sudo87 commented on code in PR #13200:
URL: https://github.com/apache/cloudstack/pull/13200#discussion_r4203073405
##########
systemvm/debian/opt/cloud/bin/configure.py:
##########
@@ -1688,11 +1688,20 @@ def processStaticNatRule(self, rule):
self.fw.append(["filter", "",
"-A FORWARD -i %s -o eth0 -d %s -m state --state
NEW -j ACCEPT " % (device, rule["internal_ip"])])
- # Configure the hairpin snat
- self.fw.append(["nat", "front", "-A POSTROUTING -s %s -d %s -j SNAT -o
%s --to-source %s" %
+ # Configure the hairpin snat for default nic or nic-aware snat for
non-default
+ apply_cross_network_snat = rule.get("should_apply_cross_network_snat",
False)
+ if apply_cross_network_snat:
+ internal_device = self.getDeviceByIp(rule["internal_ip"])
+ internal_vr_ip = self.getGuestIpByIp(rule["internal_ip"])
+ if internal_device and internal_vr_ip and internal_device !=
device:
+ self.fw.append(["nat", "front",
+ "-A POSTROUTING -o %s -d %s/32 -j SNAT
--to-source %s" % (internal_device, rule["internal_ip"], internal_vr_ip)])
Review Comment:
makes sense, will update the description.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]