如何检查virbr0的nat表?我可以看到指向主机ip的pings,但是我得到了无法到达的目标主机。
ping 192.168.10.151
PING 192.168.10.151 (192.168.10.151) 56(84) bytes of data.
From 192.168.10.100 icmp_seq=1 Destination Host Unreachable
192.168.10.100 host (br0 interface)
192.168.10.151 guest
virbr0 ip: 192.168.11.149
发布于 2013-01-23 14:45:15
sudo iptables --table nat --list --numeric --verbose
或其简短形式:
sudo iptables -t nat -L -nv
--table nat
是关键:它列出NAT表。--list
是一个明显的清单命令。--numeric
来加速它,因为否则它会对每个地址进行反向查找。--verbose
是显而易见的“我要所有输出”选项。示例输出:
$ sudo iptables -t nat -L -nv
Chain PREROUTING (policy ACCEPT 22 packets, 6050 bytes)
pkts bytes target prot opt in out source destination
Chain INPUT (policy ACCEPT 12 packets, 2994 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 5190 packets, 340K bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 5164 packets, 337K bytes)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE tcp -- * * 192.168.122.0/24 !192.168.122.0/24 masq ports: 1024-65535
8 854 MASQUERADE udp -- * * 192.168.122.0/24 !192.168.122.0/24 masq ports: 1024-65535
1 40 MASQUERADE all -- * * 192.168.122.0/24 !192.168.122.0/24
https://askubuntu.com/questions/246787
复制