在 CentOS 上,防火墙本身(firewalld / iptables)主要做包过滤,不直接提供“限速/带宽限制”功能,但可以结合其他工具实现限速。下面按常见场景说明:
❌ 不能直接限速
firewalld 只能:
✅ 但可以通过 rich rule + 其他模块 间接配合
⚠️ iptables 本身也不限速带宽
但可以使用 iptables + tc(Traffic Control) 实现限速
适合:服务器整体/网卡/IP 限速
tc qdisc add dev eth0 root tbf rate 10mbit burst 32kbit latency 400ms
tc qdisc add dev eth0 root handle 1: htb
tc class add dev eth0 parent 1: classid 1:1 htb rate 1mbit
tc filter add dev eth0 protocol ip parent 1:0 prio 1 u32 match ip src 192.168.1.100 flowid 1:1
✅ 优点:稳定、性能好
❌ 缺点:命令复杂
适合:防爆破、防 flood
iptables -A INPUT -p tcp --dport 22 -m limit --limit 3/min -j ACCEPT
❌ 不能限制 MB/s
✅ 只能限制“每秒/每分钟多少个包”
nftables 仍不直接限速带宽,但配合 tc 使用
limit_rate 100k;
wondershaper(最简单)yum install wondershaper
wondershaper eth0 1024 256
(下载 1Mbps,上传 256Kbps)
| 方式 | 是否限速带宽 | 推荐使用 |
|---|---|---|
| firewalld | ❌ | 否 |
| iptables | ❌(仅包率) | 否 |
| tc | ✅ | ✅✅✅ |
| wondershaper | ✅ | ✅ |
| Nginx/Docker | ✅(应用层) | ✅ |
如果你愿意,可以告诉我:
我可以直接给你可复制的命令。