内网机器上网
iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j SNAT -to-source 10.0.0.1
or
iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
外部到内部映射
端口映射
iptables -t nat -A PREROUTING -d 10.0.0.1 -p tcp --dport 80 -j DNAT --to-destination 192.168.1.100:80
IP 1v1
iptables -t nat -A PREROUTING -d 10.0.0.2 -j DNAT --to-destination 192.168.1.100
iptables -t nat -A POSTROUTING -s 192.168.1.100 -j SNAT --to-source 10.0.0.2
原文地址:http://xiaowei8.blog.51cto.com/2323881/1601153