NAT Table main control is the internal network and external network exchange of the problem, it functions similar to the NAT address translation function in the router, control the internal user how to access the external network, the extranet user how to access the intranet
SNAT: Source address Translation, modify the source IP of the packet for the LAN host to access the extranet, after routing the selection is created.
DNAT: Destination Address Translation, modify the destination IP of the packet, target port, for the extranet host to access the intranet server, before routing the choice to create.
Snat Construction Process:
First set up the corresponding test environment, an intranet one Apache Web server, a firewall server, an IIS server outside the network.
650) this.width=650; "style=" Float:none; "title=" 2.png "src=" http://s3.51cto.com/wyfs02/M02/6F/B3/ Wkiol1wl4ugdegaiaabbdz1lxr4843.jpg "alt=" wkiol1wl4ugdegaiaabbdz1lxr4843.jpg "/>650) this.width=650;" Style= " Float:none; "title=" 3.png "src=" http://s3.51cto.com/wyfs02/M01/6F/B3/wKioL1Wl4UHymKJlAAO0yl_9wWI588.jpg "alt=" Wkiol1wl4uhymkjlaao0yl_9wwi588.jpg "/>
650) this.width=650; "title=" 9.png "src=" Http://s3.51cto.com/wyfs02/M00/6F/B3/wKioL1Wl4beBV-wUAAE_068B1wM554.jpg " alt= "Wkiol1wl4bebv-wuaae_068b1wm554.jpg"/>
2.iptables Server adds two network cards to empty the default firewall rules
650) this.width=650; "style=" Float:none; "title=" 4.png "src=" http://s3.51cto.com/wyfs02/M01/6F/B3/ Wkiol1wl4hwzwgpcaadzyd8ma-4136.jpg "alt=" Wkiol1wl4hwzwgpcaadzyd8ma-4136.jpg "/>
650) this.width=650; "style=" Float:none; "title=" 5.png "src=" http://s3.51cto.com/wyfs02/M01/6F/B6/ Wkiom1wl4dygu3mbaajkxnshmoi416.jpg "alt=" Wkiom1wl4dygu3mbaajkxnshmoi416.jpg "/>
3. Turn on the Iptables server routing feature
650) this.width=650; "style=" Float:none; "title=" 6.png "src=" http://s3.51cto.com/wyfs02/M02/6F/B6/ Wkiom1wl4jzsxschaabpbfkzt58869.jpg "alt=" Wkiom1wl4jzsxschaabpbfkzt58869.jpg "/>
650) this.width=650; "style=" Float:none; "title=" 7.png "src=" http://s3.51cto.com/wyfs02/M00/6F/B3/ Wkiol1wl4nxwq1v7aae79uumr9e270.jpg "alt=" Wkiol1wl4nxwq1v7aae79uumr9e270.jpg "/>
4.apache server empties the default firewall rule and points the gateway to iptables
650) this.width=650; "style=" Float:none; "title=" 8.png "src=" http://s3.51cto.com/wyfs02/M02/6F/B6/ Wkiom1wl4pvc0yp7aabjlnetqze391.jpg "alt=" Wkiom1wl4pvc0yp7aabjlnetqze391.jpg "/>
650) this.width=650; "style=" Float:none; "title=" 10.png "src=" http://s3.51cto.com/wyfs02/M01/6F/B3/ Wkiol1wl4txqmllbaagn5jqbe08312.jpg "alt=" Wkiol1wl4txqmllbaagn5jqbe08312.jpg "/>
5.iptables Server configuration Snat rules to enable intranet users to access the IIS server
650) this.width=650; "style=" Float:none; "title=" 11.png "src=" http://s3.51cto.com/wyfs02/M01/6F/B6/ Wkiom1wl4w2qzloqaabrnmsnxou004.jpg "alt=" Wkiom1wl4w2qzloqaabrnmsnxou004.jpg "/>
6.IIS server does not have a gateway configured
650) this.width=650; "style=" Float:none; "title=" 12.png "src=" http://s3.51cto.com/wyfs02/M00/6F/B3/ Wkiol1wl40ez6ezqaab-wei3sg8378.jpg "alt=" Wkiol1wl40ez6ezqaab-wei3sg8378.jpg "/>
7. Ping the IIS server address on the Apache server
650) this.width=650; "style=" Float:none; "title=" 13.png "src=" http://s3.51cto.com/wyfs02/M00/6F/B6/ Wkiom1wl4w3rjtjzaaduanhoda4643.jpg "alt=" Wkiom1wl4w3rjtjzaaduanhoda4643.jpg "/>
8. Access to IE Web page in the Web, successfully
650) this.width=650; "style=" Float:none; "title=" 14.png "src=" http://s3.51cto.com/wyfs02/M02/6F/B3/ Wkiol1wl40ejfrxwaagbw1vwozi675.jpg "alt=" Wkiol1wl40ejfrxwaagbw1vwozi675.jpg "/>
Dnat Construction Process:
1. Ensure that the previous steps are done: Apache configures the gateway, iptables turns on routing, iptables two Nic, IIS does not configure the gateway, and so on.
2. First visit to try
650) this.width=650; "style=" Float:none; "title=" 1.png "src=" http://s3.51cto.com/wyfs02/M00/6F/B3/ Wkiol1wl51ktmpruaaec--dzuv0058.jpg "alt=" Wkiol1wl51ktmpruaaec--dzuv0058.jpg "/>
650) this.width=650; "style=" Float:none; "title=" 2.png "src=" http://s3.51cto.com/wyfs02/M00/6F/B6/ Wkiom1wl5xjsyd3haad5evdhlmo875.jpg "alt=" Wkiom1wl5xjsyd3haad5evdhlmo875.jpg "/>
3. Configure Dnat on the iptables server
650) this.width=650; "title=" 4.png "src=" Http://s3.51cto.com/wyfs02/M01/6F/B3/wKioL1Wl55Tg4On7AABwkazVvow373.jpg " alt= "Wkiol1wl55tg4on7aabwkazvvow373.jpg"/>
4. Access the other's Web pages in the IIS server (because the destination address translation has already been done, so the extranet client needs to access the IP address of the iptables extranet)
650) this.width=650; "title=" 3.png "src=" Http://s3.51cto.com/wyfs02/M00/6F/B3/wKioL1Wl5-fjBZETAAHRAB6gqA8376.jpg " alt= "Wkiol1wl5-fjbzetaahrab6gqa8376.jpg"/>
For the Linux firewall this piece, I will introduce so much, thank you!
Redhat Linux iptables (NAT)