vs1:~# iptables -A PREROUTING -t nat -p tcp -i vmbr0 -d 77.88.99.224 --dport 2200 -j DNAT --to-destination 172.30.0.1:2200
vs1:~# iptables -I FORWARD -d 172.30.0.1 -p tcp --dport 2200 -j ACCEPT
vs1:~# iptables -A POSTROUTING -tnat -s 172.30.0.1/32 -d ! 172.30.0.1/32 -o vmbr0 -j SNAT --to-source 77.88.99.224
vs1:~# iptables -A FORWARD -i vmbr0 --match state --state RELATED,ESTABLISHED --dest 172.30.0.1/32 -j ACCEPT
vs1:~# iptables -L -v -n
Chain INPUT (policy ACCEPT 32832 packets, 4984K bytes)
pkts bytes target prot opt in out source destination
Chain FORWARD (policy ACCEPT 81162 packets, 33M bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- * * 0.0.0.0/0 172.30.0.1 tcp dpt:2200
13 988 ACCEPT all -- vmbr0 * 0.0.0.0/0 172.30.0.1 state RELATED,ESTABLISHED
Chain OUTPUT (policy ACCEPT 28282 packets, 5244K bytes)
pkts bytes target prot opt in out source destination
vs1:~# iptables -L -v -n -t nat
Chain PREROUTING (policy ACCEPT 24648 packets, 2138K bytes)
pkts bytes target prot opt in out source destination
0 0 DNAT tcp -- vmbr0 * 0.0.0.0/0 77.88.99.224 tcp dpt:2200 to:172.30.0.1:2200
Chain OUTPUT (policy ACCEPT 1353 packets, 89960 bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 24995 packets, 2132K bytes)
pkts bytes target prot opt in out source destination
13 988 SNAT all -- * vmbr0 172.30.0.1 !172.30.0.1 to:77.88.99.224
vs1:~# ifconfig
eth0 Link encap:Ethernet HWaddr 00:16:17:be:7a:d2
inet6 addr: fe80::216:17ff:febe:7ad2/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:300695974 errors:251 dropped:0 overruns:0 frame:251
TX packets:89951554 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:395760297396 (368.5 GiB) TX bytes:40907267832 (38.0 GiB)
Interrupt:46 Base address:0x6000
eth1 Link encap:Ethernet HWaddr 00:16:17:bc:4b:d9
inet6 addr: fe80::216:17ff:febc:4bd9/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:320298 errors:0 dropped:0 overruns:0 frame:0
TX packets:110630 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:41444776 (39.5 MiB) TX bytes:36487397 (34.7 MiB)
Interrupt:47 Base address:0x8000
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:4446881 errors:0 dropped:0 overruns:0 frame:0
TX packets:4446881 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:7996380708 (7.4 GiB) TX bytes:7996380708 (7.4 GiB)
tap101i1d0 Link encap:Ethernet HWaddr f6:41:a2:f8:ed:67
inet6 addr: fe80::f441:a2ff:fef8:ed67/64 Scope:Link
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:20471526 errors:0 dropped:0 overruns:0 frame:0
TX packets:28056037 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:500
RX bytes:23451679677 (21.8 GiB) TX bytes:25132334223 (23.4 GiB)
tap102i0d0 Link encap:Ethernet HWaddr c2:24:c8:18:1a:bf
inet6 addr: fe80::c024:c8ff:fe18:1abf/64 Scope:Link
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:2226959 errors:0 dropped:0 overruns:0 frame:0
TX packets:5085102 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:500
RX bytes:2590970732 (2.4 GiB) TX bytes:2830363826 (2.6 GiB)
vmbr0 Link encap:Ethernet HWaddr 00:16:17:be:7a:d2
inet addr:77.88.99.224 Bcast:77.88.99.255 Mask:255.255.255.0
inet6 addr: fe80::216:17ff:febe:7ad2/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:64008122 errors:0 dropped:0 overruns:0 frame:0
TX packets:35896008 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:240875010626 (224.3 GiB) TX bytes:24901987770 (23.1 GiB)
vmbr1 Link encap:Ethernet HWaddr 00:16:17:bc:4b:d9
inet addr:10.42.1.2 Bcast:10.42.1.255 Mask:255.255.255.0
inet6 addr: fe80::216:17ff:febc:4bd9/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:20620676 errors:0 dropped:0 overruns:0 frame:0
TX packets:28072424 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:23184569148 (21.5 GiB) TX bytes:25143218555 (23.4 GiB)
vmbr1:1 Link encap:Ethernet HWaddr 00:16:17:bc:4b:d9
inet addr:172.30.0.254 Bcast:172.30.0.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
vs1:~# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
172.30.0.0 0.0.0.0 255.255.255.0 U 0 0 0 vmbr1
10.42.1.0 0.0.0.0 255.255.255.0 U 0 0 0 vmbr1
77.88.99.0 0.0.0.0 255.255.255.0 U 0 0 0 vmbr0
0.0.0.0 77.88.99.254 0.0.0.0 UG 0 0 0 vmbr0