Chuyển đến nội dung chính

第4課:基本防火牆——規則、鏈與群組

VyOS 防火牆架構(nftables)、input/output/forward 鏈、accept/drop/reject 規則、位址/網路/連接埠群組、狀態策略及疑難排解。

Firewall cơ bản — Rules, Chains và Groups

Kiến trúc Firewall trên VyOS

VyOS sử dụng nftables làm backend firewall (thay thế iptables từ phiên bản 1.4+). Tuy nhiên, bạn không cần viết nftables rules trực tiếp — VyOS CLI trừu tượng hóa toàn bộ qua configuration tree.

Firewall trên VyOS hoạt động dựa trên 3 loại traffic flow:

                    ┌─────────────────┐
   Incoming ──────→ │   INPUT chain   │ ──→ VyOS Router (local processes)
   Traffic          └─────────────────┘
                    ┌─────────────────┐
   Through  ──────→ │  FORWARD chain  │ ──→ Out another interface
   Traffic          └─────────────────┘
                    ┌─────────────────┐
   From VyOS ─────→ │  OUTPUT chain   │ ──→ Outgoing Traffic
   Router           └─────────────────┘
  • input: Traffic đến chính VyOS router (SSH, DNS queries đến router, etc.)
  • forward: Traffic đi qua router từ interface này sang interface khác
  • output: Traffic xuất phát từ chính router (router ping ra ngoài, NTP sync, etc.)

Tạo Firewall Rules cơ bản

Cấu trúc firewall rule

Trong VyOS 1.4+, firewall được cấu hình theo cấu trúc:

set firewall ipv4 <chain> filter rule <number> ...

# chain: input, forward, output
# number: 1-999999 (xử lý từ nhỏ đến lớn)

Default Action

Luôn đặt default-action cho mỗi chain. Best practice: drop (deny by default).

configure

# Default drop cho input — chỉ cho phép traffic được khai báo rõ
set firewall ipv4 input filter default-action 'drop'

# Default drop cho forward
set firewall ipv4 forward filter default-action 'drop'

# Output thường để accept (router cần giao tiếp với bên ngoài)
set firewall ipv4 output filter default-action 'accept'

Rule Actions

  • accept: Cho phép packet đi qua
  • drop: Loại bỏ packet không thông báo (silent drop)
  • reject: Loại bỏ và gửi ICMP error về nguồn
  • jump: Nhảy sang chain khác để xử lý

State Policy — Established / Related

Đây là rule quan trọng nhất trong mọi firewall configuration. Cho phép return traffic của các kết nối đã được thiết lập:

configure

# Cho phép established/related traffic (INPUT)
set firewall ipv4 input filter rule 10 action 'accept'
set firewall ipv4 input filter rule 10 state 'established'
set firewall ipv4 input filter rule 10 state 'related'
set firewall ipv4 input filter rule 10 description 'Allow established/related input'

# Drop invalid state
set firewall ipv4 input filter rule 20 action 'drop'
set firewall ipv4 input filter rule 20 state 'invalid'
set firewall ipv4 input filter rule 20 description 'Drop invalid input'

# Tương tự cho FORWARD chain
set firewall ipv4 forward filter rule 10 action 'accept'
set firewall ipv4 forward filter rule 10 state 'established'
set firewall ipv4 forward filter rule 10 state 'related'
set firewall ipv4 forward filter rule 10 description 'Allow established/related forward'

set firewall ipv4 forward filter rule 20 action 'drop'
set firewall ipv4 forward filter rule 20 state 'invalid'
set firewall ipv4 forward filter rule 20 description 'Drop invalid forward'

commit

Tại sao cần state policy? Khi default-action là drop, nếu không có rule established/related, response traffic (ví dụ: reply từ web server khi bạn browse) sẽ bị drop. State policy cho phép return traffic mà không cần tạo rule riêng cho mỗi kết nối.

Firewall Rules theo Interface

Cho phép SSH đến router từ LAN

# Cho phép SSH (port 22) vào router chỉ từ LAN
set firewall ipv4 input filter rule 100 action 'accept'
set firewall ipv4 input filter rule 100 protocol 'tcp'
set firewall ipv4 input filter rule 100 destination port '22'
set firewall ipv4 input filter rule 100 inbound-interface name 'eth1'
set firewall ipv4 input filter rule 100 description 'Allow SSH from LAN'

commit

Cho phép ICMP (ping) đến router

set firewall ipv4 input filter rule 110 action 'accept'
set firewall ipv4 input filter rule 110 protocol 'icmp'
set firewall ipv4 input filter rule 110 description 'Allow ICMP to router'

commit

Cho phép LAN forward ra Internet

# LAN (eth1) → WAN (eth0): cho phép tất cả
set firewall ipv4 forward filter rule 100 action 'accept'
set firewall ipv4 forward filter rule 100 inbound-interface name 'eth1'
set firewall ipv4 forward filter rule 100 outbound-interface name 'eth0'
set firewall ipv4 forward filter rule 100 description 'Allow LAN to WAN'

commit

Cho phép port forwarding traffic

# WAN → LAN: chỉ cho phép HTTP/HTTPS đến web server
set firewall ipv4 forward filter rule 200 action 'accept'
set firewall ipv4 forward filter rule 200 inbound-interface name 'eth0'
set firewall ipv4 forward filter rule 200 protocol 'tcp'
set firewall ipv4 forward filter rule 200 destination port '80,443'
set firewall ipv4 forward filter rule 200 destination address '192.168.100.100'
set firewall ipv4 forward filter rule 200 description 'Allow HTTP/HTTPS to web server'

commit

Firewall Groups

Firewall groups giúp tổ chức và tái sử dụng các tập hợp addresses, networks, ports trong nhiều rules:

Address Group

# Tạo group chứa các IP của admin
set firewall group address-group ADMIN-IPS address '192.168.100.10'
set firewall group address-group ADMIN-IPS address '192.168.100.11'
set firewall group address-group ADMIN-IPS description 'Administrator IPs'

# Sử dụng trong rule
set firewall ipv4 input filter rule 100 source group address-group 'ADMIN-IPS'

Network Group

# Group các mạng nội bộ
set firewall group network-group INTERNAL-NETS network '192.168.1.0/24'
set firewall group network-group INTERNAL-NETS network '192.168.2.0/24'
set firewall group network-group INTERNAL-NETS network '10.0.0.0/8'
set firewall group network-group INTERNAL-NETS description 'Internal Networks'

# Sử dụng trong rule
set firewall ipv4 forward filter rule 100 source group network-group 'INTERNAL-NETS'

Port Group

# Group các ports web
set firewall group port-group WEB-PORTS port '80'
set firewall group port-group WEB-PORTS port '443'
set firewall group port-group WEB-PORTS port '8080'
set firewall group port-group WEB-PORTS description 'Web Service Ports'

# Sử dụng trong rule
set firewall ipv4 forward filter rule 200 destination group port-group 'WEB-PORTS'

Logging Firewall

Bật logging để theo dõi traffic bị drop hoặc accept:

# Log tất cả traffic bị drop bởi default-action
set firewall ipv4 input filter default-log

# Log cho rule cụ thể
set firewall ipv4 input filter rule 999 action 'drop'
set firewall ipv4 input filter rule 999 log
set firewall ipv4 input filter rule 999 description 'Log and drop all other input'

commit
save

Xem logs:

# Xem firewall logs real-time
monitor log | match firewall

# Hoặc xem từ syslog
show log | match firewall

Xem và quản lý Firewall Rules

# Xem tất cả firewall rules
show firewall

# Xem rules cho chain cụ thể
show firewall ipv4 input filter

# Xem firewall statistics (packet/byte counters)
show firewall ipv4 input filter rule 100

# Xem firewall groups
show firewall group

Troubleshooting Firewall

Các lỗi thường gặp

  • Bị lock khỏi SSH: Quên tạo rule cho phép SSH trước khi set default-action drop
  • LAN không ra Internet: Thiếu forward rule từ LAN sang WAN, hoặc thiếu state established/related
  • Port forward không hoạt động: Có DNAT nhưng thiếu firewall forward rule cho traffic đó

Mẹo an toàn: Khi thay đổi firewall rules qua SSH, luôn dùng commit-confirm thay vì commit. Lệnh này sẽ tự rollback sau 10 phút nếu bạn không confirm — tránh bị lock out.

# Commit với auto-rollback sau 10 phút
commit-confirm

# Nếu mọi thứ OK, confirm để giữ changes
confirm

Debug checklist

# 1. Kiểm tra interfaces
show interfaces

# 2. Kiểm tra routing table
show ip route

# 3. Kiểm tra NAT
show nat source rules
show nat destination rules

# 4. Kiểm tra firewall rules
show firewall ipv4 input filter
show firewall ipv4 forward filter

# 5. Kiểm tra conntrack
show conntrack table ipv4

# 6. Xem logs
show log | tail 50

實作練習: Firewall hoàn chỉnh cho Home Router

Tiếp tục từ lab NAT bài trước, thêm firewall rules:

Internet
    |
[eth0: DHCP] VyOS Router [eth1: 192.168.100.1/24]
    |                          |
    |              +-----------+-----------+
    |              |                       |
    |         PC Client              Web Server
    |       192.168.100.10         192.168.100.100

Bước 1: Firewall groups

configure

# Tạo groups
set firewall group address-group WEB-SERVER address '192.168.100.100'
set firewall group port-group WEB-PORTS port '80'
set firewall group port-group WEB-PORTS port '443'

commit

Bước 2: Input chain (traffic đến router)

# Default drop
set firewall ipv4 input filter default-action 'drop'

# State policy
set firewall ipv4 input filter rule 10 action 'accept'
set firewall ipv4 input filter rule 10 state 'established'
set firewall ipv4 input filter rule 10 state 'related'

set firewall ipv4 input filter rule 20 action 'drop'
set firewall ipv4 input filter rule 20 state 'invalid'

# Allow ICMP
set firewall ipv4 input filter rule 30 action 'accept'
set firewall ipv4 input filter rule 30 protocol 'icmp'

# Allow SSH from LAN only
set firewall ipv4 input filter rule 100 action 'accept'
set firewall ipv4 input filter rule 100 protocol 'tcp'
set firewall ipv4 input filter rule 100 destination port '22'
set firewall ipv4 input filter rule 100 inbound-interface name 'eth1'

# Allow DHCP (nếu VyOS làm DHCP server)
set firewall ipv4 input filter rule 110 action 'accept'
set firewall ipv4 input filter rule 110 protocol 'udp'
set firewall ipv4 input filter rule 110 destination port '67,68'
set firewall ipv4 input filter rule 110 inbound-interface name 'eth1'

# Allow DNS (nếu VyOS làm DNS forwarder)
set firewall ipv4 input filter rule 120 action 'accept'
set firewall ipv4 input filter rule 120 protocol 'tcp_udp'
set firewall ipv4 input filter rule 120 destination port '53'
set firewall ipv4 input filter rule 120 inbound-interface name 'eth1'

commit

Bước 3: Forward chain

# Default drop
set firewall ipv4 forward filter default-action 'drop'

# State policy
set firewall ipv4 forward filter rule 10 action 'accept'
set firewall ipv4 forward filter rule 10 state 'established'
set firewall ipv4 forward filter rule 10 state 'related'

set firewall ipv4 forward filter rule 20 action 'drop'
set firewall ipv4 forward filter rule 20 state 'invalid'

# LAN → WAN: allow all
set firewall ipv4 forward filter rule 100 action 'accept'
set firewall ipv4 forward filter rule 100 inbound-interface name 'eth1'
set firewall ipv4 forward filter rule 100 outbound-interface name 'eth0'

# WAN → LAN: only allow web traffic to web server (port forward)
set firewall ipv4 forward filter rule 200 action 'accept'
set firewall ipv4 forward filter rule 200 inbound-interface name 'eth0'
set firewall ipv4 forward filter rule 200 protocol 'tcp'
set firewall ipv4 forward filter rule 200 destination group address-group 'WEB-SERVER'
set firewall ipv4 forward filter rule 200 destination group port-group 'WEB-PORTS'

commit
save

Bước 4: Kiểm tra

exit

# Xem firewall rules
show firewall ipv4 input filter
show firewall ipv4 forward filter

# Xem groups
show firewall group

# Test: SSH vào router từ LAN → OK
# Test: Ping 8.8.8.8 từ LAN client → OK
# Test: Truy cập web server từ Internet → OK
# Test: SSH vào router từ WAN → Blocked

總結

Trong bài này, bạn đã nắm được:

  • Kiến trúc firewall VyOS với nftables backend và 3 chains: input, forward, output
  • State policy (established/related) — rule quan trọng nhất
  • Tạo firewall rules: action, protocol, port, interface, address matching
  • Firewall groups: address-group, network-group, port-group — giúp quản lý dễ dàng
  • Logging firewall events để monitoring
  • Sử dụng commit-confirm để tránh bị lock out
  • Troubleshooting checklist cho firewall

Bài tiếp theo sẽ nâng cấp lên Zone-based Firewall — phương pháp quản lý firewall chuyên nghiệp hơn cho mạng nhiều zones.