1.修改服务器内核参数,服务器配置文件/etc/sysctl.conf修改或者添加内容如下
7 E2 b0 q8 q, g5 h' }- net.ipv4.ip_forward = 1
# B9 h* y& A! M - net.ipv4.conf.default.rp_filter = 0: O* n1 H3 f. B
- net.ipv4.conf.all.rp_filter = 05 G# w) F$ L# m2 F4 V, P3 G7 g, K
- net.ipv4.conf.all.send_redirects = 0 D1 V) O) b# W8 `( K
- net.ipv4.conf.default.send_redirects = 0
0 y+ Y$ \: @4 J( H6 s+ |0 J7 ^ - net.ipv4.conf.all.accept_redirects = 0
7 M# {6 n" a# K. g, E& P - net.ipv4.conf.default.accept_redirects = 05 `. T( {4 P+ P8 A6 k4 O$ V# [8 Z
- net.core.xfrm_larval_drop = 1
复制代码
* Z; E; a; y b, m' [; v/ V! j' `2.防火墙添加规则
- t7 P/ n0 ^0 f/ q- iptables -t nat -A POSTROUTING ! -s 127.0.0.1/8 -j MASQUERADE
( l2 _' P$ ~ G# S, _( Z: R! t - iptables -I FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
复制代码 |