Réseau local
FreeBox : 192.168.0.254
Réseau lan Freebox :
PC1 = 192.168.0.14
PC2 = HÔTE = 192.168.0.43
*Interfaces réseaux PC2 eth0 et br0 fournis dans le premier descriptif
configuration ip VM
allow-hotplug eth0
iface eth0 inet static
address 192.168.0.44
netmask 255.255.255.0
gateway 192.168.0.43
dns-nameservers 192.168.0.254
Visibilité réseau depuis l'hôte
/home/user# arp -n
Address HWtype HWaddress Flags Mask Iface
192.168.0.44 ether xx:xx:xx:xx:xx C br0
192.168.0.14 ether xx:xx:xx:xx:xx C br0
192.168.0.254 ether xx:xx:xx:xx:xx C br0
Ping VM vers hôte == OK
ping hôte vers VM == OK
ping vers google.fr == KO
ping vers 192.168.0.14 == KO
règles iptables hôte :
:/home/user# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:bootps
ACCEPT tcp -- anywhere anywhere tcp dpt:bootps
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere 192.168.122.0/24 ctstate RELATED,ESTABLISHED
ACCEPT all -- 192.168.122.0/24 anywhere
ACCEPT all -- anywhere anywhere
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:bootpc
iptables-save hôte :
iptables-save
# Generated by iptables-save v1.4.21 on Sun Jan 29 07:37:06 2017
*mangle
:PREROUTING ACCEPT [1094:191648]
:INPUT ACCEPT [351:34419]
:FORWARD ACCEPT [163:29239]
:OUTPUT ACCEPT [125:16405]
:POSTROUTING ACCEPT [288:45644]
-A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
COMMIT
# Completed on Sun Jan 29 07:37:06 2017
# Generated by iptables-save v1.4.21 on Sun Jan 29 07:37:06 2017
*nat
:PREROUTING ACCEPT [683:144403]
:INPUT ACCEPT [23:4389]
:OUTPUT ACCEPT [8:470]
:POSTROUTING ACCEPT [48:6824]
-A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
-A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
COMMIT
# Completed on Sun Jan 29 07:37:06 2017
# Generated by iptables-save v1.4.21 on Sun Jan 29 07:37:06 2017
*filter
:INPUT ACCEPT [371:35219]
:FORWARD ACCEPT [163:29239]
:OUTPUT ACCEPT [171:22005]
-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
-A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
COMMIT
# Completed on Sun Jan 29 07:37:06 2017
Configuration ip hôte
:/home/user# ifconfig
br0 Link encap:Ethernet HWaddr xxxxx....
inet adr:192.168.0.43 Bcast:192.168.0.255 Masque:255.255.255.0
adr inet6: fe80::20c:29ff:fe90:d386/64 Scope:Lien
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2445 errors:0 dropped:0 overruns:0 frame:0
TX packets:265 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:0
RX bytes:322355 (314.7 KiB) TX bytes:34167 (33.3 KiB)
eth0 Link encap:Ethernet HWaddr xxxxx....
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2426 errors:0 dropped:10 overruns:0 frame:0
TX packets:281 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:1000
RX bytes:356037 (347.6 KiB) TX bytes:35733 (34.8 KiB)
lo Link encap:Boucle locale
inet adr:127.0.0.1 Masque:255.0.0.0
adr inet6: ::1/128 Scope:Hôte
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
virbr0 Link encap:Ethernet HWaddr xxxxx....
inet adr:192.168.122.1 Bcast:192.168.122.255 Masque:255.255.255.0
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
vnet0 Link encap:Ethernet HWaddr xxxxx....
adr inet6: fe80::fc54:ff:fe23:f5b3/64 Scope:Lien
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:38 errors:0 dropped:0 overruns:0 frame:0
TX packets:421 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:500
RX bytes:2726 (2.6 KiB) TX bytes:51307 (50.1 KiB)