NFS服务挂载提供httpd服务 | iptables | DNS分析服务
客户机一(centos7nfs服务器):
ip地址为: 192.168.78.11 nfs服务器
网卡配置:
IP 192.168.78.11
子网掩码 255.255.255.0
网关 192.168.78.33
DNS 192.168.78.33
nfs服务器配置:
1.yum -y install nfs-utils rpcbind
2.systemctl start rpcbind
systemctl start nfs
3. mkdir share
chmod 777 share
vim /share/index.html(随便编辑点内容)
4.echo '/share 192.168.78.0/24 (rw,sync,no_root_squash) ' >> /etc/exports
4.exportfs -rv
5.showmount -e
注意:关闭firewalld.setenforce服务
客户机二(centos7 httpd服务器、内网客户机):
ip地址为: 192.168.78.22 httpd服务器
网卡配置:
IP 192.168.78.22
子网掩码 255.255.255.0
网关 192.168.78.33
DNS 192.168.78.33
httpd 和 nfs-utils rpcbind配置:
1.yum -y install httpd
systemctl start httpd
2.mkdir -p var/www/html
3.yum -y install nfs-utils rpcbind
4.systemctl start rpcbind
5.systemctl start nfs
6.showmount -e
7.mount 192.168.78.11:/share /var/www/html
服务器主机三(centos7 网关服务器,DNS分离解析服务器):
双网卡配置:
ens33:
IP 192.168.78.33
子网掩码 255.255.255.0
DNS 192.168.78.33
ens36:
IP 12.0.0.254
子网掩码 255.255.255.0
DNS 12.0.0.254
iptables网关服务器:
1.关闭防火墙、安全机制
systemctl stop firewalld
setenforce 0
2.安装iptables
yum -y install iptables iptables-service
3.配置路由转发
vim /etc/sysctl.conf
添加:net.ipv4.ip_forward=1
sysctl -p
配置规则:
SNAT:iptables -t nat -A POSTROUTING -s 192.168.78.0/24 -o ens36 -j SNAT --to 12.0.0.1
DNAT:iptables -t nat -A PREROUTING -i(入站) ens36(外网网卡) -d 12.0.0.254(外网IP) -p tcp --dport 80 -j DNAT --to-destination 192.168.78.22(内网服务器IP)
DNS分离解析服务器:
修改网关分离解析服务器主配置文件:vim /etc/named.conf
options {
listen-on-v6 poet 53 { any; };
listen-on-v6 port 53 { ::1; };
directory “/var/named”;
dump- file “/var/ named/data/cache_ dump . db”;
statistics-file “/var/named/data/named stats.txt”;
memstatistics-file “/var/named/data/named_ mem_ stats. txt”;
allow-query { any; };
修改网关分离解析服务器区域配置文件:vim /etc/named.rfc1912.zones
view "lan" {
match-clients { 192.168.78.0/24; };
zone "tk.com" IN {
type master;
file "tk.com.zone.lan";
};
zone "." IN {
type hint;
file “named.ca”;
};
};
view "wan" {
match-clients { any; };
zone "tk.com" IN {
type master;
file "tk.com.zone.wan";
};
};
修改tk.com.zone.lan和 tk.com.zone.wan 俩个文件
$TTL 1D
@ IN SOA tk.com. admin.tk.com. (
0 ; serial
1D ; refresh
1H ; retry
1W ; expire
3H ) ; minimum
NS tk.com.
A 192.168.78.33
www IN A 192.168.78.22
$TTL 1D
@ IN SOA kgc.com. admin.kgc.com. (
0 ; serial
1D ; refresh
1H ; retry
1W ; expire
3H ) ; minimum
NS kgc.com.
A 12.0.0.254
www IN A 12.0.0.12
systemctl start named
systemctl restart network
客户机四(centos7 httpd服务 外网客户机):
ip地址为: 12.0.0.12 httpd服务器
网卡配置:
IP 12.0.0.12
子网掩码 255.255.255.0
网关 12.0.0.254
DNS 12.0.0.254
httpd服务
1.yum -y install httpd
2.systemctl start httpd