问题 87
LTM 设备被配置为向一组网络服务器提供负载平衡,这些服务器根据客户端的源 IP 地址实施访问控制列表 (ACL)。ACL 位于网络级别,如果不允许连接,网络服务器将被配置为向客户端发送 TCP 重置。
虚拟服务器使用默认 OneConnect 配置文件进行配置。
网络服务器上的 ACL 定义为
允许:192.168.136.0/24
拒绝:192.168.116.0/24
数据包捕获的是流向 IP 地址为 192.168.136.100 的虚拟服务器的两个客户端数据流。
客户端 A - 源 IP 192.168.136.1 - 虚拟服务器 192.168.136.100:
客户端:
09:35:11.073623 ip 192.168.136.1.55684 > 192.168.136.100.80:S 869998901:869998901(0) win 8192 <mss
1460,nop,wscale 2,nop,nop,sackOK>
09:35:11.073931 IP 192.168.136.100.80 > 192.168.136.1.55684: S 2273668949:2273668949(0) ack
869998902 win 4380
09:35:11.074928 IP 192.168.136.1.55684 > 192.168.136.100.80: . ack 1 win 16425
09:35:11.080936 ip 192.168.136.1.55684 > 192.168.136.100.80:P 1:299(298) ack 1 win 16425
09:35:11.081029 IP 192.168.136.100.80 > 192.168.136.1.55684: . ack 299 win 4678 服务器端:
09:35:11.081022 ip 192.168.136.1.55684 > 192.168.116.128.80:S 685865802:685865802(0) win 4380 <mss
1460,nop,wscale 0,sackOK,eol>
09:35:11.081928 IP 192.168.116.128.80 > 192.168.136.1.55684: S 4193259095:4193259095(0) ack
685865803 win 5840
09:35:11.081943 IP 192.168.136.1.55684 > 192.168.116.128.80: . ack 1 win 4380
09:35:11.081955 ip 192.168.136.1.55684 > 192.168.116.128.80:P 1:299(298) ack 1 win 4380
09:35:11.083765 IP 192.168.116.128.80 > 192.168.136.1.55684: . ack 299 win 108 客户端 B - 源 IP 192.168.116.1 - 虚拟服务器 192.168.136.100:
客户端:
09:36:11.244040 ip 192.168.116.1.55769 > 192.168.136.100.80:S 3320618938:3320618938(0) win 8192
<mss 1460,nop,wscale 2,nop,nop,sackOK>
09:36:11.244152 ip 192.168.136.100.80 > 192.168.116.1.55769:S 3878120666:3878120666(0) ack
3320618939 win 4380
09:36:11.244839 IP 192.168.116.1.55769 > 192.168.136.100.80: . ack 1 win 16425
09:36:11.245830 ip 192.168.116.1.55769 > 192.168.136.100.80:P 1:299(298) ack 1 win 16425
09:36:11.245922 IP 192.168.136.100.80 > 192.168.116.1.55769: . ack 299 win 4678 服务器端:
09:36:11.245940 ip 192.168.136.1.55684 > 192.168.116.128.80:P 599:897(298) ack 4525 win 8904
09:36:11.247847 ip 192.168.116.128.80 > 192.168.136.1.55684:P 4525:5001(476) ack 897 win 142 为什么网络服务器允许第二个客户端流量?