NetVM: never NAT host<->netvm traffic (fixes host->netns CDP)
This commit is contained in:
@@ -8,7 +8,8 @@ nsexec() { ip netns exec "$NETNS" "$@"; }
|
|||||||
nsexec ip link del "$WG" 2>/dev/null || true # inside netns first
|
nsexec ip link del "$WG" 2>/dev/null || true # inside netns first
|
||||||
ip link del "$VETH" 2>/dev/null || true # also drops the netns-side peer
|
ip link del "$VETH" 2>/dev/null || true # also drops the netns-side peer
|
||||||
ip link del "$WG" 2>/dev/null || true # stray host-side copy
|
ip link del "$WG" 2>/dev/null || true # stray host-side copy
|
||||||
iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true
|
iptables -t nat -D POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE 2>/dev/null || true
|
||||||
|
iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true # old broad form
|
||||||
ip netns del "$NETNS" 2>/dev/null || true
|
ip netns del "$NETNS" 2>/dev/null || true
|
||||||
ip link del "$WG" 2>/dev/null || true # final sweep post-reap
|
ip link del "$WG" 2>/dev/null || true # final sweep post-reap
|
||||||
echo "node=$NODE down"
|
echo "node=$NODE down"
|
||||||
|
|||||||
@@ -26,8 +26,11 @@ nsexec ip link set lo up
|
|||||||
|
|
||||||
# host NAT + forwarding for the veth subnet
|
# host NAT + forwarding for the veth subnet
|
||||||
sysctl -qw net.ipv4.ip_forward=1
|
sysctl -qw net.ipv4.ip_forward=1
|
||||||
iptables -t nat -C POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || \
|
# NB: never NAT host<->netvm traffic — SNATing the host's own veth IP breaks
|
||||||
iptables -t nat -A POSTROUTING -s "$SUB" -j MASQUERADE
|
# host->netns connections (e.g. CDP): the reply would route out the tunnel.
|
||||||
|
iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true # migrate old broad rule
|
||||||
|
iptables -t nat -C POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE 2>/dev/null || \
|
||||||
|
iptables -t nat -A POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE
|
||||||
|
|
||||||
# endpoint bypasses the tunnel (else the handshake routes into itself)
|
# endpoint bypasses the tunnel (else the handshake routes into itself)
|
||||||
ENDPOINT=$(grep -oP '^\s*Endpoint\s*=\s*\K[^:;#]+' "$CONF" | head -1)
|
ENDPOINT=$(grep -oP '^\s*Endpoint\s*=\s*\K[^:;#]+' "$CONF" | head -1)
|
||||||
|
|||||||
Reference in New Issue
Block a user