Advertisement
Guest User

Untitled

a guest
Jun 26th, 2019
72
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.64 KB | None | 0 0
  1. auto lo
  2. iface lo inet loopback
  3.  
  4. auto eth0
  5. iface eth0 inet manual
  6. auto eth1
  7. iface eth1 inet manual
  8.  
  9. # Bridge interface
  10. auto br0
  11. iface br0 inet dhcp
  12. bridge_ports eth0 eth1
  13. bridge_hw aa:bb:cc:dd:ee:ff
  14.  
  15. # pre-set interface IP for client requirements, if DHCP is not working
  16. auto br0:1
  17. iface br0:1 inet static
  18. address 172.16.21.150
  19. netmask 255.255.255.0
  20. network 172.16.21.0
  21. broadcast 172.16.21.255
  22. # Gateway
  23. post-up route add default gw 172.16.21.254
  24. pre-down route del default gw 172.16.21.254
  25.  
  26.  
  27. # Set default fallback interface IP address
  28. auto br0:100
  29. iface br0:100 inet static
  30. address 169.254.111.111
  31. netmask 255.255.255.0
  32. network 169.254.111.0
  33. broadcast 169.254.111.255
  34.  
  35. # IP Forwarding im Kernel aktivieren
  36. echo 1 > /proc/sys/net/ipv4/ip_forward
  37.  
  38. # Masqerading auf br0 und br0.1 aktivieren
  39. iptables -t nat -A POSTROUTING -o br0 -j MASQUERADE
  40. iptables -t nat -A POSTROUTING -o br0:1 -j MASQUERADE
  41.  
  42. # Forwarding Regeln einrichten
  43. # Forwarding etablierter Verbindungen von extern (br0 & br0.1) nach intern (br0.100)
  44. iptables -A FORWARD -i br0 -o br0:100 -m state --state RELATED,ESTABLISHED -j ACCEPT
  45. iptables -A FORWARD -i br0:1 -o br0:100 -m state --state RELATED,ESTABLISHED -j ACCEPT
  46.  
  47. # Forwarding aller Verbindungen von intern (br0.100) nach extern (br0 & br0.1)
  48. iptables -A FORWARD -i br0:100 -o br0 -j ACCEPT
  49. iptables -A FORWARD -i br0:100 -o br0:1 -j ACCEPT
  50.  
  51. iptables -t nat -A POSTROUTING -o br0 -j MASQUERADE
  52.  
  53. iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
  54. iptables -A FORWARD --src 169.254.111.112 -j ACCEPT
  55.  
  56. sysctl -w net.ipv4.conf.all.send_redirects=0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement