{"id":81265,"date":"2020-05-12T01:42:43","date_gmt":"2020-05-11T23:42:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/bystryj-routing-i-nat-v-linux"},"modified":"2020-05-12T01:42:43","modified_gmt":"2020-05-11T23:42:43","slug":"bystryj-routing-i-nat-v-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/bystryj-routing-i-nat-v-linux","title":{"rendered":"Routimi i shpejt\u00eb dhe NAT n\u00eb Linux","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Me kalimin e adresave IPv4, shum\u00eb operator\u00eb t\u00eb telekomunikacionit jan\u00eb ballafaquar me nevoj\u00ebn p\u00ebr t\u00eb organizuar qasjen e klient\u00ebve t\u00eb tyre n\u00eb rrjet p\u00ebrmes p\u00ebrkthimit t\u00eb adresave. N\u00eb k\u00ebt\u00eb artikull do t\u00eb flas p\u00ebr se si mund t\u00eb arrihet performanca e nivelit Carrier Grade NAT n\u00eb serverat e zakonsh\u00ebm.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>Pak histori<\/h3>\n<p>\nTema e shterimit t\u00eb hap\u00ebsir\u00ebs IP IPv4 nuk \u00ebsht\u00eb e re. N\u00eb nj\u00eb moment, paraqit\u00ebn lista pritjeje n\u00eb RIPE, pastaj u shfaq\u00ebn bursa ku tregoheshin blloqet e adresave dhe merren marr\u00ebveshje p\u00ebr qiradh\u00ebnie. Gradually, operator\u00ebt e telekomunikacionit filluan t\u00eb ofronin sh\u00ebrbime interneti p\u00ebrmes p\u00ebrkthimit t\u00eb adresave dhe porteve. Disa nuk arrit\u00ebn t\u00eb merrnin mjaft adresat p\u00ebr t\u00eb dh\u00ebn\u00eb nj\u00eb adres\u00eb \"t\u00eb bardh\u00eb\" p\u00ebr \u00e7do abonent, nd\u00ebrsa disa filluan t\u00eb kursenin duke hequr dor\u00eb nga blerja e adresave n\u00eb tregun e dyt\u00eb. Prodhuesit e pajisjeve rrjet\u00ebsore e mb\u00ebshtet\u00ebn k\u00ebt\u00eb ide, pasi ky funksionalitet zakonisht k\u00ebrkon module shtes\u00eb ose licenca. P\u00ebr shembull, te Juniper, n\u00eb linj\u00ebn e routerave MX (p\u00ebrve\u00e7 MX104 dhe MX204 t\u00eb fundit), kryerja e NAPT mund t\u00eb b\u00ebhet n\u00eb nj\u00eb kart\u00eb sh\u00ebrbimi t\u00eb ve\u00e7ant\u00eb MS-MIC, te Cisco ASR1k k\u00ebrkohet licence CGN, te Cisco ASR9k \u2013 nj\u00eb moduli t\u00eb ve\u00e7ant\u00eb A9K-ISM-100 dhe licenca A9K-CGN-LIC p\u00ebr t\u00eb. N\u00eb p\u00ebrgjith\u00ebsi, k\u00ebnaq\u00ebsia kushton shum\u00eb.<\/p>\n<h3>IPTables<\/h3>\n<p>\nDetyra e kryerjes s\u00eb NAT nuk k\u00ebrkon burime t\u00eb specializuara t\u00eb p\u00ebrpunimit, e cila mund t\u00eb zgjidhet nga procesor\u00ebt e zakonsh\u00ebm, t\u00eb cil\u00ebt jan\u00eb t\u00eb instaluar, p\u00ebr shembull, n\u00eb \u00e7do router sht\u00ebpie. N\u00eb shkall\u00ebn e operator\u00ebve t\u00eb telekomunikacionit, kjo detyr\u00eb mund t\u00eb zgjidhet duke p\u00ebrdorur serverat e zakonsh\u00ebm n\u00ebn FreeBSD (ipfw\/pf) ose GNU\/Linux (iptables). Nuk do ta shqyrtojm\u00eb FreeBSD, pasi un\u00eb e kam hequr dor\u00eb q\u00eb nj\u00eb koh\u00eb t\u00eb gjat\u00eb nga p\u00ebrdorimi i k\u00ebtij OS, k\u00ebshtu q\u00eb do t\u00eb fokusohemi n\u00eb GNU\/Linux.<\/p>\n<p>Aktivizimi i p\u00ebrkthimit t\u00eb adresave nuk \u00ebsht\u00eb aspak e v\u00ebshtir\u00eb. P\u00ebr fillim, duhet t\u00eb shkruani nj\u00eb rregull n\u00eb iptables n\u00eb tabel\u00ebn nat:<\/p>\n<pre><code class=\"bash\">iptables -t nat -A POSTROUTING -s 100.64.0.0\/10 -j SNAT --to - --persistent\n<\/code><\/pre>\n<p>\nSistemi operativ do t\u00eb ngarkoj\u00eb modulimin nf_conntrack, i cili do t\u00eb mbaj\u00eb n\u00ebn mbik\u00ebqyrje t\u00eb gjitha lidhjet aktive dhe do t\u00eb b\u00ebj\u00eb transformimet e nevojshme. K\u00ebtu ka disa nuanca. S\u00eb pari, pasi flasim p\u00ebr NAT n\u00eb shkall\u00eb t\u00eb operatorit t\u00eb komunikimeve, \u00ebsht\u00eb e nevojshme t\u00eb rregullohen timeout-et, sepse me vlerat e paracaktuara, madh\u00ebsia e tabel\u00ebs s\u00eb p\u00ebrkthimit do t\u00eb rritet shum\u00eb shpejt n\u00eb p\u00ebrmasa katastrofike. M\u00eb posht\u00eb \u00ebsht\u00eb nj\u00eb shembull i konfigurimeve q\u00eb kam p\u00ebrdorur n\u00eb server\u00ebt e mi:<\/p>\n<pre><code class=\"bash\">net.ipv4.ip_forward = 1\nnet.ipv4.ip_local_port_range = 8192 65535\n\nnet.netfilter.nf_conntrack_generic_timeout = 300\nnet.netfilter.nf_conntrack_tcp_timeout_syn_sent = 60\nnet.netfilter.nf_conntrack_tcp_timeout_syn_recv = 60\nnet.netfilter.nf_conntrack_tcp_timeout_established = 600\nnet.netfilter.nf_conntrack_tcp_timeout_fin_wait = 60\nnet.netfilter.nf_conntrack_tcp_timeout_close_wait = 45\nnet.netfilter.nf_conntrack_tcp_timeout_last_ack = 30\nnet.netfilter.nf_conntrack_tcp_timeout_time_wait = 120\nnet.netfilter.nf_conntrack_tcp_timeout_close = 10\nnet.netfilter.nf_conntrack_tcp_timeout_max_retrans = 300\nnet.netfilter.nf_conntrack_tcp_timeout_unacknowledged = 300\nnet.netfilter.nf_conntrack_udp_timeout = 30\nnet.netfilter.nf_conntrack_udp_timeout_stream = 60\nnet.netfilter.nf_conntrack_icmpv6_timeout = 30\nnet.netfilter.nf_conntrack_icmp_timeout = 30\nnet.netfilter.nf_conntrack_events_retry_timeout = 15\nnet.netfilter.nf_conntrack_checksum=0\n<\/code><\/pre>\n<p>\nDhe s\u00eb dyti, pasi madh\u00ebsia e tabel\u00ebs s\u00eb p\u00ebrkthimit nuk \u00ebsht\u00eb e llogaritur t\u00eb funksionoj\u00eb n\u00eb kushte operatori t\u00eb komunikimit, \u00ebsht\u00eb e nevojshme q\u00eb t\u00eb rritet:<\/p>\n<pre><code class=\"plaintext\">net.netfilter.nf_conntrack_max = 3145728\n<\/code><\/pre>\n<p>\n \u00cbsht\u00eb gjithashtu e nevojshme t\u00eb rritet edhe numri i buckets p\u00ebr tabel\u00ebn me hash, q\u00eb ruan t\u00eb gjitha p\u00ebrkthimet (kjo \u00ebsht\u00eb nj\u00eb opsion i modulit nf_conntrack): <\/p>\n<pre><code class=\"plaintext\">options nf_conntrack hashsize=1572864\n<\/code><\/pre>\n<p>\nPas k\u00ebtyre manovrave t\u00eb thjeshta, krijohet nj\u00eb konstrukcion mjaft funksional, i cili mund t\u00eb p\u00ebrkthej\u00eb nj\u00eb num\u00ebr t\u00eb madh t\u00eb adresave t\u00eb klient\u00ebve n\u00eb nj\u00eb grup t\u00eb jashtme. Sidoqoft\u00eb, performanca e k\u00ebtij zgjidhjeje l\u00eb p\u00ebr t\u00eb d\u00ebshiruar. N\u00eb p\u00ebrpjekjet e mia t\u00eb para p\u00ebr t\u00eb p\u00ebrdorur GNU\/Linux p\u00ebr NAT (rreth vitit 2013) arrita t\u00eb merrja nj\u00eb performanc\u00eb rreth 7Gbit\/s me 0.8Mpps n\u00eb nj\u00eb server (Xeon E5-1650v2). Q\u00eb nga at\u00ebher\u00eb, ka pasur shum\u00eb optimizime t\u00eb ndryshme n\u00eb grushtin e rrjetit t\u00eb kernelit GNU\/Linux, dhe performanca e nj\u00eb serveri me t\u00eb nj\u00ebjtin hardware \u00ebsht\u00eb rritur pothuajse n\u00eb 18-19 Gbit\/s me 1.8-1.9 Mpps (k\u00ebto ishin vlerat maksimale), por k\u00ebrkesa p\u00ebr volum trafik q\u00eb p\u00ebrpunonte nj\u00eb server erdhi duke u rritur shum\u00eb m\u00eb shpejt. Si rezultat, u zhvilluan skema t\u00eb balancimit t\u00eb ngarkes\u00ebs n\u00eb server\u00eb t\u00eb ndrysh\u00ebm, por gjith\u00e7ka ka rritur kompleksitetin e konfigurimit, mb\u00ebshtetjes dhe ruajtjes s\u00eb cil\u00ebsis\u00eb s\u00eb sh\u00ebrbimeve t\u00eb ofruara.<\/p>\n<h3>NFTables<\/h3>\n<p>\nAktualisht, nj\u00eb trend i njohur n\u00eb \"transferimin e paketave\" \u00ebsht\u00eb p\u00ebrdorimi i DPDK dhe XDP. N\u00eb k\u00ebt\u00eb tem\u00eb jan\u00eb shkruar shum\u00eb artikuj, jan\u00eb b\u00ebr\u00eb shum\u00eb paraqitje t\u00eb ndryshme dhe po shfaqen produkte komerciale (p\u00ebr shembull, SKAT nga VasExperts). Por n\u00eb kushte t\u00eb burimeve t\u00eb kufizuara p\u00ebr programuesit e operator\u00ebve t\u00eb komunikimit, \u00ebsht\u00eb mjaft problematike t\u00eb zhvillosh ndonj\u00eb \"ndar\u00ebs\" n\u00eb baz\u00eb t\u00eb k\u00ebtyre kornizave. Eksplorimi i nj\u00eb zgjidhjeje t\u00eb till\u00eb m\u00eb von\u00eb do t\u00eb jet\u00eb shum\u00eb m\u00eb i komplikuar, sidomos p\u00ebr zhvillimin e mjeteve t\u00eb diagnostikimit. P\u00ebr shembull, tcpdump standard me DPDK nuk do t\u00eb funksionoj\u00eb leht\u00ebsisht, po ashtu as paketat e d\u00ebrguara prapa n\u00eb linj\u00eb me ndihm\u00ebn e XDP nuk do t\u00eb \"shihen\". N\u00eb kontekstin e t\u00eb gjitha bisedave p\u00ebr teknologjit\u00eb e reja q\u00eb kan\u00eb lidhje me forwarding-un e paketave n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit, jan\u00eb mbetur t\u00eb pap\u00ebrfillura <noindex><a rel=\"nofollow\" href=\"https:\/\/netdevconf.info\/0x13\/session.html?workshop-netfilter-mini\">referatet<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/lwn.net\/Articles\/738214\/\">artikulli<\/a><\/noindex> Pablo Neira Ayuso, mbajt\u00ebsi i iptables, rreth zhvillimit t\u00eb flow offloading n\u00eb nftables. Le t\u00eb shqyrtojm\u00eb k\u00ebt\u00eb mekaniz\u00ebm m\u00eb n\u00eb detaje.<\/p>\n<p>Ideja kryesore \u00ebsht\u00eb se n\u00ebse rrug\u00ebzuesi i kalon paketat e nj\u00eb seance n\u00eb t\u00eb dyja an\u00ebt e rrjedh\u00ebs (seanca TCP ka kaluar n\u00eb gjendjen ESTABLISHED), at\u00ebher\u00eb nuk ka nevoj\u00eb p\u00ebr kalimin e paketave t\u00eb m\u00ebtejshme t\u00eb k\u00ebsaj seance p\u00ebrmes t\u00eb gjitha rregullave t\u00eb firewall-it, pasi t\u00eb gjitha k\u00ebto kontrollime p\u00ebrfundimisht do t\u00eb p\u00ebrfundojn\u00eb me kalimin e paketit n\u00eb rrug\u00ebzim. Po ashtu, zgjedhja e rrug\u00ebs nuk duhet t\u00eb b\u00ebhet \u2014 ne tashm\u00eb e dim\u00eb n\u00eb cilin nd\u00ebrfaqe dhe cilit host duhet t'i d\u00ebrgohen paketat brenda k\u00ebsaj seance. Mbete vet\u00ebm t\u00eb ruash k\u00ebt\u00eb informacion dhe ta p\u00ebrdor\u00ebsh p\u00ebr rrug\u00ebzim n\u00eb faz\u00ebn e hershme t\u00eb p\u00ebrpunimit t\u00eb paket\u00ebve. Gjat\u00eb realizimit t\u00eb NAT-it duhet gjithashtu t\u00eb ruhet informacioni mbi ndryshimet e adresave dhe porteve, t\u00eb transformuara nga moduli nf_conntrack. Po, sigurisht, n\u00eb k\u00ebt\u00eb rast ndalohen t\u00eb punojn\u00eb policer\u00ebt e ndrysh\u00ebm dhe rregullat e tjera informativo-statistike n\u00eb iptables, por n\u00eb kuad\u00ebr t\u00eb detyr\u00ebs s\u00eb nj\u00eb NAT-i t\u00eb ve\u00e7ant\u00eb ose, p\u00ebr shembull, t\u00eb nj\u00eb interfejsi \u2014 kjo nuk \u00ebsht\u00eb kaq e r\u00ebnd\u00ebsishme, pasi sh\u00ebrbimet jan\u00eb t\u00eb shp\u00ebrndara n\u00eb pajisje.<\/p>\n<h4>Konfigurimi<\/h4>\n<p>\nP\u00ebr t\u00eb shfryt\u00ebzuar k\u00ebt\u00eb funksion na nevojitet:<\/p>\n<ul>\n<li>T\u00eb p\u00ebrdorim nj\u00eb kernel t\u00eb ri. Megjith\u00ebse funksionaliteti vet\u00eb u shfaq n\u00eb kernelin 4.16, ai ishte shum\u00eb \"i papjekur\" p\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb dhe rregullisht shkaktonte kernel panic. \u00c7do gj\u00eb u stabilizua rreth dhjetorit 2019, kur dol\u00ebn kernelat LTS 4.19.90 dhe 5.4.5.<\/li>\n<li>Riformuloni rregullat e iptables n\u00eb formatin nftables, duke p\u00ebrdorur nj\u00eb version t\u00eb mjaftuesh\u00ebm t\u00eb ri t\u00eb nftables. Funksionon sakt\u00eb n\u00eb versionin 0.9.0<\/li>\n<\/ul>\n<p>\nN\u00ebse pika e par\u00eb \u00ebsht\u00eb n\u00eb parim e qart\u00eb, gj\u00ebja kryesore \u00ebsht\u00eb t\u00eb mos harrosh t\u00eb aktivizosh modulin n\u00eb konfigurim gjat\u00eb nd\u00ebrtimit (CONFIG_NFT_FLOW_OFFLOAD=m), pika e dyt\u00eb k\u00ebrkon shpjegime. Rregullat e nftables p\u00ebrshkruhen krejt ndryshe nga ato n\u00eb iptables. <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.nftables.org\/wiki-nftables\/index.php\/Main_Page\">Dokumentacioni<\/a><\/noindex> zbarton presque t\u00eb gjitha momentet, gjithashtu ka konvertor\u00eb t\u00eb ve\u00e7ant\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/wiki.nftables.org\/wiki-nftables\/index.php\/Moving_from_iptables_to_nftables\">t\u00eb rregullave nga iptables n\u00eb nftables. Prandaj, do t\u00eb sjell vet\u00ebm nj\u00eb shembull t\u00eb konfigurimit NAT dhe flow offload. Nj\u00eb legjend\u00eb e vog\u00ebl p\u00ebr shembullin: <i>,  \u2014 k\u00ebto jan\u00eb nd\u00ebrfaqet rrjet\u00ebsore p\u00ebrmes t\u00eb cilave kalon trafiku, n\u00eb t\u00eb v\u00ebrtet\u00eb mund t\u00eb ket\u00eb m\u00eb shum\u00eb se dy. , \u2014 adresa fillestare dhe p\u00ebrfundimtare e diapazonit t\u00eb adresave \"t\u00eb bardha\".<\/a><\/noindex> Konfigurimi i NAT \u00ebsht\u00eb shum\u00eb i thjesht\u00eb:<\/p>\n<p>Me flow offload \u00ebsht\u00eb pak m\u00eb e komplikuar, por plot\u00ebsisht e qart\u00eb:<\/p>\n<pre><code class=\"bash\">#! \/usr\/sbin\/nft -f\n\ntable nat {\n        chain postrouting {\n                type nat hook postrouting priority 100;\n                oif &lt;o_if&gt; snat to &lt;pool_addr_start&gt;-&lt;pool_addr_end&gt; persistent\n        }\n}\n<\/code><\/pre>\n<p>\nJa, n\u00eb fakt, e gjith\u00eb konfigurimi. Tani, e gjith\u00eb trafiku TCP\/UDP do t\u00eb shkoj\u00eb n\u00eb tabel\u00ebn fastnat dhe do t\u00eb p\u00ebrpunohen shum\u00eb m\u00eb shpejt.<\/p>\n<pre><code class=\"bash\">#! \/usr\/sbin\/nft -f\n\ntable inet filter {\n        flowtable fastnat {\n                hook ingress priority 0\n                devices = { &lt;i_if&gt;, &lt;o_if&gt; }\n        }\n\n        chain forward {\n                type filter hook forward priority 0; policy accept;\n                ip protocol { tcp , udp } flow offload @fastnat;\n        }\n}\n<\/code><\/pre>\n<p>\nP\u00ebr t\u00eb kuptuar sa \"m\u00eb ndjesh\u00ebm m\u00eb shpejt\", do t\u00eb bashk\u00ebngjis nj\u00eb ekran t\u00eb ngarkes\u00ebs n\u00eb dy servera real\u00eb, me t\u00eb nj\u00ebjt\u00ebn konfigurim (Xeon E5-1650v2), t\u00eb nj\u00ebjt\u00eb t\u00eb konfiguruar, duke p\u00ebrdorur t\u00eb nj\u00ebjtin b\u00ebrtham\u00eb Linux, por duke e kryer NAT n\u00eb iptables (NAT4) dhe n\u00eb nftables (NAT5).<\/p>\n<h3>Rezultatet<\/h3>\n<p>\nN\u00eb ekran nuk ka grafiku t\u00eb paketave p\u00ebr sekond, por n\u00eb profilin e ngarkes\u00ebs k\u00ebta server\u00eb kan\u00eb nj\u00eb madh\u00ebsi mesatare t\u00eb paket\u00ebs rreth 800 bytes, prandaj vlerat arrijn\u00eb deri n\u00eb 1.5Mpps. Si\u00e7 duket, rezervat e performanc\u00ebs n\u00eb serverin me nftables jan\u00eb t\u00eb m\u00ebdha. N\u00eb k\u00ebt\u00eb moment, ky server p\u00ebrpunon deri n\u00eb 30Gbit\/s me 3Mpps dhe \u00ebsht\u00eb qart\u00eb n\u00eb gjendje t\u00eb arrij\u00eb limitin fizik t\u00eb rrjetit 40Gbps, duke pasur burime t\u00eb lira CPU.<\/p>\n<p><img decoding=\"async\" alt=\"Routimi i shpejt\u00eb dhe NAT n\u00eb Linux\" src=\"\/wp-content\/uploads\/2020\/05\/94bd3f58bf499ceb9837cd771cc9ef9f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nShpresoj q\u00eb ky material do t\u00eb jet\u00eb i dobish\u00ebm p\u00ebr inxhinier\u00ebt rrjetor\u00eb q\u00eb p\u00ebrpiqen t\u00eb p\u00ebrmir\u00ebsojn\u00eb performanc\u00ebn e server\u00ebve t\u00eb tyre.<\/p>\n<p>Nd\u00ebrsa adresat IPv4 po p\u00ebrfundojn\u00eb, shum\u00eb operator\u00eb t\u00eb komunikimeve jan\u00eb p\u00ebrballur me nevoj\u00ebn p\u00ebr t\u00eb organizuar qasjen e klient\u00ebve t\u00eb tyre n\u00eb rrjet duke p\u00ebrdorur p\u00ebrkthimin e adresave.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/501234\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e \u043c\u0435\u0440\u0435 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u043e\u0432 IPv4, \u043c\u043d\u043e\u0433\u0438\u0435 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u044b \u0441\u0432\u044f\u0437\u0438 \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0441\u0432\u043e\u0438\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0432 \u0441\u0435\u0442\u044c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0440\u0430\u043d\u0441\u043b\u044f\u0446\u0438\u0438 \u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443, \u043a\u0430\u043a \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0443\u0440\u043e\u0432\u043d\u044f Carrier Grade NAT \u043d\u0430 commodity \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445. \u041d\u0435\u043c\u043d\u043e\u0433\u043e \u0438\u0441\u0442\u043e\u0440\u0438\u0438 \u0422\u0435\u043c\u0430 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 IPv4 \u0443\u0436\u0435 \u043d\u0435 \u043d\u043e\u0432\u0430. \u0412 \u043a\u0430\u043a\u043e\u0439-\u0442\u043e \u043c\u043e\u043c\u0435\u043d\u0442 \u0432 RIPE \u043f\u043e\u044f\u0432\u0438\u043b\u0438\u0441\u044c \u043e\u0447\u0435\u0440\u0435\u0434\u0438 \u043e\u0436\u0438\u0434\u0430\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":81266,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-81265","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e \u043c\u0435\u0440\u0435 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u043e\u0432 IPv4, \u043c\u043d\u043e\u0433\u0438\u0435 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u044b \u0441\u0432\u044f\u0437\u0438 \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0441\u0432\u043e\u0438\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0432 \u0441\u0435\u0442\u044c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0440\u0430\u043d\u0441\u043b\u044f\u0446\u0438\u0438 \u0430\u0434\u0440\u0435\u0441\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/bystryj-routing-i-nat-v-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0411\u044b\u0441\u0442\u0440\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433 \u0438 NAT \u0432 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e \u043c\u0435\u0440\u0435 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u043e\u0432 IPv4, \u043c\u043d\u043e\u0433\u0438\u0435 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u044b \u0441\u0432\u044f\u0437\u0438 \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0441\u0432\u043e\u0438\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0432 \u0441\u0435\u0442\u044c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0440\u0430\u043d\u0441\u043b\u044f\u0446\u0438\u0438 \u0430\u0434\u0440\u0435\u0441\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/bystryj-routing-i-nat-v-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-05-11T23:42:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-05-11T23:42:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Routing i shpejt\u00eb dhe NAT n\u00eb Linux | ProHoster","description":"\ud83e\udd47Routimi i shpejt\u00eb dhe NAT n\u00eb Linux | ProHoster","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/bystryj-routing-i-nat-v-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0411\u044b\u0441\u0442\u0440\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433 \u0438 NAT \u0432 Linux | ProHoster","og:description":"\u041f\u043e \u043c\u0435\u0440\u0435 \u0438\u0441\u0447\u0435\u0440\u043f\u0430\u043d\u0438\u044f \u0430\u0434\u0440\u0435\u0441\u043e\u0432 IPv4, \u043c\u043d\u043e\u0433\u0438\u0435 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u044b \u0441\u0432\u044f\u0437\u0438 \u0441\u0442\u043e\u043b\u043a\u043d\u0443\u043b\u0438\u0441\u044c \u0441 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0441\u0432\u043e\u0438\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0432 \u0441\u0435\u0442\u044c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0442\u0440\u0430\u043d\u0441\u043b\u044f\u0446\u0438\u0438 \u0430\u0434\u0440\u0435\u0441\u043e\u0432.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/bystryj-routing-i-nat-v-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-05-11T23:42:43+00:00","article:modified_time":"2020-05-11T23:42:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"81265","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 16:01:23","updated":"2022-09-28 04:47:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/81265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=81265"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/81265\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/81266"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=81265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=81265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=81265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}