LinuxÒÁµéÔ°ÂÛ̳'s Archiver

poonline ·¢±íÓÚ 2003-12-30 11:00

ÇóÖú °¡ ¹ØÓÚiptables

ÔÚRedHat linux enterprise AS ÖУ¬iptables ÊDZàÒëÔÚÄÚºËÖС£
ÎÒÏëÀûÓÃnetfilterµÄNAT¹¦ÄÜ,°Ñweb·þÎñÆ÷µÄInternetµØÖ·Ó³Éä³ÉÄÚÍøµØÖ·¡£
Internet eth2 211.139.227.119
DMZ eth1 192.168.21.10

HTTP Internet IP 211.139.227.120
DMZ IP 192.168.21.11

ÎÒÔÚfilter±íĬÈϲßÂÔÊǽÓÊÜ¡£

ÎÒÔÚNAT±íÖÐĬÈϲßÂÔÊǽÓÊÜ£¬»¹ÓÐ
iptables -t nat -A PREROUTING -i eth2 -d 211.139.227.120 -j DNAT --to-destination 192.168.21.11
iptables -t nat -A POSTROUTING -o eth2 -s 192.168.21.11 -j SNAT --to-source 211.139.227.120

µ«ÕâÑùÉèÖò»µ«web·þÎñÆ÷²»ÄÜ·ÃÎÊinternet,´ÓinternetÒ²²»ÄÜ·ÃÎʸ÷þÎñÆ÷£¬ÎªÊ²Ã´£¿

Èç¹ûÎÒÔÚNAT±íÖнöдÈ룺
iptables -t nat -A POSTROUTING -o eth2 -j SNAT --to-source 211.139.227.119
»òÕß
iptables -t nat -A POSTROUTING -o eth2 -s 192.168.21.0/24 -j SNAT --to-source 211.139.227.119
Ôòweb·þÎñÆ÷¿ÉÒÔ·ÃÎÊinternet

µ«Èç¹ûд³É£º
iptables -t nat -A POSTROUTING -o eth2 -s 192.168.21.11 -j SNAT --to-source 211.139.227.119
Ôò²»ÄÜ·ÃÎÊinternet,Ϊʲô£¿

ÕæµÄºÜÓôÃÆ£¬¿´Á˼¸ÌìµÄÊ飬»¹ÊÇÒ»ËúºýÍ¿!!

лл¸÷λ³öÊÖ½â»ó¡£

Ò³: [1]

Powered by Discuz! Archiver 6.1.0  © 2001-2007 Comsenz Inc.