mirror of https://github.com/apache/cloudstack.git
bug CS-15972: Insert iptable rules to set vpn mark before vpn usage chain
status CS-15972: resolved fixed
This commit is contained in:
parent
7e681a701c
commit
7c1a9658fc
|
|
@ -54,9 +54,9 @@ start_ipsec() {
|
|||
enable_iptables_subnets() {
|
||||
for net in $rightnets
|
||||
do
|
||||
sudo iptables -A FORWARD -t mangle -s $leftnet -d $net -j MARK --set-mark $vpnoutmark
|
||||
sudo iptables -I FORWARD -t mangle -s $leftnet -d $net -j MARK --set-mark $vpnoutmark
|
||||
sudo iptables -A OUTPUT -t mangle -s $leftnet -d $net -j MARK --set-mark $vpnoutmark
|
||||
sudo iptables -A FORWARD -t mangle -s $net -d $leftnet -j MARK --set-mark $vpninmark
|
||||
sudo iptables -I FORWARD -t mangle -s $net -d $leftnet -j MARK --set-mark $vpninmark
|
||||
sudo iptables -A INPUT -t mangle -s $net -d $leftnet -j MARK --set-mark $vpninmark
|
||||
done
|
||||
return 0
|
||||
|
|
|
|||
Loading…
Reference in New Issue