如何在 Nexenta(Solaris)上设置 IP 转发?

如何在 Nexenta(Solaris)上设置 IP 转发?

我正在尝试在我的 Nexenta 盒子上设置 IP 转发:

root@hdd:~# uname -a
SunOS hdd 5.11 NexentaOS_134f i86pc i386 i86pc Solaris

该盒子有2个网络接口:

root@hdd:~# ifconfig -a
lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1
    inet 127.0.0.1 netmask ff000000
e1000g1: flags=1001100843<UP,BROADCAST,RUNNING,MULTICAST,ROUTER,IPv4,FIXEDMTU> mtu 1500 index 2
    inet 192.168.12.2 netmask ffffff00 broadcast 192.168.12.255
    ether 68:5:ca:9:51:b8
myri10ge0: flags=1100843<UP,BROADCAST,RUNNING,MULTICAST,ROUTER,IPv4> mtu 9000 index 3
    inet 10.10.10.10 netmask ffffff00 broadcast 10.10.10.255
    ether 0:60:dd:47:87:2
lo0: flags=2002000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv6,VIRTUAL> mtu 8252 index 1
    inet6 ::1/128

192.168.12.0 是我的普通 LAN,192.168.12.1 是防火墙/网关

10.10.10.0 是用于 iSCSI 的单独 LAN(无互联网访问)

我想设置 IP 转发,以便 10.10.10.0 上的计算机能够使用 10.10.10.10 作为网关访问互联网(我不需要任何端口转发)

我已开启IP转发:

root@hdd:~# routeadm
          Configuration   Current              Current
                 Option   Configuration        System State
---------------------------------------------------------------
           IPv4 routing   disabled             disabled
           IPv6 routing   disabled             disabled
        IPv4 forwarding   enabled              enabled
        IPv6 forwarding   disabled             disabled

       Routing services   "route:default ripng:default"

Routing daemons:

                  STATE   FMRI
               disabled   svc:/network/routing/rdisc:default
               disabled   svc:/network/routing/route:default
               disabled   svc:/network/routing/legacy-routing:ipv4
               disabled   svc:/network/routing/legacy-routing:ipv6
               disabled   svc:/network/routing/ripng:default
                 online   svc:/network/routing/ndp:default

但是当我干脆启动ipnat的时候,出现了一个错误:

root@hdd:~# ipnat -CF -f /etc/ipf/ipnat.conf
ioctl(SIOCGNATS): I/O error

配置如下:

root@hdd:~# cat /etc/ipf/ipnat.conf
#!/sbin/ipnat -f -
#
map e1000g1 10.10.10.10/24 -> 192.168.12.2/32

所以问题是如何解决这个问题。提前谢谢!

答案1

运行svcadm enable ipfilter解决了这个问题。谢谢德里克·G

相关内容