\/log\/nginx\/access.log <span class=\"token operator\">| sort | uniq -c | sort -nr  \r\n<\/span><\/span><\/span><\/span><\/code><\/pre>\n<p>\u540e\u534a\u90e8\u5206\uff0c\u6392\u5e8f\uff0c\u53bb\u91cd\uff0c\u518d\u6309\u6b21\u6570\u8fdb\u884c\u9006\u5411\u6392\u5e8f\u7684\u64cd\u4f5c\uff0c\u8ddf\u4e0a\u9762\u547d\u4ee4\u662f\u4e00\u6837\u7684\u3002<\/p>\n<p>\u627e\u51fa\u201c\u574f\u201d IP\uff0c\u5f80\u4e4b\u524d\u521b\u5efa\u7684\u96c6\u5408\u91cc\u6dfb\u52a0\u5c31\u53ef\u4ee5\u4e86\u3002<\/p>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset add vader 4.5.6.7  \r\n<\/code><\/pre>\n<p>\u6709\u591a\u5c11\u201c\u574f\u201d IP\uff0c\u5c31\u6dfb\u52a0\u591a\u5c11 IP\uff0c\u56e0\u4e3a\u9488\u5bf9\u8fd9\u4e9b\u5c01\u7981\u7684 IP \u53ea\u9700\u8981\u4e00\u6761 iptables \u89c4\u5219\uff0c\u800c\u8fd9\u4e9b IP \u662f\u4ee5 hash \u65b9\u5f0f\u5b58\u50a8\uff0c\u6240\u4ee5\u5c01\u7981\u5927\u91cf\u7684 IP \u4e5f\u4e0d\u4f1a\u5f71\u54cd\u6027\u80fd\uff0c\u8fd9\u4e5f\u662f ipset \u5b58\u5728\u7684\u6700\u5927\u76ee\u7684\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2 id=\"ipset\">ipset \u66f4\u591a\u7684\u7528\u6cd5<\/h2>\n<h3 id=\"\">\u5b58\u50a8\u7c7b\u578b<\/h3>\n<p>\u524d\u9762\u4f8b\u5b50\u4e2d\u7684 vader \u8fd9\u4e2a\u96c6\u5408\u662f\u4ee5 hash \u65b9\u5f0f\u5b58\u50a8 IP \u5730\u5740\uff0c\u4e5f\u5c31\u662f\u4ee5 IP \u5730\u5740\u4e3a hash \u7684\u952e\u3002\u9664\u4e86 IP \u5730\u5740\uff0c\u8fd8\u53ef\u4ee5\u662f\u7f51\u7edc\u6bb5\uff0c\u7aef\u53e3\u53f7\uff08\u652f\u6301\u6307\u5b9a TCP\/UDP \u534f\u8bae\uff09\uff0cmac \u5730\u5740\uff0c\u7f51\u7edc\u63a5\u53e3\u540d\u79f0\uff0c\u6216\u8005\u4e0a\u8ff0\u5404\u79cd\u7c7b\u578b\u7684\u7ec4\u5408\u3002<\/p>\n<p>\u6bd4\u5982\u6307\u5b9a <code>hash:ip,port<\/code>\u5c31\u662f IP \u5730\u5740\u548c\u7aef\u53e3\u53f7\u5171\u540c\u4f5c\u4e3a hash \u7684\u952e\u3002\u67e5\u770b ipset \u7684\u5e2e\u52a9\u6587\u6863\u53ef\u4ee5\u770b\u5230\u5b83\u652f\u6301\u7684\u6240\u6709\u7c7b\u578b\u3002<\/p>\n<p>\u4e0b\u9762\u4ee5\u4e24\u4e2a\u4f8b\u5b50\u8bf4\u660e\u3002<\/p>\n<h4 id=\"hashnet\">hash:net<\/h4>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset create r2d2 hash:net  \r\nipset add r2d2 1.2.3.0\/24  \r\nipset add r2d2 1.2.3.0\/30 nomatch  \r\nipset add r2d2 6.7.8.9  \r\nipset <span class=\"token function\">test r2d2 1.2.3.2  \r\n<\/span><\/code><\/pre>\n<p><code>hash:net<\/code> \u6307\u5b9a\u4e86\u53ef\u4ee5\u5f80 r2d2 \u8fd9\u4e2a\u96c6\u5408\u91cc\u6dfb\u52a0 IP \u6bb5\u6216 IP \u5730\u5740\u3002<\/p>\n<p>\u7b2c\u4e09\u6761\u547d\u4ee4\u91cc\u7684 <code>nomatch<\/code> \u7684\u4f5c\u7528\u7b80\u5355\u6765\u8bf4\u662f\u628a <code>1.2.3.0\/30<\/code> \u4ece <code>1.2.3.0\/24<\/code> \u8fd9\u4e00\u8303\u56f4\u76f8\u5bf9\u66f4\u5927\u7684\u6bb5\u91cc\u201c\u5265\u79bb\u201d\u4e86\u51fa\u6765\uff0c\u4e5f\u5c31\u662f\u8bf4\u6267\u884c\u5b8c <code>ipset add r2d2 1.2.3.0\/24<\/code> \u53ea\u540e1.2.3.0\/24 \u8fd9\u4e00\u6bb5 IP \u662f\u5c5e\u4e8e r2d2 \u96c6\u5408\u7684\uff0c\u6267\u884c\u4e86 <code>ipset add r2d2 1.2.3.0\/30 nomatch<\/code> \u4e4b\u540e\uff0c1.2.3.0\/24 \u91cc 1.2.3.0\/30 \u8fd9\u90e8\u5206\uff0c\u5c31\u4e0d\u5c5e\u4e8e r2d2 \u96c6\u5408\u4e86\u3002\u6267\u884c <code>ipset test r2d2 1.2.3.2<\/code> \u5c31\u4f1a\u5f97\u5230\u7ed3\u679c <code>1.2.3.2 is NOT in set r2d2.<\/code><\/p>\n<h4 id=\"hashipport\">hash:ip,port<\/h4>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset create c-3po hash:ip,port  \r\nipset add c-3po 3.4.5.6,80  \r\nipset add c-3po 5.6.7.8,udp:53  \r\nipset add c-3po 1.2.3.4,80-86  \r\n<\/code><\/pre>\n<p>\u7b2c\u4e8c\u6761\u547d\u4ee4\u6dfb\u52a0\u7684\u662f IP \u5730\u5740\u4e3a 3.4.5.6\uff0c\u7aef\u53e3\u53f7\u662f 80 \u7684\u9879\u3002\u6ca1\u6709\u6ce8\u660e\u534f\u8bae\uff0c\u9ed8\u8ba4\u5c31\u662f TCP\uff0c\u4e0b\u9762\u4e00\u6761\u547d\u4ee4\u5219\u662f\u6307\u660e\u4e86\u662f UDP \u7684 53 \u7aef\u53e3\u3002\u6700\u540e\u4e00\u6761\u547d\u4ee4\u6307\u660e\u4e86\u4e00\u4e2a IP \u5730\u5740\u548c\u4e00\u4e2a\u7aef\u53e3\u53f7\u8303\u56f4\uff0c\u8fd9\u4e5f\u662f\u5408\u6cd5\u7684\u547d\u4ee4\u3002<\/p>\n<h3 id=\"\">\u81ea\u52a8\u8fc7\u671f\uff0c\u89e3\u5c01<\/h3>\n<p>ipset \u652f\u6301 timeout \u53c2\u6570\uff0c\u8fd9\u5c31\u610f\u5473\u7740\uff0c\u5982\u679c\u4e00\u4e2a\u96c6\u5408\u662f\u4f5c\u4e3a\u9ed1\u540d\u5355\u4f7f\u7528\uff0c\u901a\u8fc7 timeout \u53c2\u6570\uff0c\u5c31\u53ef\u4ee5\u5230\u671f\u81ea\u52a8\u4ece\u9ed1\u540d\u5355\u91cc\u5220\u9664\u5185\u5bb9\u3002<\/p>\n<pre><code>ipset create obiwan hash:ip timeout 300  \r\nipset add obiwan 1.2.3.4  \r\nipset add obiwan 6.6.6.6 timeout 60  \r\n<\/code><\/pre>\n<p>\u4e0a\u9762\u7b2c\u4e00\u6761\u547d\u4ee4\u521b\u5efa\u4e86\u540d\u4e3a obiwan \u7684\u96c6\u5408\uff0c\u540e\u9762\u591a\u52a0\u4e86 timeout \u53c2\u6570\uff0c\u503c\u4e3a 300\uff0c\u5f80\u96c6\u5408\u91cc\u6dfb\u52a0\u6761\u76ee\u7684\u9ed8\u8ba4 timeout \u65f6\u95f4\u5c31\u662f 300\u3002\u7b2c\u4e09\u6761\u547d\u4ee4\u5728\u5411\u96c6\u5408\u6dfb\u52a0 IP \u65f6\u6307\u5b9a\u4e86\u4e00\u4e2a\u4e0d\u540c\u4e8e\u9ed8\u8ba4\u503c\u7684 timeout \u503c 60\uff0c\u90a3\u4e48\u8fd9\u4e00\u6761\u5c31\u4f1a\u5728 60 \u79d2\u540e\u81ea\u52a8\u5220\u9664\u3002<\/p>\n<p>\u9694\u51e0\u79d2\u6267\u884c\u4e00\u6b21 <code>ipset list obiwan<\/code> \u53ef\u4ee5\u770b\u5230\u8fd9\u4e2a\u96c6\u5408\u91cc\u6761\u76ee\u7684 timeout \u4e00\u76f4\u5728\u968f\u7740\u65f6\u95f4\u53d8\u5316\uff0c\u6807\u5fd7\u7740\u5b83\u4eec\u5728\u591a\u5c11\u79d2\u4e4b\u540e\u4f1a\u88ab\u5220\u9664\u3002<\/p>\n<p>\u5982\u679c\u8981\u91cd\u65b0\u4e3a\u67d0\u4e2a\u6761\u76ee\u6307\u5b9a timeout \u53c2\u6570\uff0c\u8981\u4f7f\u7528 <code>-exit<\/code> \u8fd9\u4e00\u9009\u9879\u3002<\/p>\n<pre><code>ipset -exist add obiwan 1.2.3.4 timeout 100  \r\n<\/code><\/pre>\n<p>\u8fd9\u6837 <code>1.2.3.4<\/code> \u8fd9\u4e00\u6761\u6570\u636e\u7684 timeout \u503c\u5c31\u53d8\u6210\u4e86 100\uff0c\u5982\u679c\u8fd9\u91cc\u8bbe\u7f6e 300\uff0c\u90a3\u4e48\u5b83\u7684 timeout\uff0c\u4e5f\u5c31\u662f\u5b58\u6d3b\u65f6\u95f4\u53c8\u91cd\u65b0\u53d8\u6210 300\u3002<\/p>\n<p>\u5982\u679c\u5728\u521b\u5efa\u96c6\u5408\u662f\u6ca1\u6709\u6307\u5b9a timeout\uff0c\u90a3\u4e48\u4e4b\u540e\u6dfb\u52a0\u6761\u76ee\u4e5f\u5c31\u4e0d\u652f\u6301 timeout \u53c2\u6570\uff0c\u6267\u884c <code>add<\/code> \u4f1a\u6536\u5230\u62a5\u9519\u3002\u60f3\u8981\u9ed8\u8ba4\u6761\u76ee\u4e0d\u4f1a\u8fc7\u671f\uff08\u81ea\u52a8\u5220\u9664\uff09\uff0c\u53c8\u9700\u8981\u6dfb\u52a0\u67d0\u4e9b\u6761\u76ee\u65f6\u52a0\u4e0a timeout \u53c2\u6570\uff0c\u53ef\u4ee5\u5728\u521b\u5efa\u96c6\u5408\u65f6\u6307\u5b9a timeout \u4e3a 0\u3002<\/p>\n<pre><code>ipset create luke hash:ip  \r\nipset add luke 5.5.5.5 timeout 100  \r\n# \u5f97\u5230\u62a5\u9519\u4fe1\u606f kernel error received: Unknown error -1\r\n<\/code><\/pre>\n<h3 id=\"\">\u66f4\u5927\uff01<\/h3>\n<p>hashsize, maxelem \u8fd9\u4e24\u4e2a\u53c2\u6570\u5206\u522b\u6307\u5b9a\u4e86\u521b\u5efa\u96c6\u5408\u65f6\u521d\u59cb\u7684 hash \u5927\u5c0f\uff0c\u548c\u6700\u5927\u5b58\u50a8\u7684\u6761\u76ee\u6570\u91cf\u3002<\/p>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset create yoda hash:ip,port hashsize 4096 maxelem 1000000  \r\nipset add yoda 3.4.5.6,3306  \r\n<\/code><\/pre>\n<p>\u8fd9\u6837\u521b\u5efa\u4e86\u540d\u4e3a yoda \u7684\u96c6\u5408\uff0c\u521d\u59cb hash \u5927\u5c0f\u662f 4096\uff0c\u5982\u679c\u6ee1\u4e86\uff0c\u8fd9\u4e2a hash \u4f1a\u81ea\u52a8\u6269\u5bb9\u4e3a\u4e4b\u524d\u7684\u4e24\u500d\u3002\u6700\u5927\u80fd\u5b58\u50a8\u7684\u6570\u91cf\u662f 100000 \u4e2a\u3002<\/p>\n<p>\u5982\u679c\u6ca1\u6709\u6307\u5b9a\uff0chashsize \u7684\u9ed8\u8ba4\u503c\u662f 1024\uff0cmaxelem \u7684\u9ed8\u8ba4\u503c\u662f 65536\u3002<\/p>\n<h3 id=\"\">\u53e6\u5916\u51e0\u6761\u5e38\u7528\u547d\u4ee4<\/h3>\n<pre class=\" language-bash\"><code class=\" language-bash\">ipset del yoda x.x.x.x    <span class=\"token comment\"># \u4ece yoda \u96c6\u5408\u4e2d\u5220\u9664\u5185\u5bb9  \r\nipset list yoda           # \u67e5\u770b yoda \u96c6\u5408\u5185\u5bb9  \r\nipset list                # \u67e5\u770b\u6240\u6709\u96c6\u5408\u7684\u5185\u5bb9  \r\nipset flush yoda          # \u6e05\u7a7a yoda \u96c6\u5408  \r\nipset flush               # \u6e05\u7a7a\u6240\u6709\u96c6\u5408  \r\nipset destroy yoda        # \u9500\u6bc1 yoda \u96c6\u5408  \r\nipset destroy             # \u9500\u6bc1\u6240\u6709\u96c6\u5408  \r\nipset save yoda           # \u8f93\u51fa yoda \u96c6\u5408\u5185\u5bb9\u5230\u6807\u51c6\u8f93\u51fa  \r\nipset save                # \u8f93\u51fa\u6240\u6709\u96c6\u5408\u5185\u5bb9\u5230\u6807\u51c6\u8f93\u51fa  \r\nipset restore             # \u6839\u636e\u8f93\u5165\u5185\u5bb9\u6062\u590d\u96c6\u5408\u5185\u5bb9  \r\n<\/span><\/code><\/pre>\n<h3 id=\"\">\u8fd8\u6709\u2026\u2026<\/h3>\n<ul>\n<li>\u5982\u679c\u521b\u5efa\u96c6\u5408\u662f\u6307\u5b9a\u7684\u5b58\u50a8\u5185\u5bb9\u5305\u542b ip, \u4f8b\u5982 <code>hash:ip<\/code> \u6216 <code>hash:ip,port<\/code> \uff0c\u5728\u6dfb\u52a0\u6761\u76ee\u65f6\uff0c\u53ef\u4ee5\u586b IP \u6bb5\uff0c\u4f46\u662f\u4ecd\u7136\u662f\u4ee5\u5355\u72ec\u4e00\u4e2a\u4e2a IP \u7684\u65b9\u5f0f\u6765\u5b58\u3002<\/li>\n<li>\u4e0a\u9762\u6240\u6709\u7684\u4f8b\u5b50\u90fd\u662f\u7528 hash \u7684\u65b9\u5f0f\u8fdb\u884c\u5b58\u50a8\uff0c\u5b9e\u9645\u4e0a ipset \u8fd8\u53ef\u4ee5\u4ee5 bitmap \u6216\u8005 link \u65b9\u5f0f\u5b58\u50a8\uff0c\u7528\u8fd9\u4e24\u79cd\u65b9\u5f0f\u521b\u5efa\u7684\u96c6\u5408\u5927\u5c0f\uff0c\u662f\u56fa\u5b9a\u7684\u3002<\/li>\n<li>\u901a\u8fc7 <code>man upset<\/code> \u548c <code>ipset \u2014help<\/code> \u53ef\u4ee5\u67e5\u5230\u66f4\u591a\u7684\u5185\u5bb9\uff0c\u5305\u62ec\u5404\u79cd\u9009\u9879\uff0c\u652f\u6301\u7684\u7c7b\u578b\u7b49\u7b49\u3002<\/li>\n<\/ul>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u5229\u7528 ipset \u5c01\u7981\u5927\u91cf IP \u4f7f\u7528 iptables \u5c01 IP\uff0c\u662f\u4e00\u79cd\u6bd4\u8f83\u7b80\u5355\u7684\u5e94\u5bf9\u7f51\u7edc\u653b\u51fb\u7684\u65b9\u5f0f\uff0c\u4e5f\u7b97\u662f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-1147","post","type-post","status-publish","format-standard","hentry","category-linux"],"_links":{"self":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/1147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1147"}],"version-history":[{"count":1,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/1147\/revisions"}],"predecessor-version":[{"id":1148,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=\/wp\/v2\/posts\/1147\/revisions\/1148"}],"wp:attachment":[{"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kumouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}