查看 /var/log/ufw.log,每 20 秒就有一条由网关去 224.0.0.1 的日志
1492 Sep 25 11:41:49 ubuntu kernel: [ 555.686523] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=20749 DF PROTO=2
1493 Sep 25 11:42:09 ubuntu kernel: [ 575.688355] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=33551 DF PROTO=2
1494 Sep 25 11:42:29 ubuntu kernel: [ 595.690207] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=37189 DF PROTO=2
1495 Sep 25 11:42:49 ubuntu kernel: [ 615.692028] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=52088 DF PROTO=2
1496 Sep 25 11:43:09 ubuntu kernel: [ 635.693902] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=56817 DF PROTO=2
1497 Sep 25 11:43:29 ubuntu kernel: [ 655.695751] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=9410 DF PROTO=2
1498 Sep 25 11:43:49 ubuntu kernel: [ 675.697587] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=29288 DF PROTO=2
1499 Sep 25 11:44:09 ubuntu kernel: [ 695.699432] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=40176 DF PROTO=2
1500 Sep 25 11:44:29 ubuntu kernel: [ 715.701274] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=51557 DF PROTO=2
1501 Sep 25 11:44:49 ubuntu kernel: [ 735.703117] [UFW BLOCK] IN=eno1 OUT= MAC=XXXXXXXXXXXX SRC=192.168.50.1 DST=224.0.0.1 LEN=36 TOS=0x00 PREC=0x00 TTL=1 ID=63617 DF PROTO=2
可以 加 deny rule 就可以了
sudo ufw deny from 192.168.50.1 to 224.0.0.1
sudo ufw reload
sudo ufw status numbered
Status: active
To Action From
-- ------ ----
[ 1] 22/tcp ALLOW IN Anywhere
[ 2] 21/tcp ALLOW IN Anywhere
[ 3] 80/tcp ALLOW IN Anywhere
[ 4] 443/tcp ALLOW IN Anywhere
[ 5] 3270/tcp ALLOW IN Anywhere
[ 6] Anywhere ALLOW IN 192.168.200.1
[ 7] Anywhere ALLOW IN 192.168.50.11
[ 8] Anywhere on tun0 ALLOW FWD Anywhere on eno1
[ 9] Anywhere on eno1 ALLOW FWD Anywhere on tun0
[10] Anywhere ALLOW IN 192.168.50.16
[11] 3306/tcp ALLOW IN Anywhere
[12] 224.0.0.1 DENY IN 192.168.50.1
[13] 22/tcp (v6) ALLOW IN Anywhere (v6)
[14] 21/tcp (v6) ALLOW IN Anywhere (v6)
[15] 80/tcp (v6) ALLOW IN Anywhere (v6)
[16] 443/tcp (v6) ALLOW IN Anywhere (v6)
[17] 3270/tcp (v6) ALLOW IN Anywhere (v6)
[18] Anywhere (v6) on tun0 ALLOW FWD Anywhere (v6) on eno1
[19] Anywhere (v6) on eno1 ALLOW FWD Anywhere (v6) on tun0
[20] 3306/tcp (v6) ALLOW IN Anywhere (v6)
如果要删除,可以用 delete
sudo ufw delete 12