【问题标题】:linux config gateway using iptables [closed]使用 iptables 的 linux 配置网关 [关闭]
【发布时间】:2015-04-06 15:17:21
【问题描述】:

我正在构建一个本地服务器集群。

 server2 eth0 IP:168.168.1.2 
              Gateway: 168.168.1.1
              NETMASK: 255.255.0.0 
 server3: eth0 IP:    168.168.1.3
               Gateway: 168.168.1.1
               NETMASK: 255.255.0.0
 server1: eth0 IP:  168.168.1.1
          eth0:1 IP x.x.x.x(provided by ISP)
                 GATWWAY x.x.x.x(provided by ISP)

我想将 server1 构建为子网的网关。 我可以成功访问server1上的公共网络。但是,它在 server2 上失败。我在 server1 上运行以下命令

 #iptables -t nat -F
 #iptables -t nat -A POSTROUTING -s 168.168.0.0/16  -o eth0:1 -j MASQUERADE
 #iptables -t nat -A POSTROUTING -o eth0:1 -j MASQUERADE

 #iptables -t nat -L

  Chain PREROUTING (policy ACCEPT)
  target     prot opt source               destination

  Chain POSTROUTING (policy ACCEPT)
  target     prot opt source               destination
  MASQUERADE  all  --  anywhere             anywhere

  Chain OUTPUT (policy ACCEPT)
  target     prot opt source               destination


  #iptables -L
  Chain INPUT (policy ACCEPT)
  target     prot opt source               destination

  Chain FORWARD (policy ACCEPT)
  target     prot opt source               destination
  ACCEPT     all  --  anywhere             anywhere

  Chain OUTPUT (policy ACCEPT)
  target     prot opt source               destination

  Chain LOGGING (0 references)
  target     prot opt source               destination

在服务器 2 上

   #ping 173.194.127.240
   PING 173.194.127.240 (173.194.127.240) 56(84) bytes of data.
   From 168.168.1.1: icmp_seq=2 Redirect Host(New nexthop: x.x.x.x(ISP gateway))
   From 168.168.1.1: icmp_seq=3 Redirect Host(New nexthop: x.x.x.x(ISP gateway))
   From 168.168.1.1: icmp_seq=4 Redirect Host(New nexthop: x.x.x.x(ISP gateway))

    --- 173.194.127.240 ping statistics ---
   6 packets transmitted, 0 received, 100% packet loss, time 5950ms

我在 server1 上的配置有什么问题。我应该如何使用 iptables 配置网关?非常感谢

【问题讨论】:

  • a) 这个问题在这里是题外话,属于serverfault.com。等待它被迁移到那里 b) 我是一个有 20 年经验的系统管理员,我既不关心也不敢直接摆弄 iptables,因为我可能做错了什么或愚蠢的事情。我强烈建议使用Tom Eastep's excellent Shorewallfirewalld 之类的东西(仅适用于类似RedHat 的系统)。对于您的用例,我会一直使用 Shorewall。

标签: linux iptables gateway


【解决方案1】:

在同一接口上同时使用 LAN 和 WAN IP 地址并不是最佳做法。我建议为您的 WAN 连接安装一个新的 NIC(例如 eth1)。您的配置看起来不错,只需在安装新网卡后使用 eth1 代替 eth0:1。

【讨论】:

  • 它有效。谢谢。
猜你喜欢
  • 2013-01-30
  • 1970-01-01
  • 1970-01-01
  • 2010-09-13
  • 2017-05-19
  • 1970-01-01
  • 2013-04-03
  • 1970-01-01
  • 2018-01-11
相关资源
最近更新 更多