mirror of https://github.com/apache/cloudstack.git
Routed VR: accept packets from related and established connections (#12986)
This commit is contained in:
parent
c6936889f5
commit
1fc4cb90bf
|
|
@ -244,6 +244,8 @@ class CsNetfilters(object):
|
|||
CsHelper.execute("nft add chain %s %s %s '{ %s }'" % (address_family, table, chain, chain_policy))
|
||||
if hook == "input" or hook == "output":
|
||||
CsHelper.execute("nft add rule %s %s %s icmp type { echo-request, echo-reply } accept" % (address_family, table, chain))
|
||||
elif hook == "forward":
|
||||
CsHelper.execute("nft add rule %s %s %s ct state established,related accept" % (address_family, table, chain))
|
||||
|
||||
def apply_nft_ipv4_rules(self, rules, type):
|
||||
if len(rules) == 0:
|
||||
|
|
|
|||
Loading…
Reference in New Issue