skorchir commented on PR #14280: URL: https://github.com/apache/cloudstack/pull/14280#issuecomment-5934109763
Tested the change on 4.22.1.1 and it fixes #14184. Environment and evidence below. **Environment** - CloudStack 4.22.1.1, KVM. - Two VPCs, one tier and one VM each: `vpca` 10.10.0.0/16 (vm-a 10.10.1.177), `vpcb` 10.20.0.0/16 (vm-b 10.20.1.131). IKEv2 site-to-site VPN between them, both sides `passive=false`, both `Connected`. - Static NAT public IP 10.201.0.104 enabled on vm-a **after** the VPN connections were created. - The patch was applied by editing `/opt/cloud/bin/configure.py` on vpca's running router (the one line from this PR), then disabling and re-enabling the static NAT so the router regenerated its rules. The router was not rebuilt. **Before (unpatched router), `iptables -t nat -S POSTROUTING` on vpca's VR** ``` -A POSTROUTING -s 10.10.1.177/32 -o eth1 -j SNAT --to-source 10.201.0.104 -A POSTROUTING -o eth1 -m mark --mark 0x525 -j ACCEPT -A POSTROUTING -o eth1 -j SNAT --to-source 10.201.0.102 ``` `tcpdump -ni eth2 icmp` on vpcb's VR while vm-a pings vm-b: ``` IP 10.201.0.104 > 10.20.1.131: ICMP echo request, id 1257, seq 1, length 64 IP 10.20.1.131 > 10.201.0.104: ICMP echo reply, id 1257, seq 1, length 64 ``` The static-NAT VM reaches the far side with its public address. **After (patched router, static NAT re-applied)** ``` -A POSTROUTING -s 10.10.1.177/32 -o eth1 -m mark ! --mark 0x525 -j SNAT --to-source 10.201.0.104 -A POSTROUTING -o eth1 -m mark --mark 0x525 -j ACCEPT -A POSTROUTING -o eth1 -j SNAT --to-source 10.201.0.102 ``` Same capture on vpcb's VR: ``` IP 10.10.1.177 > 10.20.1.131: ICMP echo request, id 1339, seq 1, length 64 IP 10.20.1.131 > 10.10.1.177: ICMP echo reply, id 1339, seq 1, length 64 ``` Private source preserved across the tunnel, with the SNAT rule still ahead of the exemption, so the ordering no longer matters. **Non-tunnel traffic still uses the static NAT.** Counters zeroed, then from vm-a: one ping across the tunnel and two HTTPS requests to the internet (`iptables -t nat -L POSTROUTING -v -n` on vpca's VR): ``` pkts target out source destination 2 SNAT eth1 10.10.1.177 0.0.0.0/0 mark match ! 0x525 to:10.201.0.104 1 ACCEPT eth1 0.0.0.0/0 0.0.0.0/0 mark match 0x525 2 SNAT eth1 0.0.0.0/0 0.0.0.0/0 to:10.201.0.102 ``` The two internet connections took the static-NAT SNAT; the tunnel flow took the 0x525 exemption. The VPN connections stayed `Connected` throughout. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
