skorchir commented on PR #14280:
URL: https://github.com/apache/cloudstack/pull/14280#issuecomment-5934109763

   Tested the change on 4.22.1.1 and it fixes #14184. Environment and evidence 
below.
   
   **Environment**
   - CloudStack 4.22.1.1, KVM.
   - Two VPCs, one tier and one VM each: `vpca` 10.10.0.0/16 (vm-a 
10.10.1.177), `vpcb` 10.20.0.0/16 (vm-b 10.20.1.131). IKEv2 site-to-site VPN 
between them, both sides `passive=false`, both `Connected`.
   - Static NAT public IP 10.201.0.104 enabled on vm-a **after** the VPN 
connections were created.
   - The patch was applied by editing `/opt/cloud/bin/configure.py` on vpca's 
running router (the one line from this PR), then disabling and re-enabling the 
static NAT so the router regenerated its rules. The router was not rebuilt.
   
   **Before (unpatched router), `iptables -t nat -S POSTROUTING` on vpca's VR**
   ```
   -A POSTROUTING -s 10.10.1.177/32 -o eth1 -j SNAT --to-source 10.201.0.104
   -A POSTROUTING -o eth1 -m mark --mark 0x525 -j ACCEPT
   -A POSTROUTING -o eth1 -j SNAT --to-source 10.201.0.102
   ```
   `tcpdump -ni eth2 icmp` on vpcb's VR while vm-a pings vm-b:
   ```
   IP 10.201.0.104 > 10.20.1.131: ICMP echo request, id 1257, seq 1, length 64
   IP 10.20.1.131 > 10.201.0.104: ICMP echo reply, id 1257, seq 1, length 64
   ```
   The static-NAT VM reaches the far side with its public address.
   
   **After (patched router, static NAT re-applied)**
   ```
   -A POSTROUTING -s 10.10.1.177/32 -o eth1 -m mark ! --mark 0x525 -j SNAT 
--to-source 10.201.0.104
   -A POSTROUTING -o eth1 -m mark --mark 0x525 -j ACCEPT
   -A POSTROUTING -o eth1 -j SNAT --to-source 10.201.0.102
   ```
   Same capture on vpcb's VR:
   ```
   IP 10.10.1.177 > 10.20.1.131: ICMP echo request, id 1339, seq 1, length 64
   IP 10.20.1.131 > 10.10.1.177: ICMP echo reply, id 1339, seq 1, length 64
   ```
   Private source preserved across the tunnel, with the SNAT rule still ahead 
of the exemption, so the ordering no longer matters.
   
   **Non-tunnel traffic still uses the static NAT.** Counters zeroed, then from 
vm-a: one ping across the tunnel and two HTTPS requests to the internet 
(`iptables -t nat -L POSTROUTING -v -n` on vpca's VR):
   ```
   pkts target  out  source       destination  
   2    SNAT    eth1 10.10.1.177  0.0.0.0/0    mark match ! 0x525 
to:10.201.0.104
   1    ACCEPT  eth1 0.0.0.0/0    0.0.0.0/0    mark match 0x525
   2    SNAT    eth1 0.0.0.0/0    0.0.0.0/0    to:10.201.0.102
   ```
   The two internet connections took the static-NAT SNAT; the tunnel flow took 
the 0x525 exemption. The VPN connections stayed `Connected` throughout.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to