当前位置:网站首页>Iptables implementation under the network limited (NTP) synchronization time custom port
Iptables implementation under the network limited (NTP) synchronization time custom port
2022-08-05 07:59:00 【Wangzai_Milk】
# requirementsntpdate 192.168.1.1:123(192.168.1.1:666->10.0.0.1->123)ntpdaete cannot specify the port, the ntpd synchronization is 192.168.1.1:123, but because 123 cannot be accessed normally, the machine has mapped port 666 to port 123 of the back-end ntp server# Solution (time synchronization server, client configuration is as follows), because REDIRECT will access the local machine or access the port in the packet header of the host with this machine as the gateway machine from the original targetThe port is replaced with the specified target port, which does not apply in this case, only the local port is forwarded to another port on the local machine# Since this is the local traffic forwarding configuration, it does not belong to other traffic forwarded to the local machine, so configuring PREROUTING DNAT has no effect, because it will not match the rules here at all# Method 1, POSTROUTING cannot configure DNATiptables -t nat -I OUTPUT -p udp -d 192.168.1.1 --dport 123 -j DNAT --to 192.168.1.1:666# Verification (because there is no actual NTP server in the backend, it will not pass here, we only need to look at the iptables rules)[[email protected] ~]# ntpdate 192.168.1.13 Aug 11:01:34 ntpdate[1734]: no server suitable for synchronization found# iptables rule verification, through pkts, bytes here, it can be seen that the rule takes effect, and the native ntpdate 192.168.1.1:123 -> ntpdate 192.168.1.1:6666 -> (this layer of network equipment is implemented)mapping) ntpdate 10.0.0.1:123[[email protected] ~]# iptables -t nat -nvLspan>Chain OUTPUT (policy ACCEPT 15 packets, 976 bytes)pkts bytes target prot opt in out source destination1 76 DNAT udp -- * * 0.0.0.0/0 192.168.1.1 udp dpt:123 to:192.168.1.1:666
边栏推荐
猜你喜欢
随机推荐
TRACE32——Go.direct
Cannot compare or sort text, ntext, and image data types
v-if/v-else根据计算判断是否显示
餐饮大单品「真香」,却没有穿透周期的能力
window.open 全屏展示
Discourse 清理存储空间的方法
moment的使用
Win10 设置锁屏壁纸提示尝试其它图片
达梦数据库大表添加字段
SVG Star Wars Style Toggle Toggle Button
Liunx教程超详细(完整)
TRACE32——C源码关联1
常用的遍历map的方法
每一个女孩曾经都是一个没有泪的天使
图扑软件与华为云共同构建新型智慧工厂
Qt writes custom controls: one of the text spotlight effects
2006年星座运势全解-巨蟹
Does Libpq support read-write separation configuration?
标准C语言15
RedisTemplate: 报错template not initialized; call afterPropertiesSet() before using it