有机器不能直接访问其余网段的服务器,须要用台机器作“跳板”。特记录windows及centos下的操做。linux
场景以下:在SRV_a上设置端口映射后,client经过访问SRV_a的port1端口便可达到访问SRV_b的port2的目的。全部操做均在SRV_a上。windows
*nat :PREROUTING ACCEPT [516:31248] :INPUT ACCEPT [516:31248] :OUTPUT ACCEPT [94:7051] :POSTROUTING ACCEPT [0:0] -A PREROUTING -p tcp -m tcp --dport port1 -j DNAT --to-destination SRV_b:port2 -A POSTROUTING -j MASQUERADE COMMIT # Completed on Thu Jun 27 14:43:55 2019 # Generated by iptables-save v1.4.21 on Thu Jun 27 14:43:55 2019 *filter :INPUT ACCEPT [5952:597704] :FORWARD ACCEPT [15:2307] :OUTPUT ACCEPT [4382:425946] COMMIT # Completed on Thu Jun 27 14:43:55 2019