This article explains how to share the internet connection from one machine to other(s).
- The machine acting as server should have an additional network device.
- That network device should be connected to the machines that are going to receive internet access. They can be one or more machines. To be able to share internet to several machines a switch is required. If you are sharing to only one machine, a crossover cable is sufficient.
This section assumes, that the network device connected to the client computer(s) is named net0 and the network device connected to the internet as internet0.
All configuration is done on the server computer, except for the final step of #Assigning ip addresses to the client pc(s).
Static IP address
On the server computer, assign a static IPv4 address to the interface connected to the other machines. The first 3 bytes of this address cannot be exactly the same as those of another interface.
# ip link set up dev net0 # ip addr add 192.168.123.100/24 dev net0 # arbitrary address
To have your static ip assigned at boot, you can use netctl.
Enable packet forwarding
Check the current packet forwarding settings:
# sysctl -a | grep forward
You will note that options exist for controlling forwarding per default, per interface, as well as separate options for IPv4/IPv6 per interface.
Enter this command to temporarily enable packet forwarding at runtime:
# sysctl net.ipv4.ip_forward=1
/etc/sysctl.d/30-ipforward.conf to make the previous change persistent after a reboot for all interfaces:
net.ipv4.ip_forward=1 net.ipv6.conf.default.forwarding=1 net.ipv6.conf.all.forwarding=1
Afterwards it is advisable to double-check forwarding is enabled as required after a reboot.
# iptables -t nat -A POSTROUTING -o internet0 -j MASQUERADE # iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT # iptables -A FORWARD -i net0 -o internet0 -j ACCEPT
Assigning ip addresses to the client pc(s)
If you are planning to regularly have several machines using the internet shared by this machine, then is a good idea to install a dhcp server.
If you are not planing to use this setup regularly, you can manually add an ip to each client instead.
Manually adding an ip
Instead of using dhcp, on each client pc, add an ip address and the default route:
# ip addr add 192.168.123.201/24 dev eth0 # arbitrary address, first three blocks must match the address from above # ip link set up dev eth0 # ip route add default via 192.168.123.100 dev eth0 # same address as in the beginning
Configure a DNS server for each client, see resolv.conf for details.
That's it. The client PC should now have Internet.
If you are able to connect the two PCs but cannot send data (for example, if the client PC makes a DHCP request to the server PC, the server PC receives the request and offers an IP to the client, but the client does not accept it, timing out instead), check that you do not have other Iptables rules interfering.