在 Debian 上做“端口映射”通常有几种常见场景,下面按使用方式和场景给你说明,最核心的是 iptables / nftables 端口转发(DNAT)。
把 本机 2222 端口 映射到 内网 192.168.1.10:22
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p
iptables -t nat -A PREROUTING -p tcp --dport 2222 -j DNAT --to-destination 192.168.1.10:22
iptables -A FORWARD -p tcp -d 192.168.1.10 --dport 22 -j ACCEPT
iptables -t nat -A POSTROUTING -j MASQUERADE
apt install iptables-persistent
netfilter-persistent save
nft add table nat
nft add chain nat prerouting { type nat hook prerouting priority 0 \; }
nft add rule nat prerouting tcp dport 2222 dnat to 192.168.1.10:22
nft add rule nat postrouting masquerade
保存:
nft list ruleset > /etc/nftables.conf
systemctl enable nftables
iptables -t nat -A PREROUTING -p tcp --dport 8080 -j REDIRECT --to-port 80
或:
nft add rule nat prerouting tcp dport 8080 redirect to :80
firewall-cmd --add-forward-port=port=2222:proto=tcp:toaddr=192.168.1.10:toport=22 --permanent
firewall-cmd --reload
ssh -L 0.0.0.0:2222:192.168.1.10:22 user@localhost
✅ 必须开启 ip_forward
✅ FORWARD 链不能 DROP
✅ 云服务器还要放行安全组
✅ Docker 会改 iptables
如果你能告诉我:
我可以给你精确命令。