diff options
author | Vishal Patil <vishal.patil@nuagenetworks.net> | 2016-11-15 21:04:20 -0500 |
---|---|---|
committer | Vishal Patil <vishal.patil@nuagenetworks.net> | 2016-11-15 21:04:20 -0500 |
commit | 769274f376ed189d74e9684e126c17f6ddd3d4ff (patch) | |
tree | 2b20aba321850a14c2b02f58f54b49cd0a876b95 /roles/nuage_node/tasks/iptables.yml | |
parent | dedc8742acecf6775dcd29a128ef1f0800c917e4 (diff) | |
download | openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.gz openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.bz2 openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.xz openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.zip |
Added ip forwarding for nuage
Diffstat (limited to 'roles/nuage_node/tasks/iptables.yml')
-rw-r--r-- | roles/nuage_node/tasks/iptables.yml | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/roles/nuage_node/tasks/iptables.yml b/roles/nuage_node/tasks/iptables.yml new file mode 100644 index 000000000..52935f075 --- /dev/null +++ b/roles/nuage_node/tasks/iptables.yml @@ -0,0 +1,17 @@ +--- +- name: IPtables | Get iptables rules + command: iptables -L --wait + register: iptablesrules + always_run: yes + +- name: Allow traffic from overlay to underlay + command: /sbin/iptables --wait -I FORWARD 1 -s {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-overlay-underlay" + when: "'nuage-overlay-underlay' not in iptablesrules.stdout" + notify: + - save iptable rules + +- name: Allow traffic from underlay to overlay + command: /sbin/iptables --wait -I FORWARD 1 -d {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-underlay-overlay" + when: "'nuage-underlay-overlay' not in iptablesrules.stdout" + notify: + - save iptable rules |