From 493560e370f179027b22f43cea48f9793b9070ea Mon Sep 17 00:00:00 2001 From: anthony Date: Mon, 25 Jun 2012 20:46:45 -0700 Subject: [PATCH] VPC : fix for CONNMARK --- patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh | 6 +----- patches/systemvm/debian/config/opt/cloud/bin/vpc_ipassoc.sh | 6 ++++++ 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh b/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh index 3f80a4ca9b8..2701ef7d1e6 100755 --- a/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh +++ b/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh @@ -2,9 +2,6 @@ plug_nic() { - sudo iptables -t mangle -A PREROUTING -i $dev -m state --state NEW -j MARK --set-mark $tableNo 2>/dev/null - sudo iptables -t mangle -A PREROUTING -i $dev -m state --state NEW -j CONNMARK --save-mark 2>/dev/null - sudo echo "$tableNo $tableName" >> /etc/iproute2/rt_tables 2>/dev/null sudo ip rule add fwmark $tableNo table $tableName 2>/dev/null sudo ip route flush table $tableName @@ -13,8 +10,7 @@ plug_nic() { unplug_nic() { - sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j MARK --set-mark $tableNo 2>/dev/null - sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --save-mark 2>/dev/null + sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --set-mark $tableNo 2>/dev/null sudo ip rule del fwmark $tableNo 2>/dev/null sudo ip route flush table $tableName diff --git a/patches/systemvm/debian/config/opt/cloud/bin/vpc_ipassoc.sh b/patches/systemvm/debian/config/opt/cloud/bin/vpc_ipassoc.sh index 7f137d10443..5f10abe3de4 100755 --- a/patches/systemvm/debian/config/opt/cloud/bin/vpc_ipassoc.sh +++ b/patches/systemvm/debian/config/opt/cloud/bin/vpc_ipassoc.sh @@ -64,6 +64,12 @@ add_an_ip () { sudo ip link set $ethDev up sudo arping -c 3 -I $ethDev -A -U -s $pubIp $pubIp fi + local tableNo=$(echo $ethDev | awk -F'eth' '{print $2}') + sudo iptables-save -t mangle | grep "PREROUTING -i $ethDev -m state --state NEW -j CONNMARK --set-mark" 2>/dev/null + if [ $? -gt 0 ] + then + sudo iptables -t mangle -A PREROUTING -i $ethDev -m state --state NEW -j CONNMARK --set-mark $tableNo 2>/dev/null + fi add_routing return $? }