X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=exec%2Fvif_up;fp=exec%2Fvif_up;h=39557df1e1d10bbc88ac5ad9b86675b3ae8181fc;hb=ff35284423a071786b6ae47544ddac43d0b253b0;hp=885f1b20356c2f9ce9c5a376f050dc3254fc0bac;hpb=96ee6572dfeba0a49a56db13854d6006b5c33c4d;p=vsys-scripts.git diff --git a/exec/vif_up b/exec/vif_up index 885f1b2..39557df 100755 --- a/exec/vif_up +++ b/exec/vif_up @@ -154,17 +154,19 @@ cmd_iptables_del_in = "/sbin/iptables -D INPUT -i %s -m mark -m state --state NE cmd_iptables_out = "/sbin/iptables -A OUTPUT -o %s -m state --state NEW -m mark ! --mark %d -j DROP" % (vif, sliceid) cmd_iptables_del_out = "/sbin/iptables -D OUTPUT -o %s -m state --state NEW -m mark ! --mark %d -j DROP 2>/dev/null" % (vif, sliceid) -public_src = os.popen("ip route get 1.1.1.1 | head -1 | awk '{print $7;}'").read().rstrip(); +public_src = os.popen("ifconfig | grep $(ip route | grep default | awk '{print $3}' | awk -F. '{print $1\"[.]\"$2}') | head -1 | awk '{print $2}' | awk -F : '{print $2}'").read().rstrip() cmd_iptables_pr = "/sbin/iptables -t nat -A POSTROUTING -s %s/%d -j SNAT --to-source %s --random" % (vip, vmask, public_src) -cmd_iptables_del_pr = "/sbin/iptables -t nat -D POSTROUTING -s %s/%d -j SNAT --to-source %s --random" % (vip, vmask, public_src) +cmd_iptables_del_pr = "/sbin/iptables -t nat -D POSTROUTING -s %s/%d -j SNAT --to-source %s --random > /dev/null 2>&1" % (vip, vmask, public_src) os.system(cmd_iptables_del_in) os.system(cmd_iptables_in) os.system(cmd_iptables_del_out) os.system(cmd_iptables_out) +# always remove snat rules +# in case there are leftovers from previous calls +os.system(cmd_iptables_del_pr) if (opt_snat): - os.system(cmd_iptables_del_pr) os.system(cmd_iptables_pr) #print cmd_iptables_del_pr #print cmd_iptables_pr