在 Debian 上“限速”通常分两种场景:
下面按常用方案说明。
例如限制 SSH(22 端口)每秒最多 3 个新连接:
nft add table inet filter
nft add chain inet filter input { type filter hook input priority 0 \; }
nft add rule inet filter input tcp dport 22 ct state new limit rate 3/second accept
nft add rule inet filter input tcp dport 22 ct state new drop
nftables 本身不能直接限速带宽,需要用 tc(Traffic Control)。
# 清除旧规则
tc qdisc del dev eth0 root 2>/dev/null
# 添加根队列(htb)
tc qdisc add dev eth0 root handle 1: htb default 30
# 添加主类(总带宽)
tc class add dev eth0 parent 1: classid 1:1 htb rate 1000mbit
# 添加限速类(10Mbps)
tc class add dev eth0 parent 1:1 classid 1:30 htb rate 10mbit ceil 10mbit
# 添加过滤器(所有流量)
tc filter add dev eth0 protocol ip parent 1:0 prio 1 u32 match ip dst 0.0.0.0/0 flowid 1:30
tc filter add dev eth0 protocol ip parent 1:0 prio 1 u32 \
match ip src 192.168.1.100 flowid 1:30
iptables -A INPUT -p tcp --dport 22 -m hashlimit \
--hashlimit-above 3/sec --hashlimit-mode srcip \
--hashlimit-name ssh --jump DROP
iptables 本身不能限速,只能打标记:
iptables -t mangle -A POSTROUTING -s 192.168.1.100 -j MARK --set-mark 10
再用 tc 按 mark 限速。
firewall-cmd --add-rich-rule='rule service name="ssh" limit value="3/s" accept'
| 需求 | 推荐 |
|---|---|
| 防 SSH 爆破 | nftables / iptables limit |
| 限制端口带宽 | tc + nftables |
| 限制单 IP 带宽 | tc + mark |
| 简单使用 | firewalld rich-rule |
如果你能说明:
我可以直接给你一套可复制的命令。