diff --git a/functions/product.sh b/functions/product.sh index f5fc28a..d7d22d8 100755 --- a/functions/product.sh +++ b/functions/product.sh @@ -221,11 +221,20 @@ enable_outbound_network_for_product_vm() { send "sed -i.orig '/DNS_UPSTREAM/c\\"DNS_UPSTREAM\\": \\"${dns_upstream}\\"' /etc/fuel/astute.yaml\r" expect "$prompt" # enable NAT (MASQUERADE) and forwarding for the public network - send "/sbin/iptables -t nat -A POSTROUTING -s $master_pub_net/24 \! -d $master_pub_net/24 -j MASQUERADE\r" + # User-defined chains are introduced by LP#1524750 + send "/sbin/iptables -t nat -N ext-nat-postrouting &>/dev/null\r" expect "$prompt" - send "/sbin/iptables -I FORWARD 1 --dst $master_pub_net/24 -j ACCEPT\r" + send "/sbin/iptables -t filter -N ext-filter-forward &>/dev/null\r" expect "$prompt" - send "/sbin/iptables -I FORWARD 1 --src $master_pub_net/24 -j ACCEPT\r" + send "/sbin/iptables -t nat -A ext-nat-postrouting -s $master_pub_net/24 \! -d $master_pub_net/24 -j MASQUERADE\r" + expect "$prompt" + send "/sbin/iptables -I ext-filter-forward 1 --dst $master_pub_net/24 -j ACCEPT\r" + expect "$prompt" + send "/sbin/iptables -I ext-filter-forward 1 --src $master_pub_net/24 -j ACCEPT\r" + expect "$prompt" + send "/sbin/iptables -t nat -A POSTROUTING -j ext-nat-postrouting\r" + expect "$prompt" + send "/sbin/iptables -t filter -A FORWARD -j ext-filter-forward\r" expect "$prompt" send "service iptables save &>/dev/null\r" expect "$prompt"