经过多次试验证明,masquerade确实可以根据网关选择外网IP来NAT,问题解决了。
- wolf@Quadranet:~$ show conntrack table ipv4
- TCP state codes: SS - SYN SENT, SR - SYN RECEIVED, ES - ESTABLISHED,
- FW - FIN WAIT, CW - CLOSE WAIT, LA - LAST ACK,
- TW - TIME WAIT, CL - CLOSE, LI - LISTEN
- CONN ID Source Destination Protocol TIMEOUT
- 396079616 192.168.180.10 224.0.0.5 ospfigp [89] 596
- 459563008 104.223.10.232:17500 104.223.10.255:17500 udp [17] 11
- 391761280 192.168.180.6 192.168.180.5 ospfigp [89] 594
- 391763872 212.83.191.243:5063 204.44.67.83:5060 udp [17] 2989
- 459568480 192.168.88.246:48428 74.125.204.100:443 tcp [6] ES 431956
- 459564160 155.94.161.150:138 155.94.161.255:138 udp [17] 1
- 459566176 192.168.180.5:37561 199.59.148.85:443 tcp [6] ES 431987
- 391760992 192.168.180.1:36718 8.8.8.8:53 udp [17] 178
- 390501728 192.168.180.9 224.0.0.5 ospfigp [89] 599
- 390502016 192.168.180.5 224.0.0.5 ospfigp [89] 599
- 459570208 192.168.88.246:61238 74.125.204.100:443 udp [17] 0
- 390497120 118.244.217.63:10141 204.44.67.83:10141 udp [17] 178
- 459570496 192.69.120.18:34218 104.223.10.56:23 tcp [6] LA 17
- 391758976 192.168.180.2 192.168.180.1 ospfigp [89] 316
- 392957888 212.83.188.161:5127 204.44.67.83:5060 udp [17] 388
- 396079040 192.168.180.6 224.0.0.5 ospfigp [89] 598
- 459566752 192.168.180.5:36718 8.8.4.4:53 udp [17] 23
- 390498560 118.244.217.63:10143 104.223.10.56:10143 udp [17] 179
- 390499712 192.168.180.1 224.0.0.5 ospfigp [89] 599
- 390498848 118.244.217.63:10142 155.94.161.109:10142 udp [17] 178
- 459568768 192.168.180.1:52848 74.125.224.122:443 tcp [6] ES 431965
- 459569056 192.168.180.5:57501 199.59.150.39:443 tcp [6] ES 431997
- 459565600 119.119.232.204:7346 155.94.161.109:22 tcp [6] ES 299
- 391762720 192.168.180.9:36718 8.8.8.8:53 udp [17] 168
- 391758688 192.168.180.5:36718 8.8.8.8:53 udp [17] 162
- 459563584 104.223.10.45:138 104.223.10.255:138 udp [17] 15
- 459563296 192.168.180.5:34465 199.59.150.42:443 tcp [6] ES 431987
- 459567904 192.168.180.5:57497 199.59.150.39:443 tcp [6] ES 431947
- 396078464 192.168.180.2 224.0.0.5 ospfigp [89] 596
- 459569920 192.168.88.246:48376 173.194.72.91:443 tcp [6] ES 93
- 391765312 192.168.180.10 192.168.180.9 ospfigp [89] 594
- 459568192 204.44.67.230:17500 204.44.67.255:17500 udp [17] 11
- 390501152 119.119.232.204:6287 155.94.161.109:22 tcp [6] ES 430905
- 459565312 192.168.88.246:48432 216.58.221.227:80 tcp [6] ES 431820
- 459565888 104.223.10.62:138 104.223.10.255:138 udp [17] 1
- 459563872 204.44.67.46:17500 255.255.255.255:17500 udp [17] 11
复制代码
- wolf@Quadranet:~$ show nat source translations
- Pre-NAT Post-NAT Prot Timeout
- 192.168.88.246 155.94.161.109 tcp 36
- 192.168.88.246 204.44.67.83 tcp 431977
- 192.168.88.246 155.94.161.109 tcp 16
- 192.168.180.1 204.44.67.83 udp 178
- 192.168.88.246 204.44.67.83 tcp 27
- 192.168.88.246 104.223.10.56 tcp 34
- 192.168.88.246 155.94.161.109 udp 156
- 192.168.88.249 155.94.161.109 tcp 431989
- 192.168.88.246 204.44.67.83 tcp 23
- 192.168.88.246 204.44.67.83 tcp 52
- 192.168.88.246 104.223.10.56 tcp 19
- 192.168.88.246 104.223.10.56 tcp 25
- 192.168.180.33 204.44.67.83 tcp 431999
- 192.168.88.246 104.223.10.56 tcp 95
- 192.168.88.246 204.44.67.83 tcp 15
- 192.168.180.9 155.94.161.109 udp 178
- 192.168.180.5:36718 155.94.161.109:1026 udp 178
- 192.168.88.246 104.223.10.56 tcp 26
- 192.168.88.246 155.94.161.109 tcp 15
- 192.168.88.246 104.223.10.56 tcp 22
- 192.168.172.12 155.94.161.109 udp 13
- 192.168.88.246 155.94.161.109 tcp 105
- 192.168.88.246 155.94.161.109 tcp 249
- 192.168.88.246 104.223.10.56 tcp 16
- 192.168.88.246 104.223.10.56 tcp 431976
- 192.168.88.246 204.44.67.83 tcp 117
- 125.88.219.97 125.88.219.97 icmp 0
复制代码 |