summaryrefslogtreecommitdiffstats
path: root/roles/nuage_node/tasks/iptables.yml
diff options
context:
space:
mode:
authorVishal Patil <vishal.patil@nuagenetworks.net>2016-11-15 21:04:20 -0500
committerVishal Patil <vishal.patil@nuagenetworks.net>2016-11-15 21:04:20 -0500
commit769274f376ed189d74e9684e126c17f6ddd3d4ff (patch)
tree2b20aba321850a14c2b02f58f54b49cd0a876b95 /roles/nuage_node/tasks/iptables.yml
parentdedc8742acecf6775dcd29a128ef1f0800c917e4 (diff)
downloadopenshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.gz
openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.bz2
openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.xz
openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.zip
Added ip forwarding for nuage
Diffstat (limited to 'roles/nuage_node/tasks/iptables.yml')
-rw-r--r--roles/nuage_node/tasks/iptables.yml17
1 files changed, 17 insertions, 0 deletions
diff --git a/roles/nuage_node/tasks/iptables.yml b/roles/nuage_node/tasks/iptables.yml
new file mode 100644
index 000000000..52935f075
--- /dev/null
+++ b/roles/nuage_node/tasks/iptables.yml
@@ -0,0 +1,17 @@
+---
+- name: IPtables | Get iptables rules
+ command: iptables -L --wait
+ register: iptablesrules
+ always_run: yes
+
+- name: Allow traffic from overlay to underlay
+ command: /sbin/iptables --wait -I FORWARD 1 -s {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-overlay-underlay"
+ when: "'nuage-overlay-underlay' not in iptablesrules.stdout"
+ notify:
+ - save iptable rules
+
+- name: Allow traffic from underlay to overlay
+ command: /sbin/iptables --wait -I FORWARD 1 -d {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-underlay-overlay"
+ when: "'nuage-underlay-overlay' not in iptablesrules.stdout"
+ notify:
+ - save iptable rules