Chr*_*ian 3 networking linux vpn iptables
我有一个堡垒主机的 VPN 设置。我正在尝试映射,10.8.0.0/17以便10.0.0.0/17将 IP 地址10.8.1.1映射到10.0.1.1我的本地网络中。
我想这个问题的罪魁祸首是
iptables -t nat -A PREROUTING -d 10.8.0.0/17 -j DNAT --to-destination 10.0.0.0-10.0.127.255
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
####
# This allows you to DNAT connections in a round-robin way over a given range of destination addresses.
# --to-destination ipaddr-ipaddr
# Address range to round-robin over.
Run Code Online (Sandbox Code Playgroud)
# What I Want:
# 10.8.0.1 -> 10.0.0.253 -> 10.0.0.1
# What I Get:
listening on tun0, link-type RAW (Raw IP), snapshot length 262144 bytes
04:41:15.934726 IP 10.8.255.1 > 10.8.0.1: ICMP echo request, id 93, seq 1, length 64
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
05:50:27.228399 IP 10.0.0.253 > 10.0.52.24: ICMP echo request, id 93, seq 1, length 64
^^^^^^^^^^
Wrong IP Address!!!
Run Code Online (Sandbox Code Playgroud)
如何将目标的(前 17 位/后 15 位)写入新目标。我想要实现的一个更清晰的例子是VPN 中的10.8.0.100与我的 LAN 网络中的10.0.0.100相关。
注意:这是我第一次在两个网络之间设置路由,如果有任何明显的错误或与正常约定不一致的地方,请指出,我还在学习中。IPTables如何nat 10.8.ab到10.0.ab?
| 网络 | 虚拟专用网IP |
|---|---|
| 10.0.0.1 | ISP网关 |
| 10.0.0.253 | 家庭 OpenVPN 网关 ( 10.8.255.2 ) |
| 网络 | 虚拟专用网IP |
|---|---|
| 10.8.0.0/16 | 保留客户端(从10.8.128.1开始) |
| 10.8.0.0/17 | 通过 10.8.255.2 IP 转发 NAT 10.8.0.0/17 -> 10.0.0.0/17 |
| 10.8.255.1 | 云服务器网关 |
| 10.8.255.2 | 家庭 OpenVPN 网关(局域网:10.0.0.253) |
| 网络 | 网关 | 笔记 |
|---|---|---|
| 10.8.0.0/16 | 10.8.255.1 | 全网 |
| 10.8.0.0/17 | 10.8.255.2 | 所有 IP 地址都应将最后 15 位转换为目标 ( 10.8.0.100 -> 10.0.0.100 ) |
root@gwhome# iptables -A FORWARD -i tun0 -o eth0 -m conntrack --ctstate NEW -j ACCEPT
root@gwhome# iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
root@gwhome# iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
root@gwhome# iptables -t nat -A PREROUTING -d 10.8.0.0/17 -j DNAT --to-destination 10.0.0.0-10.0.127.255
Run Code Online (Sandbox Code Playgroud)
这台机器不是网络网关,所以我看到有人提到需要SNAT,但我认为这个需要应该可以减轻MASQUERADE。如果能对此进行确认,我们将不胜感激。
root@cloud-server# ping 10.8.0.1 -c 3
PING 10.8.0.1 (10.8.0.1) 56(84) bytes of data.
--- 10.8.0.1 ping statistics ---
3 packets transmitted, 0 received, 100% packet loss, time 2078ms
Run Code Online (Sandbox Code Playgroud)
root@gwhome# tcpdump -i tun0 icmp
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on tun0, link-type RAW (Raw IP), snapshot length 262144 bytes
04:41:15.934726 IP 10.8.255.1 > 10.8.0.1: ICMP echo request, id 89, seq 1, length 64
04:41:16.989078 IP 10.8.255.1 > 10.8.0.1: ICMP echo request, id 89, seq 2, length 64
04:41:18.013008 IP 10.8.255.1 > 10.8.0.1: ICMP echo request, id 89, seq 3, length 64
^C
3 packets captured
3 packets received by filter
0 packets dropped by kernel
Run Code Online (Sandbox Code Playgroud)
root@gwhome# tcpdump -i eth0 icmp
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
05:50:27.228399 IP 10.0.0.253 > 10.0.52.24: ICMP echo request, id 93, seq 1, length 64
05:50:28.234007 IP 10.0.0.253 > 10.0.52.24: ICMP echo request, id 93, seq 2, length 64
05:50:29.257588 IP 10.0.0.253 > 10.0.52.24: ICMP echo request, id 93, seq 3, length 64
^C
3 packets captured
3 packets received by filter
0 packets dropped by kernel
Run Code Online (Sandbox Code Playgroud)
| 归档时间: |
|
| 查看次数: |
1504 次 |
| 最近记录: |