基于Raspberry Pi的内外网中转部署,咨询访问扩展方案
Hey there! Let’s get your Raspberry Pi set up to bridge your company’s external network and the internal media stream system in the server room. Since you already have wlan0 connected to the company’s external network and eth0 linked to the internal LAN, we can use IP forwarding and NAT rules to make cross-network access work smoothly.
Step 1: Enable IP Forwarding on the Pi
First, we need to allow the Pi to route traffic between the two interfaces:
- Open the sysctl configuration file:
sudo nano /etc/sysctl.conf - Find the line
#net.ipv4.ip_forward=1, remove the#to uncomment it, then save and exit (Ctrl+O, Enter, Ctrl+X). - Apply the change immediately:
sudo sysctl -p
Step 2: Configure NAT for Internal Devices to Access External Network
If you want the media stream system in the server room to access resources on the company’s external network, set up a masquerading rule to translate internal IPs to the Pi’s wlan0 address:
sudo iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE
Make sure the media stream system’s default gateway is set to the Pi’s eth0 IP address—this tells the system to send external traffic through the Pi.
Step 3: Set Up Port Forwarding for External Devices to Access the Media Stream System
If you need devices on the company’s external network to reach the media stream system, use port forwarding to direct traffic from the Pi’s wlan0 to the internal media stream device:
- Replace
192.168.1.100with your media stream system’s internal IP, and554with its service port (adjust based on your actual setup):# Forward incoming traffic on wlan0 port 554 to the media stream system sudo iptables -t nat -A PREROUTING -i wlan0 -p tcp --dport 554 -j DNAT --to-destination 192.168.1.100:554 # Allow the forwarded traffic through the Pi sudo iptables -A FORWARD -i wlan0 -o eth0 -p tcp --dport 554 -d 192.168.1.100 -j ACCEPT - Devices on the company’s external network can now access the media stream system using the Pi’s
wlan0IP address and port 554.
Step 4: Save Rules to Persist After Reboot
By default, iptables rules are lost when the Pi reboots. Save them and set up auto-loading:
- Install the netfilter-persistent tool:
sudo apt update && sudo apt install netfilter-persistent - Save your current iptables rules:
sudo netfilter-persistent save - Ensure the service starts on boot:
sudo systemctl enable netfilter-persistent
Verify the Setup
- Check if IP forwarding is enabled:
cat /proc/sys/net/ipv4/ip_forward(should return1). - View your current iptables rules:
sudo iptables -t nat -L -n -v. - Confirm the routing table includes both networks:
ip route show.
If you run into issues (like blocked traffic), double-check your firewall rules on the Pi, the media stream system, and the company’s external network. Adjust port numbers or IP addresses to match your actual environment.
内容的提问来源于stack exchange,提问作者B. Tsai

