|
|
发表于 2018-4-5 18:17:16
|
显示全部楼层
proxmox,iptables转发,参考:
- auto lo
- iface lo inet loopback
- auto eno1
- iface eno1 inet static
- address 192.168.1.166
- netmask 255.255.255.0
- gateway 192.168.1.1
- auto vmbr0
- iface vmbr0 inet static
- address 10.0.2.1
- netmask 255.255.255.0
- bridge_ports none
- bridge_stp off
- bridge_fd 0
- post-up echo 1 > /proc/sys/net/ipv4/ip_forward
- post-up iptables -t nat -A POSTROUTING -s '10.0.2.0/24' -o eno1 -j MASQUERADE
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 80 -j DNAT --to 10.0.2.16:80
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 443 -j DNAT --to 10.0.2.16:443
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 8834 -j DNAT --to 10.0.2.15:8834
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 3389 -j DNAT --to 10.0.2.17:3389
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 4443 -j DNAT --to 10.0.2.19:443
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 3390 -j DNAT --to 10.0.2.20:3389
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 8005 -j DNAT --to 10.0.2.21:8005
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp -m tcp --dport 3306 -j DNAT --to 10.0.2.19:6033
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp -m tcp --dport 27777 -j DNAT --to 10.0.2.19:27777
- post-up iptables -t nat -A PREROUTING -i eno1 -p tcp -m tcp --dport 8083 -j DNAT --to 10.0.2.31:8083
- post-down iptables -t nat -D POSTROUTING -s '10.0.2.0/24' -o eno1 -j MASQUERADE
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 80 -j DNAT --to 10.0.2.16:80
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 443 -j DNAT --to 10.0.2.16:443
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 8834 -j DNAT --to 10.0.2.15:8834
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 3389 -j DNAT --to 10.0.2.17:3389
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 4443 -j DNAT --to 10.0.2.19:443
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 3390 -j DNAT --to 10.0.2.20:3389
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp --dport 8005 -j DNAT --to 10.0.2.21:8005
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp -m tcp --dport 3306 -j DNAT --to 10.0.2.19:6033
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp -m tcp --dport 27777 -j DNAT --to 10.0.2.19:27777
- post-down iptables -t nat -D PREROUTING -i eno1 -p tcp -m tcp --dport 8083 -j DNAT --to 10.0.2.31:8083
复制代码 |
|