1.修改服务器内核参数,服务器配置文件/etc/sysctl.conf修改或者添加内容如下% |+ @$ p, Q+ x
- net.ipv4.ip_forward = 1
- I& O! C8 e5 V - net.ipv4.conf.default.rp_filter = 0
" n5 s) ]9 g* V: E9 I - net.ipv4.conf.all.rp_filter = 0
, r8 X# {+ F7 m/ w* n; `" K t) z - net.ipv4.conf.all.send_redirects = 0
7 Z9 K: }+ ]5 _ - net.ipv4.conf.default.send_redirects = 04 P! p6 F* k9 \5 Y3 N
- net.ipv4.conf.all.accept_redirects = 0
/ v, x. |; _, W# O# S# } - net.ipv4.conf.default.accept_redirects = 0
) X' t! `' A3 F4 G$ Q) e - net.core.xfrm_larval_drop = 1
复制代码 D" s6 `- p5 ~
2.防火墙添加规则1 \7 c1 G! Z% t; l1 ~* W# R8 f
- iptables -t nat -A POSTROUTING ! -s 127.0.0.1/8 -j MASQUERADE
( q' [5 v5 M6 x) A6 I& U) o- U - iptables -I FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
复制代码 |