有機器不能直接訪問其餘網段的服務器,須要用臺機器作「跳板」。特記錄windows及centos下的操做。linux
場景以下:在SRV_a上設置端口映射後,client經過訪問SRV_a的port1端口便可達到訪問SRV_b的port2的目的。全部操做均在SRV_a上。windows
*nat :PREROUTING ACCEPT [516:31248] :INPUT ACCEPT [516:31248] :OUTPUT ACCEPT [94:7051] :POSTROUTING ACCEPT [0:0] -A PREROUTING -p tcp -m tcp --dport port1 -j DNAT --to-destination SRV_b:port2 -A POSTROUTING -j MASQUERADE COMMIT # Completed on Thu Jun 27 14:43:55 2019 # Generated by iptables-save v1.4.21 on Thu Jun 27 14:43:55 2019 *filter :INPUT ACCEPT [5952:597704] :FORWARD ACCEPT [15:2307] :OUTPUT ACCEPT [4382:425946] COMMIT # Completed on Thu Jun 27 14:43:55 2019