如何将Windows容器配置为NAT路由器?
Windows容器出站流量统一源IP路由方案需求
- 需求目标:将一组Windows容器的出站流量路由至同一集群内的另一个Windows容器,使所有流量以相同源IP访问边缘路由器,从而匹配现有路由策略(该策略与主机IP路由策略不同)。负责路由的容器通过
docker network create -d l2bridge ...配置,拥有外部网络静态IP。 - 排除方案:
network_mode: "service:router-container"可实现需求,但因多数服务暴露相同端口,会引发端口冲突及未知问题,且无法修改端口(否则破坏现有基础设施),故该方案不可用。
已尝试的失败方案及问题
1. Server Core容器配置RRAS
尝试在Server Core容器上配置RRAS,但持续遇到源文件缺失错误,即使指定Source为install.wim等操作也无法解决,错误信息如下:
PS C:\> Install-WindowsFeature RemoteAccess Install-WindowsFeature : The request to add or remove features on the specified server failed. Installation of one or more roles, role services, or features failed. The source files could not be found. Use the "Source" option to specify the location of the files that are required to restore the feature. For more information on specifying a source location, see http://go.microsoft.com/fwlink/?LinkId=243077. Error: 0x800f081f At line:1 char:1 + Install-WindowsFeature RemoteAccess + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidOperation: (@{Vhd=; Credent...Name=localhost}:PSObject) [Install-WindowsFeature], Exception + FullyQualifiedErrorId : DISMAPI_Error__Failed_To_Enable_Updates,Microsoft.Windows.ServerManager.Commands.AddWind owsFeatureCommand
2. 设置ICS
尝试设置ICS,但创建COM对象时失败,复制C:\Windows\System32\hnet*.dll相关文件后仍无法解决,错误信息如下:
PS C:\> regsvr32 hnetcfg.dll /s PS C:\> $m = New-Object -ComObject HNetCfg.HNetShare New-Object : Retrieving the COM class factory for component with CLSID {00000000-0000-0000-0000-000000000000} failed due to the following error: 80040154 Class not registered (Exception from HRESULT: 0x80040154 (REGDB_E_CLASSNOTREG)). At line:1 char:6 + $m = New-Object -ComObject HNetCfg.HNetShare + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : ResourceUnavailable: (:) [New-Object], COMException + FullyQualifiedErrorId : NoCOMClassIdentified,Microsoft.PowerShell.Commands.NewObjectCommand
寻求解决方案
由于Windows容器灵活性低于Linux容器,现寻求可在Windows容器内运行的有效解决方案。需求背景及基础设施细节可参考本人此前的相关提问(该提问已被无故关闭)。
内容的提问来源于stack exchange,提问作者gerneio
相关产品推荐
相关产品推荐

