Repository navigation
Fix Static NAT/Port Forwarding when VM NIC is not the default #13200
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
2a88f86
4a9d0f4
6d8746f
ba07131
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1573,7 +1573,7 @@ def forward_vr(self, rule): | |
| ) | ||
| fw4 = "-j SNAT --to-source %s -A POSTROUTING -s %s -d %s/32 -o %s -p %s -m %s --dport %s" % \ | ||
| ( | ||
| self.getGuestIp(), | ||
| self.getGuestIpByIp(rule['internal_ip']), | ||
| self.getNetworkByIp(rule['internal_ip']), | ||
| rule['internal_ip'], | ||
| internal_fwinterface, | ||
|
|
@@ -1688,11 +1688,20 @@ def processStaticNatRule(self, rule): | |
| self.fw.append(["filter", "", | ||
| "-A FORWARD -i %s -o eth0 -d %s -m state --state NEW -j ACCEPT " % (device, rule["internal_ip"])]) | ||
|
|
||
| # Configure the hairpin snat | ||
| self.fw.append(["nat", "front", "-A POSTROUTING -s %s -d %s -j SNAT -o %s --to-source %s" % | ||
| # Configure the hairpin snat for default nic or nic-aware snat for non-default | ||
| apply_cross_network_snat = rule.get("should_apply_cross_network_snat", False) | ||
| if apply_cross_network_snat: | ||
| internal_device = self.getDeviceByIp(rule["internal_ip"]) | ||
| internal_vr_ip = self.getGuestIpByIp(rule["internal_ip"]) | ||
| if internal_device and internal_vr_ip and internal_device != device: | ||
| self.fw.append(["nat", "front", | ||
| "-A POSTROUTING -o %s -d %s/32 -j SNAT --to-source %s" % (internal_device, rule["internal_ip"], internal_vr_ip)]) | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. with this the vm sees every connection as coming from the router instead of the real client. should the setting description say that, since it breaks client ip logging and ip based rules inside the vm?
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. makes sense, will update the description. |
||
| else: | ||
| self.fw.append(["nat", "front", "-A POSTROUTING -s %s -d %s -j SNAT -o %s --to-source %s" % | ||
| (self.getNetworkByIp(rule['internal_ip']), rule["internal_ip"], self.getDeviceByIp(rule["internal_ip"]), self.getGuestIpByIp(rule["internal_ip"]))]) | ||
|
|
||
|
|
||
|
|
||
| class IpTablesExecutor: | ||
|
|
||
| config = None | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
what happens if the user changes the default network card of the vm later? the static nat rules arent sent again, so the router keeps the old setup and replies go out the wrong way again
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
good catch. I will re-apply the static NAT and port forwarding rules after the default NIC is updated