温馨提示×

debian防火墙如何限速

小樊
34
2026-09-26 13:36:29
栏目: 智能运维

在 Debian 上“限速”通常分两种场景:

  1. 限制某个 IP / 端口的带宽(流量限速)
  2. 限制连接速率(防止暴力破解、CC 攻击)

下面按常用方案说明。


一、使用 nftables(Debian 10+ 推荐)

1. 限制连接速率(防爆破/CC)

例如限制 SSH(22 端口)每秒最多 3 个新连接:

nft add table inet filter
nft add chain inet filter input { type filter hook input priority 0 \; }
nft add rule inet filter input tcp dport 22 ct state new limit rate 3/second accept
nft add rule inet filter input tcp dport 22 ct state new drop

2. 限速(带宽限制,需配合 tc)

nftables 本身不能直接限速带宽,需要用 tc(Traffic Control)。


二、使用 tc 做带宽限速(最常用)

例:限制 eth0 出口带宽为 10Mbps

# 清除旧规则
tc qdisc del dev eth0 root 2>/dev/null

# 添加根队列(htb)
tc qdisc add dev eth0 root handle 1: htb default 30

# 添加主类(总带宽)
tc class add dev eth0 parent 1: classid 1:1 htb rate 1000mbit

# 添加限速类(10Mbps)
tc class add dev eth0 parent 1:1 classid 1:30 htb rate 10mbit ceil 10mbit

# 添加过滤器(所有流量)
tc filter add dev eth0 protocol ip parent 1:0 prio 1 u32 match ip dst 0.0.0.0/0 flowid 1:30

限制某个 IP 的上行带宽

tc filter add dev eth0 protocol ip parent 1:0 prio 1 u32 \
match ip src 192.168.1.100 flowid 1:30

三、使用 iptables + hashlimit(老系统)

限制单 IP 每秒连接数

iptables -A INPUT -p tcp --dport 22 -m hashlimit \
--hashlimit-above 3/sec --hashlimit-mode srcip \
--hashlimit-name ssh --jump DROP

限制单 IP 带宽(配合 tc 使用)

iptables 本身不能限速,只能打标记:

iptables -t mangle -A POSTROUTING -s 192.168.1.100 -j MARK --set-mark 10

再用 tc 按 mark 限速。


四、使用 firewalld(若已安装)

firewall-cmd --add-rich-rule='rule service name="ssh" limit value="3/s" accept'

五、推荐方案总结

需求 推荐
防 SSH 爆破 nftables / iptables limit
限制端口带宽 tc + nftables
限制单 IP 带宽 tc + mark
简单使用 firewalld rich-rule

如果你能说明:

  • Debian 版本
  • 要限制 哪个 IP / 端口 / 网卡
  • 是 上行还是下行
  • 目标带宽多少

我可以直接给你一套可复制的命令。

0 踩