Skip to content

Commit 90c960e

Browse files
VPC VR: fix ACL between tier and private gateway (#10268)
1 parent 55e8eaa commit 90c960e

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

systemvm/debian/opt/cloud/bin/cs/CsAddress.py

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -542,8 +542,10 @@ def fw_vpcrouter(self):
542542
(self.dev, guestNetworkCidr, self.address['gateway'], self.dev)])
543543

544544
if self.is_private_gateway():
545-
self.fw.append(["filter", "", "-A FORWARD -d %s -o %s -j ACL_INBOUND_%s" %
545+
self.fw.append(["filter", "front", "-A FORWARD -d %s -o %s -j ACL_INBOUND_%s" %
546546
(self.address['network'], self.dev, self.dev)])
547+
self.fw.append(["filter", "front", "-A FORWARD -d %s -o %s -m state --state RELATED,ESTABLISHED -j ACCEPT" %
548+
(self.address['network'], self.dev)])
547549
self.fw.append(["filter", "", "-A ACL_INBOUND_%s -j DROP" % self.dev])
548550
self.fw.append(["mangle", "",
549551
"-A PREROUTING -m state --state NEW -i %s -s %s ! -d %s/32 -j ACL_OUTBOUND_%s" %

0 commit comments

Comments
 (0)