在Mac OS 10.11(El Capitan)上使用pfctl转发端口

Daf*_*fen 9 apache macos portforwarding vagrant osx-elcapitan

我目前正在测试我的开发环境是否会在即将推出的新Mac OS 10.11上运行,如果我可以在它发布后立即升级.在我的测试机器上,我目前正在运行Beta预览版3.一切似乎都运行正常.

我可以pfctl转发我的端口.我使用Vagrant和Parallels Desktop为我的本地Web服务器运行Debian系统.Vagrant将主机上的8080端口转发给客户端80.因此,127.0.0.1:8080工作正常.但在某些项目中,我希望拥有与生产中完全相同的本地域.(没有:8080)我也更喜欢它.;-)

为此,我使用pfctl在主机上转发80到8080.这是我的配置文件:

〜/端口转发/ pf.conf文件

rdr-anchor "forwarding"
load anchor "forwarding" from "/Users/nick/port-forwarding/rules.conf"
Run Code Online (Sandbox Code Playgroud)

〜/端口转发/ rules.conf

rdr pass on lo0 inet proto tcp from any to any port 80 -> 127.0.0.1 port 8080 
rdr pass on lo0 inet proto tcp from any to any port 443 -> 127.0.0.1 port 4433 
Run Code Online (Sandbox Code Playgroud)

要启用它,我运行:

sudo pfctl -vnf ~/port-forwarding/pf.conf
sudo pfctl -evf ~/port-forwarding/pf.conf
Run Code Online (Sandbox Code Playgroud)

这给了我这个:

pfctl: Use of -f option, could result in flushing of rules
present in the main ruleset added by the system at startup.
See /etc/pf.conf for further details.

rdr-anchor "forwarding" all

Loading anchor forwarding from /Users/nick/port-forwarding/rules.conf
rdr pass on lo0 inet proto tcp from any to any port = 80 -> 127.0.0.1 port 8080
rdr pass on lo0 inet proto tcp from any to any port = 443 -> 127.0.0.1 port 4433
pfctl: Use of -f option, could result in flushing of rules
present in the main ruleset added by the system at startup.
See /etc/pf.conf for further details.

No ALTQ support in kernel
ALTQ related functions disabled
rdr-anchor "forwarding" all

Loading anchor forwarding from /Users/nick/port-forwarding/rules.conf
rdr pass on lo0 inet proto tcp from any to any port = 80 -> 127.0.0.1 port 8080
rdr pass on lo0 inet proto tcp from any to any port = 443 -> 127.0.0.1 port 4433
pf enabled
logout
Saving session...completed.
Run Code Online (Sandbox Code Playgroud)

sudo pfctl -s nat说:

No ALTQ support in kernel
ALTQ related functions disabled
rdr-anchor "forwarding" all
Run Code Online (Sandbox Code Playgroud)

到目前为止,它看起来很好,我想.但它只是不起作用.

127.0.0.1:80- 没有连接 127.0.0.1:8080- 有效

我在Yosemite上使用相同的文件,它在那里工作正常.

有没有人知道如何使用pfctl或如果我做错了或者是否有可以报告的错误.

非常感谢

缺口

Cor*_*ory 11

这仅适用于OSX 10.11 - El Capitan - Public Beta 1

x-post来自:https: //superuser.com/questions/938999/osx-10-11-el-capitan-beta-pf-conf-behaviour-changed/943981#943981

在最新的10.11测试版中,127.0.0.1被阻止.解决方案?使用127.0.0.2.去做这个:

首先将127.0.0.2添加到环回别名 sudo ifconfig lo0 alias 127.0.0.2 up

修改您的pf规则以使用新别名. rdr pass proto tcp from any to any port 80 -> 127.0.0.2 port 8080

从命令行,不使用文件:

echo "rdr pass proto tcp from any to any port {80,8080} -> 127.0.0.2 port 8080" | pfctl -Ef - < - 一定要添加最后一个勾号,你在STDIN中管道输入)

  • 确保你使用 sudo: `echo "rdr pass proto tcp from any port {80,8080} -&gt; 127.0.0.2 port 8080" | 须藤 pfctl -Ef -` (2认同)