Kiến trúc Firewall trên VyOS
VyOS sử dụng nftables làm backend firewall (thay thế iptables từ phiên bản 1.4+). Tuy nhiên, bạn không cần viết nftables rules trực tiếp — VyOS CLI trừu tượng hóa toàn bộ qua configuration tree.
Firewall trên VyOS hoạt động dựa trên 3 loại traffic flow:
┌─────────────────┐
Incoming ──────→ │ INPUT chain │ ──→ VyOS Router (local processes)
Traffic └─────────────────┘
┌─────────────────┐
Through ──────→ │ FORWARD chain │ ──→ Out another interface
Traffic └─────────────────┘
┌─────────────────┐
From VyOS ─────→ │ OUTPUT chain │ ──→ Outgoing Traffic
Router └─────────────────┘
- input: Traffic đến chính VyOS router (SSH, DNS queries đến router, etc.)
- forward: Traffic đi qua router từ interface này sang interface khác
- output: Traffic xuất phát từ chính router (router ping ra ngoài, NTP sync, etc.)
Tạo Firewall Rules cơ bản
Cấu trúc firewall rule
Trong VyOS 1.4+, firewall được cấu hình theo cấu trúc:
set firewall ipv4 <chain> filter rule <number> ...
# chain: input, forward, output
# number: 1-999999 (xử lý từ nhỏ đến lớn)
Default Action
Luôn đặt default-action cho mỗi chain. Best practice: drop (deny by default).
configure
# Default drop cho input — chỉ cho phép traffic được khai báo rõ
set firewall ipv4 input filter default-action 'drop'
# Default drop cho forward
set firewall ipv4 forward filter default-action 'drop'
# Output thường để accept (router cần giao tiếp với bên ngoài)
set firewall ipv4 output filter default-action 'accept'
Rule Actions
accept: Cho phép packet đi quadrop: Loại bỏ packet không thông báo (silent drop)reject: Loại bỏ và gửi ICMP error về nguồnjump: Nhảy sang chain khác để xử lý
State Policy — Established / Related
Đây là rule quan trọng nhất trong mọi firewall configuration. Cho phép return traffic của các kết nối đã được thiết lập:
configure
# Cho phép established/related traffic (INPUT)
set firewall ipv4 input filter rule 10 action 'accept'
set firewall ipv4 input filter rule 10 state 'established'
set firewall ipv4 input filter rule 10 state 'related'
set firewall ipv4 input filter rule 10 description 'Allow established/related input'
# Drop invalid state
set firewall ipv4 input filter rule 20 action 'drop'
set firewall ipv4 input filter rule 20 state 'invalid'
set firewall ipv4 input filter rule 20 description 'Drop invalid input'
# Tương tự cho FORWARD chain
set firewall ipv4 forward filter rule 10 action 'accept'
set firewall ipv4 forward filter rule 10 state 'established'
set firewall ipv4 forward filter rule 10 state 'related'
set firewall ipv4 forward filter rule 10 description 'Allow established/related forward'
set firewall ipv4 forward filter rule 20 action 'drop'
set firewall ipv4 forward filter rule 20 state 'invalid'
set firewall ipv4 forward filter rule 20 description 'Drop invalid forward'
commit
Tại sao cần state policy? Khi default-action là drop, nếu không có rule established/related, response traffic (ví dụ: reply từ web server khi bạn browse) sẽ bị drop. State policy cho phép return traffic mà không cần tạo rule riêng cho mỗi kết nối.
Firewall Rules theo Interface
Cho phép SSH đến router từ LAN
# Cho phép SSH (port 22) vào router chỉ từ LAN
set firewall ipv4 input filter rule 100 action 'accept'
set firewall ipv4 input filter rule 100 protocol 'tcp'
set firewall ipv4 input filter rule 100 destination port '22'
set firewall ipv4 input filter rule 100 inbound-interface name 'eth1'
set firewall ipv4 input filter rule 100 description 'Allow SSH from LAN'
commit
Cho phép ICMP (ping) đến router
set firewall ipv4 input filter rule 110 action 'accept'
set firewall ipv4 input filter rule 110 protocol 'icmp'
set firewall ipv4 input filter rule 110 description 'Allow ICMP to router'
commit
Cho phép LAN forward ra Internet
# LAN (eth1) → WAN (eth0): cho phép tất cả
set firewall ipv4 forward filter rule 100 action 'accept'
set firewall ipv4 forward filter rule 100 inbound-interface name 'eth1'
set firewall ipv4 forward filter rule 100 outbound-interface name 'eth0'
set firewall ipv4 forward filter rule 100 description 'Allow LAN to WAN'
commit
Cho phép port forwarding traffic
# WAN → LAN: chỉ cho phép HTTP/HTTPS đến web server
set firewall ipv4 forward filter rule 200 action 'accept'
set firewall ipv4 forward filter rule 200 inbound-interface name 'eth0'
set firewall ipv4 forward filter rule 200 protocol 'tcp'
set firewall ipv4 forward filter rule 200 destination port '80,443'
set firewall ipv4 forward filter rule 200 destination address '192.168.100.100'
set firewall ipv4 forward filter rule 200 description 'Allow HTTP/HTTPS to web server'
commit
Firewall Groups
Firewall groups giúp tổ chức và tái sử dụng các tập hợp addresses, networks, ports trong nhiều rules:
Address Group
# Tạo group chứa các IP của admin
set firewall group address-group ADMIN-IPS address '192.168.100.10'
set firewall group address-group ADMIN-IPS address '192.168.100.11'
set firewall group address-group ADMIN-IPS description 'Administrator IPs'
# Sử dụng trong rule
set firewall ipv4 input filter rule 100 source group address-group 'ADMIN-IPS'
Network Group
# Group các mạng nội bộ
set firewall group network-group INTERNAL-NETS network '192.168.1.0/24'
set firewall group network-group INTERNAL-NETS network '192.168.2.0/24'
set firewall group network-group INTERNAL-NETS network '10.0.0.0/8'
set firewall group network-group INTERNAL-NETS description 'Internal Networks'
# Sử dụng trong rule
set firewall ipv4 forward filter rule 100 source group network-group 'INTERNAL-NETS'
Port Group
# Group các ports web
set firewall group port-group WEB-PORTS port '80'
set firewall group port-group WEB-PORTS port '443'
set firewall group port-group WEB-PORTS port '8080'
set firewall group port-group WEB-PORTS description 'Web Service Ports'
# Sử dụng trong rule
set firewall ipv4 forward filter rule 200 destination group port-group 'WEB-PORTS'
Logging Firewall
Bật logging để theo dõi traffic bị drop hoặc accept:
# Log tất cả traffic bị drop bởi default-action
set firewall ipv4 input filter default-log
# Log cho rule cụ thể
set firewall ipv4 input filter rule 999 action 'drop'
set firewall ipv4 input filter rule 999 log
set firewall ipv4 input filter rule 999 description 'Log and drop all other input'
commit
save
Xem logs:
# Xem firewall logs real-time
monitor log | match firewall
# Hoặc xem từ syslog
show log | match firewall
Xem và quản lý Firewall Rules
# Xem tất cả firewall rules
show firewall
# Xem rules cho chain cụ thể
show firewall ipv4 input filter
# Xem firewall statistics (packet/byte counters)
show firewall ipv4 input filter rule 100
# Xem firewall groups
show firewall group
Troubleshooting Firewall
Các lỗi thường gặp
- Bị lock khỏi SSH: Quên tạo rule cho phép SSH trước khi set default-action drop
- LAN không ra Internet: Thiếu forward rule từ LAN sang WAN, hoặc thiếu state established/related
- Port forward không hoạt động: Có DNAT nhưng thiếu firewall forward rule cho traffic đó
Mẹo an toàn: Khi thay đổi firewall rules qua SSH, luôn dùng
commit-confirmthay vìcommit. Lệnh này sẽ tự rollback sau 10 phút nếu bạn không confirm — tránh bị lock out.
# Commit với auto-rollback sau 10 phút
commit-confirm
# Nếu mọi thứ OK, confirm để giữ changes
confirm
Debug checklist
# 1. Kiểm tra interfaces
show interfaces
# 2. Kiểm tra routing table
show ip route
# 3. Kiểm tra NAT
show nat source rules
show nat destination rules
# 4. Kiểm tra firewall rules
show firewall ipv4 input filter
show firewall ipv4 forward filter
# 5. Kiểm tra conntrack
show conntrack table ipv4
# 6. Xem logs
show log | tail 50
實作練習: Firewall hoàn chỉnh cho Home Router
Tiếp tục từ lab NAT bài trước, thêm firewall rules:
Internet
|
[eth0: DHCP] VyOS Router [eth1: 192.168.100.1/24]
| |
| +-----------+-----------+
| | |
| PC Client Web Server
| 192.168.100.10 192.168.100.100
Bước 1: Firewall groups
configure
# Tạo groups
set firewall group address-group WEB-SERVER address '192.168.100.100'
set firewall group port-group WEB-PORTS port '80'
set firewall group port-group WEB-PORTS port '443'
commit
Bước 2: Input chain (traffic đến router)
# Default drop
set firewall ipv4 input filter default-action 'drop'
# State policy
set firewall ipv4 input filter rule 10 action 'accept'
set firewall ipv4 input filter rule 10 state 'established'
set firewall ipv4 input filter rule 10 state 'related'
set firewall ipv4 input filter rule 20 action 'drop'
set firewall ipv4 input filter rule 20 state 'invalid'
# Allow ICMP
set firewall ipv4 input filter rule 30 action 'accept'
set firewall ipv4 input filter rule 30 protocol 'icmp'
# Allow SSH from LAN only
set firewall ipv4 input filter rule 100 action 'accept'
set firewall ipv4 input filter rule 100 protocol 'tcp'
set firewall ipv4 input filter rule 100 destination port '22'
set firewall ipv4 input filter rule 100 inbound-interface name 'eth1'
# Allow DHCP (nếu VyOS làm DHCP server)
set firewall ipv4 input filter rule 110 action 'accept'
set firewall ipv4 input filter rule 110 protocol 'udp'
set firewall ipv4 input filter rule 110 destination port '67,68'
set firewall ipv4 input filter rule 110 inbound-interface name 'eth1'
# Allow DNS (nếu VyOS làm DNS forwarder)
set firewall ipv4 input filter rule 120 action 'accept'
set firewall ipv4 input filter rule 120 protocol 'tcp_udp'
set firewall ipv4 input filter rule 120 destination port '53'
set firewall ipv4 input filter rule 120 inbound-interface name 'eth1'
commit
Bước 3: Forward chain
# Default drop
set firewall ipv4 forward filter default-action 'drop'
# State policy
set firewall ipv4 forward filter rule 10 action 'accept'
set firewall ipv4 forward filter rule 10 state 'established'
set firewall ipv4 forward filter rule 10 state 'related'
set firewall ipv4 forward filter rule 20 action 'drop'
set firewall ipv4 forward filter rule 20 state 'invalid'
# LAN → WAN: allow all
set firewall ipv4 forward filter rule 100 action 'accept'
set firewall ipv4 forward filter rule 100 inbound-interface name 'eth1'
set firewall ipv4 forward filter rule 100 outbound-interface name 'eth0'
# WAN → LAN: only allow web traffic to web server (port forward)
set firewall ipv4 forward filter rule 200 action 'accept'
set firewall ipv4 forward filter rule 200 inbound-interface name 'eth0'
set firewall ipv4 forward filter rule 200 protocol 'tcp'
set firewall ipv4 forward filter rule 200 destination group address-group 'WEB-SERVER'
set firewall ipv4 forward filter rule 200 destination group port-group 'WEB-PORTS'
commit
save
Bước 4: Kiểm tra
exit
# Xem firewall rules
show firewall ipv4 input filter
show firewall ipv4 forward filter
# Xem groups
show firewall group
# Test: SSH vào router từ LAN → OK
# Test: Ping 8.8.8.8 từ LAN client → OK
# Test: Truy cập web server từ Internet → OK
# Test: SSH vào router từ WAN → Blocked
總結
Trong bài này, bạn đã nắm được:
- Kiến trúc firewall VyOS với nftables backend và 3 chains: input, forward, output
- State policy (established/related) — rule quan trọng nhất
- Tạo firewall rules: action, protocol, port, interface, address matching
- Firewall groups: address-group, network-group, port-group — giúp quản lý dễ dàng
- Logging firewall events để monitoring
- Sử dụng
commit-confirmđể tránh bị lock out - Troubleshooting checklist cho firewall
Bài tiếp theo sẽ nâng cấp lên Zone-based Firewall — phương pháp quản lý firewall chuyên nghiệp hơn cho mạng nhiều zones.