Browse Source

Move iptables rules to user-defined chains

Firewall rules should be managed by Puppet, which will purge current
firewall ruleset and replace it by the one provided by a corresponding
manifest.

We need to move rules introduced by product.sh to separate user-defined
chains which are not purged by Puppet so they will be retained after the
manifest gets applied.

Change-Id: I57e9f58c6bad32b23b179499f0514edf5357bd31
Partial-Bug: #1524750
Dmitry Bilunov 3 years ago
parent
commit
3b40e0c284
1 changed files with 12 additions and 3 deletions
  1. 12
    3
      functions/product.sh

+ 12
- 3
functions/product.sh View File

@@ -221,11 +221,20 @@ enable_outbound_network_for_product_vm() {
221 221
         send "sed -i.orig '/DNS_UPSTREAM/c\\"DNS_UPSTREAM\\": \\"${dns_upstream}\\"' /etc/fuel/astute.yaml\r"
222 222
         expect "$prompt"
223 223
         # enable NAT (MASQUERADE) and forwarding for the public network
224
-        send "/sbin/iptables -t nat -A POSTROUTING -s $master_pub_net/24 \! -d $master_pub_net/24 -j MASQUERADE\r"
224
+        # User-defined chains are introduced by LP#1524750 
225
+        send "/sbin/iptables -t nat -N ext-nat-postrouting &>/dev/null\r"
225 226
         expect "$prompt"
226
-        send "/sbin/iptables -I FORWARD 1 --dst $master_pub_net/24 -j ACCEPT\r"
227
+        send "/sbin/iptables -t filter -N ext-filter-forward &>/dev/null\r"
227 228
         expect "$prompt"
228
-        send "/sbin/iptables -I FORWARD 1 --src $master_pub_net/24 -j ACCEPT\r"
229
+        send "/sbin/iptables -t nat -A ext-nat-postrouting -s $master_pub_net/24 \! -d $master_pub_net/24 -j MASQUERADE\r"
230
+        expect "$prompt"
231
+        send "/sbin/iptables -I ext-filter-forward 1 --dst $master_pub_net/24 -j ACCEPT\r"
232
+        expect "$prompt"
233
+        send "/sbin/iptables -I ext-filter-forward 1 --src $master_pub_net/24 -j ACCEPT\r"
234
+        expect "$prompt"
235
+        send "/sbin/iptables -t nat -A POSTROUTING -j ext-nat-postrouting\r"
236
+        expect "$prompt"
237
+        send "/sbin/iptables -t filter -A FORWARD -j ext-filter-forward\r"
229 238
         expect "$prompt"
230 239
         send "service iptables save &>/dev/null\r"
231 240
         expect "$prompt"

Loading…
Cancel
Save