1.ip route包也确定有安装。
2.以下是计算节点 ping 网络节点 实例通道 网卡的截图
3.网络节点ping 计算节点截图
iptables
除了-A POSTROUTING -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
是我自己加的 其他 都是系统自动生成的
# Generated by iptables-save v1.4.21 on Fri Dec 26 16:39:23 2014
*nat
:PREROUTING ACCEPT [884:153497]
:INPUT ACCEPT [1:52]
:OUTPUT ACCEPT [7:599]
:POSTROUTING ACCEPT [5:332]
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
COMMIT
# Completed on Fri Dec 26 16:39:23 2014
# Generated by iptables-save v1.4.21 on Fri Dec 26 16:39:23 2014
*mangle
:PREROUTING ACCEPT [485:95832]
:INPUT ACCEPT [485:95832]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [379:80138]
:POSTROUTING ACCEPT [379:80138]
-A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
-A POSTROUTING -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
COMMIT
# Completed on Fri Dec 26 16:39:23 2014
# Generated by iptables-save v1.4.21 on Fri Dec 26 16:39:23 2014
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1734:374214]
-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 5900:5999 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Fri Dec 26 16:39:23 2014
|