NetVM: CDP bridge — REDIRECT veth IP:CDP_PORT to loopback in netns
This commit is contained in:
@@ -55,6 +55,14 @@ nsexec ip link set "$WG" up
|
|||||||
nsexec ip route replace default dev "$WG"
|
nsexec ip route replace default dev "$WG"
|
||||||
nsexec ip -6 route replace default dev "$WG" 2>/dev/null || true
|
nsexec ip -6 route replace default dev "$WG" 2>/dev/null || true
|
||||||
|
|
||||||
|
# CDP bridge: chromium binds DevTools to loopback only; redirect the veth
|
||||||
|
# IP:CDP_PORT there so the host (and SSH-forwarded operators) can reach it.
|
||||||
|
# (netns iptables is namespaced; rules vanish with the netns on down.)
|
||||||
|
nsexec sysctl -qw net.ipv4.conf.all.route_localnet=1
|
||||||
|
nsexec sysctl -qw "net.ipv4.conf.${VPEER}.route_localnet=1"
|
||||||
|
nsexec iptables -t nat -C PREROUTING -d "$PEER_IP" -p tcp --dport "$CDP_PORT" -j REDIRECT --to-port "$CDP_PORT" 2>/dev/null || \
|
||||||
|
nsexec iptables -t nat -A PREROUTING -d "$PEER_IP" -p tcp --dport "$CDP_PORT" -j REDIRECT --to-port "$CDP_PORT"
|
||||||
|
|
||||||
# wait for handshake (first one can take ~10s)
|
# wait for handshake (first one can take ~10s)
|
||||||
HS=""
|
HS=""
|
||||||
for i in $(seq 1 10); do
|
for i in $(seq 1 10); do
|
||||||
|
|||||||
Reference in New Issue
Block a user