Adiciona uma entrada DNAT a uma tabela DNAT.
Descrição da operação
Cada entrada DNAT consiste nos seguintes parâmetros: ExternalIp, ExternalPort, IpProtocol, InternalIp e InternalPort. Após adicionar uma entrada DNAT, o NAT gateway encaminha pacotes pelo protocolo especificado de ExternalIp:ExternalPort para InternalIp:InternalPort e envia as respostas de volta pela mesma rota.
Ao chamar esta operação, observe os seguintes limites:
-
CreateForwardEntry é uma operação assíncrona. Após o envio de uma solicitação, o sistema retorna um ID de solicitação e executa a tarefa em segundo plano. Você pode chamar a operação DescribeForwardTableEntries para consultar o status da tarefa.
Se a entrada DNAT estiver no estado Pending, o sistema está adicionando a entrada DNAT. Você pode apenas consultar a entrada DNAT, mas não pode realizar outras operações.
Se a entrada DNAT estiver no estado Available, a entrada DNAT foi adicionada.
-
Você não pode chamar repetidamente a operação CreateForwardEntry para adicionar uma entrada DNAT dentro de um período de tempo específico.
-
Todas as combinações de ExternalIp, ExternalPort e IpProtocol usadas em entradas DNAT devem ser únicas. Você não pode distribuir solicitações para mais de uma instância Elastic Compute Service (ECS) se essas solicitações forem iniciadas a partir do mesmo endereço IP de origem, recebidas na mesma porta e usarem o mesmo protocolo.
-
As combinações de IpProtocol, InternalIp e InternalPort devem ser únicas.
-
Se uma ou mais entradas DNAT na tabela DNAT estiverem no estado Pending ou Modifying, você não poderá adicionar entradas DNAT à tabela DNAT.
-
Você pode adicionar no máximo 100 entradas DNAT a uma tabela DNAT.
-
Para um endereço de elastic IP (EIP) usado por um Internet NAT gateway ou um endereço NAT IP usado por um Virtual Private Cloud (VPC) NAT gateway, observe o seguinte limite: Se o endereço IP tiver o mapeamento de IP ativado e estiver especificado em uma entrada DNAT, o endereço IP não poderá ser usado por outra entrada DNAT ou SNAT.
Experimente agora
Testar
Autorização RAM
Parâmetros da solicitação
|
Parâmetro |
Tipo |
Obrigatório |
Descrição |
Exemplo |
| RegionId |
string |
Sim |
O ID da região do NAT gateway. Você pode chamar a operação DescribeRegions para obter o ID da região. |
cn-hangzhou |
| ForwardTableId |
string |
Sim |
O ID da tabela DNAT. |
ftb-bp1mbjubq34hlcqpa**** |
| ExternalIp |
string |
Sim |
|
116.28.XX.XX |
| ExternalPort |
string |
Sim |
|
8080 |
| InternalIp |
string |
Sim |
|
192.168.XX.XX |
| InternalPort |
string |
Sim |
|
80 |
| IpProtocol |
string |
Sim |
O protocolo. Valores válidos:
|
TCP |
| ForwardEntryName |
string |
Não |
O nome da entrada DNAT. O nome deve ter de 2 a 128 caracteres. Deve começar com uma letra e não pode começar com |
ForwardEntry-1 |
| ClientToken |
string |
Não |
O token do cliente usado para garantir a idempotência da solicitação. Você pode usar o cliente para gerar o token, mas deve garantir que o token seja único entre diferentes solicitações. O token pode conter apenas caracteres ASCII. Nota
Se você não especificar este parâmetro, o sistema usará automaticamente o ID da solicitação como o token do cliente. O ID da solicitação pode ser diferente para cada solicitação. |
0c593ea1-3bea-11e9-b96b-88e9fe6**** |
| PortBreak |
boolean |
Não |
Especifica se deve ativar a quebra de porta. Valores válidos:
Nota
Quando as entradas DNAT e SNAT usam o mesmo endereço IP público, se você precisar configurar um número de porta maior que 1024, deverá definir PortBreak como true. |
false |
| DryRun |
boolean |
Não |
Especifica se deve ser realizado um dry run da solicitação. Valores válidos:
|
false |
Elementos de resposta
|
Elemento |
Tipo |
Descrição |
Exemplo |
|
object |
|||
| ForwardEntryId |
string |
O ID da entrada DNAT. |
fwd-119smw5tkasdf**** |
| RequestId |
string |
O ID da solicitação. |
A4AEE536-A97A-40EB-9EBE-53A6948A6928 |
Exemplos
Resposta de sucesso
JSON formato
{
"ForwardEntryId": "fwd-119smw5tkasdf****",
"RequestId": "A4AEE536-A97A-40EB-9EBE-53A6948A6928"
}
Códigos de erro
|
Código de status HTTP |
Código de erro |
Mensagem de erro |
Descrição |
|---|---|---|---|
| 400 | UnsupportedFeature.PrivateLinkEnabled | The feature of PrivateLinkEnabled is not supported. | |
| 400 | UnsupportedFeature.PortSegment | The feature of PortSegment is not supported. | |
| 400 | ExclusiveParam.%sAnd%s | The param of %s and %s are mutually exclusive. | You cannot specify %s and %s at the same time. |
| 400 | DuplicatedParam.InternalPort | The param of %s is duplicated. | Duplicate or occupied InternalPort parameter |
| 400 | DuplicatedParam.ExternalPort | The param of %s is duplicated. | The DNAT public network port has been used repeatedly. |
| 400 | OperationFailed.AnyPortConfig | Operation failed because any port correspondence any protocol | The operation failed. There is a conflict with another entry, any port or any protocol type. |
| 400 | OperationUnsupported.ForwardEntry | Duplicated destination ip port is unsupported. | You cannot specify duplicate destination IP addresses or destination ports. |
| 400 | InvalidIp.NotInNatgw | The specified Ip not belong to natgateway. | |
| 400 | QuotaExceeded.ForwardEntry | The quota of %s is exceeded, usage %s/%s. | |
| 400 | IncorrectStatus.NatIp | The status of %s [%s] is incorrect. | The status of NatIp is incorrect. |
| 400 | Forbidden.IpHasBeenUsedInSnat | The source ip can't be used. Because it has been used in snat. | |
| 400 | InvalidExternalIp.Malformed | The specified ExternalIp is not a valid IP address. | |
| 400 | InvalidInternalIp.Malformed | The specified InternalIp is not a valid IP address. | |
| 400 | InvalidExternalPort.Malformed | The specified ExternalPort is not a valid port. | |
| 400 | InvalidInternalPort.Malformed | The specified InternalPort is not a valid port. | |
| 400 | Forbidden.DestnationIpOutOfVpcCIDR | The specified Internal Ip is Out of VPC CIDR. | |
| 400 | Forbidden.DestinationIpOutOfVswitchCIDR | The specified Internal Ip is Out of VSwitch CIDR. | |
| 400 | InvalidProtocal.ValueNotSupported | The specified IpProtocol does not support. | |
| 400 | IncorretForwardEntryStatus | Some Forward entry status blocked this operation.. | |
| 400 | ForwardEntry.Duplicated | The specified ExternalIp, IpProtocol, ExternalPort,InternalIp, InternalPort is duplicated | |
| 400 | Forbidden.ExternalIp.UsedInSnatTable | The specified ExternalIp is already used in SnatTable | |
| 400 | Forbindden | The specified Instance already bind eip | |
| 400 | Forbidden.InternalIpOutOfVpcCIDR | The specified Internal Ip is Out of VPC CIDR. | |
| 400 | Invalid.natgwNotExist | The specified natgateway not exist. | |
| 400 | MissingParameter | Missing mandatory parameter | |
| 400 | AnyPort.PortMustBeZero | any port port must be zero. | |
| 400 | InvalidParameter.Name.Malformed | The specified Name is not valid. | |
| 400 | IncorrectStatus.ForwardEntry | The status of %s [%s] is incorrect. | The DNAT entry to be deleted is in an invalid state. |
| 400 | Duplicated.DestinationPort | The specified param DestinationPort is duplicated. | |
| 400 | OperationUnsupported.EipInBinding | Create snat entry with eip in associating status is unsupported. | You cannot use an associated EIP when you create an SNAT entry. |
| 400 | QuotaExceeded.ForwardEntrySessionManytoOne | The dnat session quota is exceed. | The number of DNAT sessions exceeds the upper limit. |
| 400 | TaskConflict | The operation is too frequent, please wait a moment and try again. | Your requests are too frequent. Try again later. |
| 400 | OperationFailed.DnatPortRangeLimit | The maximum number of port ranges that can be specified is exceeded. | The maximum number of port ranges that can be specified is exceeded. |
| 400 | IncorrectStatus.NATGW | NATGW status is invalid. | The NAT gateway is in an invalid state. |
| 400 | OperationFailed.ForwardEntryNotAllowSrcIpEqualDstIp | The source IP of forward entry is not allowed to equal destination IP. | The public IP address of the DNAT entry is not allowed to be equal to the private IP address. |
| 500 | System.Error | ERROR SYSTEM ERROR. | |
| 500 | InternalError | The request processing has failed due to some unknown error. | |
| 404 | ResourceNotFound.NatIp | The specified resource of %s is not found. | |
| 404 | InvalidRegionId.NotFound | The specified RegionId does not exist in our records. | |
| 404 | InvalidForwardTableId.NotFound | Specified forward table does not exist. | |
| 404 | InvalidExternalIp.NotFound | Specified External Ip address does not found on the VRouter |
Consulte Códigos de Erro para uma lista completa.
Notas de versão
Consulte Notas de Versão para uma lista completa.