Debian – Policy Routing – iptables mark routing

                                                                                         ________
                                                                  +------------+        /
                                                      192.168.1.1 |            |       |
                                                 +----------------+ Provider 1 +-------
        __                                       | eth0           |            |     /
    ___/  \_                              +------+----------+     +------------+    |
  _/        \ mark network 172.16.10.0/24 |   192.168.1.2   |                       /
 /             \         172.16.10.1 eth1 |                 |                       |
| Local network --------------------------+  Linux router   |                       |     Internet
 \           __/        172.16.2.1 eth1:0 |                 |                       |
   \__     __/                            | default gateway |                       \
      \___/                               +------+----------+     +------------+    |
                                                 | eth2           |            |     \
                                                 +----------------+ Provider 2 +-------
                                                                  |            |       |
                                                                  +------------+        \________

Първо трябва да добавим таблица например с номер 200 и име T1 в /etc/iproute2/rt_tables

255     local
254     main
253     default
0       unspec
#
# local
#
#1      inr.ruhep
201 T1

След което следва самата конфигурация

ip route add 127.0.0.0/8 dev lo table T1
ip route add 192.168.1.0/30 dev eth0 src 192.168.1.2 table T1
ip route add 172.16.10.0/24 dev eth1 src 172.16.10.1 table T1
ip route add default via 192.168.1.1 table T1

iptables -A PREROUTING -t mangle -s 172.16.10.0/24 -j MARK --set-mark 101
ip rule add fwmark 101 table T1

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.