iptables 源地址转换 和 目标地址转换 命令行参考



#!/bin/bash

/sbin/iptables -F

/sbin/iptables -X

/sbin/iptables -Z

/sbin/iptables -F -t nat

/sbin/iptables -X -t nat

/sbin/iptables -Z -t nat

echo 1 > /proc/sys/net/ipv4/ip_forward

#==============================目的地址转换========================================================

#mysql数据库

/sbin/iptables -t nat -A PREROUTING -p tcp -m tcp --dport 2345 -j DNAT --to-destination 10.141.83.177:3306

#壳牌

/sbin/iptables -t nat -A PREROUTING -p tcp -m tcp --dport 2222 -j DNAT --to-destination 10.161.185.133:22

#中化云龙

/sbin/iptables -t nat -A PREROUTING -p tcp -m tcp --dport 2223 -j DNAT --to-destination 10.162.70.3:22 

#中化重庆涪陵

/sbin/iptables -t nat -A PREROUTING -p tcp -m tcp --dport 2224 -j DNAT --to-destination 10.161.174.110:22 

#中化吉林长山

/sbin/iptables -t nat -A PREROUTING -p tcp -m tcp --dport 2225 -j DNAT --to-destination 10.161.215.203:22 

#中化山东肥业

/sbin/iptables -t nat -A PREROUTING -p tcp -m tcp --dport 2226 -j DNAT --to-destination 10.161.171.92:22 

#==============================源地址转换==========================================================

#mysql数据库

/sbin/iptables -t nat -A POSTROUTING -d 10.141.83.177/32 -p tcp -j SNAT --to-source 10.161.212.214  

#壳牌

/sbin/iptables -t nat -A POSTROUTING -d 10.161.185.133/32 -p tcp -j SNAT --to-source 10.161.212.214 

#中化云龙

/sbin/iptables -t nat -A POSTROUTING -d 10.162.70.3/32 -p tcp -j SNAT --to-source 10.161.212.214 

#中化重庆涪陵

/sbin/iptables -t nat -A POSTROUTING -d 10.161.174.110/32 -p tcp -j SNAT --to-source 10.161.212.214 

#中化吉林长山

/sbin/iptables -t nat -A POSTROUTING -d 10.161.215.203/32 -p tcp -j SNAT --to-source 10.161.212.214 

#中化山东肥业

/sbin/iptables -t nat -A POSTROUTING -d 10.161.171.92/32 -p tcp -j SNAT --to-source 10.161.212.214

/etc/init.d/iptables save

/sbin/service iptables restart


转载于:https://my.oschina.net/u/2471041/blog/530108