在防火墙后面 ping 通,有些主机成功,有些主机失败?

在防火墙后面 ping 通,有些主机成功,有些主机失败?

我在防火墙下,可以 ping 通某些主机,但不能 ping 通其他主机

我的 IP 地址172.19.7.111 mask 255.255.240.0

我可以 ping 到主机172.19.2.111(我用 Angry IP Scanner 发现的),但不能 ping 到172.19.2.167我的 rapsberry。

我检查了两个主机的 IP 地址ifconfig。两者都有mask 255.255.240.0

未到达的主机不会被 Angry IP Scanner 检测到。

使用 nmap 命令扫描主机 172.19.2.167 (wlan0) 的网络以查找开放端口

nmap -v -sT 172.19.4.47 -Pn

 Completed Connect Scan at 20:28, 14.39s elapsed (1000 total ports)
    Nmap scan report for 172.19.4.167
    Host is up (0.11s latency).
    All 1000 scanned ports on 172.19.4.167 are filtered

我可以通过 eth0 (192.168.0.0 /24 网络) ping 该主机 1“72.19.4.167”

使用 eth0 网络(1952.168.0.0/24)进行扫描(同一主机)

于 21:20 启动连接扫描,扫描 192.168.0.2 [1000 个端口]

Discovered open port 22/tcp on 192.168.0.2
Completed Connect Scan at 21:20, 0.14s elapsed (1000 total ports)
Nmap scan report for 192.168.0.2
Host is up (0.011s latency).
Not shown: 999 closed ports
PORT   STATE SERVICE
22/tcp open  ssh
MAC Address: B8:27:EB:D5:44:B8 (Raspberry Pi Foundation)

网关扫描(172.19.0.5)

Starting Nmap 6.40 ( http://nmap.org ) at 2014-04-28 21:12 CEST
Initiating ARP Ping Scan at 21:12
Scanning 172.19.0.5 [1 port]
Completed ARP Ping Scan at 21:12, 0.02s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 21:12
Completed Parallel DNS resolution of 1 host. at 21:12, 0.01s elapsed
Initiating Connect Scan at 21:12
Scanning pftw01.crous.lan (172.19.0.5) [1000 ports]
Discovered open port 53/tcp on 172.19.0.5
Discovered open port 8080/tcp on 172.19.0.5
Discovered open port 22/tcp on 172.19.0.5
Discovered open port 8000/tcp on 172.19.0.5
Discovered open port 8001/tcp on 172.19.0.5
Completed Connect Scan at 21:12, 4.41s elapsed (1000 total ports)
Nmap scan report for pftw01.crous.lan (172.19.0.5)
Host is up (0.0045s latency).
Not shown: 995 filtered ports
PORT     STATE SERVICE
22/tcp   open  ssh
53/tcp   open  domain
8000/tcp open  http-alt
8001/tcp open  vcom-tunnel
8080/tcp open  http-proxy
MAC Address: 00:0C:29:D4:41:EB (VMware)

有什么解释吗?

答案1

172.19.7.111/20 和 172.19.2.111/20 位于同一子网。172.192.2.167 肯定位于不同的子网。我认为您需要添加规则以在两个子网之间转发数据包。

答案2

您可以从位于私有网络 172.19.2.111 内的主机获得答案,但不能从公共互联网 172.192.2.167 获得答案 - 请查看私有网络列表 - 只有 172.16.0.1 至 172.31.255.254 是私有网络 - 这些范围之外的每个 IP 地址都将被路由到互联网。

相关内容