- 論壇徽章:
- 0
|
單網(wǎng)卡綁定多個(gè)ip來(lái)實(shí)現(xiàn)分配更多ip,即多個(gè)網(wǎng)段ip劃分.
########################
#edit by xiaokong####
########################
shared-network Inside{
subnet 192.168.0.0 netmask 255.255.255.0{
range 192.168.0.6 192.168.0.254;
######如果不過(guò)期的話,可以把下邊兩個(gè)時(shí)間設(shè)為-1########
default-lease-time 600;
max-lease-time 7200;
option domain-name-servers 218.56.57.58,202.102.152.3;
option routers 192.168.0.1;
}
subnet 192.168.2.0 netmask 255.255.255.0{
range 192.168.2.6 192.168.2.254;
default-lease-time 600;
max-lease-time 7200;
option domain-name-servers 218.56.57.58,202.102.152.3;
option routers 192.168.2.1;
}
}
##########下邊兩句會(huì)使不同交換機(jī)下的電腦盡量不在同一個(gè)ip段下#########
host 01{
hardware ethernet 00:E0:4C:10:7F:00;
fixed-address 192.168.0.1;
}
host 21{
hardware ethernet 00:E0:4C:10:7F:00;
fixed-address 192.168.2.1;
}
防火墻的設(shè)置,同時(shí)用該服務(wù)器做路由
#!/bin/bash
iptables -F
iptables -t nat -F
#setup default policies to handle unmatched traffic
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
# lock our services
iptables -I INPUT 1 -i eth0 -j ACCEPT
iptables -I INPUT 1 -i lo -j ACCEPT
iptables -I FORWARD -i eth0 -d 192.168.0.0/255.255.255.0 -j DROP
iptables -A FORWARD -i eth0 -s 192.168.0.0/255.255.255.0 -j ACCEPT
iptables -A FORWARD -i eth1 -d 192.168.0.0/255.255.255.0 -j ACCEPT
iptables -A FORWARD -i eth0 -s 192.168.2.0/255.255.255.0 -j ACCEPT
iptables -A FORWARD -i eth1 -d 192.168.2.0/255.255.255.0 -j ACCEPT
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
本文來(lái)自ChinaUnix博客,如果查看原文請(qǐng)點(diǎn):http://blog.chinaunix.net/u/26883/showart_1862836.html |
|