Usually the server has many network cards, so it may be connected to different networks. In an isolated network, some services may Communication is required. At this time, the server can be configured to assume the function of forwarding data packets.
1. Query the port mapping situation
netsh interface portproxy show v4tov4
2. Query the port mapping situation of a certain IP
netsh interface portproxy show v4tov4 | find "[IP]"例:netsh interface portproxy show v4tov4 | find "192.168.1.1"
3. Add a port mapping
netsh interface portproxy add v4tov4 listenaddress=[外网IP] listenport=[外网端口] connectaddress=[内网IP] connectport=[内网端口]例:netsh interface portproxy add v4tov4 listenaddress=2.2.2.2 listenport=8080 connectaddress=192.168.1.50 connectport=80
4. Delete a port mapping
netsh interface portproxy delete v4tov4 listenaddress=[外网IP] listenport=[外网端口]例:netsh interface portproxy delete v4tov4 listenaddress=2.2.2.2 listenport=8080
1. 允许数据包转发
echo 1 >/proc/sys/net/ipv4/ip_forwardiptables -t nat -A POSTROUTING -j MASQUERADEiptables -A FORWARD -i [内网网卡名称] -j ACCEPTiptables -t nat -A POSTROUTING -s [内网网段] -o [外网网卡名称] -j MASQUERADE例:echo 1 >/proc/sys/net/ipv4/ip_forwardiptables -t nat -A POSTROUTING -j MASQUERADEiptables -A FORWARD -i ens33 -j ACCEPTiptables -t nat -A POSTROUTING -s 192.168.50.0/24 -o ens37 -j MASQUERADE
2. 设置端口映射
iptables -t nat -A PREROUTING -p tcp -m tcp --dport [外网端口] -j DNAT --to-destination [内网地址]:[内网端口]例:iptables -t nat -A PREROUTING -p tcp -m tcp --dport 6080 -j DNAT --to-destination 10.0.0.100:6090
VMWare Workstation Pro
5 台最小化安装的 centos 7 虚拟机
##Internal network and External network is relative to Server4<span style="outline: 0px;font-size: 17px;"></span>
. Server1<span style="outline: 0px;font-size: 17px;"></span>
and Server2<span style="outline: 0px;font-size: 17px;"></span>
are two servers in the intranet environment ; Server3<span style="outline: 0px;font-size: 17px;"></span>
is a server in an external network environment; Server4<span style="outline: 0px;font-size: 17px;"></span>
is a dual network card host, connected to 192.168.50.0/24<span style="outline: 0px;font-size: 17px;"></span>
and 172.16.2.0 respectively /24<span style="outline: 0px;font-size: 17px;"></span>
Two networks.
用 Python 在<span style="outline: 0px;font-size: 17px;">Server1</span>
上搭建一个简单的 HTTP 服务
cd ~echo "server1" > index.htmlpython -m SimpleHTTPServer 8080
<span style="outline: 0px;font-size: 17px;">Server2、Server3</span>
同理
在<span style="outline: 0px;font-size: 17px;">client</span>
上访问<span style="outline: 0px;font-size: 17px;">Server1</span>
的资源
curl http://192.168.50.11:8080/index.html
在<span style="outline: 0px;font-size: 17px;">client</span>
上访问<span style="outline: 0px;font-size: 17px;">Server2</span>
的资源
curl http://192.168.50.12:8080/index.htm
在<span style="outline: 0px;font-size: 17px;">client</span>
上访问<span style="outline: 0px;font-size: 17px;">Server3</span>
的资源
curl http://172.16.2.11:8080/index.html
可以看到,外网的
<span style="outline: 0px;font-size: 17px;">client</span>
是无法访问内网<span style="outline: 0px;font-size: 17px;">Server1</span>
,<span style="outline: 0px;font-size: 17px;">Server2</span>
的资源的。
<span style="outline: 0px;font-size: 17px;">Server4</span>
上配置端口映射临时配置
#允许数据包转发echo 1 >/proc/sys/net/ipv4/ip_forwardiptables -t nat -A POSTROUTING -j MASQUERADEiptables -A FORWARD -i ens33 -j ACCEPTiptables -t nat -A POSTROUTING -s 192.168.50.0/24 -o ens37 -j MASQUERADE#设置端口映射iptables -t nat -A PREROUTING -p tcp -m tcp --dport 8081 -j DNAT --to-destination 192.168.50.11:8080iptables -t nat -A PREROUTING -p tcp -m tcp --dport 8082 -j DNAT --to-destination 192.168.50.12:8080
永久配置
如果需要永久配置,则将以上命令追加到
<span style="outline: 0px;font-size: 17px;">/etc/rc.local</span>
文件。
在<span style="outline: 0px;font-size: 17px;">client</span>
上访问 Server1 的资源
curl http://172.16.2.100:8081/index.html
在<span style="outline: 0px;font-size: 17px;">client</span>
上访问<span style="outline: 0px;font-size: 17px;">Server2</span>
的资源
curl http://172.16.2.100:8082/index.html
在<span style="outline: 0px;font-size: 17px;">client</span>
上访问<span style="outline: 0px;font-size: 17px;">Server3</span>
的资源
curl http://172.16.2.11:8080/index.html
<span style="outline: 0px;font-size: 17px;">Server4</span>
为 Windows,替换一下相应的命令即可Windows 的 IP 信息如下
Network Card | IP Address | Subnet Mask | Default Gateway | ##Remarks |
---|---|---|---|---|
192.168.50.105 | 255.255.255.0 | - | Internal network card | |
172.16.2.105 | 255.255.255.0 | - | External network card |