- 论坛徽章:
- 0
|
原帖由 chenyx 于 2009-12-28 21:14 发表 ![]()
楼主那个网卡对应试外网啊?
画个简单的topo图,另外,把route表和iptables规则贴上来
画个简单的top结构:
内网---------------------------||-------------------------Host----------------------------||----------------------------外网
(1.1.1.x/24) eth0 eth1 (192.168.1.X/24)
(1.1.1.12/8) (192.168.1.111/24)
设置转发前的route 和 iptables-save:
ping 外网(www.baidu.com)和网关(192.168.1.1)正常
[root@localhost ~]# cat /proc/sys/net/ipv4/ip_forward
0
[root@localhost ~]#
[root@localhost ~]# ping www.baidu.com
PING www.a.shifen.com (119.75.216.30) 56(84) bytes of data.
64 bytes from 119.75.216.30: icmp_seq=1 ttl=57 time=11.3 ms |
设置转发前的route信息和iptables-save:
[root@localhost ~]# route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.1.0 * 255.255.255.0 U 0 0 0 eth1
link-local * 255.255.0.0 U 0 0 0 eth1
1.0.0.0 * 255.0.0.0 U 0 0 0 eth0
default bogon 0.0.0.0 UG 0 0 0 eth1
[root@localhost ~]#
[root@localhost ~]# iptables-save
# Generated by iptables-save v1.3.8 on Tue Dec 29 13:01:03 2009
*mangle
:PREROUTING ACCEPT [7229:375737]
:INPUT ACCEPT [55:23148]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [22:3517]
:POSTROUTING ACCEPT [22:3517]
COMMIT
# Completed on Tue Dec 29 13:01:03 2009
# Generated by iptables-save v1.3.8 on Tue Dec 29 13:01:03 2009
*filter
:INPUT ACCEPT [490:127160]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [131:14861]
COMMIT
# Completed on Tue Dec 29 13:01:03 2009
# Generated by iptables-save v1.3.8 on Tue Dec 29 13:01:03 2009
*nat
:PREROUTING ACCEPT [14634:718198]
:POSTROUTING ACCEPT [9:728]
:OUTPUT ACCEPT [9:728]
COMMIT
# Completed on Tue Dec 29 13:01:03 2009 |
设置转发后的route和iptables-save:
[root@localhost ~]# cat /proc/sys/net/ipv4/ip_forward
1
[root@localhost ~]# ping 192.168.1.1
PING 192.168.1.1 (192.168.1.1) 56(84) bytes of data.
--- 192.168.1.1 ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 999ms
[root@localhost ~]# ping www.baidu.com
PING www.a.shifen.com (119.75.213.61) 56(84) bytes of data.
--- www.a.shifen.com ping statistics ---
1 packets transmitted, 0 received, 100% packet loss, time 0ms
[root@localhost ~]# route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.1.0 * 255.255.255.0 U 0 0 0 eth1
link-local * 255.255.0.0 U 0 0 0 eth1
1.0.0.0 * 255.0.0.0 U 0 0 0 eth0
default bogon 0.0.0.0 UG 0 0 0 eth1
[root@localhost ~]#
[root@localhost ~]# iptables-save
# Generated by iptables-save v1.3.8 on Tue Dec 29 13:05:02 2009
*mangle
:PREROUTING ACCEPT [27346:1510208]
:INPUT ACCEPT [672:215813]
:FORWARD ACCEPT [4485:217272]
:OUTPUT ACCEPT [297:39158]
:POSTROUTING ACCEPT [4782:256430]
COMMIT
# Completed on Tue Dec 29 13:05:02 2009
# Generated by iptables-save v1.3.8 on Tue Dec 29 13:05:02 2009
*filter
:INPUT ACCEPT [1107:319825]
:FORWARD ACCEPT [4485:217272]
:OUTPUT ACCEPT [406:50502]
COMMIT
# Completed on Tue Dec 29 13:05:02 2009
# Generated by iptables-save v1.3.8 on Tue Dec 29 13:05:02 2009
*nat
:PREROUTING ACCEPT [31991:1558602]
:POSTROUTING ACCEPT [2325:112206]
:OUTPUT ACCEPT [18:1316]
COMMIT
# Completed on Tue Dec 29 13:05:02 2009
[root@localhost ~]# |
|
|