diff --git a/bin/netvm-node-down.sh b/bin/netvm-node-down.sh index 45db6fa..373b597 100755 --- a/bin/netvm-node-down.sh +++ b/bin/netvm-node-down.sh @@ -8,7 +8,8 @@ nsexec() { ip netns exec "$NETNS" "$@"; } nsexec ip link del "$WG" 2>/dev/null || true # inside netns first ip link del "$VETH" 2>/dev/null || true # also drops the netns-side peer ip link del "$WG" 2>/dev/null || true # stray host-side copy -iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true +iptables -t nat -D POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE 2>/dev/null || true +iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true # old broad form ip netns del "$NETNS" 2>/dev/null || true ip link del "$WG" 2>/dev/null || true # final sweep post-reap echo "node=$NODE down" diff --git a/bin/netvm-node-up.sh b/bin/netvm-node-up.sh index 5ddb7bd..8787eda 100755 --- a/bin/netvm-node-up.sh +++ b/bin/netvm-node-up.sh @@ -26,8 +26,11 @@ nsexec ip link set lo up # host NAT + forwarding for the veth subnet sysctl -qw net.ipv4.ip_forward=1 -iptables -t nat -C POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || \ - iptables -t nat -A POSTROUTING -s "$SUB" -j MASQUERADE +# NB: never NAT host<->netvm traffic — SNATing the host's own veth IP breaks +# host->netns connections (e.g. CDP): the reply would route out the tunnel. +iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true # migrate old broad rule +iptables -t nat -C POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE 2>/dev/null || \ + iptables -t nat -A POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE # endpoint bypasses the tunnel (else the handshake routes into itself) ENDPOINT=$(grep -oP '^\s*Endpoint\s*=\s*\K[^:;#]+' "$CONF" | head -1)