Bonjour,
Voici mon objectif:
freebox<=>[enp2s0]-serveur ubuntu 20.04 - [enp3s0]<=>réseau local(routeur netgear ou autre)
Je souhaite utiliser le pc hébergeant le serveur comme routeur et pouvoir bloquer des connexions internet de certaines IP avec iptables.
Voici mon fichier *.yaml:
network:
version: 2
renderer: networkd
ethernets:
enp3s0:
dhcp4: false
enp2s0:
optional: true
dhcp4: false
bridges:
br0:
interfaces: [enp3s0,enp2s0]
Le retour de
sudo netplan --debug generate
DEBUG:command generate: running ['/lib/netplan/generate']
** (generate:14596): DEBUG: 20:28:18.058: Processing input file /etc/netplan/00-installer-config.yaml..
** (generate:14596): DEBUG: 20:28:18.058: starting new processing pass
** (generate:14596): DEBUG: 20:28:18.058: We have some netdefs, pass them through a final round of validation
** (generate:14596): DEBUG: 20:28:18.058: enp2s0: setting default backend to 1
** (generate:14596): DEBUG: 20:28:18.058: Configuration is valid
** (generate:14596): DEBUG: 20:28:18.058: enp3s0: setting default backend to 1
** (generate:14596): DEBUG: 20:28:18.058: Configuration is valid
** (generate:14596): DEBUG: 20:28:18.058: br0: setting default backend to 1
** (generate:14596): DEBUG: 20:28:18.058: Configuration is valid
** (generate:14596): DEBUG: 20:28:18.059: Generating output files..
** (generate:14596): DEBUG: 20:28:18.059: openvswitch: definition enp3s0 is not for us (backend 1)
** (generate:14596): DEBUG: 20:28:18.059: NetworkManager: definition enp3s0 is not for us (backend 1)
** (generate:14596): DEBUG: 20:28:18.059: openvswitch: definition enp2s0 is not for us (backend 1)
** (generate:14596): DEBUG: 20:28:18.059: NetworkManager: definition enp2s0 is not for us (backend 1)
** (generate:14596): DEBUG: 20:28:18.059: openvswitch: definition br0 is not for us (backend 1)
** (generate:14596): DEBUG: 20:28:18.059: NetworkManager: definition br0 is not for us (backend 1)
(generate:14596): GLib-DEBUG: 20:28:18.059: posix_spawn avoided (fd close requested)
(generate:14596): GLib-DEBUG: 20:28:18.060: posix_spawn avoided (fd close requested)
Avec cette configuration, j'ai bien une connexion internet sur ce qui est branché sur enp3s0, mais impossible de bloquer l'ip avec cette commande:
sudo iptables -A INPUT -s 192.168.x.xxx -j DROP
J'ai beaucoup cherché sur google des configurations similaires, mais je ne trouve pas grand chose, netplan est mal expliqué.
Donc je recherche surtout des informations claires sur netplan.