Merge "Remove hardcoded libvirt default network iptalbes rules"
This commit is contained in:
commit
f50ecef245
|
@ -966,10 +966,6 @@ tripleo::firewall::firewall_rules:
|
|||
'140 network cidr nat':
|
||||
chain: FORWARD
|
||||
destination: {{NETWORK_CIDR}}
|
||||
# TODO: Do we still want this?
|
||||
'141 libvirt network nat':
|
||||
chain: FORWARD
|
||||
destination: 192.168.122.0/24
|
||||
'142 tripleo-ui':
|
||||
dport:
|
||||
- 3000
|
||||
|
|
|
@ -7,8 +7,6 @@ iptables -w -t nat -N BOOTSTACK_MASQ_NEW
|
|||
# Build the chain we want.
|
||||
{{#masquerade_networks}}
|
||||
NETWORK={{.}}
|
||||
# Workaround iptables not permitting two -d parameters in one call.
|
||||
iptables -w -t nat -A BOOTSTACK_MASQ_NEW -s $NETWORK -d 192.168.122.1 -j RETURN
|
||||
iptables -w -t nat -A BOOTSTACK_MASQ_NEW -s $NETWORK ! -d $NETWORK -j MASQUERADE
|
||||
{{/masquerade_networks}}
|
||||
# Link it in.
|
||||
|
|
Loading…
Reference in New Issue