ip link set dev ens4 mtu 1500
ip a show ens4
3: ens4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether fa:16:3e:e9:56:c2 brd ff:ff:ff:ff:ff:ff
inet 10.4.2.136/24 brd 10.4.2.255 scope global ens4
valid_lft forever preferred_lft forever
inet6 fe80::f816:3eff:fee9:56c2/64 scope link
valid_lft forever preferred_lft forever
Voilà quelques logs tcpdump/iptables sur l'instance NAT pour un dig google.com
lancé depuis le server PRIVATE.
tcpdump -vvvi ens3 proto UDP
08:21:59.841306 IP (tos 0x0, ttl 63, id 6482, offset 0, flags [DF], proto UDP (17), length 67)
NAT_INSTANCE.49562 > cdns.ovh.net.domain: [udp sum ok] 17502+ [1au] A? google.com. ar: . OPT UDPsize=512 (39)
08:21:59.841307 IP (tos 0x0, ttl 63, id 6483, offset 0, flags [DF], proto UDP (17), length 67)
NAT_INSTANCE.com.41889 > cdns.ovh.net.domain: [udp sum ok] 45715+ [1au] A? google.com. ar: . OPT UDPsize=512 (39)
08:21:59.852405 IP (tos 0x0, ttl 53, id 38483, offset 0, flags [none], proto UDP (17), length 83)
cdns.ovh.net.domain > NAT_INSTANCE.com.41889: [udp sum ok] 45715 q: A? google.com. 1/0/1 google.com. [4m35s] A 216.58.213.142 ar: . OPT UDPsize=1232 (55)
08:21:59.852443 IP (tos 0x0, ttl 53, id 52103, offset 0, flags [none], proto UDP (17), length 83)
cdns.ovh.net.domain > NAT_INSTANCE.com.49562: [udp sum ok] 17502 q: A? google.com. 1/0/1 google.com. [3m24s] A 172.217.13.110 ar: . OPT UDPsize=1232 (55)
tcpdump -vvvi ens4 host 10.4.2.129 and proto UDP
08:21:59.841306 IP (tos 0x0, ttl 64, id 48968, offset 0, flags [DF], proto UDP (17), length 67)
PRIVATE_INSTANCE.36822 > cdns.ovh.net.domain: [udp sum ok] 43395+ [1au] A? google.com. ar: . OPT UDPsize=512 (39)
08:21:59.841307 IP (tos 0x0, ttl 64, id 48969, offset 0, flags [DF], proto UDP (17), length 67)
PRIVATE_INSTANCE.56182 > cdns.ovh.net.domain: [udp sum ok] 18446+ [1au] A? google.com. ar: . OPT UDPsize=512 (39)
08:21:59.852405 IP (tos 0x0, ttl 52, id 11689, offset 0, flags [none], proto UDP (17), length 83)
cdns.ovh.net.domain > PRIVATE_INSTANCE.36822: [udp sum ok] 43395 q: A? google.com. 1/0/1 google.com. [3m32s] A 216.58.213.142 ar: . OPT UDPsize=1232 (55)
08:21:59.852443 IP (tos 0x0, ttl 52, id 11690, offset 0, flags [none], proto UDP (17), length 83)
cdns.ovh.net.domain > PRIVATE_INSTANCE.56182: [udp sum ok] 18446 q: A? google.com. 1/0/1 google.com. [3m32s] A 216.58.213.142 ar: . OPT UDPsize=1232 (55)
iptables -t nat -I POSTROUTING 1 -j LOG --log-prefix "NAT1:" --log-level 7
Jul 19 08:21:59 nat-sbg7-0 kernel: [ 471.943456] NAT1:IN= OUT=ens3 SRC=10.4.2.129 DST=213.186.33.99 LEN=67 TOS=0x0
0 PREC=0x00 TTL=63 ID=48968 DF PROTO=UDP SPT=36822 DPT=53 LEN=47
Jul 19 08:21:59 nat-sbg7-0 kernel: [ 471.943540] NAT1:IN= OUT=ens3 SRC=10.4.2.129 DST=213.186.33.99 LEN=67 TOS=0x0
0 PREC=0x00 TTL=63 ID=48969 DF PROTO=UDP SPT=56182 DPT=53 LEN=47