1. 内网机器上网

    iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j SNAT -to-source 10.0.0.1

    or

    iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE


  2. 外部到内部映射

    端口映射

    iptables -t nat -A PREROUTING -d 10.0.0.1 -p tcp --dport 80 -j DNAT --to-destination 192.168.1.100:80     

    IP 1v1

    iptables -t nat -A PREROUTING -d 10.0.0.2 -j DNAT --to-destination 192.168.1.100

    iptables -t nat -A POSTROUTING -s 192.168.1.100 -j SNAT --to-source 10.0.0.2