CS-15506 : allow traffic going out domr in FORWARD chain

This commit is contained in:
anthony 2012-07-09 18:29:49 -07:00
parent 08b9b3bc5b
commit 5cd6516d21
1 changed files with 4 additions and 0 deletions

View File

@ -15,6 +15,7 @@
# @VERSION@
source /root/func.sh
source /opt/cloud/bin/vpc_func.sh
lock="biglock"
locked=$(getLockFile $lock)
@ -31,6 +32,9 @@ usage() {
add_snat() {
logger -t cloud "$(basename $0):Added SourceNAT $pubIp on interface $ethDev"
vpccidr=$(getVPCcidr)
sudo iptables -D FORWARD -s $vpccidr ! -d $vpccidr -j ACCEPT
sudo iptables -A FORWARD -s $vpccidr ! -d $vpccidr -j ACCEPT
sudo iptables -t nat -D POSTROUTING -j SNAT -o $ethDev --to-source $pubIp
sudo iptables -t nat -A POSTROUTING -j SNAT -o $ethDev --to-source $pubIp
return $?