Centos 6.x 多宿主路由問題

Centos 6.x 多宿主路由問題

我有一個難題,想聽聽任何指示(現在已經為此工作了 2 天,需要將此伺服器投入生產)。

我的“google-foo”對此並不強。

我有一個多宿主 Linux 伺服器 - Centos 6.x

我刪除了該伺服器上雙 10 Gig 連接埠上的 LACP/綁定。

儘管嘗試為每個 NIC 設定單獨的 ip 路由,但一切都是透過 NIC em3(系統的預設路由)發出的。我希望這個系統的行為是為了:

   - em3 to only handle external (internet) traffic.
   - em2 to only handle 10 Gig traffic
   - em1 to handle everything else / internal traffic.

網路上的下一跳是:

  - em1 & em2 go to a good L2/L3, 10 Gig switch 
  - em3 goes to a decent L2/L3, 1 Gig switch

注意:IP 位址已被修改了一點。

em1 是一個內部 1 Gig 網絡,它有權查看內部網路上的所有內容,並且能夠透過我們的預設防火牆/路由器存取開放互聯網。

em1 is  10.10.18.21/16    gw is to be 10.10.5.1

em2 是一個內部 10 Gig 網絡,只能看到該網段上的其他 10 Gig 設備。

em2 is  10.16.64.21/26    gw is to be 10.16.64.21

em3 是允許遠端連線授權使用者的外部網路。

em3 is  10.48.61.80/24    gw is to be 10.48.61.1

我在 /etc/iproute/rt_tables 檔案中新增了條目,如下所示:

#
# reserved values
#
255 local
254 main
253 default
0   unspec
#
# local
#
#1  inr.ruhep
10 em1table
20 em2table
30 em3table

我還創建了“路線”和“規則”文件。

-rw-r--r--  1 root root    98 Feb 15 08:54 route-em1
-rw-r--r--  1 root root    87 Feb 16 12:31 route-em2
-rw-r--r--  1 root root   102 Feb 16 10:37 route-em3
-rw-r--r--  1 root root    65 Feb 15 08:11 rule-em1
-rw-r--r--  1 root root    68 Feb 16 12:32 rule-em2
-rw-r--r--  1 root root    68 Feb 16 10:37 rule-em3


[/etc/sysconfig/network-scripts]$ cat route-em1
10.10.18.0 dev em1 src 10.10.18.21 table em1table
default via 10.10.5.1 dev em1 table em1table
[/etc/sysconfig/network-scripts]$ cat rule-em1
from 10.10.18.21/16 table em1table
to 10.10.5.1 table em1table


[/etc/sysconfig/network-scripts]$ cat route-em2
10.16.64.0/28 dev em2 table em2table
default via 10.16.64.254 dev em2 table em2table
[/etc/sysconfig/network-scripts]$ cat rule-em2
from 10.16.64.21/28 table em2table
to 10.16.64.254 table em2table

67.134
[/etc/sysconfig/network-scripts]$ cat route-em3
10.48.161.0 dev em3 src 10.48.161.82 table em3table
default via 10.48.161.1 dev em3 table em3table
[/etc/sysconfig/network-scripts]$ cat rule-em3
from 10.48.161.82/24 table em3table
to 10.48.161.1 table em3table


[/etc/sysconfig/network-scripts]$ ip route show table em1table
10.10.18.0 dev em1  scope link  src 10.10.18.21 
default via 10.10.5.1 dev em1 

[/etc/sysconfig/network-scripts]$ ip route show table em2table
10.16.64.0/28 dev em2  scope link 
default via 10.16.64.254 dev em2 

[/etc/sysconfig/network-scripts]$ ip route show table em3table
10.48.161.0 dev em3  scope link  src 10.48.161.82 
default via 10.48.161.1 dev em3 

以下是一些附加資訊:

[/etc/sysconfig/network-scripts]$ route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
10.48.161.0     0.0.0.0         255.255.255.0   U     0      0        0 em3
10.16.64.0      0.0.0.0         255.255.192.0   U     0      0        0 em2
10.10.0.0       0.0.0.0         255.255.0.0     U     0      0        0 em1
169.254.0.0     0.0.0.0         255.255.0.0     U     1002   0        0 em1
169.254.0.0     0.0.0.0         255.255.0.0     U     1003   0        0 em2
169.254.0.0     0.0.0.0         255.255.0.0     U     1004   0        0 em3
0.0.0.0         10.48.161.1     0.0.0.0         UG    0      0        0 em3
[/etc/sysconfig/network-scripts]$ 


[/etc/sysconfig/network-scripts]$ ip route show
10.48.161.0/24 dev em3  proto kernel  scope link  src 10.48.161.82 
10.16.64.0/18 dev em2  proto kernel  scope link  src 10.16.64.21 
10.10.0.0/16 dev em1  proto kernel  scope link  src 10.10.18.21 
169.254.0.0/16 dev em1  scope link  metric 1002 
169.254.0.0/16 dev em2  scope link  metric 1003 
169.254.0.0/16 dev em3  scope link  metric 1004 
default via 10.48.161.1 dev em3 
[/etc/sysconfig/network-scripts]$ 


[/etc/sysconfig/network-scripts]$ ip route show to match 10.16.64.0/28
10.16.64.0/18 dev em2  proto kernel  scope link  src 10.16.64.21 
default via 67.134.161.1 dev em3 

[/etc/sysconfig/network-scripts]$ ip route show to match 10.10.18.0/16
10.10.0.0/16 dev em1  proto kernel  scope link  src 10.10.18.21 
default via 67.134.161.1 dev em3 

[/etc/sysconfig/network-scripts]$ ip route show to match 67.134.161.0/24
10.48.161.0/24 dev em3  proto kernel  scope link  src 10.48.161.82 
default via 10.48.161.1 dev em3 



[/etc/sysconfig/network-scripts]$ cat ifcfg-em1
DEVICE=em1
#MASTER=bond0
#SLAVE=yes
HWADDR=c8:1f:66:f4:ce:10
TYPE=Ethernet
UUID=bfa14e4a-66b0-4b83-93a4-094f9090aea7
ONBOOT=yes
NM_CONTROLLED=no
BOOTPROTO=none
IPADDR=10.10.18.21
PREFIX=16
#GATEWAY=10.10.5.1
DNS1=10.10.5.8
DNS2=10.10.5.9
DOMAIN=AXS
DEFROUTE=YES
IP4_FAILURE_FATAL=yes
IP6INIT=no
NAME="em1"
NETMASK=255.255.0.0
IPV6INIT=no
USERCTL=no

[/etc/sysconfig/network-scripts]$ cat ifcfg-em2
DEVICE=em2
#MASTER=bond0
#SLAVE=yes
HWADDR=c8:1f:66:f4:ce:12
TYPE=Ethernet
UUID=c8c5e1fb-ba40-4537-89ad-f7df5de59f8b
ONBOOT=yes
NM_CONTROLLED=no
BOOTPROTO=none
IPADDR=10.16.64.21
PREFIX=18
#GATEWAY=10.16.64.254
DNS1=10.10.5.8
DNS2=10.10.5.9
DOMAIN=AXS
#DEFROUTE=YES
IP4_FAILURE_FATAL=yes
IP6INIT=no
NAME="em2"
#IPADDR=10.16.64.21
NETMASK=255.255.192.0
IPV6INIT=no
USERCTL=no

[/etc/sysconfig/network-scripts]$ cat ifcfg-em3
DEVICE=em3
HWADDR=C8:1F:66:F4:CE:14
TYPE=Ethernet
UUID=aa9552be-0075-46b2-8eff-b7c49c8c999f
ONBOOT=yes
NM_CONTROLLED=no
BOOTPROTO=none
IPADDR=10.48.161.82
PREFIX=24
GATEWAY=10.48.161.1
DNS1=10.10.5.8
DNS2=10.10.5.9
DNS3=205.171.3.65
DNS4=8.8.8.8
DOMAIN=axs.tv
DEFROUTE=yes
IPV4_FAILURE_FATAL=yes
IPV6INIT=no
USERCTL=no

而且,當我嘗試 ping 每個介面時:

[/etc/sysconfig/network-scripts]$ ping -I em1 10.10.5.1
PING 10.10.5.1 (10.10.5.1) from 10.10.18.21 em1: 56(84) bytes of data.
--- 10.10.5.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2846ms
rtt min/avg/max/mdev = 0.081/0.101/0.135/0.024 ms

[/etc/sysconfig/network-scripts]$ ping -I em2 10.16.64.154
PING 10.16.64.154 (10.16.64.154) from 10.16.64.21 em2: 56(84) bytes of data.
--- 10.16.64.154 ping statistics ---
5 packets transmitted, 0 received, +3 errors, 100% packet loss, time 4022ms
pipe 3

[/etc/sysconfig/network-scripts]$ ping -I em3 www.google.com
--- www.google.com ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3366ms
rtt min/avg/max/mdev = 2.657/2.679/2.711/0.041 ms

答案1

我知道這是舊條目,但是,仍然出現在多家庭搜尋中。
新增額外網關時我很困惑,一次只能使用一個網關。
指定主網關,始終搶佔所有流量。
我只用三個設定解決了我的問題:
在您最喜歡的 sysctl 腳本上添加以下內容:(我在 Centos 上使用 /usr/lib/sysctl.d/99-multihome)

# add forwarding
net.ipv4.ip_forward = 1
# Accept source routing
net.ipv4.conf.default.accept_source_route = 1
net.ipv4.conf.all.accept_source_route = 1

請注意,可以確定您的防火牆在處理此變更時能夠勝任其工作。

相關內容