Warum werden bestimmte Pakete im öffentlichen VLAN gelöscht?
Virtuelle Private Cloud Klassische Infrastruktur
Sie stellen fest, dass Ihre IBM Cloud Kubernetes Service-Worker bestimmte ungültige Pakete oder Ingress-Pakete in einem öffentlichen VLAN mit privaten Quellenadressen löschen. Sie erstellen beispielsweise eine Lastausgleichsfunktion für Anwendungen
(Application Load Balancer, ALB) für Ihren Cluster, können aber keine Verbindung zu dieser Funktion herstellen. Sie erhalten eine Nachricht ähnlich der folgenden: Unable to connect to <ALB>.
Wenn Sie für bestimmte angepasste Netzkonfigurationen beispielsweise ein VPN konfigurieren, um Ingress-Datenverkehr zu einer öffentlichen IKS-Lastausgleichsfunktion zuzulassen, der von privaten IP-Quellenadressen stammt, wird Ihr angepasster Datenverkehr möglicherweise gelöscht und ist nicht mehr verfügbar. Diese Aktion wird durch die DDOS-Regeln (DDOS = Distributed Denial of Service) verursacht, die in einer durch Mangling verschlüsselten IP-Tabelle für Kubernetes-Workerknoten festgelegt sind.
Die durch Mangling verschlüsselte IP-Tabelle enthält die folgenden Regeln.
2488 214K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID /* DDOS: Blocks RST flood and TCP XMAS Flood (w and w/o data) */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x03/0x03 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x06 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x05/0x05 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x11/0x01 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x30/0x20 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x11/0x01 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x18/0x08 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x3F /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x29 /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x2B /* DDOS: Invalid packets */
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x37 /* DDOS: Invalid packets */
0 0 DROP all -- eth1 * 224.0.0.0/3 0.0.0.0/0 /* DDOS: Drop private source IPs */
21803 1744K DROP all -- eth1 * 169.254.0.0/16 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 DROP all -- eth1 * 172.16.0.0/12 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 DROP all -- eth1 * 192.0.2.0/24 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 DROP all -- eth1 * 0.0.0.0/8 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 DROP all -- eth1 * 240.0.0.0/5 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 DROP all -- eth1 * 10.0.0.0/8 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 DROP all -- eth1 * 192.168.0.0/16 0.0.0.0/0 /* DDOS: Drop private source IPs */
0 0 ACCEPT all -- vethlocal * 127.0.0.0/8 0.0.0.0/0 /* DDOS: Accept local LB traffic */
0 0 DROP all -- !lo * 127.0.0.0/8 0.0.0.0/0 /* DDOS: Drop private source IPs */
Beheben Sie dieses Problem, indem Sie eine private Lastausgleichsfunktion erstellen, um diesen Datenverkehr mit den privaten IP-Quellenadressen zuzulassen. Wenn das Problem dadurch nicht behoben wird oder Sie aus irgendeinem Grund keine private Lastausgleichsfunktion erstellen können, erstellen Sie eine Dämongruppe, zum Entfernen der Regeln, die das Problem verursachen.