This is an automated email from the ASF dual-hosted git repository. DaanHoogland pushed a commit to branch ghi14184-vpnVsSnat-fix in repository https://gitbox.apache.org/repos/asf/cloudstack.git
commit a551b2ebd7b267188685e3f8e3d5a1743650c53a Author: Daan Hoogland <[email protected]> AuthorDate: Thu Oct 1 11:05:22 2026 +0200 mark vpn traffic as exemption for return routes --- systemvm/debian/opt/cloud/bin/configure.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/systemvm/debian/opt/cloud/bin/configure.py b/systemvm/debian/opt/cloud/bin/configure.py index bf48be66694..c484ca444ee 100755 --- a/systemvm/debian/opt/cloud/bin/configure.py +++ b/systemvm/debian/opt/cloud/bin/configure.py @@ -1530,7 +1530,6 @@ class CsForwardingRules(CsDataBag): self.fw.append(["nat", "", fw_output_rule]) def processStaticNatRule(self, rule): - # FIXME this needs ordering with the VPN no nat rule device = self.getDeviceByIp(rule["public_ip"]) if device is None: raise Exception("Ip address %s has no device in the ips databag" % rule["public_ip"]) @@ -1556,8 +1555,9 @@ class CsForwardingRules(CsDataBag): self.fw.append(["nat", "front", "-A PREROUTING -d %s/32 -j DNAT --to-destination %s" % (rule["public_ip"], rule["internal_ip"])]) + # Skip VPN-marked traffic so chain order vs the site-to-site VPN exemption doesn't matter. self.fw.append(["nat", "front", - "-A POSTROUTING -o %s -s %s/32 -j SNAT --to-source %s" % (device, rule["internal_ip"], rule["public_ip"])]) + "-A POSTROUTING -o %s -s %s/32 -m mark ! --mark 0x525 -j SNAT --to-source %s" % (device, rule["internal_ip"], rule["public_ip"])]) self.fw.append(["nat", "front", "-A OUTPUT -d %s/32 -j DNAT --to-destination %s" % (rule["public_ip"], rule["internal_ip"])]) self.fw.append(["filter", "",
