mirror of
https://github.com/TeaOSLab/EdgeAdmin.git
synced 2025-11-16 21:50:24 +08:00
实现基础的DDoS防护
This commit is contained in:
@@ -0,0 +1,112 @@
|
||||
Vue.component("ddos-protection-ip-list-config-box", {
|
||||
props: ["v-ip-list"],
|
||||
data: function () {
|
||||
let list = this.vIpList
|
||||
if (list == null) {
|
||||
list = []
|
||||
}
|
||||
return {
|
||||
list: list,
|
||||
isAdding: false,
|
||||
addingIP: {
|
||||
ip: "",
|
||||
description: ""
|
||||
}
|
||||
}
|
||||
},
|
||||
methods: {
|
||||
add: function () {
|
||||
this.isAdding = true
|
||||
let that = this
|
||||
setTimeout(function () {
|
||||
that.$refs.addingIPInput.focus()
|
||||
})
|
||||
},
|
||||
confirm: function () {
|
||||
let ip = this.addingIP.ip
|
||||
if (ip.length == 0) {
|
||||
this.warn("请输入IP")
|
||||
return
|
||||
}
|
||||
|
||||
let exists = false
|
||||
this.list.forEach(function (v) {
|
||||
if (v.ip == ip) {
|
||||
exists = true
|
||||
}
|
||||
})
|
||||
if (exists) {
|
||||
this.warn("IP '" + ip + "'已经存在")
|
||||
return
|
||||
}
|
||||
|
||||
let that = this
|
||||
Tea.Vue.$post("/ui/validateIPs")
|
||||
.params({
|
||||
ips: [ip]
|
||||
})
|
||||
.success(function () {
|
||||
that.list.push({
|
||||
ip: ip,
|
||||
description: that.addingIP.description
|
||||
})
|
||||
that.notifyChange()
|
||||
that.cancel()
|
||||
})
|
||||
.fail(function () {
|
||||
that.warn("请输入正确的IP")
|
||||
})
|
||||
},
|
||||
cancel: function () {
|
||||
this.isAdding = false
|
||||
this.addingIP = {
|
||||
ip: "",
|
||||
description: ""
|
||||
}
|
||||
},
|
||||
remove: function (index) {
|
||||
this.list.$remove(index)
|
||||
this.notifyChange()
|
||||
},
|
||||
warn: function (message) {
|
||||
let that = this
|
||||
teaweb.warn(message, function () {
|
||||
that.$refs.addingIPInput.focus()
|
||||
})
|
||||
},
|
||||
notifyChange: function () {
|
||||
this.$emit("change", this.list)
|
||||
}
|
||||
},
|
||||
template: `<div>
|
||||
<div v-if="list.length > 0">
|
||||
<div class="ui label basic tiny" v-for="(ipConfig, index) in list">
|
||||
{{ipConfig.ip}} <span class="grey small" v-if="ipConfig.description.length > 0">({{ipConfig.description}})</span> <a href="" @click.prevent="remove(index)" title="删除"><i class="icon remove"></i></a>
|
||||
</div>
|
||||
<div class="ui divider"></div>
|
||||
</div>
|
||||
<div v-if="isAdding">
|
||||
<div class="ui fields inline">
|
||||
<div class="ui field">
|
||||
<div class="ui input left labeled">
|
||||
<span class="ui label">IP</span>
|
||||
<input type="text" v-model="addingIP.ip" ref="addingIPInput" maxlength="40" size="20" placeholder="IP" @keyup.enter="confirm" @keypress.enter.prevent="1"/>
|
||||
</div>
|
||||
</div>
|
||||
<div class="ui field">
|
||||
<div class="ui input left labeled">
|
||||
<span class="ui label">备注</span>
|
||||
<input type="text" v-model="addingIP.description" maxlength="10" size="10" placeholder="备注(可选)" @keyup.enter="confirm" @keypress.enter.prevent="1"/>
|
||||
</div>
|
||||
</div>
|
||||
<div class="ui field">
|
||||
<button class="ui button tiny" type="button" @click.prevent="confirm">确定</button>
|
||||
<a href="" @click.prevent="cancel()">取消</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div v-if="!isAdding">
|
||||
<button class="ui button tiny" type="button" @click.prevent="add">+</button>
|
||||
</div>
|
||||
</div>`
|
||||
})
|
||||
@@ -0,0 +1,115 @@
|
||||
Vue.component("ddos-protection-ports-config-box", {
|
||||
props: ["v-ports"],
|
||||
data: function () {
|
||||
let ports = this.vPorts
|
||||
if (ports == null) {
|
||||
ports = []
|
||||
}
|
||||
return {
|
||||
ports: ports,
|
||||
isAdding: false,
|
||||
addingPort: {
|
||||
port: "",
|
||||
description: ""
|
||||
}
|
||||
}
|
||||
},
|
||||
methods: {
|
||||
add: function () {
|
||||
this.isAdding = true
|
||||
let that = this
|
||||
setTimeout(function () {
|
||||
that.$refs.addingPortInput.focus()
|
||||
})
|
||||
},
|
||||
confirm: function () {
|
||||
let portString = this.addingPort.port
|
||||
if (portString.length == 0) {
|
||||
this.warn("请输入端口号")
|
||||
return
|
||||
}
|
||||
if (!/^\d+$/.test(portString)) {
|
||||
this.warn("请输入正确的端口号")
|
||||
return
|
||||
}
|
||||
let port = parseInt(portString, 10)
|
||||
if (port <= 0) {
|
||||
this.warn("请输入正确的端口号")
|
||||
return
|
||||
}
|
||||
if (port > 65535) {
|
||||
this.warn("请输入正确的端口号")
|
||||
return
|
||||
}
|
||||
|
||||
let exists = false
|
||||
this.ports.forEach(function (v) {
|
||||
if (v.port == port) {
|
||||
exists = true
|
||||
}
|
||||
})
|
||||
if (exists) {
|
||||
this.warn("端口号已经存在")
|
||||
return
|
||||
}
|
||||
|
||||
this.ports.push({
|
||||
port: port,
|
||||
description: this.addingPort.description
|
||||
})
|
||||
this.notifyChange()
|
||||
this.cancel()
|
||||
},
|
||||
cancel: function () {
|
||||
this.isAdding = false
|
||||
this.addingPort = {
|
||||
port: "",
|
||||
description: ""
|
||||
}
|
||||
},
|
||||
remove: function (index) {
|
||||
this.ports.$remove(index)
|
||||
this.notifyChange()
|
||||
},
|
||||
warn: function (message) {
|
||||
let that = this
|
||||
teaweb.warn(message, function () {
|
||||
that.$refs.addingPortInput.focus()
|
||||
})
|
||||
},
|
||||
notifyChange: function () {
|
||||
this.$emit("change", this.ports)
|
||||
}
|
||||
},
|
||||
template: `<div>
|
||||
<div v-if="ports.length > 0">
|
||||
<div class="ui label basic tiny" v-for="(portConfig, index) in ports">
|
||||
{{portConfig.port}} <span class="grey small" v-if="portConfig.description.length > 0">({{portConfig.description}})</span> <a href="" @click.prevent="remove(index)" title="删除"><i class="icon remove"></i></a>
|
||||
</div>
|
||||
<div class="ui divider"></div>
|
||||
</div>
|
||||
<div v-if="isAdding">
|
||||
<div class="ui fields inline">
|
||||
<div class="ui field">
|
||||
<div class="ui input left labeled">
|
||||
<span class="ui label">端口</span>
|
||||
<input type="text" v-model="addingPort.port" ref="addingPortInput" maxlength="5" size="5" placeholder="端口号" @keyup.enter="confirm" @keypress.enter.prevent="1"/>
|
||||
</div>
|
||||
</div>
|
||||
<div class="ui field">
|
||||
<div class="ui input left labeled">
|
||||
<span class="ui label">备注</span>
|
||||
<input type="text" v-model="addingPort.description" maxlength="12" size="12" placeholder="备注(可选)" @keyup.enter="confirm" @keypress.enter.prevent="1"/>
|
||||
</div>
|
||||
</div>
|
||||
<div class="ui field">
|
||||
<button class="ui button tiny" type="button" @click.prevent="confirm">确定</button>
|
||||
<a href="" @click.prevent="cancel()">取消</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div v-if="!isAdding">
|
||||
<button class="ui button tiny" type="button" @click.prevent="add">+</button>
|
||||
</div>
|
||||
</div>`
|
||||
})
|
||||
@@ -0,0 +1,110 @@
|
||||
Vue.component("node-ddos-protection-config-box", {
|
||||
props: ["v-ddos-protection-config", "v-default-configs", "v-is-node", "v-cluster-is-on"],
|
||||
data: function () {
|
||||
let config = this.vDdosProtectionConfig
|
||||
if (config == null) {
|
||||
config = {
|
||||
tcp: {
|
||||
isPrior: false,
|
||||
isOn: false,
|
||||
maxConnections: 0,
|
||||
maxConnectionsPerIP: 0,
|
||||
newConnectionsRate: 0,
|
||||
allowIPList: [],
|
||||
ports: []
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// initialize
|
||||
if (config.tcp == null) {
|
||||
config.tcp = {
|
||||
isPrior: false,
|
||||
isOn: false,
|
||||
maxConnections: 0,
|
||||
maxConnectionsPerIP: 0,
|
||||
newConnectionsRate: 0,
|
||||
allowIPList: [],
|
||||
ports: []
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
return {
|
||||
config: config,
|
||||
defaultConfigs: this.vDefaultConfigs,
|
||||
isNode: this.vIsNode,
|
||||
|
||||
isAddingPort: false
|
||||
}
|
||||
},
|
||||
methods: {
|
||||
changeTCPPorts: function (ports) {
|
||||
this.config.tcp.ports = ports
|
||||
},
|
||||
changeTCPAllowIPList: function (ipList) {
|
||||
this.config.tcp.allowIPList = ipList
|
||||
}
|
||||
},
|
||||
template: `<div>
|
||||
<input type="hidden" name="ddosProtectionJSON" :value="JSON.stringify(config)"/>
|
||||
|
||||
<p class="comment">功能说明:此功能为<strong>试验性质</strong>,目前仅能防御简单的DDoS攻击,试验期间建议仅在被攻击时启用,仅支持已安装<code-label>nftables v0.9</code-label>以上的Linux系统。<pro-warning-label></pro-warning-label></p>
|
||||
|
||||
<div class="ui message" v-if="vClusterIsOn">当前节点所在集群已设置DDoS防护。</div>
|
||||
|
||||
<h4>TCP设置</h4>
|
||||
<table class="ui table definition selectable">
|
||||
<prior-checkbox :v-config="config.tcp" v-if="isNode"></prior-checkbox>
|
||||
<tbody v-show="config.tcp.isPrior || !isNode">
|
||||
<tr>
|
||||
<td class="title">启用</td>
|
||||
<td>
|
||||
<checkbox v-model="config.tcp.isOn"></checkbox>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
<tbody v-show="config.tcp.isOn && (config.tcp.isPrior || !isNode)">
|
||||
<tr>
|
||||
<td class="title">单节点TCP最大连接数</td>
|
||||
<td>
|
||||
<digit-input name="tcpMaxConnections" v-model="config.tcp.maxConnections" maxlength="6" size="6" style="width: 6em"></digit-input>
|
||||
<p class="comment">单个节点可以接受的TCP最大连接数。如果为0,则默认为{{defaultConfigs.tcpMaxConnections}}。</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>单IP TCP最大连接数</td>
|
||||
<td>
|
||||
<digit-input name="tcpMaxConnectionsPerIP" v-model="config.tcp.maxConnectionsPerIP" maxlength="6" size="6" style="width: 6em"></digit-input>
|
||||
<p class="comment">单个IP可以连接到节点的TCP最大连接数。如果为0,则默认为{{defaultConfigs.tcpMaxConnectionsPerIP}};最小值为{{defaultConfigs.tcpMinConnectionsPerIP}}。</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>单IP TCP新连接速率</td>
|
||||
<td>
|
||||
<div class="ui input right labeled">
|
||||
<digit-input name="tcpNewConnectionsRate" v-model="config.tcp.newConnectionsRate" maxlength="6" size="6" style="width: 6em" :min="defaultConfigs.tcpNewConnectionsMinRate"></digit-input>
|
||||
<span class="ui label">个新连接/每分钟</span>
|
||||
</div>
|
||||
<p class="comment">单个IP可以创建TCP新连接的速率。如果为0,则默认为{{defaultConfigs.tcpNewConnectionsRate}};最小值为{{defaultConfigs.tcpNewConnectionsMinRate}}。</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>TCP端口列表</td>
|
||||
<td>
|
||||
<ddos-protection-ports-config-box :v-ports="config.tcp.ports" @change="changeTCPPorts"></ddos-protection-ports-config-box>
|
||||
<p class="comment">默认为80和443两个端口。</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>IP白名单</td>
|
||||
<td>
|
||||
<ddos-protection-ip-list-config-box :v-ip-list="config.tcp.allowIPList" @change="changeTCPAllowIPList"></ddos-protection-ip-list-config-box>
|
||||
<p class="comment">在白名单中的IP不受当前设置的限制。</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
<div class="margin"></div>
|
||||
</div>`
|
||||
})
|
||||
Reference in New Issue
Block a user