Merge "Don't match input interface in POSTROUTING table"
This commit is contained in:
commit
29ccecebd7
@ -883,9 +883,8 @@ class RouterInfo(BaseRouterInfo):
|
|||||||
|
|
||||||
def _prevent_snat_for_internal_traffic_rule(self, interface_name):
|
def _prevent_snat_for_internal_traffic_rule(self, interface_name):
|
||||||
return (
|
return (
|
||||||
'POSTROUTING', '! -i %(interface_name)s '
|
'POSTROUTING', '! -o %(interface_name)s -m conntrack '
|
||||||
'! -o %(interface_name)s -m conntrack ! '
|
'! --ctstate DNAT -j ACCEPT' %
|
||||||
'--ctstate DNAT -j ACCEPT' %
|
|
||||||
{'interface_name': interface_name})
|
{'interface_name': interface_name})
|
||||||
|
|
||||||
def external_gateway_nat_fip_rules(self, ex_gw_ip, interface_name):
|
def external_gateway_nat_fip_rules(self, ex_gw_ip, interface_name):
|
||||||
|
Loading…
x
Reference in New Issue
Block a user