Portál AbcLinuxu, 10. května 2025 16:33
iptables -A PREROUTING -p tcp -m tcp -d 153.65.122.239 --dport 9980 -j DNAT --to-destination 39.80.8.6:9980 iptables: No chain/target/match by that name iptables -A FORWARD -m state -p tcp -d 39.80.8.6 --dport 9980 --state NEW,ESTABLISHED,RELATED -j ACCEPT iptables -A POSTROUTING -p tcp -m tcp -s 39.80.8.6 --sport 9980 -j SNAT --to-source 153.65.122.239 iptables: No chain/target/match by that nameFORWARD chain je OK:
Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destinationNasel jsem stranku, kde meli podobny problem a chybel ip_conntrack, ten mam.
lsmod|grep con ip_conntrack 78492 4 ipt_MASQUERADE,xt_state,iptable_nat,ip_nat nfnetlink 23752 2 ip_nat,ip_conntrack Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 192.168.1.0 * 255.255.255.0 U 0 0 0 vlan4 link-local * 255.255.0.0 U 0 0 0 eth0 153.65.0.0 * 255.255.0.0 U 0 0 0 eth2 39.96.0.0 * 255.240.0.0 U 0 0 0 eth1 39.80.0.0 * 255.240.0.0 U 0 0 0 eth0 39.64.0.0 * 255.240.0.0 U 0 0 0 byn0 loopback * 255.0.0.0 U 0 0 0 lo default 153.65.122.1 0.0.0.0 UG 0 0 0 eth2
PREROUTING
i POSTROUTING
jsou v tabulce nat
, takže se tam určitě někde musí objevit parametr -t nat
.
echo '1' > /proc/sys/net/ipv4/conf/eth0/forwarding echo '1' > /proc/sys/net/ipv4/conf/eth2/forwarding iptables -t nat -A PREROUTING -p tcp -m tcp -d 153.65.122.239 --dport 9980 -j DNAT --to-destination 39.80.8.6:9980 iptables -A FORWARD -m state -p tcp -d 39.80.8.6 --dport 9980 --state NEW,ESTABLISHED,RELATED -j ACCEPT iptables -t nat -A POSTROUTING -p tcp -m tcp -s 39.80.8.6 --sport 9980 -j SNAT --to-source 153.65.122.239Kdyz provedu (
/etc/init.d/network restart), aby se aktivovalo povoleni forward mezi rozhrannimi, tak se to samo opet zakaze(ve forwarding je opet nula). Nemohl by byt problem tam? Jarda
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.