@[Centos7虚拟机安装Jumpserver堡垒机详解]
官方文档: https://docs.jumpserver.org/zh/1.4.8/setup_by_centos7.html
1.环境声明 (真机操作可忽略此步)
虚拟机 Centos 版本(全新 centos7 虚拟机):
[root@localhost ~]# cat /etc/redhat-release
CentOS Linux release 7.7.1908 (Core)
真机网卡配置:
# vbr网卡设置
[root@room9pc01 ~]# vim /etc/libvirt/qemu/networks/vbr.xml
<network>
<name>vbr</name>
<forward mode='nat'/>
<bridge name='vbr' stp='on' delay='0'/>
<ip address='192.168.1.254' netmask='255.255.255.0'> # vbr的ip设置为192.168.1.254
<dhcp>
<range start='192.168.1.100' end='192.168.1.200'/> # DHCP自动分发ip,可忽略
</dhcp>
</ip>
</network>
[root@room9pc01 ~]#virsh net-define vbr.xml # 执行定义网络
[root@room9pc01 ~]#virsh net-start vbr # 启用网络
[root@room9pc01 ~]#virsh net-autostart vbr # 开机自启
# 查看vbr网卡ip是否正确(inet 192.168.1.254)
[root@cjj ~]# ifconfig vbr
vbr: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.1.254 netmask 255.255.255.0 broadcast 192.168.1.255
ether 52:54:00:35:6e:56 txqueuelen 1000 (Ethernet)
RX packets 1221159 bytes 113750199 (108.4 MiB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 1751507 bytes 2461512863 (2.2 GiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
# 本机路由转发功能,1为开启,0为关闭
# 开启设置为 echo 1 > /proc/sys/net/ipv4/ip_forward
[root@cjj ~]# cat /proc/sys/net/ipv4/ip_forward
1
# 修改真机DNS解析服务器ip
[root@cjj ~]# vim /etc/resolv.conf
......
servername 176.130.0.200 # 本教程环境中域名解析服务器ip,也可以使用8.8.8.8或114.114.114.114
虚拟机网卡配置:
[root@localhost ~]# cat /etc/resolv.conf #指定域名解析服务器(真机ip)
nameserver 192.168.1.254
#设置ip方法1
[root@localhost ~]# nmcli connection modify eth0 ipv4.method manual ipv4.addresses 192.168.1.200/24 ipv4.gateway 192.168.1.254 connection.autoconnect yes
[root@localhost ~]# nmcli connection up eth0
#设置ip方法2
[root@localhost ~]# vim /etc/sysconfig/network-scripts/ifcfg-eth0
TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=none
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=eth0
DEVICE=eth0
ONBOOT=yes
IPADDR=192.168.1.200
PREFIX=24
GATEWAY=192.168.1.254