From ff35284423a071786b6ae47544ddac43d0b253b0 Mon Sep 17 00:00:00 2001 From: Claudio-Daniel Freire Date: Wed, 18 May 2011 18:31:35 +0200 Subject: [PATCH] Fix SNAT option in tun/tap vsys scripts --- exec/vif_down | 13 ++++++++----- exec/vif_up | 8 +++++--- 2 files changed, 13 insertions(+), 8 deletions(-) diff --git a/exec/vif_down b/exec/vif_down index 8f87a89..af4be16 100755 --- a/exec/vif_down +++ b/exec/vif_down @@ -34,14 +34,17 @@ if re.match(r'(tun|tap)%d-\d+' % sliceid, vif ) is None: -# Bring interface down - -cmd_ifconfig = "/sbin/ifconfig %s down" % (vif) -os.system(cmd_ifconfig) - # Remove iptables rules +public_src = os.popen("ifconfig | grep $(ip route | grep default | awk '{print $3}' | awk -F. '{print $1\"[.]\"$2}') | head -1 | awk '{print $2}' | awk -F : '{print $2}'").read().rstrip() cmd_iptables_del_in = "/sbin/iptables -D INPUT -i %s -m mark ! --mark %d -j DROP 2>/dev/null" % (vif, sliceid) cmd_iptables_del_out = "/sbin/iptables -D OUTPUT -o %s -m mark ! --mark %d -j DROP 2>/dev/null" % (vif, sliceid) +cmd_iptables_del_pr = "/sbin/iptables -t nat -D POSTROUTING -s `ip ro | grep 'dev %s' | head -1 | awk '{print $1}'` -j SNAT --to-source %s --random" % (vif, public_src,) os.system(cmd_iptables_del_in) os.system(cmd_iptables_del_out) +os.system(cmd_iptables_del_pr) + +# Bring interface down +cmd_ifconfig = "/sbin/ifconfig %s down" % (vif) +os.system(cmd_ifconfig) + diff --git a/exec/vif_up b/exec/vif_up index 885f1b2..39557df 100755 --- a/exec/vif_up +++ b/exec/vif_up @@ -154,17 +154,19 @@ cmd_iptables_del_in = "/sbin/iptables -D INPUT -i %s -m mark -m state --state NE cmd_iptables_out = "/sbin/iptables -A OUTPUT -o %s -m state --state NEW -m mark ! --mark %d -j DROP" % (vif, sliceid) cmd_iptables_del_out = "/sbin/iptables -D OUTPUT -o %s -m state --state NEW -m mark ! --mark %d -j DROP 2>/dev/null" % (vif, sliceid) -public_src = os.popen("ip route get 1.1.1.1 | head -1 | awk '{print $7;}'").read().rstrip(); +public_src = os.popen("ifconfig | grep $(ip route | grep default | awk '{print $3}' | awk -F. '{print $1\"[.]\"$2}') | head -1 | awk '{print $2}' | awk -F : '{print $2}'").read().rstrip() cmd_iptables_pr = "/sbin/iptables -t nat -A POSTROUTING -s %s/%d -j SNAT --to-source %s --random" % (vip, vmask, public_src) -cmd_iptables_del_pr = "/sbin/iptables -t nat -D POSTROUTING -s %s/%d -j SNAT --to-source %s --random" % (vip, vmask, public_src) +cmd_iptables_del_pr = "/sbin/iptables -t nat -D POSTROUTING -s %s/%d -j SNAT --to-source %s --random > /dev/null 2>&1" % (vip, vmask, public_src) os.system(cmd_iptables_del_in) os.system(cmd_iptables_in) os.system(cmd_iptables_del_out) os.system(cmd_iptables_out) +# always remove snat rules +# in case there are leftovers from previous calls +os.system(cmd_iptables_del_pr) if (opt_snat): - os.system(cmd_iptables_del_pr) os.system(cmd_iptables_pr) #print cmd_iptables_del_pr #print cmd_iptables_pr -- 2.43.0