单网卡绑定多个ip来实现分配更多ip,即多个网段ip划分.
########################
#edit by xiaokong####
########################
shared-network Inside{
subnet 192.168.0.0 netmask 255.255.255.0{
range 192.168.0.6 192.168.0.254;
######如果不过期的话,可以把下边两个时间设为-1########
default-lease-time 600;
max-lease-time 7200;
option domain-name-servers 218.56.57.58,202.102.152.3;
option routers 192.168.0.1;
}
subnet 192.168.2.0 netmask 255.255.255.0{
range 192.168.2.6 192.168.2.254;
default-lease-time 600;
max-lease-time 7200;
option domain-name-servers 218.56.57.58,202.102.152.3;
option routers 192.168.2.1;
}
}
##########下边两句会使不同交换机下的电脑尽量不在同一个ip段下#########
host 01{
hardware ethernet 00:E0:4C:10:7F:00;
fixed-address 192.168.0.1;
}
host 21{
hardware ethernet 00:E0:4C:10:7F:00;
fixed-address 192.168.2.1;
}
防火墙的设置,同时用该服务器做路由
#!/bin/bash
iptables -F
iptables -t nat -F
#setup default policies to handle unmatched traffic
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
# lock our services
iptables -I INPUT 1 -i eth0 -j ACCEPT
iptables -I INPUT 1 -i lo -j ACCEPT
iptables -I FORWARD -i eth0 -d 192.168.0.0/255.255.255.0 -j DROP
iptables -A FORWARD -i eth0 -s 192.168.0.0/255.255.255.0 -j ACCEPT
iptables -A FORWARD -i eth1 -d 192.168.0.0/255.255.255.0 -j ACCEPT
iptables -A FORWARD -i eth0 -s 192.168.2.0/255.255.255.0 -j ACCEPT
iptables -A FORWARD -i eth1 -d 192.168.2.0/255.255.255.0 -j ACCEPT
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
阅读(2420) | 评论(0) | 转发(0) |