首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >使用pfSense设置1:1 NAT

使用pfSense设置1:1 NAT
EN

Server Fault用户
提问于 2011-10-28 18:10:36
回答 1查看 8.2K关注 0票数 4

pfSense框:

  • 公共IP 208.43.30.118-.117
  • 私人知识产权: 192.168.1.1

我需要在专用网络192.168.1.5中提供到VM的1:1 NAT映射

我无法得到1:1的NAT工作,虽然应该是直接的.

输出.

代码语言:javascript
复制
$ pfctl -s rules
scrub in on em0 all fragment reassemble
scrub in on em1 all fragment reassemble
anchor "relayd/*" all
block drop in log all label "Default deny rule"
block drop out log all label "Default deny rule"
block drop in quick inet6 all
block drop out quick inet6 all
block drop quick proto tcp from any port = 0 to any
block drop quick proto tcp from any to any port = 0
block drop quick proto udp from any port = 0 to any
block drop quick proto udp from any to any port = 0
block drop quick from <snort2c> to any label "Block snort2c hosts"
block drop quick from any to <snort2c> label "Block snort2c hosts"
block drop in log quick proto carp from (self) to any
pass quick proto carp all keep state
pass quick proto pfsync all keep state
block drop in log quick proto tcp from <sshlockout> to any port = ssh label "sshlockout"
block drop in log quick proto tcp from <webConfiguratorlockout> to any port = http label "webConfiguratorlockout"
block drop in quick from <virusprot> to any label "virusprot overload table"
block drop in log quick on em0 from <bogons> to any label "block bogon networks from WAN"
block drop in on ! em0 inet from 208.43.30.112/29 to any
block drop in inet from 208.43.30.118 to any
block drop in inet from 208.43.30.117 to any
block drop in on ! em1 inet from 192.168.1.0/24 to any
block drop in inet from 192.168.1.1 to any
block drop in on em0 inet6 from fe80::250:56ff:fe8b:571e to any
block drop in on em1 inet6 from fe80::250:56ff:fe8b:571f to any
pass in on lo0 all flags S/SA keep state label "pass loopback"
pass out on lo0 all flags S/SA keep state label "pass loopback"
pass out all flags S/SA keep state allow-opts label "let out anything from firewall host itself"
pass out route-to (em0 208.43.30.113) inet from 208.43.30.118 to ! 208.43.30.112/29 flags S/SA keep state allow-opts label "let out anything from firewall host itself"
pass in quick on em1 proto tcp from any to (em1) port = http flags S/SA keep state label "anti-lockout rule"
anchor "userrules/*" all
pass in quick on em0 reply-to (em0 208.43.30.113) inet proto tcp from any to 192.168.1.5 port = http flags S/SA keep state label "USER_RULE: allow webtraffic"
pass in quick on em1 inet from 192.168.1.0/24 to any flags S/SA keep state label "USER_RULE: Default allow LAN to any rule"
anchor "tftp-proxy/*" all

我试着用端口转发和1:1 NAT设置它几次,但是流量没有转发到内部IP。我做错了什么?

接口外部IP内部IP目的IP描述

WAN 208.43.30.117局域网网192.168.1.5在内部ip外转发

附加ip只是一个ip别名(Virtual ),在通过gui上传命令输出之前,我已经添加了1:1 NAT规则,为什么这没有反映在发布的输出中

EN

回答 1

Server Fault用户

发布于 2011-12-31 17:42:46

我犯的错误不是将客户端的网关配置为指向pfsense。

nat客户端有多个网卡,默认网关设置为另一个网卡。

一旦修好,问题就解决了。

票数 2
EN
页面原文内容由Server Fault提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://serverfault.com/questions/325790

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档