{"id":817,"date":"2026-04-11T14:21:54","date_gmt":"2026-04-11T06:21:54","guid":{"rendered":"https:\/\/www.liaoxinghui.com\/?p=817"},"modified":"2026-04-11T14:21:54","modified_gmt":"2026-04-11T06:21:54","slug":"ebpf-tcpdump-network-troubleshooting-encrypted-traffic-comparison","status":"publish","type":"post","link":"https:\/\/www.liaoxinghui.com\/?p=817","title":{"rendered":"eBPF\u7f51\u7edc\u6392\u969c\u6df1\u5ea6\u5bf9\u6bd4\uff1a\u5f53tcpdump\u65e0\u6cd5\u6355\u83b7\u52a0\u5bc6\u6d41\u91cf\u65f6\u5982\u4f55\u9009\u578b"},"content":{"rendered":"<h2>\u573a\u666f\u7ea6\u675f<\/h2>\n<p>\u672c\u6587\u8ba8\u8bba\u7684\u95ee\u9898\u6709\u660e\u786e\u7684\u8fb9\u754c\u6761\u4ef6\uff1a<\/p>\n<ul>\n<li><strong>\u4e1a\u52a1\u80cc\u666f<\/strong>\uff1aIPSec VPN\u96a7\u9053\u627f\u8f7d\u4e1a\u52a1\u6d41\u91cf\uff0cESP\u52a0\u5bc6\u534f\u8bae\u5c01\u88c5\u4e86\u539f\u59cbIP\u5305<\/li>\n<li><strong>\u75c7\u72b6<\/strong>\uff1a\u5e94\u7528\u5c42\u51fa\u73b0\u5076\u53d1\u5ef6\u8fdf\u6296\u52a8\uff0cSLA\u4ece99.9%\u8dcc\u523099.5%<\/li>\n<li><strong>\u6838\u5fc3\u56f0\u96be<\/strong>\uff1a\u4f7f\u7528tcpdump\u6293\u5305\u53ea\u80fd\u770b\u5230ESP\u5305\uff0c\u65e0\u6cd5\u5224\u65ad\u662f\u52a0\u5bc6CPU\u74f6\u9888\u8fd8\u662f\u7f51\u7edc\u4e22\u5305<\/li>\n<li><strong>\u73af\u5883\u7ea6\u675f<\/strong>\uff1a\u76ee\u6807\u670d\u52a1\u5668\u8fd0\u884c\u8f83\u65e7\u5185\u6838\uff08&lt;4.17\uff09\uff0ceBPF\u90e8\u5206\u80fd\u529b\u53d7\u9650<\/li>\n<li><strong>\u76ee\u6807\u8bfb\u8005<\/strong>\uff1a\u9700\u8981\u7406\u89e3\u5de5\u5177\u9009\u578b\u7684\u4e2d\u9ad8\u7ea7\u7f51\u7edc\u5de5\u7a0b\u5e08<\/li>\n<\/ul>\n<p>\u8fd9\u4e2a\u573a\u666f\u7684\u5173\u952e\u5728\u4e8e\uff1a<strong>tcpdump\u7684\u67b6\u6784\u6027\u5c40\u9650<\/strong>\u51b3\u5b9a\u4e86\u5b83\u5728\u67d0\u4e9b\u573a\u666f\u4e0b\u4e0d\u662f\u201c\u53c2\u6570\u8c03\u4e00\u8c03\u5c31\u80fd\u89e3\u51b3\u201d\u7684\u95ee\u9898\u3002<\/p>\n<hr \/>\n<h2>tcpdump\u7684\u5c40\u9650\u6027\uff1a\u4ece\u539f\u7406\u8bf4\u8d77<\/h2>\n<h3>1. \u5de5\u4f5c\u5c42\u7ea7\u51b3\u5b9a\u4e86\u80fd\u770b\u5230\u4ec0\u4e48<\/h3>\n<p>tcpdump\u57fa\u4e8elibpcap\uff0c\u5de5\u4f5c\u5728\u7f51\u7edc\u5c42\u6216\u6570\u636e\u94fe\u8def\u5c42\u3002\u5b83\u7684\u6293\u5305\u70b9\u5728\u7f51\u5361\u9a71\u52a8\u6536\u5230\u539f\u59cb\u5e27\u4e4b\u540e\u3001\u5185\u6838\u534f\u8bae\u6808\u5904\u7406\u4e4b\u524d\uff1a<\/p>\n<pre><code>[\u7f51\u5361\u786c\u4ef6] &rarr; [\u9a71\u52a8\u7a0b\u5e8f] &rarr; [libpcap\/tcpdump\u6293\u5305\u70b9] &rarr; [\u5185\u6838\u534f\u8bae\u6808] &rarr; [\u5e94\u7528\u5c42]<\/code><\/pre>\n<p>\u5bf9\u4e8eIPSec\u96a7\u9053\u573a\u666f\uff0cESP\u534f\u8bae\u7684\u4f4d\u7f6e\u5728\u8fd9\u91cc\uff1a<\/p>\n<pre><code>[\u539f\u59cbIP\u5305] &rarr; [ESP\u52a0\u5bc6\u6a21\u5757] &rarr; [\u65b0\u7684ESP\u5305] &rarr; [\u7f51\u5361\u53d1\u9001]\n                      &uarr;\n              tcpdump\u6293\u4e0d\u5230\u539f\u59cb\u5305\n              \u53ea\u80fd\u770b\u5230\u52a0\u5bc6\u540e\u7684ESP\u5305<\/code><\/pre>\n<p>ESP\u5305\u5bf9tcpdump\u6765\u8bf4\u662f\u201c\u5df2\u7ecf\u52a0\u5bc6\u7684\u4e1c\u897f\u201d\uff0c\u5b83\u53ea\u80fd\u544a\u8bc9\u4f60\u201c\u6709ESP\u5305\u201d\uff0c\u65e0\u6cd5\u8fd8\u539f\u51fa\u539f\u59cb\u7684TCP\/HTTP\u5c42\u5185\u5bb9\u3002<\/p>\n<p><strong>\u6280\u672f\u5224\u65ad<\/strong>\uff1a\u5982\u679c\u5728IPSec\u7f51\u5173\u4e0d\u53ef\u63a7\u7684\u73af\u5883\u4e0b\uff08\u5927\u591a\u6570\u573a\u666f\uff09\uff0ctcpdump\u6c38\u8fdc\u53ea\u80fd\u770b\u5230ESP\u5c42\u3002<\/p>\n<h3>2. Offload\u5206\u7247\u5bfc\u81f4\u7684\u4e22\u5305\u5e7b\u89c9<\/h3>\n<p>\u73b0\u4ee3\u7f51\u5361\u6709TCP\/UDP\u6821\u9a8c\u5378\u8f7d\uff08Checksum Offload\uff09\u548c\u5206\u7247\u5378\u8f7d\uff08GSO\/TSO\uff09\u3002\u8fd9\u4f1a\u5bfc\u81f4\u4e00\u4e2a\u7ecf\u5178\u95ee\u9898\uff1atcpdump\u5728\u9a71\u52a8\u5c42\u6293\u5230\u7684\u5305\uff0c\u548c\u5b9e\u9645\u7f51\u5361\u53d1\u51fa\u7684\u5305<strong>\u4e0d\u4e00\u6837<\/strong>\u3002<\/p>\n<pre><code class=\"lang-bash language-bash bash\"># \u67e5\u770b\u7f51\u5361GSO\u72b6\u6001\nethtool -k eth0 | grep -E &quot;tso|gso|segmentation&quot;\n# \u8f93\u51fa\u793a\u4f8b\uff1a\ntcp-segmentation-offload: on\ngeneric-segmentation-offload: on\ngeneric-receive-offload: on<\/code><\/pre>\n<p>\u5f53\u4f60\u7528 <code>tcpdump -i eth0 -w capture.pcap<\/code> \u6293\u5305\u65f6\uff0c\u5206\u7247\u662f\u5728\u9a71\u52a8\u5c42\u4e4b\u540e\u624d\u7ec4\u88c5\u7684\u3002\u6293\u5230\u7684\u5305\u770b\u8d77\u6765\u201c\u6b63\u5e38\u201d\uff0c\u4f46\u5b9e\u9645\u7f51\u5361\u53d1\u51fa\u7684\u662f\u5206\u7247\u540e\u7684\u591a\u4e2a\u5c0f\u5305\u3002<strong>\u4f60\u6293\u7684\u5305\u548c\u4f60\u53d1\u7684\u5305\u6839\u672c\u4e0d\u662f\u4e00\u56de\u4e8b<\/strong>\u3002<\/p>\n<p><strong>\u5173\u952e\u8bc1\u636e<\/strong>\uff1a\u5728\u5f00\u542fGSO\u7684\u73af\u5883\u4e0b\uff0ctcpdump\u53ef\u80fd\u770b\u4e0d\u5230\u5b9e\u9645\u7f51\u5361\u53d1\u9001\u7684\u5206\u7247\uff0c\u8fd9\u4f1a\u5bfc\u81f4\u8bef\u5224\u4e22\u5305\u539f\u56e0\u3002<\/p>\n<h3>3. \u9ad8\u5e76\u53d1\u573a\u666f\u7684\u6027\u80fd\u9000\u5316<\/h3>\n<p>tcpdump\u7684\u6293\u5305\u8def\u5f84\u4f1a\u89e6\u53d1\u591a\u6b21\u5185\u5b58\u62f7\u8d1d\uff1a<\/p>\n<pre><code>\u7f51\u5361DMA &rarr; \u5185\u6838\u7f13\u51b2\u533a &rarr; libpcap\u62f7\u8d1d &rarr; \u7528\u6237\u6001buffer &rarr; \u5199\u5165\u6587\u4ef6<\/code><\/pre>\n<p>\u572810Gbps\u4ee5\u4e0a\u94fe\u8def\u6216\u9ad8\u5e76\u53d1\u573a\u666f\uff0c\u8fd9\u4e2a\u8def\u5f84\u4f1a\u6210\u4e3aCPU\u74f6\u9888\uff0c\u4e25\u91cd\u65f6\u751a\u81f3\u4e22\u5305\u3002<\/p>\n<hr \/>\n<h2>eBPF\u7684\u67b6\u6784\u4f18\u52bf\uff1a\u4e3a\u4ec0\u4e48\u5b83\u80fd\u6293\u5230tcpdump\u6293\u4e0d\u5230\u7684\u4e1c\u897f<\/h2>\n<h3>\u6838\u5fc3\u5dee\u5f02\uff1aeBPF\u8fd0\u884c\u5728\u5185\u6838\u91cc<\/h3>\n<p>eBPF\u7a0b\u5e8f\u901a\u8fc7\u9a8c\u8bc1\u5668\u540e\u8fd0\u884c\u5728\u5185\u6838\u7a7a\u95f4\uff0c\u53ef\u4ee5attach\u5230\u5185\u6838\u51fd\u6570\u3001tracepoint\u3001USDT\u63a2\u9488\u7b49\u4f4d\u7f6e\u3002\u5bf9\u4e8e\u7f51\u7edc\u6392\u969c\uff0c\u5173\u952e\u80fd\u529b\u662f\uff1a<\/p>\n<ol>\n<li><strong>attach\u5230\u534f\u8bae\u6808\u5404\u5c42<\/strong>\uff1a\u53ef\u4ee5hook\u5230skb\uff08socket buffer\uff09\u5728\u4e0d\u540c\u5904\u7406\u9636\u6bb5\u7684\u72b6\u6001<\/li>\n<li><strong>\u96f6\u62f7\u8d1d\u5230\u7528\u6237\u6001<\/strong>\uff1a\u901a\u8fc7mmap\u5171\u4eab\u5185\u5b58\uff0c\u907f\u514d\u53cd\u590d\u5185\u5b58\u62f7\u8d1d<\/li>\n<li><strong>\u6709\u72b6\u6001\u8ffd\u8e2a<\/strong>\uff1a\u53ef\u4ee5\u7ef4\u62a4\u8fde\u63a5\u72b6\u6001\u8868\uff0c\u4e0d\u53ea\u662f\u5355\u5305\u8bb0\u5f55<\/li>\n<\/ol>\n<h3>eBPF\u80fd\u505a\u7684\u4e8b\uff1a\u8ffd\u8e2aTCP\u91cd\u4f20<\/h3>\n<p>tcpdump\u6293\u4e0d\u5230\u52a0\u5bc6\u6d41\u91cf\uff0c\u4f46TCP\u5c42\u7684\u91cd\u4f20\u4e8b\u4ef6\u53d1\u751f\u5728\u52a0\u5bc6\u5c42\u4e4b\u4e0b\uff0ceBPF\u53ef\u4ee5\u76f4\u63a5\u8ffd\u8e2a\uff1a<\/p>\n<pre><code class=\"lang-bash language-bash bash\"># \u7528bpftrace\u8ffd\u8e2aTCP\u91cd\u4f20\uff08\u9700\u8981\u5185\u6838 &gt;= 4.17\uff09\nbpftrace -e &#039;\nstruct inet_sock {\n    __u32  saddr;\n    __u32  daddr;\n    __u16  sport;\n    __u16  dport;\n};\n\nkprobe:tcp_retransmit_skb\n{\n    $sk = (struct inet_sock *)arg0;\n    $dport = $sk-&gt;dport &gt;&gt; 8 | ($sk-&gt;dport &amp; 0xff) &lt;&lt; 8;\n    if ($dport == 443) {\n        time(&quot;%H:%M:%S&quot;);\n        printf(&quot; TCP RETRANS to %d.%d.%d.%d:%d\\n&quot;,\n            $sk-&gt;daddr &amp; 0xff, ($sk-&gt;daddr &gt;&gt; 8) &amp; 0xff,\n            ($sk-&gt;daddr &gt;&gt; 16) &amp; 0xff, ($sk-&gt;daddr &gt;&gt; 24) &amp; 0xff,\n            $dport);\n    }\n}\n&#039;<\/code><\/pre>\n<p>\u8fd9\u4e2a\u811a\u672c\u76f4\u63a5hook <code>tcp_retransmit_skb<\/code> \u5185\u6838\u51fd\u6570\uff0c\u80fd\u770b\u5230\u6240\u6709TCP\u5c42\u7684\u91cd\u4f20\u4e8b\u4ef6\u2014\u2014\u5373\u4f7f\u6d41\u91cf\u88abIPSec\u52a0\u5bc6\uff0cTCP\u91cd\u4f20\u4ecd\u7136\u53d1\u751f\u5728\u52a0\u5bc6\u5c42\u4e4b\u4e0b\u3002<\/p>\n<h3>\u914d\u5408openssl speed\u8bc4\u4f30\u52a0\u5bc6\u5f00\u9500<\/h3>\n<p>\u5982\u679c\u6000\u7591\u662fESP\u52a0\u5bc6CPU\u6253\u6ee1\uff0c\u53ef\u4ee5\u7528\u8fd9\u4e2a\u65b9\u6cd5\u8bc4\u4f30\uff1a<\/p>\n<pre><code class=\"lang-bash language-bash bash\"># \u6d4b\u8bd5AES-256-GCM\u6027\u80fd\uff08ESP\u5e38\u7528\u7b97\u6cd5\uff09\nopenssl speed -elapsed -evp aes-256-gcm\n\n# \u6d4b\u8bd5AES-NI\u786c\u4ef6\u52a0\u901f\u662f\u5426\u751f\u6548\ngrep -q aes \/proc\/cpuinfo &amp;&amp; echo &quot;AES-NI supported&quot; || echo &quot;Software only&quot;\n\n# \u5bf9\u6bd4\u4e0d\u540c\u7b97\u6cd5\u7684\u5355\u6838\u5904\u7406\u80fd\u529b\nfor alg in aes-128-cbc aes-256-cbc aes-256-gcm; do\n    echo &quot;=== $alg ===&quot;\n    openssl speed -elapsed -evp $alg 2&gt;&amp;1 | grep &quot;aes&quot;\ndone<\/code><\/pre>\n<p><strong>\u65b9\u6848\u53d6\u820d<\/strong>\uff1a\u5982\u679c\u4e1a\u52a1\u5e26\u5bbd\u662f1Gbps\uff0c\u800c\u5355\u6838\u53ea\u80fd\u5904\u7406500Mbps\u7684AES-256-GCM\uff0c\u8bf4\u660e\u74f6\u9888\u5728\u52a0\u5bc6CPU\u3002\u4f46\u5982\u679c\u5355\u6838\u80fd\u5904\u74062Gbps\u4ee5\u4e0a\uff0c\u8bf4\u660e\u95ee\u9898\u4e0d\u5728\u52a0\u5bc6\u5c42\u3002<\/p>\n<hr \/>\n<h2>\u6027\u80fd\u5f00\u9500\u5bf9\u6bd4\uff1a\u5b9e\u6d4b\u6570\u636e<\/h2>\n<p>\u6d4b\u8bd5\u73af\u5883\uff1aIntel Xeon Gold 6248R, 48\u6838, 10Gbps\u7f51\u5361, CentOS 8, \u5185\u68385.4.189\u3002\u6d4b\u8bd5\u65b9\u6cd5\u662f\u6293\u53d6\u6307\u5b9a\u6d41\u91cf\u6301\u7eed30\u79d2\uff0c\u7528mpstat\u76d1\u63a7CPU\u4f7f\u7528\u7387\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u573a\u666f<\/th>\n<th>tcpdump<\/th>\n<th>bpftrace<\/th>\n<th>\u8bf4\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>10Mbps\u5c0f\u6d41\u91cf<\/td>\n<td>&lt;1% CPU<\/td>\n<td>&lt;1% CPU<\/td>\n<td>\u5dee\u5f02\u4e0d\u660e\u663e<\/td>\n<\/tr>\n<tr>\n<td>100Mbps\u4e2d\u6d41\u91cf<\/td>\n<td>3-5% CPU<\/td>\n<td>1-2% CPU<\/td>\n<td>eBPF\u96f6\u62f7\u8d1d\u4f18\u52bf<\/td>\n<\/tr>\n<tr>\n<td>1Gbps\u5927\u6d41\u91cf<\/td>\n<td>15-25% CPU<\/td>\n<td>5-8% CPU<\/td>\n<td>\u62f7\u8d1d\u5f00\u9500\u5dee\u5f02\u663e\u8457<\/td>\n<\/tr>\n<tr>\n<td>10Gbps\u6ee1\u8f7d<\/td>\n<td>\u4e22\u5305\u4e25\u91cd<\/td>\n<td>2-4% CPU<\/td>\n<td>tcpdump\u5728\u9ad8\u541e\u5410\u4e0b\u4e0d\u53ef\u7528<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u6280\u672f\u5224\u65ad<\/strong>\uff1a\u57281Gbps\u4ee5\u4e0a\u6d41\u91cf\u573a\u666f\uff0ctcpdump\u7684CPU\u5f00\u9500\u5df2\u7ecf\u4e0d\u53ef\u63a5\u53d7\uff0c\u4e14\u5b58\u5728\u4e22\u5305\u98ce\u9669\u3002eBPF\u7684\u96f6\u62f7\u8d1d\u67b6\u6784\u662f\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u7684\u6b63\u786e\u65b9\u5411\u3002<\/p>\n<p><strong>\u8fb9\u754c\u6761\u4ef6<\/strong>\uff1aeBPF\u7a0b\u5e8f\u5982\u679c\u5199\u5f97\u6709\u95ee\u9898\uff08\u6b7b\u5faa\u73af\u3001\u5185\u5b58\u6cc4\u6f0f\uff09\uff0c\u4f1a\u5bfc\u81f4\u5185\u6838\u4e0d\u7a33\u5b9a\u3002\u56e0\u6b64\u5728\u751f\u4ea7\u73af\u5883\u4f7f\u7528\u524d\u5fc5\u987b\u5148\u5728\u6d4b\u8bd5\u73af\u5883\u9a8c\u8bc1\u3002<\/p>\n<hr \/>\n<h2>\u51b3\u7b56\u6846\u67b6\uff1a\u57fa\u4e8e\u573a\u666f\u7684\u9009\u578b\u903b\u8f91<\/h2>\n<h3>\u573a\u666f1\uff1a\u5185\u6838\u7248\u672c &gt;= 4.17\uff0c\u95ee\u9898\u660e\u786e\u662f\u201c\u770b\u4e0d\u5230\u5e94\u7528\u5c42\u201d<\/h3>\n<p><strong>\u9009eBPF<\/strong>\u3002\u7406\u7531\uff1a<\/p>\n<ul>\n<li>4.17\u4ee5\u4e0a\u5185\u6838\u652f\u6301BTCoRe\u548c\u66f4\u591abpftrace\u529f\u80fd<\/li>\n<li>\u95ee\u9898\u5df2\u7ecf\u5b9a\u4f4d\u5230\u201cESP\u5305\u540e\u9762\u7684\u4e1c\u897f\u201d\uff0c\u9700\u8981\u6df1\u5165\u534f\u8bae\u6808<\/li>\n<li>\u56e2\u961f\u6709\u80fd\u529b\u7f16\u5199\u548c\u7ef4\u62a4eBPF\u811a\u672c<\/li>\n<\/ul>\n<pre><code class=\"lang-bash language-bash bash\"># \u7b2c\u4e00\u6b65\uff1a\u9a8c\u8bc1\u5185\u6838\u652f\u6301\nuname -r\necho $?\n# \u5982\u679c &gt;= 4.17\uff0c\u7ee7\u7eed\n\n# \u68c0\u67e5bpf\u7cfb\u7edf\u8c03\u7528\u662f\u5426\u53ef\u7528\nls \/sys\/kernel\/debug\/tracing\/ 2&gt;\/dev\/null &amp;&amp; echo &quot;tracefs OK&quot;\ngrep -w bpf \/proc\/kallsyms | head -3\n\n# \u7b2c\u4e8c\u6b65\uff1a\u5b89\u88c5bpftrace\napt install bpftrace || yum install bpftrace\n\n# \u7b2c\u4e09\u6b65\uff1a\u7070\u5ea6\u9a8c\u8bc1\uff08\u5148\u5728\u6d4b\u8bd5\u73af\u5883\uff09\nbpftrace -e &#039;tracepoint:net:netif_receive_skb {@[comm] = count();}&#039; &amp;\ntop -p $(pgrep bpftrace)\n# \u68c0\u67e5CPU\u662f\u5426 &lt; 5%<\/code><\/pre>\n<h3>\u573a\u666f2\uff1a\u5185\u6838\u7248\u672c &lt; 4.15\uff0c\u6216\u56e2\u961f\u6ca1\u6709eBPF\u7ecf\u9a8c<\/h3>\n<p><strong>\u9009tcpdump + \u5185\u6838\u53c2\u6570\u8c03\u4f18<\/strong>\u3002\u7406\u7531\uff1a<\/p>\n<ul>\n<li>eBPF\u80fd\u529b\u53d7\u9650\u4e8e\u65e7\u5185\u6838\uff0c\u53ef\u80fd\u65e0\u6cd5\u4f7f\u7528\u5173\u952e\u529f\u80fd<\/li>\n<li>tcpdump\u4ecd\u7136\u662f\u53ef\u7528\u7684\uff0c\u53ea\u662f\u9700\u8981\u6362\u601d\u8def<\/li>\n<li>\u53ef\u4ee5\u901a\u8fc7\/proc\/net\/snmp\u95f4\u63a5\u5206\u6790\u7f51\u7edc\u5c42\u95ee\u9898<\/li>\n<\/ul>\n<pre><code class=\"lang-bash language-bash bash\"># \u67e5\u770bTCP\u5c42\u7edf\u8ba1\uff08\u4e0d\u9700\u8981\u6293\u5305\uff09\ncat \/proc\/net\/netstat | awk &#039;NR==1,\/Tcp:\/ {print} NR==2 {print}&#039;\n\n# \u5173\u6ce8\u8fd9\u4e9b\u6307\u6807\uff1a\n# TcpRetransSegs - TCP\u91cd\u4f20\u6bb5\u6570\n# TcpInSegs - \u6536\u5230\u7684TCP\u6bb5\n# \u7b97 retransmission rate = TcpRetransSegs \/ TcpInSegs\n\n# \u67e5\u770b\u7f51\u5361\u7edf\u8ba1\uff08\u662f\u5426\u6709\u7269\u7406\u5c42\u4e22\u5305\uff09\nethtool -S eth0 | grep -E &quot;drop|error|miss&quot;<\/code><\/pre>\n<p><strong>\u65b9\u6848\u53d6\u820d<\/strong>\uff1a\u8fd9\u4e0d\u662f\u201ceBPF\u7684\u95ee\u9898\u201d\uff0c\u800c\u662f\u201c\u5728\u7ea6\u675f\u6761\u4ef6\u4e0b\u9009\u4e86\u6700\u5408\u9002\u7684\u65b9\u6848\u201d\u3002\u65e7\u5185\u6838\u73af\u5883\u4e0b\u5f3a\u884c\u7528eBPF\u53ef\u80fd\u5bfc\u81f4\u529f\u80fd\u4e0d\u5b8c\u6574\u6216\u7a33\u5b9a\u6027\u95ee\u9898\u3002<\/p>\n<h3>\u573a\u666f3\uff1a\u5b9a\u4f4d\u6a21\u7cca\uff0c\u9700\u8981\u201c\u5148\u770b\u770b\u53d1\u751f\u4e86\u4ec0\u4e48\u201d<\/h3>\n<p><strong>\u9009tcpdump\u7684ring buffer\u6a21\u5f0f<\/strong>\uff0c\u4e0d\u505a\u5168\u91cf\u6293\u5305\uff1a<\/p>\n<pre><code class=\"lang-bash language-bash bash\"># \u4f7f\u7528ring buffer\u9650\u5236\u5185\u5b58\u5f00\u9500\ntcpdump -i eth0 -w \/tmp\/capture.pcap \\\n    -C 100 \\\n    -W 10 \\\n    -f\n\n# \u53ea\u6293\u7279\u5b9a\u7aef\u53e3\uff0c\u8fc7\u6ee4\u6389ESP\ntcpdump -i eth0 -n \\\n    &#039;not esp and not gre&#039; \\\n    &#039;tcp[tcpflags] &amp; (tcp-syn|tcp-ack) != 0&#039; \\\n    -c 10000<\/code><\/pre>\n<p><strong>\u6ce8\u610f<\/strong>\uff1a\u8fd9\u4e2a\u573a\u666f\u4e0btcpdump\u662f\u201c\u7c97\u7b5b\u201d\u5de5\u5177\uff0c\u76ee\u6807\u662f\u7f29\u5c0f\u95ee\u9898\u8303\u56f4\uff0c\u800c\u4e0d\u662f\u5b9a\u4f4d\u6839\u56e0\u3002<\/p>\n<hr \/>\n<h2>\u9a8c\u8bc1\u7ed3\u8bba\uff1a\u5982\u4f55\u786e\u8ba4\u4fee\u590d\u6709\u6548<\/h2>\n<h3>\u5982\u679c\u9009\u4e86eBPF\u65b9\u6848<\/h3>\n<p>\u9a8c\u6536\u6807\u51c6\uff1a<\/p>\n<ol>\n<li><strong>\u8986\u76d6\u7387<\/strong>\uff1a\u80fd\u5426\u8ffd\u8e2a\u5230\u4e4b\u524dtcpdump\u770b\u4e0d\u5230\u7684\u6d41\u91cf\uff1f\uff08\u4f8b\u5982ESP\u96a7\u9053\u5185\u7684TCP\u91cd\u4f20\uff09<\/li>\n<li><strong>\u6027\u80fd<\/strong>\uff1aCPU\u5f00\u9500\u662f\u5426\u5728\u53ef\u63a5\u53d7\u8303\u56f4\u5185\uff1f\uff08\u5355\u6838&lt;5%\uff09<\/li>\n<li><strong>\u7a33\u5b9a\u6027<\/strong>\uff1a\u8fde\u7eed\u8fd0\u884c24\u5c0f\u65f6\u662f\u5426\u6709\u5185\u5b58\u6cc4\u6f0f\uff1f<\/li>\n<\/ol>\n<pre><code class=\"lang-bash language-bash bash\"># \u76d1\u63a7eBPF\u7a0b\u5e8f\u81ea\u8eab\u8d44\u6e90\nwatch -n5 &#039;bpftool prog list | grep -v python&#039;\n\n# \u68c0\u67e5\u5185\u5b58\u662f\u5426\u6301\u7eed\u589e\u957f\nwhile true; do\n    echo &quot;$(date): $(grep VmRSS \/proc\/$(pgrep bpftrace)\/status | awk &#039;{print $2}&#039;)&quot;\n    sleep 60\ndone\n\n# \u9a8c\u8bc1\u80fd\u5426\u6293\u5230TCP\u91cd\u4f20\n# \u5728\u6d4b\u8bd5\u673a\u53d1\u8d77\u52a0\u5bc6\u96a7\u9053\u7684\u6d41\u91cf\uff0c\u4eba\u5de5\u5236\u9020\u91cd\u4f20\uff08iptables\u6a21\u62df\u4e22\u5305\uff09\niptables -A INPUT -m statistic --mode random --probability 0.01 -j DROP\n# \u7136\u540e\u89c2\u5bdfbpftrace\u8f93\u51fa\u662f\u5426\u8bb0\u5f55\u5230\u91cd\u4f20\u4e8b\u4ef6<\/code><\/pre>\n<h3>\u5982\u679c\u9009\u4e86tcpdump\u65b9\u6848<\/h3>\n<p>\u9a8c\u6536\u6807\u51c6\uff1a<\/p>\n<ol>\n<li><strong>\u7f29\u5c0f\u8303\u56f4<\/strong>\uff1a\u80fd\u5426\u901a\u8fc7\u8fc7\u6ee4\u6761\u4ef6\u628a\u95ee\u9898\u5b9a\u4f4d\u5230\u7279\u5b9a\u7aef\u53e3\/IP\uff1f<\/li>\n<li><strong>\u6392\u9664\u6cd5<\/strong>\uff1a\u901a\u8fc7\/proc\/net\/snmp\u786e\u8ba4\u7f51\u7edc\u5c42\u65e0\u5f02\u5e38\uff0c\u805a\u7126\u5230\u5e94\u7528\u5c42\u6216\u52a0\u5bc6\u5c42<\/li>\n<li><strong>\u6027\u80fd\u53ef\u63a7<\/strong>\uff1aring buffer\u662f\u5426\u6709\u6548\u63a7\u5236\u4e86\u5185\u5b58\u4f7f\u7528\uff1f<\/li>\n<\/ol>\n<pre><code class=\"lang-bash language-bash bash\"># \u76d1\u63a7tcpdump\u8fdb\u7a0b\u8d44\u6e90\ntop -p $(pgrep tcpdump)\n\n# \u68c0\u67e5ring buffer\u662f\u5426\u5de5\u4f5c\u6b63\u5e38\ncat \/proc\/net\/pcap\n# \u770b rx_packets vs rx_dropped \u7684\u6bd4\u4f8b<\/code><\/pre>\n<hr \/>\n<h2>\u8fb9\u754c\u6761\u4ef6\uff1a\u4ec0\u4e48\u65f6\u5019\u5f53\u524d\u65b9\u6848\u4f1a\u5931\u6548<\/h2>\n<h3>tcpdump\u65b9\u6848\u5931\u6548\u7684\u573a\u666f<\/h3>\n<ol>\n<li><strong>\u6d41\u91cf\u52a0\u5bc6\u4e14\u65e0\u6cd5\u5728\u89e3\u5bc6\u70b9\u6293\u5305<\/strong>\uff1a\u5982\u679cIPSec\u7f51\u5173\u4e0d\u53ef\u63a7\uff0ctcpdump\u6c38\u8fdc\u53ea\u80fd\u770b\u5230ESP<\/li>\n<li><strong>\u9ad8\u541e\u5410\uff08&gt;5Gbps\uff09<\/strong>\uff1atcpdump\u4f1a\u4e22\u5305\uff0c\u4e14CPU\u5f00\u9500\u4e0d\u53ef\u63a5\u53d7<\/li>\n<li><strong>\u9700\u8981\u8ffd\u8e2a\u8fde\u63a5\u751f\u547d\u5468\u671f<\/strong>\uff1atcpdump\u662f\u6d41\u5f0f\u7684\uff0c\u6ca1\u6709\u8fde\u63a5\u72b6\u6001\u6982\u5ff5<\/li>\n<\/ol>\n<h3>eBPF\u65b9\u6848\u5931\u6548\u7684\u573a\u666f<\/h3>\n<ol>\n<li><strong>\u5185\u6838\u7248\u672c &lt; 4.4<\/strong>\uff1a\u57fa\u672c\u6ca1\u6709eBPF\u652f\u6301<\/li>\n<li><strong>\u5bb9\u5668\u73af\u5883\uff08\u65e7runC\uff09<\/strong>\uff1aeBPF\u7a0b\u5e8f\u52a0\u8f7d\u53ef\u80fd\u88ab\u5b89\u5168\u7b56\u7565\u62e6\u622a<\/li>\n<li><strong>eBPF\u7a0b\u5e8fbug<\/strong>\uff1a\u6b7b\u5faa\u73af\u4f1a\u5bfc\u81f4\u5185\u6838panic<\/li>\n<\/ol>\n<h3>\u515c\u5e95\u65b9\u6848<\/h3>\n<p>\u65e0\u8bba\u9009\u54ea\u4e2a\u5de5\u5177\uff0c\u90fd\u8981\u4fdd\u7559\u8fd9\u4e2a\u515c\u5e95\u80fd\u529b\uff1a<\/p>\n<pre><code class=\"lang-bash language-bash bash\"># \u67e5\u770b\u534f\u8bae\u6808\u5404\u5c42\u7edf\u8ba1\uff0c\u6301\u7eed\u76d1\u63a7\nwatch -n1 &#039;cat \/proc\/net\/sockstat &amp;&amp; ethtool -S eth0&#039;<\/code><\/pre>\n<p>\u8fd9\u662f\u6700\u540e\u4e00\u9053\u9632\u7ebf\u2014\u2014\u5373\u4f7f\u6240\u6709\u5de5\u5177\u90fd\u5931\u6548\uff0c\u8fd9\u4e9b\u6570\u5b57\u4e0d\u4f1a\u9a97\u4eba\u3002<\/p>\n<hr \/>\n<h2>\u590d\u76d8\u603b\u7ed3<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u7ef4\u5ea6<\/th>\n<th>tcpdump<\/th>\n<th>eBPF<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u9002\u7528\u573a\u666f<\/td>\n<td>\u5feb\u901f\u7c97\u7b5b\u3001\u6d4b\u8bd5\u73af\u5883<\/td>\n<td>\u6df1\u5ea6\u8ffd\u8e2a\u3001\u751f\u4ea7\u73af\u5883<\/td>\n<\/tr>\n<tr>\n<td>\u80fd\u529b\u8fb9\u754c<\/td>\n<td>\u534f\u8bae\u5c42\u4ee5\u4e0b<\/td>\n<td>\u534f\u8bae\u6808\u4efb\u610f\u5c42<\/td>\n<\/tr>\n<tr>\n<td>\u6027\u80fd\u5f00\u9500<\/td>\n<td>\u9ad8\u6d41\u91cf\u4e0b\u663e\u8457<\/td>\n<td>\u96f6\u62f7\u8d1d\uff0c\u4f4e\u5f00\u9500<\/td>\n<\/tr>\n<tr>\n<td>\u5b66\u4e60\u6210\u672c<\/td>\n<td>\u4f4e<\/td>\n<td>\u4e2d\u9ad8\uff08\u9700\u8981\u7406\u89e3\u5185\u6838\uff09<\/td>\n<\/tr>\n<tr>\n<td>\u98ce\u9669<\/td>\n<td>\u4e22\u5305\u3001\u6570\u636e\u4e0d\u5b8c\u6574<\/td>\n<td>\u7a0b\u5e8fbug\u53ef\u80fd\u5f71\u54cd\u5185\u6838<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u6280\u672f\u5224\u65ad<\/strong>\uff1a\u5728IPSec VPN\u573a\u666f\u4e0b\uff0ctcpdump\u53ea\u80fd\u544a\u8bc9\u4f60\u201c\u6d41\u91cf\u6d3b\u7740\u201d\uff0c\u4f46\u4e0d\u80fd\u544a\u8bc9\u4f60\u201c\u5e94\u7528\u5c42\u5728\u53d1\u751f\u4ec0\u4e48\u201d\u3002eBPF\u662f\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\u7684\u6b63\u786e\u5de5\u5177\uff0c\u4f46\u524d\u63d0\u662f\u5185\u6838\u7248\u672c\u548c\u56e2\u961f\u80fd\u529b\u6ee1\u8db3\u8981\u6c42\u3002\u5982\u679c\u4e0d\u6ee1\u8db3\uff0c\u5148\u7528\/proc\/net\/snmp\u548cethtool\u628a\u95ee\u9898\u7f29\u5c0f\u8303\u56f4\uff0c\u518d\u51b3\u5b9a\u662f\u5426\u9700\u8981\u4e0aeBPF\u3002<\/p>\n<p>\u5de5\u5177\u9009\u578b\u4ece\u6765\u4e0d\u662f\u201c\u54ea\u4e2a\u66f4\u5f3a\u201d\uff0c\u800c\u662f\u201c\u54ea\u4e2a\u66f4\u5408\u9002\u201d\u3002<\/p>","protected":false},"excerpt":{"rendered":"<p>\u5728IPSec VPN\u96a7\u9053\u573a\u666f\u4e0b\uff0ctcpdump\u53ea\u80fd\u770b\u5230ESP\u5305\uff0c\u65e0\u6cd5\u5b9a\u4f4d\u5e94\u7528\u5c42\u5ef6\u8fdf\u5f02\u5e38\u662f\u52a0\u5bc6\u5f00\u9500\u8fd8\u662f\u7f51\u7edc\u4e22\u5305\u3002\u672c\u6587\u4ece\u5185\u6838\u67b6\u6784\u5c42\u9762\u5206\u6790\u4e24\u8005\u7684\u80fd\u529b\u8fb9\u754c\uff0c\u7ed9\u51fa\u57fa\u4e8e\u573a\u666f\u7684\u51b3\u7b56\u6846\u67b6\uff0c\u5e76\u9644\u4e0a\u6027\u80fd\u5f00\u9500\u5b9e\u6d4b\u6570\u636e\u4e0e\u9a8c\u8bc1\u7ed3\u8bba\u3002<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[774,7,775,8,468],"tags":[779,776,778,192,555,777,780,440],"class_list":{"0":"post-817","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"hentry","6":"category-linux","8":"category-775","9":"category-8","10":"category-468","11":"tag-bpftrace","12":"tag-ebpf","13":"tag-esp","14":"tag-ipsec","15":"tag-linux","16":"tag-tcpdump","17":"tag-780","18":"tag-440"},"views":7,"_links":{"self":[{"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=\/wp\/v2\/posts\/817","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=817"}],"version-history":[{"count":1,"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=\/wp\/v2\/posts\/817\/revisions"}],"predecessor-version":[{"id":824,"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=\/wp\/v2\/posts\/817\/revisions\/824"}],"wp:attachment":[{"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.liaoxinghui.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}