# 端口映射 方案一 iptables -t nat -A PREROUTING -d 11.12.13.2 -p tcp --dport 80 -j DNAT --to 192.168.1.3 iptables -t nat -A OUTPUT -d 11.12.13.2 -p tcp --dport 80 -j DNAT --to 192.168.1.3 #allow NAT server to access 11.12.13.2:80 iptables -t nat -A POSTROUTING -d 192.168.1.3 -p tcp --dport 80 -j SNAT --to 192.168.1.1 # SNAT all forward packets iptables -A FORWARD -p tcp -d 192.168.1.3 --dport 80 -j ACCEPT # Not need if policy of FORWARD chain is set to ACCEPT
# 端口映射 方案二 iptables -t nat -A PREROUTING -d 11.12.13.2 -p tcp --dport 80 -j DNAT --to 192.168.1.3 iptables -t nat -A OUTPUT -d 11.12.13.2 -p tcp --dport 80 -j DNAT --to 192.168.1.3 #allow NAT server to access 11.12.13.2:80 iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -d 192.168.1.3 -p tcp --dport 80 -j SNAT --to 192.168.1.1 # SNAT only intranet forward packets iptables -A FORWARD -p tcp -d 192.168.1.3 --dport 80 -j ACCEPT # Not need if policy of FORWARD chain is set to ACCEPT
| I | Attachment | Action | Size | Date | Who | Comment |
|---|---|---|---|---|---|---|
| | 1_resize.jpg | manage | 25.7 K | 28 Jul 2008 - 09:53 | Main.yfang | |
| | 2_resize.jpg | manage | 28.0 K | 31 Jul 2008 - 07:59 | Main.yfang | |
| | 3_resize.jpg | manage | 28.2 K | 28 Jul 2008 - 09:57 | Main.yfang |