3.5.3. 创​​​​​​​建​​​​​​​网​​​​​​​络​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​过​​​​​​​滤​​​​​​​规​​​​​​​则​​​​​​​


Before assigning any iptables rules for FTP service, review the information in 第 3.4.1 节 “分​​​​​​​配​​​​​​​防​​​​​​​火​​​​​​​墙​​​​​​​标​​​​​​​记​​​​​​​” concerning multi-port services and techniques for checking the existing network packet filtering rules.
Below are rules which assign the same firewall mark, 21, to FTP traffic. For these rules to work properly, you must also use the VIRTUAL SERVER subsection of Piranha Configuration Tool to configure a virtual server for port 21 with a value of 21 in the Firewall Mark field. See 第 4.6.1 节 “「​​​​​​​虚​​​​​​​拟​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​」​​​​​​​子​​​​​​​界​​​​​​​面​​​​​​​” for details.

3.5.3.1. 主​​​​​​​动​​​​​​​连​​​​​​​接​​​​​​​规​​​​​​​则​​​​​​​

主​​​​​​​动​​​​​​​连​​​​​​​接​​​​​​​的​​​​​​​规​​​​​​​则​​​​​​​告​​​​​​​知​​​​​​​内​​​​​​​核​​​​​​​接​​​​​​​受​​​​​​​并​​​​​​​转​​​​​​​发​​​​​​​在​​​​​​​端​​​​​​​口​​​​​​​ 20(FTP 数​​​​​​​据​​​​​​​端​​​​​​​口​​​​​​​)中​​​​​​​进​​​​​​​入​​​​​​​内​​​​​​​部​​​​​​​浮​​​​​​​动​​​​​​​ IP 地​​​​​​​址​​​​​​​的​​​​​​​连​​​​​​​接​​​​​​​。​​​​​​​
以​​​​​​​下​​​​​​​ iptables 命​​​​​​​令​​​​​​​允​​​​​​​许​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​接​​​​​​​受​​​​​​​ IPVS 不​​​​​​​了​​​​​​​解​​​​​​​的​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​的​​​​​​​外​​​​​​​发​​​​​​​连​​​​​​​接​​​​​​​。​​​​​​​
/sbin/iptables -t nat -A POSTROUTING -p tcp -s n.n.n.0/24 --sport 20 -j MASQUERADE
In the iptables command, n.n.n should be replaced with the first three values for the floating IP for the NAT interface's internal network interface defined in the GLOBAL SETTINGS panel of Piranha Configuration Tool.
Red Hat logoGithubRedditYoutubeTwitter

学习

尝试、购买和销售

社区

关于红帽文档

通过我们的产品和服务,以及可以信赖的内容,帮助红帽用户创新并实现他们的目标。

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

© 2024 Red Hat, Inc.