Skip to content

Commit 8d3468e

Browse files
committed
VPC VR: update iptables rule
This fixes the issue that SSH/ping does not work from vm in private network to vm in vpc, if - VPC tier uses ACL default_allow - private gateway uses ACL "allow egress but deny ingress"
1 parent 84c2a8a commit 8d3468e

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

systemvm/debian/opt/cloud/bin/cs/CsAddress.py

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -544,6 +544,8 @@ def fw_vpcrouter(self):
544544
if self.is_private_gateway():
545545
self.fw.append(["filter", "front", "-A FORWARD -d %s -o %s -j ACL_INBOUND_%s" %
546546
(self.address['network'], self.dev, self.dev)])
547+
self.fw.append(["filter", "front", "-A FORWARD -d %s -o %s -m state --state RELATED,ESTABLISHED -j ACCEPT" %
548+
(self.address['network'], self.dev)])
547549
self.fw.append(["filter", "", "-A ACL_INBOUND_%s -j DROP" % self.dev])
548550
self.fw.append(["mangle", "",
549551
"-A PREROUTING -m state --state NEW -i %s -s %s ! -d %s/32 -j ACL_OUTBOUND_%s" %

0 commit comments

Comments
 (0)