ich nutze auf dem Hypervisor eine VPN-Verbindung, die die KVMs, die sich hinter einer Bridge (172.16.100.0/24) befinden, auch nutzen sollen:
Code: Alles auswählen
# Auf dem Hypervisor:
# ip r
0.0.0.0/1 via 10.8.0.5 dev tun0
128.0.0.0/1 via 10.8.0.5 dev tun0
default via 192.168.0.1 dev ETHbr0
10.8.0.1 via 10.8.0.5 dev tun0
10.8.0.5 dev tun0 proto kernel scope link src 10.8.0.6
44.55.66.77 via 192.168.0.1 dev ETHbr0
172.16.100.0/24 dev NATbr7 proto kernel scope link src 172.16.100.1
192.168.0.0/27 dev ETHbr0 proto kernel scope link src 192.168.0.19
# ip a
2: enp0s31f6: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast master ETHbr0 state UP group default qlen 1000
link/ether xx:xx:xx:xx:xx brd ff:ff:ff:ff:ff:ff
6: ETHbr0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether xx:xx:xx:xx:xx brd ff:ff:ff:ff:ff:ff
inet 192.168.0.19/27 scope global ETHbr0
valid_lft forever preferred_lft forever
7: NATbr7: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether xx:xx:xx:xx:xx brd ff:ff:ff:ff:ff:ff
inet 172.16.100.1/24 scope global NATbr7
valid_lft forever preferred_lft forever
10: vnet1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast master NATbr7 state UNKNOWN group default qlen 1000
link/ether xx:xx:xx:xx:xx brd ff:ff:ff:ff:ff:ff
25: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 100
link/none
inet 10.8.0.6 peer 10.8.0.5/32 scope global tun0
valid_lft forever preferred_lft forever
# iptables -t nat -S
-P PREROUTING ACCEPT
-P INPUT ACCEPT
-P OUTPUT ACCEPT
-P POSTROUTING ACCEPT
-A POSTROUTING -s 172.16.100.0/24 -o ETHbr0 -j MASQUERADE
# iptables -S
-P INPUT DROP
-P FORWARD DROP
-P OUTPUT DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A FORWARD -s 172.16.100.0/24 -i NATbr7 -j ACCEPT
-A FORWARD -d 172.16.100.0/24 -o NATbr7 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -d 44.55.66.77/32 -p udp -j ACCEPT
-A OUTPUT -o tun0 -j ACCEPT
# In der VM:
# ip r
default via 172.16.100.1 dev ens3
172.16.100.0/24 dev ens3 proto kernel scope link src 172.16.100.40
Kann mir bitte jemand helfen? Danke im Voraus.
Viele Grüße,
bumer